Standards Summary
Release 2026.Q3
This page describes what Bronze, Silver, and Gold represent. It does not publish scoring, evidence-acceptance rules, or how a reviewer reaches a decision.
Aligned with NIST CSF 2.0, CIS Controls v8
- Reviewed
- July 13, 2026
- Published
- July 13, 2026
Release summary
This Standards Summary describes what Legacy Core credentials represent as reviewed on July 13, 2026. The pathway is aligned with NIST Cybersecurity Framework 2.0 and CIS Controls v8. This cycle also monitors NIST IR 8374 Rev. 1 (final June 11, 2026) and California CCPA §7123(c) for future alignment review. Monitored frameworks are tracked only and are not part of the current credential standard. The public summary describes outcomes. It does not publish scoring, thresholds, or review procedures.
Framework alignment
Recognized sources the pathway is aligned with. Alignment is not endorsement or certification.
- View framework →
NIST Cybersecurity Framework(2.0)
NIST
- View framework →
CIS Controls(v8)
Center for Internet Security
Standards Summary — Release 2026.Q3
The published outcome standard each tier is verified against. Businesses are not expected to implement Silver and Gold alone. Alliance Partners may help implement security. Legacy Core determines whether the credential has been earned. Silver and Gold cannot be self-attested.
Silver — Evidence-Verified Implementation
S-IAIdentity and access
The business can show that access to accounts and systems is controlled, not merely claimed.
S-DPData protection
The business knows what client data it holds, where it lives, and how it is handled.
S-RSResilience
The business can show backup and recovery practices that go beyond storing files in the cloud.
S-SOSecurity operations
Device, email, and network protections appropriate to the business have been put in place.
What this means for medical & dental practices under HIPAA →
S-GVGovernance
Written practices, incident readiness, and team awareness support the credential. A verbal promise is not enough.
Gold — Ongoing Verified Readiness
Gold is issued after review of this pathway. Legacy Core does not continuously monitor credentialed businesses in-product.
G-OVOngoing visibility
Gold looks for continued awareness of systems and practices, not a one-time implementation snapshot.
G-DRDemonstrated recovery
Recovery and response have been shown to work in the business, not only written down.
G-MRMaintained readiness
Practices stay current. Gold is not issued on a stale implementation claim.
You don't do this alone.
Alliance Partners may help businesses implement cybersecurity improvements. Legacy Core determines whether the Legacy Core credential has been earned. Partners cannot purchase, guarantee, or self-award a Trust Badge.
Businesses may also progress through an independent review pathway. Silver and Gold cannot be earned through self-attestation.
Monitored
Frameworks tracked for future alignment review. Not part of the assessment basis.
- View framework →
NIST IR 8374 Rev. 1 — Ransomware Risk Management (CSF 2.0 Community Profile)(Rev. 1)
NIST
New this cycle. Final June 11, 2026, superseding the 2022 profile. Monitored for future alignment review.
- View framework →
California CCPA §7123(c)
State of California
18-control structure.