The badge states that a report of factual findings exists and leads to the page where anyone can verify its identity. It carries no rating, no score, no maturity level and no expiry date, because the report produces none.
Variant
Preview
The code to paste
Paste it where you want the badge to appear, usually the footer or an about page. It loads no script and sets no cookie.
In your footer, where it stays visible without taking attention.
On the page describing your governance, your compliance or your approach.
In a tender response, as an image, with the reference legible.
Next to a checkout button or a payment form. The report says nothing about your security or your payments, and placing it there makes it say what it does not.
On a page describing a scope other than the report's. The badge points to the agreed scope, which is named on the verification page.
Three rules, and they are not courtesies
Only display the badge of a report you hold. The verification page names the organisation; a badge placed by a third party still leads there, and the discrepancy shows.
Do not modify the image. It is served from our address and updates on its own; a copy saved on your side stops following.
Check that the link works before publishing, by clicking it from your own page.
What makes it disappear
The badge stops leading to a valid page if the report is withdrawn. We withdraw a report in two cases only: at your written request, or if we establish that it has been presented as attesting something other than what it attests. In both cases you are told beforehand.