TL;DR
• Badges are the widest-distributing embeddable asset and the most abused. The tactic splits cleanly into two things that look identical and are opposites: a link scheme wearing a badge, and a genuine certification that happens to carry a link.
• The scheme version is not a grey area. Google’s spam policy names the exact mechanisms it relies on — requiring a link as part of a Terms of Service, and widely distributed links in templates and footers with keyword-rich anchors. A fake “award” that hands out followed, optimised links is a named violation with a badge for camouflage.
• The ethical discipline rests on one principle: the badge link is never the point. It should be nofollow and pass no PageRank by design. The value of a real certification programme is trust, referral, brand-entity distribution, and the editorial coverage the programme earns around itself.
• This article gives you the Certification Legitimacy Test: five gates — Real standard, Fail state, Verification, Link discipline, Revenue honesty — with the first two decisive. It works both ways: to design a legitimate programme, and to judge whether a badge you have been offered is a trap.
• The gold-standard pattern is a UK one. Cyber Essentials badges link to a verification register, so one click proves the badge is genuine. The link points to proof, not to a money page — which is exactly what makes it ethical and exactly why it is safe.
• Run a programme only if the certification is real. If nobody could ever fail it, it is not a certification; it is a link-distribution vehicle, and building one is building a scheme.
Of all the embeddable assets a brand can distribute, the badge travels furthest. A single certification mark can end up in the footers of thousands of recipient sites, each one carrying a link back to the issuer. That reach is exactly why badges have the worst reputation in link building — because the same mechanism that powers a legitimate trust mark powers the oldest link scheme on the web, and from a distance the two are indistinguishable. Getting this right is entirely a matter of telling them apart, in your own programme and in the ones you are invited to join. It is one of the more nuanced link-building strategies precisely because the line between ethical and manipulative is a handful of design decisions, not a category.
The distinction this guide draws is simple to state and easy to get wrong: a certification is a badge you earn by meeting a real standard, displayed to signal trust, with a link that points to proof. A badge-link scheme is an “award” invented to give people a reason to place a followed, keyword-rich link to the issuer’s site. Everything below is about staying firmly on the first side of that line — and recognising, quickly, when someone is trying to pull you onto the second. Get it right and a badge programme is among the most durable trust-and-distribution assets a brand can own; get it wrong and it is a manual action waiting to be issued, dressed up as a compliment.
Two things that look the same
Start with the abused version, because you have almost certainly received it. The email arrives unbidden: your business has been “selected” as a winner of the Best of [Your Town] award, or a five-star award for your software, or an industry “excellence” accolade you have never heard of. There were no entry criteria you met, no assessment, no possibility of not winning. The catch is always the same: to “claim” the award you display a badge, and the badge carries a link — often with a keyword-rich anchor — back to the awarding site. Sometimes there is a plaque to buy. The award exists to manufacture links and, secondarily, to sell trophies. It certifies nothing.
Now the legitimate version, and the contrast is total. Consider Cyber Essentials, the UK government-backed security certification overseen by the National Cyber Security Centre and delivered through IASME. An organisation earns it by meeting five defined technical controls, verified by self-assessment or, at the higher Plus tier, independent testing. It is annual. You can fail it. And the badge an organisation displays links to its entry on the IASME verification register — one click takes a visitor to proof the certificate is genuine. The link exists to verify, not to rank. Other genuine UK marks work the same way: the government-endorsed TrustMark scheme for home-improvement trades, with real standards and audits; B Corp certification for social and environmental performance; Red Tractor for food assurance. Each certifies something real, each can be failed, and each points its link at verification.
The single fastest tell
Can you fail it? A genuine certification has a standard you can miss and applicants who do not qualify. A scheme “selects” everyone who might place a link and rejects no one. If nobody ever fails, there is no standard being certified — only links being distributed. Every other difference flows from this one.
It helps to understand why this particular scheme has proved so durable. Badges exploit two real human tendencies at once: the desire for recognition, and the reflex to trust a mark of approval. That is why the fake-award email works on otherwise sensible business owners — winning feels good, and displaying the badge feels like marketing rather than manipulation. The tactic has survived for well over a decade, from the “five-star” download-site badges of the 2000s to today’s “best of” local-business rackets, precisely because it dresses a link request in the language of achievement. The abuse is old; what has changed is that Google’s naming of the mechanisms, and its improved detection, have made the followed-link version actively dangerous rather than merely tacky. The recognition can still be real. The links cannot be the reason.
