Certification program · Verification register

The certificate, in plain terms.

The complete disclaimer and limitation language that applies to every Cyber 360 certificate and public register entry.

Concept draft for program review · Final language subject to Program Office approval

Standard Certificate Disclaimer

This certificate reflects cybersecurity safeguards, documentation, policies, procedures, tools, and readiness practices reviewed as part of the Cyber 360 Certification Program for the organization and certified location named on this certificate.

This certificate is issued as a point-in-time recognition based on evidence reviewed within the agreed assessment scope and as of the assessment date shown. It does not constitute a guarantee, warranty, legal opinion, audit opinion, insurance approval, government certification, or assurance of full cybersecurity, privacy, regulatory, contractual, or compliance status.

This certificate applies only to the certified location, network environment, systems, users, documentation, and reviewed scope identified for the Cyber 360 assessment. It should not be interpreted as applying to unreviewed companies, related entities, affiliated locations, networks, systems, users, vendors, or services.

The organization remains responsible for maintaining its cybersecurity controls, documentation, policies, procedures, user practices, vendor relationships, systems, and operational decisions after the certificate is issued.

Cybersecurity conditions may change after assessment due to new systems, users, vendors, software, threats, incidents, expired licenses, disabled controls, operational changes, or other factors. No Cyber 360 certificate level guarantees that the organization or certified location will remain secure, compliant, breach-free, insurable, or protected against future cyber incidents.

Certificate validity may be verified through the Cyber 360 public verification process where available.

Public Verification Disclaimer

The Cyber 360 certificate status shown on a public verification page confirms only the certificate level, status, issue date, expiration or renewal date, last assessment date, and reviewed scope information available through the public verification record for the certified location shown.

Public verification does not disclose private review findings, technical details, vulnerabilities, internal reports, sensitive business information, personal information, protected data, or confidential evidence.

The certificate is a point-in-time recognition based on reviewed evidence for the certified location and reviewed scope. It is not a guarantee of security, compliance, insurance approval, or protection from future cyber incidents.

Public Verification Notice

Public verification confirms certificate status and basic certificate information only. It does not guarantee security, compliance, insurance approval, or protection from future incidents. It also does not disclose confidential review findings, technical details, vulnerabilities, or private evidence.

Scope Limitation

Each Cyber 360 assessment is performed within an agreed scope: the certified location, the identified network environment, and the specific systems, users, and documentation defined for the review. Statements on a certificate or verification page apply only within that scope. Nothing in the certificate or its verification record extends any representation to environments, systems, entities, or services that were not part of the reviewed scope.

Expired, Suspended, Revoked, and Superseded Certificates

  • Expired: The certificate validity period has ended and the certificate should not be presented as current. An expired certificate may be renewed through a renewal assessment.
  • Suspended: The certificate is temporarily inactive pending review, clarification, or updated information. A suspended certificate should not be presented as valid while the suspension is in effect.
  • Revoked: The certificate has been withdrawn and should no longer be used or displayed as valid in any form, including printed certificates, stickers, marketing materials, and electronic representations.
  • Superseded: A newer certificate has replaced the prior certificate. The superseded certificate should no longer be presented; verification of the current certificate is available through the current certificate’s QR code or verification code.
  • Under Review: The certificate or related scope is being reviewed before status is confirmed. Verifiers should rely on the status shown on the public verification page at the time of verification.

Use of Certificates and Program Marks

Certificate holders may display their certificate, QR sticker, and level designation for the certified location while the certificate status is Active. Certificates and program marks may not be altered, transferred to another location or entity, or presented in a way that misrepresents the certificate level, status, scope, or certified location. Suspected misuse can be reported through the contact page.

Verification Is the Authoritative Record

The public verification page reflects the current status of a certificate and is updated when status changes occur. In any conflict between a printed or displayed certificate and the public verification record, the public verification record controls.


Cyber 360 Certification Program, administered by the Cyber 360 Program Office. This page presents the program’s standard disclaimer language. Concept draft for review; final language subject to Program Office approval.