News | July 21, 2009

Epicor Awarded PCI DSS Compliance Certification

Source: Innovative Retail Technologies
IRVINE, Calif., July 21, 2009 — Epicor Software Corporation (NASDAQ: EPIC), a leading provider of enterprise business software solutions to the midmarket and Global 1000 companies, today announced its Retail Software as a Service (SaaS) hosted solution has been awarded compliance status with the Payment Card Industry-Data Security Standard version 1.1 (PCI DSS). Customers and prospects can now find Epicor on the VISA Global List of PCI DSS Validated Service Providers.

The certification was achieved after an extensive independent audit of Epicor Retail's hosted infrastructure operations and processes conducted by Trustwave, a third-party qualified security assessor from the PCI Security Standards Council.

The PCI assessment process focuses solely on the security of cardholder data, whether Epicor has effectively implemented information security policies and processes, and if there are adequate security measures to comply with the requirements to protect cardholder data within the hosted environment. Additionally, the assessment reviewed whether Epicor is employing payment industry best-practices and provides recommendations for remediation of any non-compliant policies, processes, procedures, system configurations or vulnerabilities.

Security of cardholder data has become one of the biggest issues facing the payment card industry. The PCI DSS standard represents the best practices defined by the PCI Security Standards Council, covering 12 industry-wide requirements for security management, policies, procedures, network architecture, software design and other critical protective measures, that service providers must adhere to in order to safeguard sensitive data.

According to Mim Burt, research director in Gartner Retail Industry Advisory Services, "Over the past five years, the rise in the usage of cards for consumer payments has — not surprisingly — been accompanied by more attempted thefts of sensitive payment card data and related fraud." Burt recommends that retailers "Ensure that the technology providers supporting payment processors are compliant with industry standards."

"Our validation as a certified PCI DSS compliant solution is a significant differentiator for Epicor Retail when it comes to securing business in a hosted environments," said David Henning, executive vice president and general manager for Epicor Retail. "We are the only provider that offers a complete solution with a full range of support services that leverages our extensive in-house expertise from development to deployment through training. Our SaaS solution enables retailers to leverage a trusted and proven solution, delivering everything a retailer needs — including the peace of mind that comes from third-party validation of our cardholder data security processes."

Cavaliers Leverage Epicor to Stay Ahead of the PCI Compliance Game

One customer leveraging Epicor's hosted, SaaS retail operating model — and staying ahead of the game when it comes to PCI DSS compliance — is Michael Thom, Director of Merchandising for Cavaliers Operating Co., the corporate entity that operates the National Basketball Association team, the Cleveland Cavaliers. The Cavs sell branded merchandise throughout its 2,500-sq.-ft. flagship store as well as eight retail stores at Quicken Loans Arena, where the Cavaliers play, as well as online at CavaliersTeamShop.com.

"Understanding and addressing PCI compliance across retail operations is a complex task, adds a significant cost of doing business, and is especially challenging for lean organizations such as ours," said Thom. "Epicor's third-party validation of its cardholder data security processes and PCI DSS compliance most definitely enhances the overall value proposition of its SaaS offering."

Epicor Retail SaaS is an all-inclusive offering developed, implemented and maintained by Epicor, and delivered directly to stores and head office via high-speed persistent networks. The solutions included in Epicor's Saas offering give retailers the same advanced functionality as best-of-breed systems used by the world's leading retailers, in a format that dramatically reduces capital investment and implementation requirements. And because Epicor takes care of everything, including software, hardware, services, and support, SaaS also minimizes in-house resource requirements and overall total cost of ownership.

Today, many of the world's leading retailers utilize Epicor Retail solutions and services to become more profitable, productive and competitive. Epicor's solutions leverage proven Microsoft .NET technology to improve business operations and meet the evolving merchandise and service expectations of today's cross-channel shoppers. Epicor delivers comprehensive retail management solutions to enterprises in all tiers — from regional chains to multichannel global brands. Retail customers include hundreds of marquee names, from Aéropostale, American Eagle Outfitters, and Ann Taylor to Zales and Zumiez.

About Epicor Software Corporation
Epicor Software is a global leader delivering business software solutions to the manufacturing, distribution, retail, hospitality and services industries. With 20,000 customers in over 150 countries, Epicor provides integrated enterprise resource planning (ERP), customer relationship management (CRM), supply chain management (SCM) and enterprise retail software solutions that enable companies to drive increased efficiency and improve profitability. Founded in 1984, Epicor celebrates 25 years of technology innovation delivering business solutions that provide the scalability and flexibility businesses need to build competitive advantage. Epicor provides a comprehensive range of services with a single point of accountability that promotes rapid return on investment and low total cost of ownership, whether operating business on a local, regional or global scale. The Company's worldwide headquarters are located in Irvine, California with offices and affiliates around the world. For more information, visit www.epicor.com.