Practical certification for real-world organizations.
Cyber 360 exists to make cybersecurity readiness visible, verifiable, and achievable, one location at a time.
Program philosophy
Evidence over assertion.
Plenty of organizations say they take security seriously. Cyber 360 is built on a simpler, harder standard: recognition should rest on what an authorized assessor can actually review, the safeguards, policies, procedures, tools, and documentation genuinely in place at a location.
The program is designed for the organizations that make up the real economy: small and mid-sized businesses, medical and dental offices, nonprofits, schools, professional practices, and municipal offices. The review is practical, the language is plain, and the maturity path is achievable. The program does not require any particular product, vendor, or technology stack, different organizations may use different systems and providers, provided the relevant safeguards and evidence can be reviewed.
Every certificate is a point-in-time recognition tied to a defined scope. That honesty is a feature, not a caveat: it is what keeps a register entry credible for the people who rely on it.
- Evidence-based Certificates reflect safeguards an authorized assessor reviewed, never a self-graded checklist.
- Location-based Each certificate belongs to a specific certified location and its reviewed environment.
- Privacy-first Public verification shows approved certificate facts only. Findings and evidence stay internal.
- Growth-oriented Bronze through Platinum forms a maturity path, with tracked next steps for every location.
The model
Certified locations, not certified companies.
Security lives in the details of a specific place: its network, its systems, its people, its practices. A company’s headquarters and its satellite office can have very different security realities, so the register records them separately.
One company, many locations
A company may hold certificates for one, several, or all of its locations. Each is certified on its own merits, with its own register entry.
Certificates that mean something
Because each certificate maps to a reviewed environment, a verifier knows exactly what was recognized, the certified location named on the certificate, within its reviewed scope.
No blanket claims
A certificate for one location does not extend to unreviewed affiliates, other offices, networks, systems, or vendors. If the location represents the full organization, the certificate reflects that scope.
The review
How an assessment enters the register.
A clear, respectful process with a defined scope, and strict protection of everything you share.
-
Scope is agreed up front
You and the program agree on the location, network environment, systems, and target certificate level before the review begins.
-
An authorized assessor reviews evidence
The assessor examines safeguards, policies, procedures, tools, and documentation against the requirements for your target level.
-
Results are documented and quality-checked
Findings are recorded internally, and a program administrator independently reviews and approves the assessment before anything is issued.
-
The certificate is issued and verifiable
An approved assessment produces a certificate with a QR code and non-guessable verification code, plus a curated public register entry.
-
The maturity path continues
Each location gets a tracked path, current level, recommended next level, target date, and practical next steps, plus renewal reminders to keep certification current.
The journey
A maturity path, not a one-time exam.
Not every organization begins at the same maturity level, and not every organization carries the same risks, resources, or regulatory obligations. The four designations recognize progress, from foundational readiness toward stronger safeguards, better evidence, recurring review, and mature governance.
- Bronze Establish the foundation: essential account, endpoint, and backup protections with basic user guidance.
- Silver Build core readiness: broad MFA, tested backups, training, patching cadence, and written procedures.
- Gold Operate with maturity: detection and response, vendor review, logging, and layered safeguards.
- Platinum Lead with governance: continuous monitoring, tested response exercises, and comprehensive documentation.
Honest limits
What a certificate is, and what it is not.
A Cyber 360 certificate is a point-in-time recognition based on evidence reviewed within an agreed scope, as of the assessment date shown. It is not a guarantee, warranty, legal opinion, audit opinion, insurance approval, government certification, or assurance of full cybersecurity or compliance status.
Conditions change, new systems, users, vendors, and threats emerge after any review. That is why certificates carry validity periods and renewal dates, and why every entry has a public status that can be checked at any time.
Program administrator
The Cyber 360 Program Office.
The Cyber 360 Certification Program is administered by the Cyber 360 Program Office. The Program Office manages assessor authorizations, assessment approvals, certificate issuance, renewals, and the public verification service, and independently reviews every assessment before a certificate is issued.
- Administrator
- Cyber 360 Program Office
- [email protected]
- Telephone
- (718) 393-5343