CIFSO 5000 Certification
The independent standard for certifying the value and transferability of organisations
AEGRYN. INDEPENDENT CERTIFICATION BODY. SWITZERLAND
The independent standard for certifying the value and transferability of organisations
AEGRYN. INDEPENDENT CERTIFICATION BODY. SWITZERLAND
CIFSO 5000
5
dimensions assessed
100
scoring points
5
grade levels
12
months of validity
01
Existing standards certify systems and processes. CIFSO 5000 is a quality audit of the valuation of a company's assets: it certifies the value and transferability of an organisation.
A company can be fully compliant operationally and still be difficult to value, finance or transfer. Like a collector's watch without its papers, it loses part of its value for lack of proof. CIFSO 5000 closes this gap: it is the title deed of the organisation's value. It independently and verifiably documents what constitutes its real value: its code and architecture, its rights, its financial health, its security and sovereignty (including its exposure to third-party AI solutions), its organisational resilience. And it sets the reference value with the CIFSO Valuation Index as the source.
The result is an official, versioned and defensible grade that can be presented to investors, acquirers, banks, partners or successors as third-party proof of the organisation's quality and transferability.
Why CIFSO 5000 Certification?
Existing standards certify systems and processes. CIFSO 5000 certifies value and transferability. These are two different, complementary objects, not competitors.
02
CIFSO 5000 is designed for executives and shareholders who need to demonstrate, defend or transfer the value of their organisation.
Objectify the value built, prepare a sale or fundraising, and structure succession.
Secure a succession and arbitrate between heirs or partners on an independent, documented basis.
Obtain a third-party assessment of organisational quality before, during and after the investment.
Reduce information asymmetry, accelerate due diligence and make price negotiation more reliable.
Complement financial analysis with a structured reading of organisational risk and resilience.
Compare subsidiaries or targets on a homogeneous, auditable scale.
03
A CIFSO 5000 grade turns internal convictions into external evidence.
A grade issued by an independent body carries more weight than any internal presentation.
A documented, transferable organisation negotiates better: less uncertainty discount, fewer warranties required.
The certification report pre-structures the information expected by acquirers and investors.
Each scored dimension identifies concrete levers to progress to the next grade.
The grade can be communicated in tenders, partnerships and banking relationships.
Certification proves the organisation does not depend on a single person and can be taken over.
04
CIFSO is the acronym of the five dimensions assessed. Each is weighted and scored against documented criteria.
Each asset is assessed across four independent dimensions, each scored from 0 to 25 points. The total score out of 100 determines the grade.
Code & Architecture
Weight
20 pts
Source code quality, architecture, test coverage, technical debt, dependencies, documentation. What makes the asset transferable without its author. Reviewed by senior engineers.
Criteria assessed
IP & Rights
Weight
20 pts
Trademark, software rights assignment, open-source licences, client and supplier contracts, disputes. The chain of title: what an acquirer checks first.
Criteria assessed
Finances & Metrics
Weight
20 pts
ARR, MRR, recurrence, churn, margins, cash flow, client concentration, growth history. All data verified against documents.
Criteria assessed
04. The methodological framework: five dimensions
Security & Sovereignty
Weight
20 pts
GDPR and LPD compliance, infrastructure security, access management, third-party audits, and AI exposure: provider inventory, sovereignty of data shared, client protection. Real control of assets and data.
Criteria assessed
Organisation & Talent
Weight
20 pts
Founder dependency, leadership team quality, succession plan, process documentation, transfer capacity. A company too dependent on its founder trades 20 to 30% below its intrinsic value.
Criteria assessed
C
20 pts
I
20 pts
F
20 pts
S
20 pts
O
20 pts
05
Five levels, from the exceptional AEG ★ grade to grade B. Each grade corresponds to an organisational profile and a precise score range.
| Grade | Score | Rarity | Profile |
|---|---|---|---|
| AEG ★ Exceptional | 90–100 / 100 | < 5% of certified assets | Exceptional asset. Reference architecture, strong IP, top-decile financial metrics, perfect compliance. Eligible for institutional transactions. |
| AAA Excellent | 75–89 / 100 | 10–15% of certified assets | High-quality asset with solid fundamentals across all four dimensions. A few documented improvement areas but not blocking. |
| AA Solid | 60–74 / 100 | 25–30% of certified assets | Good quality asset with identified strengths and clearly documented improvement areas. Eligible for standard M&A processes. |
| A Developing | 45–59 / 100 | 30–35% of certified assets | Developing asset with identifiable potential but structural weaknesses to address. Eligible for Aegryn Review with remediation plan. |
| B Emerging | 30–44 / 100 | 15–20% of certified assets | Early stage asset with partial fundamentals. Certification accompanied by a detailed remediation report. Not eligible for M&A without improvement. |
06
Six structured steps, each with defined inputs, deliverables and outcomes. The process is identical for every certified organisation.
File reception, completeness verification, and pre-qualification within 5 business days.
