Reviewed, not self-declared
An authorized assessor examines the safeguards, policies, procedures, tools, and documentation actually in place, within a clearly agreed scope. Never a self-graded questionnaire.
About the programCyber 360 is an evidence-based certification program for the organizations that make up the real economy. An authorized assessor reviews the safeguards actually in place at a specific location; the result is a register entry that anyone holding its codes can confirm in seconds.
Readiness made visible, verifiable and renewable.
The program
Most businesses that take security seriously have no simple way to show it. A Cyber 360 certificate gives your location a credible, checkable answer to the question, “How do we know you take this seriously?”
An authorized assessor examines the safeguards, policies, procedures, tools, and documentation actually in place, within a clearly agreed scope. Never a self-graded questionnaire.
About the programEach certificate covers exactly one location, never a whole company. A verifier knows precisely what was recognized, the certified location, within its reviewed scope.
How the model worksEvery certificate carries a QR code and a non-guessable verification code. Clients and partners confirm status in seconds, without any sensitive detail being exposed.
Verify a certificateCertificate levels
Four designations, one practical maturity path. Every level reflects safeguards actually reviewed at your location, start where you are and move up on the record.
The essential building blocks, reviewed and documented: account security basics, endpoint protection, data backups, and plain-language user guidance.
Core safeguards substantially in place: broad MFA, tested backups, awareness training, a patching cadence, and written security procedures.
Layered, monitored defenses: managed detection, incident response planning, vendor review, centralized logging, and network safeguards.
Mature governance: continuous monitoring, exercised response plans, layered controls, and a complete, current documentation suite.
Certificate levels
Program insights
No organization is too small or too unimportant to be targeted. Phishing, stolen passwords, ransomware, and fake invoices reach businesses of every size, preparation decides what they cost.
The same tools that draft your documents write better phishing. The program reviews AI usage rules and agent boundaries so productivity gains never become privacy or security losses.
Most modern attacks begin with a stolen credential, not a virus. MFA coverage, privileged-account controls, and offboarding are reviewed from the first level up.
The register looks for evidence, not promises, read how the program reviews multi-factor authentication, tested backups, employee awareness, vendor risk and incident response, or start with the frequently asked questions.
Public verification
Enter the certificate number and verification code printed on the certificate, or scan its QR code to open the entry directly. Verification is an exact lookup, and the program publishes no directory of certified organizations.