Quote in 48 hours
Get a custom quote
Fixed-fee scoping in 24 hours. No sales pitch.
The short answer: Atlassian Marketplace ISVs that handle customer data are required to complete an annual third-party penetration test under the Cloud Fortified, Cloud Security Participant, or Runs On Atlassian programs. The test must cover the app, its backend, and any data flows touching Atlassian APIs. Reports must be submitted to Atlassian or made available on request.
If you ship a Jira, Confluence, Bitbucket, or Compass app and you handle anything beyond static configuration, this article tells you exactly what is required, what auditors look at, and how to get through the program without an eight-week consulting engagement.
What is the Atlassian Cloud Fortified program?
Cloud Fortified is Atlassian's premium security tier for Marketplace apps. It signals to enterprise buyers that the app has been independently verified against Atlassian's security baseline. Fortified status requires an annual penetration test, an active bug bounty program (typically on Bugcrowd or HackerOne), and reliability commitments. Cloud Fortified apps sell faster into regulated industries because they pre-clear most enterprise security review questions.
What is the Cloud Security Participant program?
Cloud Security Participant is the baseline tier. Any Marketplace app that requests scopes beyond READ for user-installed content is expected to participate. It requires annual penetration testing and a public security disclosure process. Skipping it is increasingly a deal-breaker for B2B sales motions.
What does an Atlassian Marketplace pentest cover?
The penetration test must cover, at minimum:
- The Forge or Connect application surface, including all macros, web panels, modules, and admin pages
- All backend services and APIs the app communicates with, whether self-hosted or on a managed platform
- Authentication and authorization flows, including OAuth, JWT validation, and tenant isolation
- Data handling, encryption at rest and in transit, and any third-party processor data flows
- Forge-specific concerns: storage API usage, egress permissions, and runtime sandbox boundaries
- Connect-specific concerns: iframe sandboxing, JWT signature verification, and host-side XSS
How often is the Atlassian pentest required?
Annually. Atlassian also expects an additional test after any significant architectural change. If you migrate from Connect to Forge, change cloud providers, or alter your data model, a fresh test is required even if your annual is current.
Who can perform the Atlassian Marketplace penetration test?
The tester must be independent (not on the app's engineering team), demonstrably qualified (industry certifications such as OSCP, OSWE, CREST, or equivalent), and the engagement must follow a recognized methodology (OWASP Application Security Verification Standard, PTES, or NIST SP 800-115). Atlassian does not require a specific vendor, but reports from unrecognized parties get rejected during program review.
What does the report need to contain?
Atlassian expects a report that includes:
- Executive summary written for non-technical reviewers
- Scope statement listing every app, environment, and API tested
- Methodology and tooling used
- Findings ranked by CVSS 3.1 with proof of concept
- Remediation recommendations for every finding
- Retest results confirming remediation, dated within the program window
- Tester certifications and engagement dates
How much does an Atlassian Marketplace pentest cost?
Typical pricing for a single Marketplace app ranges from $5,000 to $15,000 in 2026. Forge apps tend to land on the lower end because the attack surface is constrained by Atlassian's runtime. Connect apps with self-hosted backends land higher because the entire backend surface is in scope. See our companion piece on penetration test cost in 2026 for the full pricing breakdown.
What about bug bounty?
Cloud Fortified requires an active, public bug bounty. Cloud Security Participant requires a documented disclosure policy. The two are not interchangeable. Many ISVs run a private Bugcrowd or HackerOne program for cost control and only flip to public during Fortified review.
Common findings on Atlassian Marketplace apps
- JWT validation gaps on Connect apps that trust the iss or aud claim without verifying signature against the install record
- Cross-tenant data leakage when storage keys are constructed from request-supplied identifiers
- SSRF via webhook configuration where the app fetches user-supplied URLs without an allowlist
- Insecure Forge storage using app storage for tenant-scoped data instead of installation storage
- Permission scope sprawl requesting broader scopes than the app actually uses
How StealthNet AI streamlines Marketplace pentests
Our Marketplace pentest service uses AI agents to cover the breadth (every endpoint, every iframe, every storage key pattern) while senior testers chain attacks unique to Forge and Connect architectures. Most engagements complete in 5 to 10 business days with a fixed fee, an Atlassian-compliant report, and one round of retest. We have shipped reports accepted by Cloud Fortified review on first submission.
Frequently asked questions
Do Forge apps need a penetration test?
Yes, if the app processes user data, integrates external services, or requests scopes beyond basic read access. Forge reduces but does not eliminate the attack surface.
Does Atlassian provide a list of approved pentest vendors?
No. Atlassian requires that the tester be independent and qualified, but does not maintain a vendor list. Buyers select their own provider.
How long does Cloud Fortified review take?
Initial review typically takes 4 to 8 weeks from submission. A clean, properly formatted pentest report shortens this significantly.
What happens if I miss the annual pentest deadline?
Cloud Fortified status is revoked until a current report is submitted. Listings remain live, but the Fortified badge is removed and enterprise customers may pause renewals.
Can I use a SOC 2 audit instead of a Marketplace pentest?
No. SOC 2 audits cover controls; a Marketplace pentest validates the app's runtime security. Atlassian requires both for Cloud Fortified.
Does the pentest need to be done in production?
Production-equivalent staging is acceptable and usually preferred. The scope must match production configuration and data flows.
Related reading
- Salesforce AppExchange security review pentest guide — the equivalent program for the Salesforce ecosystem.
- Web application penetration testing service — the scope most Marketplace ISVs need.
- AppExchange penetration testing — our delivery model for marketplace partners.
