B Series, Building Certification

CERTIFY THE
BUILDING, NOT
JUST THE TEAM.

The CRE Cybersecurity Institute B Series is an independent certification program for commercial properties, Bronze through Platinum. A structured assessment against defined CRE cyber controls, producing a certificate, a gap analysis, and a remediation roadmap your team can act on immediately.

The Four Tiers

EVERY BUILDING HAS
A STARTING POINT.
FIND YOURS.

Each tier builds on the one below it. Most organizations start at Bronze or Silver and work toward Gold over 12–24 months. Platinum is the benchmark for flagship assets in institutional portfolios.

Bronze-B
BRONZE
Certified Cyber Building, Bronze
Annual renewal · Controls verification only
Required Controls
VLAN segmentation between IT and OT/BAS networks
Default credential elimination across all networked systems
MFA enforced on all remote access paths
OT/BAS asset inventory completed and documented
Incident response plan documented and approved
Vendor remote access policy in place
Security awareness training for all building staff
What You Receive
Bronze-B certification letter and digital badge
Gap analysis report with prioritized remediation items
90-minute verification call with assessor
12-month certification validity
Begin Bronze Assessment →
Timeline: 3–4 weeks from kickoff to certificate
Silver-B · Most Common
SILVER
Certified Cyber Building, Silver
Annual renewal · Controls verification + spot check
All Bronze-B controls, plus:
Firewall-enforced full network segmentation (IT/OT/guest)
EDR deployed on all IT-class endpoints
SIEM with OT log ingestion and alerting rules
Formal vendor access management program
Annual penetration test (IT and OT/BAS in scope)
Patch management program with documented cadence
Privileged access workstation or PAM for critical systems
Tenant data segregation documented and tested
What You Receive
Silver-B certification letter and digital badge
Full gap analysis + remediation roadmap (prioritized by risk)
Technical verification component (network diagram review)
Tenant disclosure documentation template
12-month certification validity
Begin Silver Assessment →
Timeline: 6–8 weeks from kickoff to certificate
Gold-B · Insurer Recognized
GOLD
Certified Cyber Building, Gold
Annual renewal · Controls verification + technical review
All Silver-B controls, plus:
Full NIST CSF 2.0 maturity documentation (all 6 functions)
NDR deployed on OT/BAS network segments
24/7 MDR monitoring with CRE-context alerting
Tested IR plan with annual OT-aware tabletop exercise
Vulnerability management program covering OT systems
Third-party risk assessments for all OT/BAS vendors
Board or executive-level cyber risk reporting
Zero trust network architecture for IT/OT boundaries
What You Receive
Gold-B certification letter and digital badge
Full NIST CSF 2.0 maturity report (board-ready format)
Insurance carrier submission package, satisfies most UW questionnaires
Remediation roadmap with 12-month execution milestones
Tenant trust documentation package
Begin Gold Assessment →
Timeline: 10–14 weeks from kickoff to certificate
Platinum-B · Highest Standard
PLATINUM
Certified Cyber Building, Platinum
Annual renewal · Full annual re-verification
All Gold-B controls, plus:
Red team adversarial testing, both IT and OT in scope
Continuous OT network monitoring with anomaly detection
Physical security systems integrated into cyber monitoring
Supply chain security program for all technology vendors
Cyber resilience testing (backup, recovery, continuity)
Formal cyber risk quantification (FAIR or equivalent)
Tenant-facing security SLA in lease addenda
Carrier premium discount program eligible
What You Receive
Platinum-B certification letter and digital badge
Full red team report with executive and technical findings
Public portfolio certification badge display rights
Dedicated CRE Cybersecurity Institute advisory support (quarterly)
Carrier premium discount program enrollment support
Begin Platinum Assessment →
Timeline: Scoped individually · typically 16–20 weeks

Side by Side

TIER COMPARISON

What each tier includes, what it delivers, and who it's for.

Bronze-B Silver-B Gold-B Platinum-B
Assessment & Process
Timeline to certificate3–4 wks6–8 wks10–14 wks16–20 wks
Technical verification component
Adversarial / red team testing
Controls Coverage
Network segmentation (IT/OT)
EDR on IT endpoints
SIEM with OT log ingestion
NDR on OT segments
NIST CSF 2.0 maturity documentation
Annual penetration test
OT-aware IR tabletop exercise
Continuous OT monitoring
Deliverables & Value
Certification letter + badge
Gap analysis + remediation roadmap
Board-ready NIST CSF maturity report
Insurance carrier submission package✓ Included✓ Included
Tenant disclosure documentation✓ Template✓ Full package✓ Full package
Carrier premium discount eligible✓ Eligible
Public portfolio badge display rights✓ Yes
Dedicated quarterly advisory support✓ Included

Deliverables

EVERY ASSESSMENT
PRODUCES A WORKING DOCUMENT

Certification isn't the end, it's the benchmark. Every tier produces actionable outputs your team can put to work immediately.

