The Atlassian Enterprise Certified (AEC) program recognizes Marketplace apps that meet rigorous enterprise standards for security, reliability, privacy, accessibility, and responsible AI use — going beyond the baseline security requirements required of all Marketplace cloud apps. The Atlassian Enterprise Certified program gives customers a clear, Atlassian-verified signal that an app is ready for their most business-critical needs.
The Atlassian Enterprise Certified program is open to all Forge cloud apps.
The Atlassian Enterprise Certified program will begin onboarding apps in Q3 CY2026. At the time of program onboarding, we will stop accepting new submissions for the Cloud Fortified Apps Program. Cloud Fortified will be phased out by the end of CY2026.
We will share more details via a Changelog on how to apply for the program once it is open.
An app must meet the following requirements to be eligible for the Atlassian Enterprise Certified program. Each requirement lists the validation steps Atlassian carries out to confirm compliance.
ID | Requirement | Validation |
|---|---|---|
1.1 | Evidence that a current annual penetration test has been completed. This could be the report behind NDA on your trust center or an attestation letter from your CREST accredited pen test provider. |
|
1.2 | Public (or in the process of becoming public) security vulnerability reporting using Atlassian's Bug Bounty program. |
|
1.3 | If the app processes or stores data outside of Atlassian's infrastructure, an architecture, data flow or network diagram should be publicly available (ideally on your trust center). Note: This can be protected by an NDA or a password. |
|
1.4 | The app does not use any Connect modules. |
|
1.5 | The app does not collect or store credentials belonging to Atlassian user accounts, such as user passwords or personal API tokens, unless the app has an approved PAT usage exemption documented via an ADDON ticket. Note: OAuth and other short-lived access tokens must only be cached in memory with a TTL no longer than the token's |
|
1.6 | Any Atlassian end user data stored outside the Atlassian apps or users' browsers must use full disk encryption at rest (including any app logs). |
|
1.7 | The app only requests access to the data it needs (least privileged access). |
|
1.8 | The app logs must not include personal data or credentials. Note: "personal data" is defined as information about an identified or identifiable natural person, or which otherwise constitutes "personal data", "personal information", "personally identifiable information" or similar terms as defined in Applicable Data Protection Law. |
|
1.9 | The app must publicly document (ideally on your trust center) what data is stored in the app logs and the retention period of these logs. Note: This can be protected by an NDA or a password. |
|
1.10 | Any Atlassian End User Data accessed by an application or a service should be authenticated and authorized appropriately. |
|
1.11 | The app must not use end-of-life NodeJS runtimes. |
|
1.12 | The app must be transparent about all data egress. Notes:
|
|
1.13 | Vulnerability Scanning. |
|
1.14 | App must default to |
|
1.15 | App developers must ensure that any external services their app calls are only accessible over HTTPS with TLS 1.2+ (or higher). Note: Forge-managed egress already enforces this, so this requirement applies to any additional outbound connections or infrastructure the partner controls. |
|
1.16 | Apps must not use third-party dependencies or packages with known Critical and High severity vulnerabilities, and must prioritize patching when new vulnerabilities are disclosed. |
|
ID | Requirement | Validation |
|---|---|---|
2.1 | Publicly documented incident management process, including a public Statuspage. |
|
2.2 | Participation in a collaborative incident response program with Atlassian. |
|
2.3 | Partner must respond within 1 day (24 hours) to critical customer support issues, 5 days a week, in the Marketplace Partner's local timezone. |
|
ID | Requirement | Validation |
|---|---|---|
3.1 | Public trust center available. |
|
3.2 | SOC 2 Type II or ISO 27001 compliance. |
|
3.3 | If an app stores data remotely, it should support Data Residency (pinning and migration). Note:
|
|
3.4 | The app clearly discloses its data retention and deletion policies covering any data egressed from the app. Note: This can be protected by an NDA or a password. |
|
3.5 | Publicly available privacy policy. |
|
ID | Requirement | Validation |
|---|---|---|
4.1 | The app has a Voluntary Product Accessibility Template (VPAT) publicly available. Notes:
|
|
ID | Requirement | Validation |
|---|---|---|
5.1 | If the app uses AI, there is a publicly available AI usage policy (ideally on the partner trust center). |
|
Rate this page: