Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For a paid solution, budget $999 for each AppExchange security review attempt, including a resubmission. Salesforce says free solutions do not pay the fee. The published timeline is roughly four to five weeks for a typical review, but preparation, queue delays, and remediation can extend the schedule. Your total project cost will also include internal engineering and testing time; Salesforce does not publish an all-in cost for that work.

Salesforce’s materials are transitioning from the AppExchange name to AgentExchange. The current ISVforce guide uses “AgentExchange Security Review”; this article uses AppExchange to match the familiar term in the question. The fee and process discussed here refer to Salesforce’s marketplace security review.

What to include in your budget

Separate the known marketplace fee from the work your team must estimate. The fee is per attempt; engineering preparation, testing, and any vulnerability fixes vary by product and are not included in Salesforce’s published fee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Cost or effort What to budget
Salesforce review fee for a paid solution $999 per attempt, according to Salesforce Trailhead’s current page accessed October 7, 2026. A resubmission is another attempt.
Salesforce review fee for a free solution No fee under the current ISVforce Guide.
Preparation and remediation labor Not stated by Salesforce. Estimate internally based on your architecture, submission readiness, and any findings.
External security preparation or testing Not stated by Salesforce. If you use outside help, scope it around your product and review needs.

Salesforce changed to per-attempt pricing on March 16, 2023. Its earlier $2,550 initial review fee and $150 annual fee are historical, not current budget figures. Salesforce Developers explains the fee change.

How long the review may take

Salesforce’s current ISVforce Guide estimates one to two weeks for Security Review Operations to check submission readiness, followed by three to four weeks for first Product Security testing. For a resubmission that demonstrates progress fixing vulnerabilities, the guide estimates two to three weeks of testing. Trailhead describes four to five weeks as a typical overall duration.

These are estimates, not service guarantees. Salesforce says turnaround depends on submission completeness and queue volume. Treat remediation and another attempt as additional schedule risk: plan to submit well before a fixed launch date rather than assuming the published review window includes time to fix findings.

What can add preparation time

Requirements depend on the solution’s architecture. Use Salesforce’s submission guidance and tailored checklist builder to determine what applies to your product. Common preparation items include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Usage documentation and relevant customer, administrator, and user documentation.
  • Architecture and data-flow documentation, including flows between Salesforce and any composite sites, mobile apps, or browser extensions.
  • Scanner reports, along with explanations for findings you believe are false positives. For managed packages, upload Salesforce Code Analyzer reports or justify why you are not providing them.
  • Working test environments, integrations, and credentials that let reviewers exercise the solution.

Connected apps and integrations

Salesforce’s Connected Apps and External Client Apps guidance, published September 8, 2026, says review scope includes the packaged app configuration and integrations used by the solution. This can cover web applications, REST APIs, mobile apps, browser plugins, and desktop apps. Salesforce says new integrations must use External Client Apps (ECAs) instead of Connected Apps.

For applicable integrations, use least-privilege OAuth scopes and explain any need for broad scopes. Document how secrets are handled and provide integration credentials so reviewers can test the connection. Salesforce says client keys for packaged ECAs may be included in submission documents, but client secrets should not. See the Salesforce submission guidance for Connected Apps and External Client Apps for the specific requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why a clean scan does not guarantee approval

Salesforce recommends Code Analyzer as an initial check, but automated scanning cannot find every issue a manual review may uncover. The review is black-box and time-limited; findings may describe a class of problem without listing every affected instance, and reviewers may not initially detect every issue type. Salesforce lists concerns such as SQL/SOQL injection, cross-site scripting, insecure authentication and access control, and platform-specific vulnerabilities.

Publishers remain responsible for identifying and fixing all instances of security issues across their solution. As Salesforce Developers puts it, “The Security Review is not there to find all the security issues for you, this is something that should be built into your development process and reviewed regularly.” Read the full Salesforce Code Analyzer and review guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to plan your submission

  1. Confirm the current fee and workflow. Check the Partner Console before payment; Salesforce’s fee and naming can change.
  2. Map your architecture. List packages, connected components, integrations, client apps, and data flows so you can use the relevant checklist.
  3. Prepare evidence and access. Assemble documentation and scanner results, explain false positives, and verify test environments and credentials.
  4. Reserve review and repair time. Allow for the published stage estimates, queue variability, fixes, and a possible paid resubmission.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.