21 September 2026, 10:05 PM
For SaaS companies, the Atlassian Marketplace can open the door to a huge pool of businesses already using Jira, Jira Service Management, and Confluence. Atlassian says the Marketplace now has more than 6,000 apps, over 2,000 partners, and more than $6 billion in lifetime sales.
But getting an app in front of those buyers is only part of the job. Enterprise customers also want to know what the app can access, where their data goes, and whether another vendor could introduce new security risks. Verizon’s 2026 DBIR found that third parties were involved in 48% of confirmed breaches, compared with 30% in 2025.
That makes Atlassian Marketplace Security a real product requirement. The testing approach also changes depending on whether your app uses Forge, Connect, OAuth, or external services.
The rest of this guide breaks down what Atlassian expects, what testers look for, and where CREST testing comes into the picture.
How Qualysec Helps You Pass Your Atlassian Security Reviews
For SaaS vendors preparing for an Atlassian review, Qualysec can support the self managed testing route as a CREST-accredited penetration testing provider. Atlassian requires this accreditation when a vendor wants a non-Bugcrowd assessment recognised under its program.
The scope can be built around the app architecture instead of using one fixed checklist. Forge, Connect, and mixed applications each place different parts of the attack surface under Atlassian or vendor control.
Qualysec can also organise findings in a way that makes them easier to act on and submit, including:
Source: https://qualysec.com/atlassian-marketplace-security/
But getting an app in front of those buyers is only part of the job. Enterprise customers also want to know what the app can access, where their data goes, and whether another vendor could introduce new security risks. Verizon’s 2026 DBIR found that third parties were involved in 48% of confirmed breaches, compared with 30% in 2025.
That makes Atlassian Marketplace Security a real product requirement. The testing approach also changes depending on whether your app uses Forge, Connect, OAuth, or external services.
The rest of this guide breaks down what Atlassian expects, what testers look for, and where CREST testing comes into the picture.
How Qualysec Helps You Pass Your Atlassian Security Reviews
For SaaS vendors preparing for an Atlassian review, Qualysec can support the self managed testing route as a CREST-accredited penetration testing provider. Atlassian requires this accreditation when a vendor wants a non-Bugcrowd assessment recognised under its program.
The scope can be built around the app architecture instead of using one fixed checklist. Forge, Connect, and mixed applications each place different parts of the attack surface under Atlassian or vendor control.
Qualysec can also organise findings in a way that makes them easier to act on and submit, including:
- Affected endpoint or component
- User and tenant context
- Severity and technical evidence
- Reproduction details
- Recommended remediation
- Retest status
Source: https://qualysec.com/atlassian-marketplace-security/