Inputs
Submission form, data room, financial statements (last 2 years), IP register, key contracts, org chart, codebase access if applicable
Outputs
Pre-qualification letter confirming scope, timeline, and any missing items
Outcomes
Qualified file and established audit schedule. Incomplete files are returned without grading.
In-depth analysis of Code & Architecture and Security & Sovereignty by two certified senior analysts.
Inputs
Source code, IP documentation (patents, trademarks, licenses), security policies, vulnerability scan reports, GDPR register, cloud architecture
Outputs
Technical audit report with C and S scores, critical vulnerability identification, IP chain-of-title verification
Outcomes
Objective assessment of code quality, IP ownership, and cybersecurity posture according to EU standards (NIS2, DORA, GDPR).
Financial metrics verification and governance integrity audit.
Inputs
Accounting records, ARR/MRR documentation, cap table, shareholder agreements, client contracts, regulatory filings, dispute history
Outputs
Financial audit report with F and I scores, client concentration analysis, regulatory and contractual compliance verification
Outcomes
Validation of financial transferability, cap table integrity, and regulatory compliance. Reliable basis for valuation.
06. The certification process
Assessment of organizational resilience, management depth, and succession readiness.
Inputs
Detailed org chart, key-person contracts, succession plan, management team CVs, retention data, structured interviews with founder and key managers
Outputs
Organizational audit report with O score, founder dependency assessment, key-person risk analysis
Outcomes
Identification of operational continuity risks and organizational strengthening levers. Most undervalued dimension in transactions.
Both analysts deliberate following a reproducible protocol and produce the independent certification report.
Inputs
All previous audit reports (C, I, F, S, O), CIFSO 5000 scoring grid, deliberation protocol
Outputs
Complete certification report with official grade (★ to B), detailed sub-code table per dimension, quantified improvement recommendations
Outcomes
Objective and reproducible grade. Protocol requires agreement within ±1 sub-code. Discrepancy triggers independent arbitration.
Official CIFSO 5000 certificate issuance and publication in the Aegryn certified registry.
Inputs
Validated certification report, certified organization identity, chosen certification format (Express/Standard/Premium)
Outputs
Official CIFSO 5000 certificate, digital badge, public registry entry, certified portal access
Outcomes
Certified organization with versioned grade viewable by qualified investors, acquirers, and partners. Validity: 12 months.
07
From submission to grade issuance, certification takes 15 to 35 business days depending on the size and complexity of the organisation.
Engagement letter signature, document file transmission, scoping interview with management.
Document review, interviews with key functions, cross-checks and additional requests.
Scoring of the five dimensions by the lead analyst, independent review by a second analyst, arbitration if divergent.
Report presentation to management, factual comments period, issuance of the versioned certificate.
Certification process
From submission to grade issuance: 15 to 35 business days depending on the size and complexity of the organisation.
Timelines run from receipt of a complete file. Organisations with structured documentation typically fall in the lower range.
08
Certification produces a set of deliverables designed to be shared with your stakeholders.
Versioned document stating the grade, score, issue date, validity date and unique verification identifier.
Detailed analysis of the five dimensions, scoring by criterion, findings, strengths and areas of vigilance.
Prioritised recommendations to progress to the next grade, with estimated score impact.
Grade badge, authorised wording and usage guidelines for your materials, tenders and data rooms.
Public verification page allowing any third party to confirm the authenticity and validity of the grade.
09
A CIFSO 5000 grade is valid for 12 months from its issue date. Beyond that, it is displayed as expired on the verification page.
A CIFSO 5000 grade is valid for 12 months from its issue date. Beyond that, it is displayed as expired on the verification page.
Renewal follows a streamlined process if documentation is kept up to date. Any significant change (change of control, restructuring, major incident) may warrant early reassessment.
Every grade is versioned. Any revision generates a new version with full traceability; the original grade remains accessible.
The certified organisation has 15 days to submit factual comments. A reasoned appeal triggers a review by an analyst who did not take part in the initial assessment.
10
The value of a grade rests entirely on the independence and rigour of those who issue it.
Each assessment is led by a lead analyst trained in the CIFSO 5000 protocol and bound by a code of ethics.
A second independent analyst systematically reviews the scoring before any grade is issued.
Any financial, commercial or personal link with the assessed organisation leads to the analyst's recusal.
Aegryn does not certify an organisation it advises on the assessed scope.
11
CIFSO 5000 replaces no existing standard. It assesses a different object.
| Standard | Certified object | Question answered |
|---|---|---|
| ISO 9001 | Quality management system | Are processes under control? |
| ISO 27001 | Information security | Is information protected? |
| Financial audit | Annual accounts | Are the accounts true and fair? |
| CIFSO 5000 | Organisational value and transferability | Is the organisation worth what it claims and can it be transferred? |
Existing certifications are valuable inputs to the CIFSO 5000 assessment and generally strengthen the score of the relevant dimensions.
12
Submit your organisation and receive your official grade within 15 to 35 business days.