Why the scheme version is a named violation, not a grey area
People treat badge links as an ethical grey zone. Google does not. Its spam policies name, by category, the precise mechanisms a badge-link scheme depends on. “Requiring links as part of a Terms of Service or other agreement” is listed as a link scheme — and “you must link back to display this badge” is exactly that requirement. “Widely distributed links in the footers or templates of various sites” is listed too — and a badge dropped into a thousand recipient footers is the textbook case. Add keyword-rich anchor text, which Google names separately, and a badge scheme manages to hit three named categories at once. There is no interpretation to argue about.
Be clear about who carries the risk, because it is asymmetric. In a badge-link scheme the issuer — the party who invented the award — is the intended beneficiary, accumulating thousands of followed, keyword-anchored inbound links from recipient sites. That concentrated, templated, identical-anchor inbound pattern is precisely what Google’s systems are tuned to catch, and the issuer is the one exposed to a manual action for an unnatural link profile. The recipient who displays the badge carries a smaller but real risk: an unnatural outbound link that marks their page as part of a low-quality pattern. If you are considering launching a programme to “get links at scale,” you are volunteering to be the issuer — the party the enforcement is aimed at. For anyone already caught on either side, the remedy is the ordinary one: nofollow or remove the offending links, then pursue manual-action recovery through a reconsideration request.
The “requiring a link” clause deserves a moment, because it is where well-meaning programmes stumble. It is tempting to write “by using this badge you agree to link back to us” into your terms — it feels like fair exchange, credit for a mark. But that exact sentence is the thing Google lists as a scheme, and it converts an honest trust mark into a manufactured link the instant it appears. The fix is simple and costs you nothing real: offer the badge freely, provide an embed with a nofollow verification link, and let recipients display it because it helps them, not because your terms compel it. A link a recipient places voluntarily is worth more to you in every way that survives scrutiny than one you extracted by contract.
The reframe: the badge link is never the point
Here is the shift that makes an ethical programme not just safe but better. The badge link should be nofollow, passing no PageRank by design — so if the link is where you expected the value, an ethical programme looks worthless. It is not, because the value was never in the badge link. It is in four other things, every one of which a real certification produces and a scheme cannot.
- Trust and conversion. A recognised mark on a recipient’s site raises confidence and conversion for them — which is why they display it voluntarily — and builds the issuer’s authority as the body that sets the standard.
- Referral traffic. The verification link sends real people from recipient sites to the issuer’s register and programme pages. Nofollow does nothing to referral clicks.
- Brand-entity distribution. A mark appearing across many trusted sites teaches the web — and Google’s Knowledge Graph — that your brand is the source of a standard. That entity association is durable and is a genuine ranking asset in 2026, even though no single badge link carries PageRank.
- Editorial coverage. A credible certification earns writing about it: journalists and bloggers explaining the standard, recipients announcing they achieved it, directories listing certified organisations. Those editorial links — placed by others, in their own words — are followed, natural, and are the real SEO payoff. The programme provokes them; the badge link never had to carry anything.
It is worth dwelling on how different these returns are from what the scheme chases. A followed badge link is a static, identical, template-placed transfer of a little PageRank — and at scale it is a net negative, because the pattern is what draws enforcement. An editorial mention of your certification, a referral relationship, an entity association: these are compounding, defensible assets that grow as the programme matures and that no competitor can fake by inventing their own award. The scheme optimises for the one return that is both smallest and most dangerous, and forgoes the four that actually matter. Choosing the ethical model is not a sacrifice made for safety’s sake; it is choosing the better returns and declining the worse one.
This maps onto how Google treats the attributes in 2026. Nofollow, sponsored and UGC are hints, not absolute directives — Google may still use a nofollow link to understand entities and the shape of the web, which is why a nofollow mark from an authoritative recipient still contributes to your brand’s standing. But you never build on that; you treat the badge link as carrying zero ranking credit and let the editorial links and entity signals do the work. If the difference between a followed and nofollowed link feels load-bearing to your plan, our primer on nofollow value and trust signals in the 2026 data is worth a read before you build anything.
