Commercial software intelligenceEvidence checked · 8 September 2026
SkuTrace

Commercial product change, preserved as evidence.

SK-2026-025 · Enforcement & transition policy

Atlassian makes shorter Marketplace cloud-app vulnerability SLOs enforceable from September

Atlassian shortened remediation windows for Marketplace cloud-app vulnerabilities and set September 2026 as the enforcement start.

Enforcement scheduled

Commercial transition

Previous stateMarketplace cloud apps were governed by the earlier vulnerability remediation windows.
New stateShorter severity-based remediation SLOs become enforceable under Marketplace policy.

Who is affected

Atlassian Marketplace cloud-app vendors and customers assessing vendor security posture.

Action required

Map open vulnerabilities to the new deadlines, update remediation operations and respond to Atlassian enforcement notices.

Evidence boundary

The source establishes policy enforcement, not that every vulnerability causes immediate delisting. Exact treatment depends on severity, programme rules and vendor response.

Connected NeoLinks intelligence

Related evidence across the network

Curated because the records share a publisher, platform, commercial model, control or procurement context. Each destination preserves its own evidence boundary.

ContractLens · security policy · procurement demand

CISO-as-a-Service and cyber-governance procurement

Marketplace vulnerability-remediation policy is supplier-side evidence; ContractLens shows a public buyer seeking governance, risk and security advisory capability.

Timeline

  1. Effective milestone

    Shorter severity-based remediation SLOs become enforceable under Marketplace policy.

Official sources