Salesforce is proud to announce the achievement of both Cyber Essentials (CE) and Cyber Essentials Plus (CE+) certifications under the UK government-backed Cyber Essentials scheme, administered by the National Cyber Security Centre (NCSC). These certifications are a direct reflection of our Trust First commitment – demonstrating that Salesforce meets independently verified, government-recognized standards for protecting against the most common cyber threats facing organizations today.

Why Cyber Essentials and Cyber Essentials Plus matter to you
The UK Cyber Essentials scheme is a requirement for government suppliers handling financial or personal data, and a growing number of private sector organizations also require their suppliers to hold Cyber Essentials certification. Demonstrated alignment to this certification scheme provides assurance that effective security posture management is in place to protect sensitive data entrusted to suppliers.
The scheme addresses five critical security controls: Firewalls, Secure Configuration, User Access Control, Malware Protection, and Security Update Management. It is composed of two assurance levels:
- Cyber Essentials (CE): Validates fundamental technical controls through a verified self-assessment, reviewed by an external certifying body.
- Cyber Essentials Plus (CE+): Provides additional assurance through hands-on technical testing of implemented controls, conducted by an authorized third-party assessor. CE+ is the highest level of assurance within the scheme.
By achieving both levels, Salesforce enables UK customers, including public sector agencies, to confidently select Salesforce while meeting their own procurement and supply chain security obligations.
Our Continued Investment in Trust
These certifications complement Salesforce’s extensive portfolio of globally and regionally recognized standards. Within the UK, Salesforce maintains compliance with frameworks such as the NHS Data Security and Protection Toolkit (DSPT). Globally, Salesforce holds certifications including ISO 27001 (Information Security), PCI DSS (Payment Security), and ISO 42001 (AI Governance), among others. This further solidifies our position as a trusted partner for public sector agencies, regulated industries, and organizations of all sizes operating in the UK and beyond.
To learn more about our compliance posture, visit the Salesforce Compliance Site.
Security resources
Curious about more ways to bolster the security of your Salesforce org? Check out our guide for additional guidance and resources.