Three legitimate badge models (and how each earns its links)
“Badge” covers several distinct arrangements, and they do not share a risk profile. Sorting yours into the right model clarifies both the ethical discipline and where the value legitimately comes from.
| Model | What it is | Where the value legitimately sits |
| Third-party certification you earn | You meet an external standard (Cyber Essentials, B Corp, ISO) and display its badge | Trust and conversion on your site, plus referral; you are the recipient, so risk is minimal if the mark is genuine |
| A certification you run for others | You set a real standard and certify qualifying organisations, who then display your badge | Entity authority, editorial coverage of the standard, and referral — never the nofollow badge links themselves |
| Review / marketplace badges | A platform (a review site, a marketplace) issues badges based on verified customer data | Social proof and conversion; the badge links to the live profile, so it verifies by nature and is honest by design |
The pattern across all three is identical: the badge certifies something a third party can verify, and the link points at that verification. The first model is the one most brands live in, and it is nearly risk-free because you are simply displaying a mark you earned. The second is the one that carries the scheme risk and therefore the discipline, because you become the issuer whose inbound links accumulate. The third is honest almost by construction, because a review or marketplace badge links to a live profile whose data proves the claim — there is nothing to fake. What none of the three does is treat the badge link as a PageRank pipe; the moment a model depends on that, it has left this table and become a scheme.
The Certification Legitimacy Test
The Legitimacy Test scores a badge programme across five gates. Use it in both directions: to check that a programme you are designing is a real certification rather than a scheme, and to judge whether a badge you have been offered is worth displaying or a trap to decline. Score each gate 0 (scheme-like), 1 (weak) or 2 (genuine) — but the first two gates are decisive: fail either Real standard or Fail state and the programme is a link scheme regardless of the rest.
| Gate | The question | Genuine (score 2) when… |
| 1. Real standard (decisive) | Is there a published standard with criteria a recipient must actually meet, and an assessment? | There are explicit, public criteria and a real evaluation — not “you were selected” with no basis |
| 2. Fail state (decisive) | Can an applicant fail? Are there organisations that do not qualify? | Failing is genuinely possible and happens; the mark means something because not everyone gets it |
| 3. Verification | Does the badge link to independent proof the recipient holds it? | The link points to a register or certificate that proves the badge is current and real |
| 4. Link discipline | Is the badge link nofollow, branded or verification-pointing, and never required to display the mark? | Nofollow, no keyword anchor, and displaying the badge is not conditional on giving a link |
| 5. Revenue honesty | If money changes hands, is it for assessment and administration, not for the “award” itself? | Fees cover real evaluation; there is no plaque-selling or pay-to-win mechanic |
Read the result plainly. Fail either decisive gate and no total can rescue it — a badge with no standard and no fail state is a link scheme, and you should neither run it nor join it. Pass both decisive gates and the remaining three tell you how well-built the programme is and where to tighten it. A vanity-award email scores 0 on gates 1 and 2 before you finish reading it; Cyber Essentials scores 2 across all five. Most real decisions sit in between, and the test tells you exactly which gate needs work. Running this same audit across your competitors’ badge links with a competitor backlink analysis also reveals which of their trust marks are load-bearing and which are vanity-award noise that will not survive scrutiny.
If you run a badge or certification programme
The issuer carries the scheme risk, so the issuer carries the discipline. Six rules turn a programme from a liability into a genuine trust asset, and they are the operational form of the Legitimacy Test.
- Certify something real, with a fail state. Publish criteria, assess against them, and be willing to reject applicants who do not meet them. This one decision is what makes everything downstream legitimate.
- Make the badge link nofollow. Bake rel=“nofollow” into the embed code you provide. You give up a PageRank benefit you should not have been relying on, and you protect every recipient — and yourself — from an unnatural-link pattern at scale.
- Point the link at verification, not a money page. The link should resolve to the recipient’s certificate or register entry, proving the badge is genuine, not to your commercial landing page. This is the Cyber Essentials model, and it is the single clearest signal that your programme certifies rather than manipulates.
- Never require the link. Displaying the badge must not be conditional on a backlink. Requiring a link in your terms is a named link scheme; offer credit, never compel it.
- Use branded, non-keyword anchors and alt text. The mark’s name or your brand — never “best [service] in [city]”. Keyword-rich anchors distributed across recipients are the fastest route to a manual action.
- Ship a clean, honest embed. One visible, removable badge; no hidden second link; lightweight and accessible. Make it trivial for a recipient to display correctly.
