Certification program · Verification register

Practical certification for real-world organizations.

Cyber 360 exists to make cybersecurity readiness visible, verifiable, and achievable, one location at a time.

Program philosophy

Evidence over assertion.

Plenty of organizations say they take security seriously. Cyber 360 is built on a simpler, harder standard: recognition should rest on what an authorized assessor can actually review, the safeguards, policies, procedures, tools, and documentation genuinely in place at a location.

The program is designed for the organizations that make up the real economy: small and mid-sized businesses, medical and dental offices, nonprofits, schools, professional practices, and municipal offices. The review is practical, the language is plain, and the maturity path is achievable. The program does not require any particular product, vendor, or technology stack, different organizations may use different systems and providers, provided the relevant safeguards and evidence can be reviewed.

Every certificate is a point-in-time recognition tied to a defined scope. That honesty is a feature, not a caveat: it is what keeps a register entry credible for the people who rely on it.

  • Evidence-based Certificates reflect safeguards an authorized assessor reviewed, never a self-graded checklist.
  • Location-based Each certificate belongs to a specific certified location and its reviewed environment.
  • Privacy-first Public verification shows approved certificate facts only. Findings and evidence stay internal.
  • Growth-oriented Bronze through Platinum forms a maturity path, with tracked next steps for every location.

The model

Certified locations, not certified companies.

Security lives in the details of a specific place: its network, its systems, its people, its practices. A company’s headquarters and its satellite office can have very different security realities, so the register records them separately.

One organization certificates held per location Brooklyn office Silver · Active C360-SIL-2026-00125 Queens office Working to Bronze no certificate yet Warehouse Not in scope not reviewed
Each location has its own certificate level, assessment history, renewal schedule, and verification record. A certificate never extends to unreviewed offices, networks, systems, or vendors.

One company, many locations

A company may hold certificates for one, several, or all of its locations. Each is certified on its own merits, with its own register entry.

Certificates that mean something

Because each certificate maps to a reviewed environment, a verifier knows exactly what was recognized, the certified location named on the certificate, within its reviewed scope.

No blanket claims

A certificate for one location does not extend to unreviewed affiliates, other offices, networks, systems, or vendors. If the location represents the full organization, the certificate reflects that scope.

In practice: “Example Organization, Inc., Brooklyn Office” can hold a Silver certificate while the company’s new Queens office is still working toward Bronze. Each location’s verification page tells its own accurate story.

The review

How an assessment enters the register.

A clear, respectful process with a defined scope, and strict protection of everything you share.

  1. Scope is agreed up front

    You and the program agree on the location, network environment, systems, and target certificate level before the review begins.

  2. An authorized assessor reviews evidence

    The assessor examines safeguards, policies, procedures, tools, and documentation against the requirements for your target level.

  3. Results are documented and quality-checked

    Findings are recorded internally, and a program administrator independently reviews and approves the assessment before anything is issued.

  4. The certificate is issued and verifiable

    An approved assessment produces a certificate with a QR code and non-guessable verification code, plus a curated public register entry.

  5. The maturity path continues

    Each location gets a tracked path, current level, recommended next level, target date, and practical next steps, plus renewal reminders to keep certification current.

Evidence stays private. Review findings, technical details, and uploaded evidence default to internal-only visibility. They are never displayed publicly, and public achievements appear only after explicit administrator approval. Read how data is handled.

The journey

A maturity path, not a one-time exam.

Not every organization begins at the same maturity level, and not every organization carries the same risks, resources, or regulatory obligations. The four designations recognize progress, from foundational readiness toward stronger safeguards, better evidence, recurring review, and mature governance.

  • Bronze Establish the foundation: essential account, endpoint, and backup protections with basic user guidance.
  • Silver Build core readiness: broad MFA, tested backups, training, patching cadence, and written procedures.
  • Gold Operate with maturity: detection and response, vendor review, logging, and layered safeguards.
  • Platinum Lead with governance: continuous monitoring, tested response exercises, and comprehensive documentation.

See what each level reviews

Honest limits

What a certificate is, and what it is not.

A Cyber 360 certificate is a point-in-time recognition based on evidence reviewed within an agreed scope, as of the assessment date shown. It is not a guarantee, warranty, legal opinion, audit opinion, insurance approval, government certification, or assurance of full cybersecurity or compliance status.

Conditions change, new systems, users, vendors, and threats emerge after any review. That is why certificates carry validity periods and renewal dates, and why every entry has a public status that can be checked at any time.

Read the full certificate disclaimer

Program administrator

The Cyber 360 Program Office.

The Cyber 360 Certification Program is administered by the Cyber 360 Program Office. The Program Office manages assessor authorizations, assessment approvals, certificate issuance, renewals, and the public verification service, and independently reviews every assessment before a certificate is issued.

Administrator
Cyber 360 Program Office

Contact the program