Security review

CRM Security Due Diligence Checklist for Small Businesses

Review CRM identity, permissions, integrations, exports, logs, recovery, vendor evidence, and offboarding before storing customer data in a platform.

Editorially reviewed · Updated July 22, 2026 · Research and planning information

A CRM can contain customer identities, communications, sales notes, contracts, and commercial history. Security review should match the sensitivity of that data and the business impact of misuse or loss. This checklist organizes questions for the business owner and qualified security or privacy advisers; it is not a certification of any vendor.

Classify data and access

List the data planned for the CRM and explicitly exclude fields that have no approved purpose. Identify administrators, regular users, temporary staff, contractors, integrations, and service accounts. Define least-privilege roles for viewing, editing, exporting, deleting, configuring, and installing applications.

Require multifactor authentication where available, starting with administrative and sensitive accounts. CISA recommends MFA broadly and favors stronger phishing-resistant methods where practical. Test account recovery and offboarding so an employee departure does not leave active sessions, API keys, shared passwords, or personal ownership of critical integrations.

Review integrations and data movement

Map every connected form, email service, calendar, accounting tool, support desk, data warehouse, and automation service. Record what data each integration reads and writes, the credential owner, permission scope, log location, failure alert, and removal process. Avoid granting a connector full access when its documented purpose requires less.

Check how exports, backups, attachments, mobile apps, and browser extensions handle data. A vendor’s security page does not automatically cover every third-party app installed into the account.

Collect evidence for core controls

AreaQuestionEvidence to retain
IdentityAre MFA, SSO, and session controls available on the chosen tier?Configuration screenshot and plan terms
AuthorizationCan roles limit exports, deletion, and sensitive fields?Normal-user permission test
LoggingWhich admin and data events are recorded and retained?Sample log and retention statement
RecoveryHow are accidental deletion and service interruption handled?Recovery documentation and tested process
ExitCan records, relationships, and files be exported?Opened sample export

Document vendor and internal responsibilities

Review current contractual terms, privacy documentation, security statements, incident notification language, subprocessors, data location choices, support contacts, deletion procedures, and independent assurance reports appropriate to the decision. Have qualified reviewers address regulated or contractually restricted data.

Security also depends on internal operation. Assign owners for access reviews, integration inventory, configuration changes, incident reporting, vendor notices, backup or export routines, and user training. Reassess after a major plan change, acquisition, integration, incident, or renewal.

Sources and verification starting points

Product features and documentation can change. Open current provider and authority pages before making a material decision.