The two embeds side by side make the whole distinction concrete. First, the version that is a scheme:
Do NOT distribute — followed, keyword-rich, points to a money page:
<!– scheme: the ‘award’ exists to place this link –>
<a href=”https://issuer.example/best-plumber-london”>
best plumber London 2026 award winner</a>
Now the ethical version — same badge, distributed just as widely, no scheme:
Distribute this — nofollow, branded, links to verification:
<!– ethical: the link proves the badge is genuine –>
<a href=”https://certifier.example/verify/your-org-id”
rel=”nofollow”>
<img src=”https://certifier.example/badge/basic.svg”
alt=”Certified: Example Standard (verify)”
width=”120″ height=”48″ loading=”lazy”>
</a>
Running a real certification is not free, and that cost is the point — it is what keeps the programme honest. Assessing applicants against a genuine standard takes people and time; a serious programme is an operating cost, not a link-farming shortcut. If you are not prepared to fund real evaluation, you are not building a certification, and you should not build it at all. As with any distributed asset, apply an honest kill test: if, after a genuine launch, almost no qualifying organisation chooses to display your badge, the mark carries no trust and the programme has failed at its actual job. Do not prop it up by making the link mandatory or the criteria trivial — that only converts a failed trust asset into a live sponsorship-style arrangement masquerading as a standard. Retire it instead.
One operational detail is easy to underestimate: the verification destination is something you have to build and maintain, not an afterthought. Each certified organisation needs a stable page — a register entry or certificate URL — that a visitor can reach in one click to confirm the badge is current and real. That page is what makes the link honest, and it is also what protects your recipients, because a badge that resolves to living proof cannot be misused by a lapsed or fraudulent holder. Keep it accurate: when a certification expires or is revoked, the verification page must say so. A programme whose badges outlive their verification is one that has quietly stopped certifying anything, and the drift usually starts on the day the register stops being maintained.
If you display someone else’s badge
Most brands are on the receiving end far more often than the issuing end, and the discipline here is mostly about judgement. When you earn a genuine certification, display it with confidence: link it to your verification page so visitors can confirm it, keep it where it aids trust (a footer, an about or trust page, near the checkout), and do not worry about the nofollow — a well-run programme has already handled that in its embed. Linking out to a legitimate certifier is a natural, honest act, the web equivalent of citing your source.
The judgement you actually need is upstream: telling a real certification from a vanity-award trap before you accept it. Run the Legitimacy Test in reverse on any “you’ve won” email. Did you meet published criteria, or were you simply “selected”? Could you have failed? Is there a fee to “claim” it or a plaque to buy? Does the badge want a followed, keyword-rich link to a commercial page rather than a verification page? Two or three yeses and it is a link scheme soliciting you — decline it, and do not place the link. Displaying a fake award does nothing for your credibility with informed customers and quietly enlists your site into someone else’s manipulation.
If you have already placed such links — many sites have, often years ago and forgotten — treat it as routine hygiene. Find them by auditing your outbound links in your backlink and site-audit tools, then nofollow or remove the links to any “award” that fails the Legitimacy Test. It is the same clean-up discipline you would apply to old guest-post links with over-optimised anchors, and it is rarely urgent — but it is worth doing before an audit, not after.
One further recipient nuance, for brands that hold several genuine certifications: displaying many real badges is fine and often valuable, but keep them proportionate and grouped where they aid trust rather than scattered as a wall of logos in a sitewide footer. A tidy trust or about page that gathers your genuine marks — each linking to its verification — reads as credibility; a footer stuffed with a dozen badges on every page reads as anxiety, and a template-wide block of outbound badge links is the one recipient-side pattern that can start to look unnatural. Genuine marks, sensibly placed, linked to proof: that is the whole of the recipient’s job.
The ethical distribution discipline, at a glance
| Do | Don’t |
| Certify a real, published standard applicants can fail | Invent an “award” everyone wins to justify a link |
| Make the badge link rel=“nofollow” | Distribute followed, PageRank-passing badge links at scale |
| Point the link at a verification register or certificate | Point the link at a commercial or keyword-targeted page |
| Offer the badge freely; credit is optional | Require a backlink as a condition of displaying the badge |
| Use branded or mark-name anchors and alt text | Use keyword-rich anchors like “best [service] in [city]” |
| Measure trust, referral, entity and editorial coverage | Measure the raw count of distributed badge links |
Measuring a badge programme honestly
Because the badge link is nofollow, the obvious metric — how many sites display your badge — is the one that misleads. A high badge count with no trust behind it is exactly what a vanity award produces, so counting badges measures the wrong thing and flatters the scheme version. Track instead the returns the reframe identified: the editorial referring domains that link to your programme in their own words, the referral traffic the verification links send, the growth in branded and “[standard]-certified” search demand, and how often your standard is named as a source in AI answers about your field. Point your analytics and backlink tools at those signals, not at the badge tally. A programme with fifty badges and a dozen genuine editorial mentions is healthier than one with five thousand badges and none, because the twelve mentions are the followed, earned links that actually compound.
