Standards Release
Release 2026.Q3
Assessment basis: NIST CSF 2.0, CIS Controls v8
- Reviewed
- July 13, 2026
- Published
- July 13, 2026
Release summary
This release documents the assessment basis for Legacy Core's 15-part readiness assessment as reviewed on July 13, 2026. The readiness assessment is built on NIST Cybersecurity Framework 2.0 and CIS Controls v8. This cycle also begins monitoring NIST IR 8374 Rev. 1 (final June 11, 2026) and California CCPA §7123(c) for future alignment review. Monitored frameworks are tracked only and are not part of the assessment basis.
Assessment Basis
Frameworks the 15-part readiness assessment is built on.
- View framework →
NIST Cybersecurity Framework(2.0)
NIST
- View framework →
CIS Controls(v8)
Center for Internet Security
Tier Requirements — Release 2026.Q3
The published requirements each tier is verified against. Businesses are not expected to implement or document these alone — Alliance Partners are professional IT and security firms who implement the work, assemble the evidence, and attest to it. Self-attestation is never accepted.
Silver — Verified Implementation
S1Security policies
Written rules for how the business handles data and incidents
S2Asset inventory
Every device, app, and cloud service is documented
S3Data awareness
The business knows what client data it holds and where it lives
S4Multi-factor authentication
Active on email, banking, and critical systems
S5Access control
Unique logins, right-sized access, clean offboarding
What this means for medical & dental practices under HIPAA →
S6Updates
Devices and software stay current
S7Backup
Critical data is backed up automatically
S8Device protection
Locked, encrypted, malware-protected endpoints
S9Email protections
The business domain is protected against impersonation
S10Network basics
Firewall on, Wi-Fi secured
S11Incident plan
The business knows exactly who to call if something happens
S12Team awareness
Everyone can spot phishing and handle data safely
Gold — Sustained & Monitored
Everything in Silver, maintained, plus:
G1Ongoing monitoring
Endpoint/network monitoring on a defined review cadence
G2Vulnerability management
Weaknesses found and fixed on a cycle
G3Backup tested
A restore has been proven within the past 12 months
G4Plan exercised
The response plan practiced within the past 12 months
G5Access reviewed
Annual review of accounts and access
G6Vendors reviewed
Critical vendors checked annually
G7Recurring awareness
Security awareness on a recurring schedule
What this means for medical & dental practices under HIPAA →
G8Actively maintained
A qualified partner keeps practices current, evidence refreshed annually
You don't do this alone.
- 1An Alliance Partner — a professional firm whose specialty matches the work — implements and documents the requirements with you.
- 2The partner attests to each requirement with supporting evidence.
- 3Legacy Core reviews the attestation packet and issues the Trust Badge to the public registry.
Alliance Partners are reviewed before they can attest. Prefer an independent route? Third-party verification is available.
Monitored
Frameworks tracked for future alignment review. Not part of the assessment basis.
- View framework →
NIST IR 8374 Rev. 1 — Ransomware Risk Management (CSF 2.0 Community Profile)(Rev. 1)
NIST
New this cycle. Final June 11, 2026, superseding the 2022 profile. Under review against the current 15-area readiness assessment.
- View framework →
California CCPA §7123(c)
State of California
18-control structure.