Skip to content

The 27 Shopify security checks Black Cat runs

Black Cat SSPM evaluates 27 security policies against your Shopify configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Shopify — what access Black Cat needs, and why.

Access control & privilege (16)

Data sharing & exposure (6)

Other checks (5)

severity: high Staff MFA Disabled fix difficulty: easy #

Enable two-factor authentication for the flagged Shopify staff member

  1. Log in to the Shopify admin as a store owner or staff with admin permissions
  2. Navigate to Settings > Users and permissions
  3. Click on the staff member's name to open their profile
  4. Under "Security", locate the two-step authentication section
  5. Ask the staff member to enable two-step authentication from their own account settings, or require it store-wide
  6. Confirm the staff member has completed the two-step authentication enrollment

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical Account Owner MFA Disabled fix difficulty: easy #

Enable two-factor authentication on the store owner account

  1. Log in to Shopify using the store owner account credentials
  2. Click on your account avatar in the top-right corner and select "Manage account"
  3. Navigate to the "Security" section
  4. Under "Two-step authentication", click "Turn on two-step authentication"
  5. Choose an authentication method (authenticator app recommended) and complete enrollment
  6. Store the backup codes in a secure password manager

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Webhook Private Destination fix difficulty: easy #

Update the webhook destination to a valid public HTTPS endpoint

  1. Log in to the Shopify admin as the store owner or staff with notification permissions
  2. Navigate to Settings > Notifications
  3. Scroll to the "Webhooks" section at the bottom of the page
  4. Identify the webhook pointing to a localhost or private IP address
  5. Delete the webhook and recreate it with a publicly reachable HTTPS URL
  6. Verify the new endpoint receives test webhook payloads successfully

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.6 NIS2 Directive NIS2-21.a.2 DORA (SaaS Security) DORA-9.9

severity: low Webhook XML Format fix difficulty: easy #

Switch webhook format from XML to JSON for stronger HMAC signature verification

  1. Log in to the Shopify admin as the store owner or staff with notification permissions
  2. Navigate to Settings > Notifications
  3. Scroll to the "Webhooks" section at the bottom of the page
  4. Delete the webhook using XML format
  5. Recreate the webhook with the same topic and destination URL, selecting JSON as the format
  6. Update the receiving endpoint to parse JSON payloads if it currently expects XML

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Store Setup Required fix difficulty: easy #

Complete the Shopify store setup to ensure all security features are active

  1. Log in to the Shopify admin as the store owner
  2. Follow the setup wizard prompts to complete store configuration
  3. Verify that all required settings are configured including payments, shipping, and taxes
  4. Confirm the store is no longer flagged as requiring setup

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial