TECHNOLOGIES: SALESFORCE COMMERCE CLOUD

Salesforce Commerce Cloud Penetration Testing

Every custom feature in a B2C Commerce storefront sits in a cartridge layered over Salesforce’s code, yours alone to secure. We test that cartridge, its API clients and its Business Manager access. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Salesforce Commerce Cloud Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Cartridges

Every storefront customisation in B2C Commerce, from checkout logic to loyalty integrations, is delivered as a cartridge layered on top of Salesforce’s base code, and that layering is exactly what a test has to follow.

Why the cartridge and integration layer carries the risk, not the Salesforce platform

A B2C Commerce storefront is built from cartridges: layered code modules that extend or override the base Storefront Reference Architecture (SFRA), each with its own controllers, ISML templates and business logic. A cartridge added for a promotion, a loyalty scheme or a regional checkout flow can just as easily reintroduce a class of bug the base code already handles correctly, whether that is a controller that skips a permission check, a template that renders customer input without escaping it, or a form that never validates the request that submitted it. We review the cartridges your team has written or customised, not Salesforce’s own SFRA base code.

Every integration and headless storefront talks to B2C Commerce through the Commerce API (SCAPI) or the older Open Commerce API (OCAPI), authenticated with a client ID registered as either a public client for a browser or mobile app, or a private client holding a secret for server-side calls. Shopper Login (SLAS) issues the guest and registered-customer access tokens those clients present on every request, and Salesforce’s own PWA Kit builds a headless React storefront on exactly this model, calling the same Commerce APIs from a frontend hosted on Managed Runtime instead of a server-rendered SFRA site. Whichever storefront architecture your business runs, the client ID’s scope and the token it issues decide what a holder of either can reach.

Beyond the storefront and its APIs, Business Manager is where staff manage catalogues, promotions, customer service cases and site configuration, and where order and ERP export jobs are scheduled and authorised. Access here is controlled by the roles and permissions assigned to each Business Manager user, and a role scoped too broadly can reach customer records, order history and payment details that a support agent role was never meant to see. We also check that sandbox realms, used for development and for this test, cannot reach production data or credentials, and that the reverse is equally true.

SCOPE

What we pen test on a Salesforce Commerce Cloud platform

CC-01

Cartridge and controller override logic

Whether a custom cartridge’s controllers, appended, prepended or replaced ahead of the base SFRA controller chain, preserve the authentication and validation checks the original controller performed, rather than quietly dropping one on the way through.

CC-02

CSRF protection on storefront forms

Whether every state-changing storefront action, checkout, account changes, address book, wishlist, requires and validates a CSRF token before it runs, rather than relying on the session cookie alone.

CC-03

ISML template output encoding

Whether customer-controlled input rendered back through ISML templates, search terms, product reviews, gift messages, delivery instructions, is encoded for its context rather than output as-is.

CC-04

Business Manager roles and permissions

Whether each Business Manager user is scoped to the roles and permissions their job needs, catalogue, promotions, customer service or configuration, rather than holding administrator-level access by default.

CC-05

SCAPI and OCAPI client ID scope

Whether each registered API client, storefront, integration or headless frontend, is limited to the specific Commerce API and Data API resources it needs, and what a leaked client ID and secret would expose.

CC-06

SLAS shopper authentication

Whether guest and registered-customer sessions use the correct client type, a public client for a browser or mobile app or a private client for server-side calls, and whether a guest token can be escalated into actions a registered customer’s token should require.

CC-07

Headless PWA Kit storefront and Managed Runtime

For a headless build, how the PWA Kit frontend hosted on Managed Runtime handles shopper sessions and tokens server-side before they reach the browser, and whether the same access controls apply as on a server-rendered SFRA site.

CC-08

Customer data and order ownership

Whether a shopper account, storefront request or API call can be made to view or modify another customer’s profile, address book, saved payment methods or order history by changing an identifier.

CC-09

Order export and ERP integration endpoints

How order data reaches your OMS, ERP or fulfilment systems, whether by export job, webhook or custom REST or SOAP service, and whether that endpoint authenticates the request and limits what it returns.

CC-10

Sandbox and production separation

Whether sandbox realm credentials, API clients or test catalogue and customer data can reach a production instance, and what your integration or storefront code does if it receives the wrong realm’s identifiers.

OUR PROCESS

Salesforce Commerce Cloud Application Penetration Testing: From Scope to Attestation

01

Scope the platform

We map every cartridge, API client, integration and storefront (SFRA or headless PWA Kit) in scope, and confirm which realms are sandbox and which are production.

02

Test against sandbox first

Cartridge, Business Manager, SCAPI, OCAPI and SLAS testing runs against your sandbox realm and test accounts wherever the check allows; anything that genuinely needs production is agreed with you first and run read-only.

03

Exploit the business logic

CREST-certified testers chain findings across cartridge overrides, API client scope, Business Manager roles and order data, covering forged requests, permission gaps and token misuse rather than relying on scanner output alone.

04

Report and retest

Executive summary, technical report with CVSS scores and reproduction steps, a walkthrough call, free retest after remediation, and an attestation letter.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Salesforce Commerce Cloud pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Salesforce Commerce Cloud Application Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,180–£5,860
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,470–£11,320
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Salesforce Commerce Cloud Application Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need?

Read access to your custom cartridge source code, a Business Manager account in your sandbox with a limited role, and a sandbox API client ID and secret for SCAPI, OCAPI and SLAS testing. We do not need production Business Manager access or your live customer database.

Does this touch live customer data or real orders?

No, wherever the check allows. Testing runs against your sandbox realm, which mirrors production configuration without live customer or payment data. Anything that must run against a production instance is agreed with you in advance and scoped tightly, typically read-only.

How long does a Salesforce Commerce Cloud test take?

A single platform, one storefront and its immediate integrations, is a 3-day scope. A headless PWA Kit build alongside a server-rendered site, multiple sites or locales, or several ERP and OMS integrations add testing days, agreed before the engagement starts.

We run a headless PWA Kit storefront, not classic SFRA. Can you still test it?

Yes. We test whichever storefront architecture is live, a server-rendered SFRA site, a headless PWA Kit frontend on Managed Runtime, or both, since both call the same underlying cartridges, Business Manager configuration and Commerce APIs.

What is out of scope?

Salesforce’s own multi-tenant B2C Commerce infrastructure, its managed services and its base SFRA code. We test the cartridges, controllers and templates your team has written or customised, your API client configuration, Business Manager setup and your order and ERP integrations.

Does Salesforce have a policy on this kind of testing?

Salesforce publishes terms covering security testing of B2C Commerce, including its sandbox realms and what can be tested without prior notice. We confirm the current wording with you during scoping and design the engagement around whatever rules of engagement apply at the time.

Do you test order exports and ERP integrations?

Yes. We treat every order export job, webhook and custom REST or SOAP connector to your OMS, ERP or fulfilment system as its own test area, checking how each one authenticates and what data it exposes if that authentication fails.

Our storefront uses several cartridges from a third-party implementation partner. Do you review those too?

Yes. We test every cartridge active on your instance regardless of who wrote it, since a vulnerability in a partner-built cartridge is exploitable through your storefront in exactly the same way as one in code your own team wrote.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Salesforce Commerce Cloud platform

Every custom feature in a B2C Commerce storefront sits in a cartridge layered over Salesforce’s code, yours alone to secure. We test that cartridge, its API clients and its Business Manager access. CREST-certified testers, fixed price from £4,180 for a 3-day single-platform scope, quoted within 24 hours.