📋
Gap Analysis Report

A structured assessment of your building's current controls against the tier standard. Every gap is categorized by severity, mapped to a control domain, and linked to a remediation recommendation.

Bronze Silver Gold Platinum
🏆
Certification Letter & Badge

A signed certification letter for your property, a digital badge for tenant materials and marketing, and a listing in the CRE Cybersecurity Institute public building registry, verifiable by tenants, investors, and insurers.

Bronze Silver Gold Platinum
🗺️
Remediation Roadmap

A 12-month execution plan sequencing remediation items by risk priority and implementation complexity. Built for your team, not for a consultant to bill against. Quick wins in the first 30 days, strategic items across the year.

Bronze Silver Gold Platinum
📊
NIST CSF 2.0 Maturity Report

A board-ready maturity assessment mapped to all six NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) with current-state scores, target-state recommendations, and a visual maturity heatmap.

Gold Platinum
🔒
Insurance Carrier Package

Gold-B produces a documentation package structured to satisfy most cyber insurance underwriting questionnaires. Includes control evidence summaries, assessment findings, and a standardized security posture declaration signed by the assessor.

Gold Platinum
🤝
Tenant Trust Documentation

Silver and above produce templated tenant documentation, a one-page building security summary designed for RFP responses and lease addenda, and a full disclosure package for institutional tenants requiring documented security posture.

Silver Gold Platinum

Assessment Process

FROM KICKOFF TO
CERTIFIED

01
Kickoff & Scoping

30-minute call to confirm building scope, relevant systems, and documentation required for your tier

Week 1
02
Questionnaire & Evidence

Structured questionnaire covering all controls for your tier. You submit supporting documentation, network diagrams, policies, vendor contracts

Weeks 1–3
03
Verification Review

Assessor reviews documentation and, for Silver and above, conducts a technical verification. Platinum includes on-site or remote red team engagement

Weeks 3–6
04
Report & Certificate Issued

Gap analysis, remediation roadmap, and all tier deliverables delivered. Certificate and digital badge issued. Building listed in public registry

Certificate issued

Why Organizations Certify

THE BUSINESS CASE
FOR EACH USE CASE

📉
Insurance Premium Reduction

Cyber insurers are increasing CRE premiums in response to OT/BAS incidents. Gold-B and Platinum-B documentation satisfies most underwriting questionnaires and signals a mature posture at renewal. Early carrier conversations have been strongly positive on premium impact.

Gold-B +
Platinum-B eligible for carrier discount program
🏢
Institutional Tenant Due Diligence

Law firms, financial services companies, technology tenants, and government contractors increasingly include cybersecurity requirements in RFPs and lease addenda. A B Series certification letter is a concise, third-party-verified answer, faster to produce and more credible than an internal security summary.

58%
of enterprise RFPs now include cybersecurity requirements
📈
Investor & Lender Confidence

Institutional investors and lenders are beginning to ask about cyber risk as part of property due diligence. A building certification provides a structured, repeatable answer, and demonstrates that cyber risk is managed proactively rather than reactively after an incident.

Growing
LP and lender cybersecurity due diligence requirements
🛠️
Structured Remediation

Most CRE organizations don't know exactly where their building security gaps are, or how to prioritize fixing them. The assessment process itself produces the gap analysis and remediation roadmap that most internal teams lack the framework to build independently. The certificate is the output; the roadmap is the value.

All tiers
Include actionable remediation roadmap

Who Certifies

RIGHT TIER FOR
EVERY ORGANIZATION

01
REITs & Institutional Owners

Publicly traded REITs and institutional portfolio owners certifying flagship assets for investor and board reporting. Typically Gold-B or Platinum-B for top assets.

Gold-B for NIST CSF board reporting
Platinum-B for flagship Class A assets
Bronze-B or Silver-B for the broader portfolio
SEC cyber disclosure documentation
02
Private Operators & Managers

Private CRE firms and third-party managers certifying individual properties to differentiate with institutional tenants, satisfy lease requirements, and leverage at insurance renewal.