There is a useful diagnostic hidden in the numbers. If recipients display your badge but nobody ever writes about your standard, the certification is probably too easy or too obscure to be worth remarking on — a signal to raise the bar or explain the standard better, not to chase more badges. If, conversely, the editorial coverage runs ahead of the badge count, the standard is respected and the programme is working exactly as intended. The metrics that matter are the ones a scheme cannot fake, which is precisely why they are the ones to watch.
Set a review point a year out and ask one blunt question: if the badge links had never passed any ranking value at all — which, built correctly, they never did — would the programme still have been worth running? For a genuine certification the answer is an easy yes, because the trust, referrals, coverage and entity authority all stand on their own. If the honest answer is no, the programme was only ever a link scheme you had told yourself was something else, and the review is the moment to stop and rebuild it around a standard that means something.
Notice that every row reduces to the same underlying question the Legitimacy Test asks: is the badge certifying something, or distributing something? The left column describes a mark that certifies and lets the certification earn its own recognition; the right column describes an award manufactured to move a link. If you can hold that single distinction in mind, you do not really need to memorise the rows — each “do” and “don’t” is just the same principle applied to a different decision. And it scales down as neatly as it scales up: the test is identical whether you are a global standards body or a small brand deciding whether to display the badge that landed in your inbox this morning.
A worked example: an ethical UK certification programme
Take an anonymised case. A UK B2B software firm serving the property sector wants a badge programme, having noticed how many links competitors seem to farm through “top proptech” awards. Instead of inventing an award, it builds a genuine certification: a published standard for data-handling and integration quality that partner apps must meet, assessed by the firm’s team, renewed annually, with a real possibility of failing. That single decision routes the whole programme onto the ethical side of the line.
Run the Legitimacy Test. Real standard: published criteria and an assessment — score 2. Fail state: partners genuinely fail and must remediate — score 2. Both decisive gates pass, so this is a certification, not a scheme. Verification: each certified partner’s badge links to a page on the firm’s site confirming the partner’s current status — score 2. Link discipline: the embed is rel=“nofollow”, the anchor is the certification’s name, and display is never conditional on a link — score 2. Revenue honesty: a modest assessment fee covers the real evaluation work, with no plaque to buy — score 2. A clean pass on all five.
Now watch where the value actually comes from, none of it from the badge links themselves. Certified partners display the mark because it helps them win deals, sending referral traffic to the firm’s verification pages. Trade publications write about the new standard and name the firm as its author — followed, editorial links the programme provoked. A directory of certified partners becomes a resource others cite. Over a year, the firm becomes the recognised entity behind “[standard]-certified” in its niche, and answer engines begin naming it when asked who sets the bar. The nofollow badges distributed the trust; the editorial coverage, referrals and entity authority are the payoff. Contrast the counterfactual: had the firm run the “top proptech award” its competitors run, it would have collected followed keyword links, an unnatural inbound profile, and a manual-action liability — more links, and less of everything that matters. The ethical version is not the compromise. It is the stronger play, which is the theme understanding what link building is really for keeps returning to.
Play it forward and the compounding is visible. Each annual renewal cycle refreshes the coverage and adds newly certified partners; each partner who wins a deal partly on the strength of the mark has a reason to keep displaying it and to tell others; the standard itself becomes a small piece of category infrastructure that the firm owns. Now change one variable to see how thin the margin of discipline is: if the firm had quietly made certification automatic for any paying partner — removing the fail state to grow the badge count — every downstream benefit would collapse. The coverage would dry up because there would be nothing worth writing about, the trust would evaporate the first time a certified partner disappointed a customer, and the inbound links would start to look like what they had become: a scheme. The entire value chain hangs on the one decision to let applicants fail.
The bottom line
Badge and certification programmes can distribute links across the web at a scale almost nothing else matches — and they can do it ethically, but only by giving up the one thing the scheme version is built to steal: the followed, keyword-rich link. Make the badge link nofollow, point it at verification, never require it, and certify something an applicant can genuinely fail. Do that, and the programme earns its keep through trust, referral, entity authority and editorial coverage, which are worth more and cannot be penalised.
The test at the centre of all of it is the one you can apply in a sentence: can you fail it? If the answer is no, you are not looking at a certification — you are looking at a link scheme with a badge for a disguise, whether you are being invited to join one or tempted to build one. Certify something real, credit it honestly, and let the mark travel. Distribution at this scale is a privilege that belongs only to programmes that actually mean something.
