Salesforce Commerce Cloud Penetration Testing
Every custom feature in a B2C Commerce storefront sits in a cartridge layered over Salesforce’s code, yours alone to secure. We test that cartridge, its API clients and its Business Manager access. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Every storefront customisation in B2C Commerce, from checkout logic to loyalty integrations, is delivered as a cartridge layered on top of Salesforce’s base code, and that layering is exactly what a test has to follow.
Why the cartridge and integration layer carries the risk, not the Salesforce platform
A B2C Commerce storefront is built from cartridges: layered code modules that extend or override the base Storefront Reference Architecture (SFRA), each with its own controllers, ISML templates and business logic. A cartridge added for a promotion, a loyalty scheme or a regional checkout flow can just as easily reintroduce a class of bug the base code already handles correctly, whether that is a controller that skips a permission check, a template that renders customer input without escaping it, or a form that never validates the request that submitted it. We review the cartridges your team has written or customised, not Salesforce’s own SFRA base code.
Every integration and headless storefront talks to B2C Commerce through the Commerce API (SCAPI) or the older Open Commerce API (OCAPI), authenticated with a client ID registered as either a public client for a browser or mobile app, or a private client holding a secret for server-side calls. Shopper Login (SLAS) issues the guest and registered-customer access tokens those clients present on every request, and Salesforce’s own PWA Kit builds a headless React storefront on exactly this model, calling the same Commerce APIs from a frontend hosted on Managed Runtime instead of a server-rendered SFRA site. Whichever storefront architecture your business runs, the client ID’s scope and the token it issues decide what a holder of either can reach.
Beyond the storefront and its APIs, Business Manager is where staff manage catalogues, promotions, customer service cases and site configuration, and where order and ERP export jobs are scheduled and authorised. Access here is controlled by the roles and permissions assigned to each Business Manager user, and a role scoped too broadly can reach customer records, order history and payment details that a support agent role was never meant to see. We also check that sandbox realms, used for development and for this test, cannot reach production data or credentials, and that the reverse is equally true.
SCOPE
What we pen test on a Salesforce Commerce Cloud platform
Cartridge and controller override logic
Whether a custom cartridge’s controllers, appended, prepended or replaced ahead of the base SFRA controller chain, preserve the authentication and validation checks the original controller performed, rather than quietly dropping one on the way through.
CSRF protection on storefront forms
Whether every state-changing storefront action, checkout, account changes, address book, wishlist, requires and validates a CSRF token before it runs, rather than relying on the session cookie alone.
ISML template output encoding
Whether customer-controlled input rendered back through ISML templates, search terms, product reviews, gift messages, delivery instructions, is encoded for its context rather than output as-is.
Business Manager roles and permissions
Whether each Business Manager user is scoped to the roles and permissions their job needs, catalogue, promotions, customer service or configuration, rather than holding administrator-level access by default.
SCAPI and OCAPI client ID scope
Whether each registered API client, storefront, integration or headless frontend, is limited to the specific Commerce API and Data API resources it needs, and what a leaked client ID and secret would expose.
SLAS shopper authentication
Whether guest and registered-customer sessions use the correct client type, a public client for a browser or mobile app or a private client for server-side calls, and whether a guest token can be escalated into actions a registered customer’s token should require.
Headless PWA Kit storefront and Managed Runtime
For a headless build, how the PWA Kit frontend hosted on Managed Runtime handles shopper sessions and tokens server-side before they reach the browser, and whether the same access controls apply as on a server-rendered SFRA site.
Customer data and order ownership
Whether a shopper account, storefront request or API call can be made to view or modify another customer’s profile, address book, saved payment methods or order history by changing an identifier.
Order export and ERP integration endpoints
How order data reaches your OMS, ERP or fulfilment systems, whether by export job, webhook or custom REST or SOAP service, and whether that endpoint authenticates the request and limits what it returns.
Sandbox and production separation
Whether sandbox realm credentials, API clients or test catalogue and customer data can reach a production instance, and what your integration or storefront code does if it receives the wrong realm’s identifiers.
OUR PROCESS
Salesforce Commerce Cloud Application Penetration Testing: From Scope to Attestation
Scope the platform
We map every cartridge, API client, integration and storefront (SFRA or headless PWA Kit) in scope, and confirm which realms are sandbox and which are production.
Test against sandbox first
Cartridge, Business Manager, SCAPI, OCAPI and SLAS testing runs against your sandbox realm and test accounts wherever the check allows; anything that genuinely needs production is agreed with you first and run read-only.
Exploit the business logic
CREST-certified testers chain findings across cartridge overrides, API client scope, Business Manager roles and order data, covering forged requests, permission gaps and token misuse rather than relying on scanner output alone.
Report and retest
Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation, and an attestation letter.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Salesforce Commerce Cloud pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Salesforce Commerce Cloud Application Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
3 to 5 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote7 to 9 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Salesforce Commerce Cloud For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Salesforce Commerce Cloud Application Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need?
Read access to your custom cartridge source code, a Business Manager account in your sandbox with a limited role, and a sandbox API client ID and secret for SCAPI, OCAPI and SLAS testing. We do not need production Business Manager access or your live customer database.
Does this touch live customer data or real orders?
No, wherever the check allows. Testing runs against your sandbox realm, which mirrors production configuration without live customer or payment data. Anything that must run against a production instance is agreed with you in advance and scoped tightly, typically read-only.
How long does a Salesforce Commerce Cloud test take?
A single platform, one storefront and its immediate integrations, is a 3-day scope. A headless PWA Kit build alongside a server-rendered site, multiple sites or locales, or several ERP and OMS integrations add testing days, agreed before the engagement starts.
We run a headless PWA Kit storefront, not classic SFRA. Can you still test it?
Yes. We test whichever storefront architecture is live, a server-rendered SFRA site, a headless PWA Kit frontend on Managed Runtime, or both, since both call the same underlying cartridges, Business Manager configuration and Commerce APIs.
What is out of scope?
Salesforce’s own multi-tenant B2C Commerce infrastructure, its managed services and its base SFRA code. We test the cartridges, controllers and templates your team has written or customised, your API client configuration, Business Manager setup and your order and ERP integrations.
Does Salesforce have a policy on this kind of testing?
Salesforce publishes terms covering security testing of B2C Commerce, including its sandbox realms and what can be tested without prior notice. We confirm the current wording with you during scoping and design the engagement around whatever rules of engagement apply at the time.
Do you test order exports and ERP integrations?
Yes. We treat every order export job, webhook and custom REST or SOAP connector to your OMS, ERP or fulfilment system as its own test area, checking how each one authenticates and what data it exposes if that authentication fails.
Our storefront uses several cartridges from a third-party implementation partner. Do you review those too?
Yes. We test every cartridge active on your instance regardless of who wrote it, since a vulnerability in a partner-built cartridge is exploitable through your storefront in exactly the same way as one in code your own team wrote.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Salesforce Commerce Cloud platform
Every custom feature in a B2C Commerce storefront sits in a cartridge layered over Salesforce’s code, yours alone to secure. We test that cartridge, its API clients and its Business Manager access. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.



