Marketplace Partner Program clarification required

Hej Atlassian!

Can you please clarify whether a public bug bounty program is a requirement for the Marketplace Partner Program?

Because this change log entry seems to suggest as much:

However, the Marketplace Partner Program itself does not indicate any such requirement as it does not specify whether it should be private or public:

If you follow that link, the only mention of having a public program is in the “Additional recommendations”, which seems to indicate that it is optional. Yet, looking at the wording, it seems like it isn’t optional at all:

It would be great if you can let us know what is expected of us. Also, given the poor execution of this requirement, can you please extend the deadline of June 30? Seems like you dropped the ball here, would be nice if it isn’t on the Partners to have to pick it up (again).

Cheers,

Remie

cc: @ChrisHemphill1

Agree with @remie here. We’re also quite confused about the transition to the public program and what is required and what not.

Ok, so it seems like Atlassian has been doing a bit of implied reasoning here.

They made changes to the Bug Bounty Program and communicated those changes separately (https://developer.atlassian.com/platform/marketplace/bug-bounty-going-public/)

That change requires all Bug Bounty programs that are paid for by Atlassian to go public:

  • By June 30th, 2026: Program must be fully public or scheduled to go public with Bugcrowd.

This change is mandator for all Atlassian managed Bug Bounty programs:

No exceptions policy:
Unfortunately there are no exceptions and all Atlassian managed marketplace bug bounty programs must be public or actively working toward transitioning to a public program.

With the most important aspect of the change being:

Enforcement actions:
If you are not in the process of going public by the compliance deadline, Atlassian is entitled to pause and deactivate your bug bounty program.

So basically, the change to the Bug Bounty program requires you to go public, or your Atlassian managed Bug Bounty program will be deactivated.

From that, it logically follows that you no longer meet the requirement of having a Paid Bug Bounty Program participation and thus not meeting the criteria for the Marketplace Partner program and thus loosing your badge.

All of this is implied logic.

Atlassian never clearly communicated specifically that Marketplace Partner Program participants are required to migrate to a public bug bounty program. Which is why there is now confusion and why partners will need to scramble.

Once again, Atlassian proves why siloed autonomous disconnected teams that do not communicate which each other are really a bad idea.

I’ve been trying to explain to Atlassian that this is perhaps the worst possible timing for bug bounty programs to go public.

We’re in this no-mans land right now where powerful cybersecurity LLMs are finding 100s of new vulnerabilities in codebases, but the general developer public do not yet have access to these models.

As soon as these new models are released there’s a risk of an avalanche of new discoveries that could obliterate the administration and funding pools for every public bug bounty.

The same can be said of the Forge migration deadline which would have saved partners $millions had Atlassian simply pushed it to EOY27 when the models will be orders of magnitude more capable.