Bronze-B or Silver-B as entry points
Tenant RFP cybersecurity response
Insurance renewal documentation
Competitive differentiation in Class A leasing
03
Single-Asset Owners

Single-asset or small portfolio owners who want a structured assessment of their building's cyber posture and a clear remediation plan, without needing to build an internal security program from scratch.

Bronze-B to establish a baseline
Gap analysis drives remediation priority
Tenant trust documentation for key tenants
Path to Silver-B over 12 months

Annual Renewal

CERTIFICATION STAYS
CURRENT

Building certifications renew annually via a controls verification review, not a full re-assessment. Lower ongoing cost once the foundational work is done.

Bronze-B
Scoped to portfolio
Document review + 30-min verification call. Confirm controls remain in place. No new questionnaire.
Silver-B
Scoped to portfolio
Document review + spot-check technical verification. Confirm new pen test completed. Updated tenant disclosure.
Gold-B
Scoped to portfolio
Controls review + updated NIST CSF maturity scoring. Confirm MDR and NDR still active. Updated insurance package.
Platinum-B
Scoped to portfolio
Full annual re-verification including red team planning, updated maturity report, and advisory review session.

Common Questions

BUILDING CERT FAQ

Assessment Process
Controls & Requirements
Business Value
Renewal
What does the assessment actually involve?+

Bronze and Silver begin with a structured questionnaire covering all required controls, followed by document review (network diagrams, policies, vendor contracts, patch reports). Bronze concludes with a 90-minute verification call. Silver adds a technical verification component, typically a network architecture review and configuration sample check. Gold and Platinum include additional technical verification; Platinum includes adversarial red team testing with OT/BAS systems in scope.

Do we need to be on-site, or is it remote?+

Bronze and Silver assessments are fully remote, questionnaire, document review, and verification call via video. Gold can be conducted remotely for most components with a remote technical review. Platinum typically includes at least one on-site visit for physical systems review and red team scoping, though the engagement is largely remote-capable.

What if we don't meet all requirements for our target tier?+

Most buildings don't pass on first assessment, that's expected. The assessment produces a gap analysis identifying what's missing. You have 90 days to remediate and resubmit documentation before the assessment fee is forfeited. If significant gaps exist, we'll recommend a lower tier as an interim certification while you work toward the target tier. Many buildings start at Bronze-B and advance to Silver-B within 12 months.

We use legacy OT systems. Can we still certify?+

Yes. Legacy OT systems, including Windows XP endpoints running BAS controllers, are common in the CRE environment and are explicitly part of the assessment framework. Controls like network segmentation, compensating controls, and monitoring are designed to address legacy systems that can't be patched. Bronze-B is specifically designed to be achievable without requiring OT hardware replacement.

Does the assessment scope include physical security systems?+

Physical access control systems (Lenel, Software House, etc.) and IP-connected surveillance systems (Avigilon, Milestone, Genetec) are included in Silver-B and above. They're treated as OT infrastructure, assessed for network exposure, credential hygiene, and patch status. Platinum-B includes physical security systems in the red team scope.

Will Gold-B actually reduce our insurance premium?+

We are actively working with cyber insurance carriers on a formal premium discount program for Gold-B and Platinum-B buildings. The Gold-B documentation package satisfies most carrier underwriting questionnaires and has been well-received in early carrier conversations. Until the formal program is established, the documentation package provides strong evidence for negotiations at renewal, several organizations have used it successfully to justify premium reductions.

Can tenants verify our certification?+

Yes. All certified buildings are listed in the CRE Cybersecurity Institute public building registry, verifiable by certificate number. Tenants can confirm tier, certificate date, and renewal status. The registry is designed to be referenced in RFP responses and lease addenda.

What triggers a full reassessment vs. a renewal review?+

Annual renewal is a controls verification review, not a full reassessment, it confirms that controls remain in place and documentation is current. A full reassessment is triggered when: (1) you're pursuing a higher tier, (2) a material change occurs to the building's IT/OT environment (major system replacement, significant network redesign), or (3) a material cybersecurity incident affects the certified building.

READY TO CERTIFY
YOUR BUILDING?

Start with Bronze-B, the fastest path to a structured gap analysis and a certified building. Most organizations are assessment-ready within two weeks of kickoff.

Questions? Email credentialing@cre-ci.com, we respond within one business day.