Salesforce’s Root Certificate Update Explained
Blog
Recently, many Salesforce customers received an email like the one below:
“IMPORTANT: Prepare for Upcoming Root Certificate Changes Effective February 5”
If you’re responsible for fundraising systems, integrations, or data flows, that kind of message is enough to stop you mid-scroll. The email references “root certificates”, “trust chains”, and potential impacts, but doesn’t clearly explain what to check or whether most organisations are actually at risk.
Let’s cut through the noise!
For the vast majority of nonprofits and fundraising teams, this change is unlikely to cause any disruption. That said, it’s worth understanding what’s happening and doing a quick sense-check, especially if you rely on custom integration platforms or older systems.
This post explains the change in plain terms, outlines when it might matter, and suggests some simple actions you can take.

What’s Actually Changing?
At a high level, Salesforce is changing the root security certificate it uses to secure browser traffic and inbound API calls. This certificate is part of the technology that enables HTTPS, the “S” in “secure”, which ensures data moving between Salesforce and browsers or connected systems is encrypted and trusted.

A simple analogy
Think of this like airport security:
- When requested by your browser or connected system, Salesforce presents an ID (its certificate) to prove it is who it says it is
- That ID is checked against a list of trusted authorities (the “trust store”)
- If the ID traces back to a trusted authority, the connection is allowed
Salesforce is changing which trusted authority it uses. The new one, DigiCert G2, has been widely trusted by operating systems and browsers for over a decade.
Why is Salesforce Making This Change?
Salesforce is making this change because the currently used root certificate is scheduled to be distrusted from April 2026. Certificate authorities periodically retire older root certificates for good security hygiene, and platforms must move away from them ahead of those deadlines.
In a nutshell, this is routine housekeeping not an emergency response.
Will This Affect Our Fundraising Systems?
In most cases, no. You are very unlikely to be affected if:
- Your team uses modern, regularly updated browsers
- Your computers and servers receive operating system updates
- Your Salesforce integrations run on supported, maintained platforms
However, there are a few edge cases where issues could theoretically arise.
Situations where extra care may be needed
You may want to double-check if:
- You use very old systems or middleware
Systems that haven’t been updated in 10+ years may not recognise newer trusted certificates. - Users are running out-of-date browsers or operating systems
Browsers or OS versions that have not received updates for many years may not include newer root certificates in their trust stores. - An integration was explicitly “pinned” to Salesforce’s current certificate
This is uncommon, and Salesforce advise not to do it, but if this approach has been taken in any of your integrations it could cause trust failures when the certificate changes.
Salesforce’s change is coming into place on 5 February 2026, so any investigation should be done in advance of this.

How to Make Sure a Trust Store is Up-to-Date
In almost all cases, the answer is reassuringly straightforward. The best way to keep a trust store up-to-date is simply to keep the application or operating system itself up to date. Modern software updates include refreshed trust stores automatically.
In practical terms:
- Browsers and operating systems
Keeping these on recent versions ensures their trust stores are current. - Servers and integration platforms
Applying vendor-provided updates keeps certificate trust aligned with current standards.
If you want to inspect what certificates are trusted at the operating system level in Windows, Microsoft provides guidance on how to check this here: https://learn.microsoft.com/en-us/windows-hardware/drivers/install/certificate-stores
If you are unsure whether you could be affected, this is a good point to involve your Salesforce partner, your internal IT team, or your integration provider.
Looking Ahead: Possible Future Changes (G3 Migration)
Salesforce has also indicated, in a pinned post in the Trailblazer community, that this may not be the final change.
There may be a subsequent migration to DigiCert G3, which uses more modern cryptographic standards. DigiCert G3 roots were widely adopted into major trust stores around 2018 to 2019, meaning systems would generally need to have been updated within the last 6 to 7 years to trust them automatically.
All the same principles would apply for this migration, so making sure your applications and browsers are kept up-to-date today will ensure you’re also ready if and when this change comes.
Final Thoughts
The wording of Salesforce’s email may have sounded alarming, but for most nonprofits and fundraising teams, this change will pass unnoticed.
If your systems are reasonably modern and maintained, you are almost certainly fine. If you rely on older infrastructure, this is a good prompt to do a quick health check, not a cause for panic.
If you would like support reviewing your Salesforce integrations or understanding how these changes relate to your fundraising data flows, the Giveclarity team is always happy to help.
Further Reading and Official Resources
- Salesforce: Security Keys Policy and Rotation
- Salesforce: Certificate and Trust Store Management
- Trailblazer Community: Security and Certificate Updates (Pinned Post)
- Cloud Sundial: How TLS and Certificate Trust Works
About the author:
Lawrence Newcombe is Head of Product at Giveclarity