Silver & Gold
Evidence is how higher tiers stay honest.
Silver and Gold require evidence demonstrating that cybersecurity practices have progressed beyond awareness into documented implementation and ongoing readiness. They cannot be earned through self-attestation.
Evidence helps distinguish claimed cybersecurity practices from documented implementation. Exact requirements vary by credential tier and business environment and are evaluated under the applicable Legacy Core Standards Release.
Identity and access
SILVERGOLDHow the business controls who can reach accounts, systems, and client information. Silver and Gold look for documented implementation, not a claim that passwords exist.
Data protection
SILVERGOLDHow the business handles, stores, and shares client and sensitive information. Higher tiers require evidence that those practices are in place, not only described.
Resilience
SILVERGOLDHow the business can recover from disruption and keep operating. Gold expects a stronger showing that recovery is practiced, not only planned.
Security operations
SILVERGOLDDay-to-day protections around devices, email, and monitoring appropriate to the business. Gold is where ongoing visibility matters more than a one-time setup.
Governance
SILVERGOLDWritten practices, incident readiness, vendor oversight, and team awareness. Evidence requirements vary by credential tier and business environment.
Integrity rules
- Self-attestation alone is never sufficient for Silver or Gold.
- Alliance Partners may help implement security. Legacy Core determines whether the credential has been earned.
- Evidence is reviewed under the applicable Legacy Core credential standard.
- Sensitive security evidence is not displayed in the Public Business Trust Registry.
- Evidence supports higher credential tiers. It does not replace legal or compliance obligations.
Bronze establishes baseline readiness through the Trust Audit. Silver verifies implementation. Gold demonstrates continued maturity. See Trust Badges for how tiers are earned, and the Legacy Core Standards Summary. For why evidence matters, see Evidence.
Boundary
What a Legacy Core credential does not attest to
A Trust Badge documents demonstrated readiness against a dated Standards Release (assessment basis: NIST CSF 2.0 and CIS Controls v8). It is not a substitute for industry-specific legal or regulatory obligations.
- FTC Safeguards Rule or WISP compliance (CPAs / tax preparers)
- HIPAA compliance or OCR audit readiness (medical / dental)
- ABA or State Bar ethics sign-off (attorneys)
- SEC Regulation S-P compliance (investment advisers)
- NAIC Insurance Data Security Model Law (including in California — not adopted)
- CCPA cybersecurity audits (threshold-gated regulation)
- Cyber insurance approval or claim guarantee
- Penetration test, SOC 2, CMMC, or government endorsement
Legacy Core is aligned with NIST CSF 2.0 and CIS Controls v8. Legacy Core is not affiliated with, endorsed by, or accredited by NIST, CIS, or any government agency. Tracking a framework does not constitute a determination of legal or regulatory compliance. Legacy Core supports cybersecurity readiness and trust-building and does not provide legal advice. Businesses should consult qualified legal or compliance professionals regarding requirements specific to their industry and operations.
Industry-specific obligations by vertical: Regulatory context guides
Start with documented readiness.
Earn Bronze first. Then work with an Alliance Partner as cybersecurity maturity grows. Legacy Core still decides whether Silver or Gold has been earned.