Skip to Content
0%

Salesforce Earns CMMC Level 2 Certification

Salesforce joins an elite group of early leaders providing mission-critical security and assurance.

It’s a big deal for our Department of War (DoW), Intelligence Community, and associated industrial base customers. Protecting sensitive information is essential to securing the Department of War (DoW) supply chain. With full enforcement of cybersecurity requirements for DoW contractors beginning in November 2025, compliance is no longer optional—it’s mission-critical now.

We’re proud to announce that Salesforce has achieved its Cybersecurity Maturity Model Certification (CMMC) Level 2 certification for its Public Sector Enclave used by the Salesforce National Security and Public Sector Professional Services teams. This milestone demonstrates that Salesforce’s Public Sector organization has built a secure and compliant enclave that meets the following standards. 

  • 48 CFR (The Federal Acquisition Regulation),
  • DFARS 252.204-7021, and 
  • NIST SP 800-171 Revision 2 requirements

At the time of this announcement, fewer than 400 organizations have achieved either a final or conditional CMMC Level 2 certification following a Certified Third-Party Assessor Organization assessment. That represents less than 0.3% of defense industrial base companies, making Salesforce part of a small group of early leaders in CMMC compliance.

Achieving CMMC Level 2 certification is a huge milestone for Salesforce and for our customers. This certification gives our national security customers assurance that we have the technology and process safeguards in place to secure their mission-critical data. This certification is a clear demonstration of Salesforce’s #1 core value of Trust: we prioritize customer data security, system availability, and transparency above all else.” 

Larry Dillard, Vice President, Salesforce Professional Services

Why this matters for your business: This achievement provides a level of assurance to government customers, contractors, and subcontractors who interact with Salesforce and who process, store or transmit Controlled Unclassified Information to/with Salesforce National Security and Salesforce Public Sector Professional Services.

Salesforce Security Made Simple with Invisibles, Configurables and Enhanceables

Salesforce Security Made Simple with Invisibles, Configurables and Enhanceables
Salesforce Security Made Simple with Invisibles, Configurables and Enhanceables
Want a fun, approachable way to explain security best practices to your admin and dev networks? Listen to the latest episode of Awesome Admins!

Get the latest articles in your inbox.