Legacy Core

Silver & Gold

Evidence is how higher tiers stay honest.

Silver and Gold require evidence demonstrating that cybersecurity practices have progressed beyond awareness into documented implementation and ongoing readiness. They cannot be earned through self-attestation.

Evidence helps distinguish claimed cybersecurity practices from documented implementation. Exact requirements vary by credential tier and business environment and are evaluated under the applicable Legacy Core Standards Release.

Integrity rules

  • Self-attestation alone is never sufficient for Silver or Gold.
  • Alliance Partners may help implement security. Legacy Core determines whether the credential has been earned.
  • Evidence is reviewed under the applicable Legacy Core credential standard.
  • Sensitive security evidence is not displayed in the Public Business Trust Registry.
  • Evidence supports higher credential tiers. It does not replace legal or compliance obligations.

Bronze establishes baseline readiness through the Trust Audit. Silver verifies implementation. Gold demonstrates continued maturity. See Trust Badges for how tiers are earned, and the Legacy Core Standards Summary. For why evidence matters, see Evidence.

Boundary

What a Legacy Core credential does not attest to

A Trust Badge documents demonstrated readiness against a dated Standards Release (assessment basis: NIST CSF 2.0 and CIS Controls v8). It is not a substitute for industry-specific legal or regulatory obligations.

  • FTC Safeguards Rule or WISP compliance (CPAs / tax preparers)
  • HIPAA compliance or OCR audit readiness (medical / dental)
  • ABA or State Bar ethics sign-off (attorneys)
  • SEC Regulation S-P compliance (investment advisers)
  • NAIC Insurance Data Security Model Law (including in California — not adopted)
  • CCPA cybersecurity audits (threshold-gated regulation)
  • Cyber insurance approval or claim guarantee
  • Penetration test, SOC 2, CMMC, or government endorsement

Legacy Core is aligned with NIST CSF 2.0 and CIS Controls v8. Legacy Core is not affiliated with, endorsed by, or accredited by NIST, CIS, or any government agency. Tracking a framework does not constitute a determination of legal or regulatory compliance. Legacy Core supports cybersecurity readiness and trust-building and does not provide legal advice. Businesses should consult qualified legal or compliance professionals regarding requirements specific to their industry and operations.

Industry-specific obligations by vertical: Regulatory context guides

Start with documented readiness.

Earn Bronze first. Then work with an Alliance Partner as cybersecurity maturity grows. Legacy Core still decides whether Silver or Gold has been earned.

Evidence for Silver & Gold — Legacy Core | Legacy Core