Enterprise Certified · 1.1
“Evidence that a current annual penetration test has been completed.”
Accepted from Atlassian’s Bugcrowd program or a CREST-accredited vendor. A bug bounty alone does not satisfy it.
Read the requirementThree Atlassian policies decide how you buy a pentest. We are built for all three.
“Evidence that a current annual penetration test has been completed.”
Accepted from Atlassian’s Bugcrowd program or a CREST-accredited vendor. A bug bounty alone does not satisfy it.
Read the requirement“You must use a CREST Accredited testing vendor.”
Your report goes to Atlassian via an ECOHELP ticket. We write it to drop straight into that flow.
Program pageCritical in 10 days. High in 4 weeks.
A missed Critical hides your app. We flag Criticals within 24 hours and retest your fix free, inside the window.
PolicyDiscounted pricing for every Atlassian Marketplace partner. Priced per application by endpoint count, and fixed after a 15-minute scope call.
Under 20 endpoints
$2,500
Under 40 endpoints
$4,500
Under 60 endpoints
$6,000
From scope call to submitted report, with Atlassian’s steps built in.
Fifteen minutes with Usama.
Endpoint count, Forge or Connect, the badge you are chasing and your deadline. You leave the call with a fixed price and a start date.
Fixed quote on the callFour to five working days.
The AI Pentest Agent maps your app and its APIs at speed. Accredited engineers then exploit, chain and validate what it finds, so you get real attack paths, not scanner noise.
Criticals flagged in 24hJira-ready, timed to Atlassian’s clocks.
Each finding arrives CVSS-scored with reproduction steps and the fix your engineers need, ordered by Atlassian’s windows: Critical 10 days, High 4 weeks.
Help on the fix includedRetest, clean report, attestation.
We re-run every exploit to confirm it is closed, then issue the clean health report and attestation letter. Attach it to your ECOHELP ticket and move on.
Free retestThe price is on this page. The call is for scoping, not for a quote.
Book a callAtlassian’s Enterprise Certified requirement 1.1 accepts a current annual penetration test from its Bugcrowd program or from a CREST-accredited vendor, and its self-managed pentest route requires a CREST-accredited vendor. CyberFortify is a CREST member company accredited for Penetration Testing and AI-Enabled Penetration Testing; the listing is on the CREST Marketplace. Atlassian reviews each report through an ECOHELP ticket, which is why we write to their scoping template.
For Enterprise Certified, yes. Requirement 1.1 is the pentest and requirement 1.2 is the bug bounty program; they are listed separately, not as alternatives. A pentest also gives you a dated report and an attestation letter that enterprise procurement teams ask for, which a bounty cannot.
We test both. A Connect app’s scope includes your hosted backend, its iframe integration and the JWT handling; a Forge app’s scope centres on resolvers, storage, egress permissions and Custom UI. Tell us which on the scope call and the endpoint count follows.
One distinct API route, page or function in scope. Most single-product Marketplace apps land under 20, which is the $2,500 tier. We confirm the count together on the scope call and the price is fixed from then on.
Scheduling is usually within a week of the scope call. Testing for most apps takes about a week. Criticals are flagged within 24 hours of discovery rather than held for the final report.
You hear about it within 24 hours with reproduction steps and a recommended fix. Atlassian’s Security Bug Fix Policy gives you 10 days for a Critical and 4 weeks for a High once it is filed, so we help with the fix and retest it free inside that window.
Yes. Findings are mapped to the relevant controls and the clean health report plus attestation goes into your audit file as the independent penetration test evidence. Gold and Platinum Marketplace partners who need SOC 2 Type 2 or ISO 27001 anyway get both uses from one engagement.
CREST-accredited engineers led by Usama Gul, CyberFortify’s founder, who is also your first call. Our AI Pentest Agent handles breadth; every finding is validated and exploited by a human before it reaches your report.
Every assignment is covered by professional liability insurance and cyber-insured through Koop. Our ISO 27001 and ISO 9001 certificates are available on request.
Your first call is with Usama Gul, the founder and the engineer who leads your test. You’ll leave with a clear scope and a fixed price.
Atlassian, Atlassian Marketplace, Forge, Connect and Bugcrowd are trademarks of their owners. CyberFortify is an independent vendor and is not endorsed by Atlassian.