Thank you for sharing this update. I’d like to shift the discussion from reaction to practical compliance impact, particularly for customers operating in regulated and contract-driven environments.
For many Epicor customers, ERP deployment decisions are constrained not by preference, but by ITAR, EAR, DFARS, CMMC (NIST 800-171), ISO, SOX, and customer-mandated audit rights. With that context, I have several specific questions that are critical for planning and risk management:
- ITAR / EAR (U.S. Person Access)
• Can Epicor contractually guarantee that only U.S. persons (including during support, maintenance, emergency response, and incident investigation) can access ITAR or EAR controlled data in Epicor Cloud?
• How is this enforced and independently evidenced for audits?
- CMMC / NIST 800-171 Control Ownership
• Will Epicor provide control-level mappings showing which CMMC Level 2 / NIST 800-171 controls are customer-owned vs Epicor-owned?
• How can customers obtain audit-ready evidence (logs, access records, patch history, administrative activity) without relying solely on SOC summaries?
- DFARS & Incident Response
• In the event of a CUI or CDI incident, who has authority over containment, investigation, and reporting timelines?
• How quickly can customers access the data required to meet 72-hour DFARS reporting obligations?
- Data Residency, Subprocessors, and Support
• Can Epicor commit to U.S. only data residency, backups, and disaster recovery for regulated customers?
• Is Epicor able to restrict or disclose subprocessor and offshore support access, including during escalation scenarios?
- Customers Unable to Migrate to Cloud
• For customers contractually or regulatorily unable to migrate, what is Epicor’s long-term strategy once on-prem innovation ends?
• Are options such as extended on-prem innovation, compliance-focused releases, or alternative support models being considered?
This is not a cloud-vs-on-prem debate. Many customers understand Epicor’s strategic direction. The concern is whether regulated customers are being given a viable, defensible path forward or whether they are being forced to choose between compliance risk and platform stagnation.
Clear, specific answers to these questions would go a long way in helping customers plan responsibly.