The catalogue, expanded.
Four designations, explained in plain language. Every level reflects safeguards actually reviewed at your location, pick a realistic starting point, and the maturity path takes you the rest of the way.
C360-B:2026
Bronze, Foundational readiness Bronze
Bronze records that a location has put the essential building blocks of cybersecurity in place. It is the honest, achievable starting point for organizations getting serious about security.
- What it helps demonstrate
-
- Essential protections exist and are in use
- Someone is accountable for security basics
- The organization has begun a deliberate security effort
- Typical organization fit
-
- Small offices and practices
- Organizations early in their security journey
- Locations establishing a baseline before moving up
- Examples of safeguards reviewed
-
- Password practices and MFA on email accounts
- Endpoint protection on workstations
- Basic data backups
- Software update habits
- Basic user security guidance
- Limitations
Bronze does not mean the organization has a mature cybersecurity program. It records that foundational cybersecurity readiness was reviewed and documented within the agreed assessment scope, as of the assessment date shown on the certificate.
C360-S:2026
Silver, Core readiness Silver
Silver records a location where core cybersecurity safeguards, policies, procedures, and documentation are substantially in place, security as a routine practice, not a one-time project.
- What it helps demonstrate
-
- Core safeguards are broadly applied and documented
- Staff receive security awareness training
- Recovery basics are tested, not assumed
- Typical organization fit
-
- Established SMBs and professional practices
- Medical, dental, and legal offices
- Nonprofits and schools with active IT support
- Examples of safeguards reviewed
-
- MFA across email, remote access, and key systems
- Backups with periodic restore testing
- Endpoint protection with monitoring
- Security awareness training program
- Patching cadence and access reviews
- Written security procedures
- Limitations
Silver records that core safeguards were substantially in place within the reviewed scope at the time of assessment. It is not an audit opinion, and it does not certify affiliates, systems, or locations outside that scope.
C360-G:2026
Gold, Advanced readiness Gold
Gold records a location operating with layered, monitored defenses and documented response capability, appropriate for organizations that handle sensitive or regulated information.
- What it helps demonstrate
-
- Threats are actively detected and responded to
- An incident response plan exists and is assigned
- Vendors and access are managed deliberately
- Typical organization fit
-
- Organizations handling sensitive or regulated data
- Locations with contractual security obligations
- Businesses with managed IT or security services
- Examples of safeguards reviewed
-
- Endpoint detection and response (EDR) coverage
- Documented, assigned incident response plan
- Centralized logging and alert review
- Vendor and third-party risk review
- Network segmentation fundamentals
- Policy suite with periodic review
- Limitations
Gold reflects the reviewed environment as of the assessment date. It does not guarantee that threats will be detected or prevented, and it does not extend to unreviewed vendors, systems, or environments.
C360-P:2026
Platinum, Comprehensive readiness Platinum
Platinum records a location with mature, governed, continuously monitored cybersecurity practices, the program’s highest recognition of readiness within the reviewed scope.
- What it helps demonstrate
-
- Security is governed at the leadership level
- Response capability is exercised, not just written
- Controls are layered, monitored, and improved
- Typical organization fit
-
- Locations with the highest readiness expectations
- Organizations serving security-conscious clients
- Environments with significant data or uptime stakes
- Examples of safeguards reviewed
-
- Continuous monitoring and alerting approach
- Tabletop or response exercises
- Layered access, network, and data controls
- Executive-level security governance
- Comprehensive, current documentation suite
- Continuous improvement and review cycle
- Limitations
Platinum is the program’s highest recognition of readiness within the reviewed scope, not a guarantee of security, compliance, insurability, or protection from future cyber incidents.
At a glance
Level comparison.
| Designation | Focus | Typical fit | Review depth |
|---|---|---|---|
| C360-B:2026 Bronze |
Essential protections in place | Small offices establishing a baseline | Foundational safeguards and basic practices |
| C360-S:2026 Silver |
Core safeguards, training, and documentation | Established SMBs, medical & professional offices | Core controls plus procedures and testing |
| C360-G:2026 Gold |
Detection, response, and vendor management | Organizations with sensitive or regulated data | Advanced controls, monitoring, and response planning |
| C360-P:2026 Platinum |
Governance, monitoring, and continuous improvement | Locations with the highest readiness expectations | Comprehensive review across all program areas |
Read this part too
Limitations apply at every level.
Every certificate has the same honest boundaries. Each certificate applies only to the certified location and reviewed scope, as of the assessment date. No level guarantees that the organization will remain secure, compliant, breach-free, insurable, or protected against future cyber incidents. Certificates expire and must be renewed; the current status of any certificate is always available through public verification.