SMB1001 explained: the Australian cyber certification built for small business

A few years ago the cyber security section of a tender or supplier questionnaire was a tick box. Now it is often a direct question: do you hold a recognised cyber security certification? For most small and medium businesses the answer has been no. ISO 27001 is a large, expensive project, and the Essential Eight gives you a maturity level to work towards but no certificate to show anyone.

SMB1001 was written to fill that gap. It is an Australian standard built for smaller organisations, with five tiers you can certify against one step at a time. This guide covers what it is, what each tier asks for and what it costs. It also covers what a certificate proves, what it does not prove and how to decide whether it is worth doing for your business.

What is SMB1001?

SMB1001 is a cyber security standard published by Dynamic Standards International (DSI), an Australian standards body. The first edition came out in 2023 and DSI revises it every year. The current version, SMB1001:2026, was released in late 2025 and businesses have been certifying against it since January 2026.

It is organised into five tiers: Bronze, Silver, Gold, Platinum and Diamond. Each tier includes everything in the tier below and adds more controls. The controls are grouped into five areas. Three are technical: technology management, access management plus backup and recovery. The other two cover people and paperwork: education and training, and policies and processes.

Certification is issued through CyberCert, the platform that runs SMB1001 certification. One point up front: SMB1001 is a private standard. It is not written or endorsed by the Australian Signals Directorate (ASD), and it is not named in the Cyber Security Act 2024 or the critical infrastructure rules. That does not make it less useful. It does change what it can and cannot prove, which we come back to below.

The five SMB1001 tiers at a glance

The five SMB1001 tiers from Bronze to Diamond, showing that Bronze, Silver and Gold are self attested by a director and Platinum and Diamond need an independent audit
The big dividing line is between Gold and Platinum: the first three tiers are signed off by a director, the top two are audited.

The most important line in SMB1001 is not between any two tiers. It is between Gold and Platinum. Bronze, Silver and Gold are self attested, which means a company director confirms the controls are in place and signs for it. Platinum and Diamond require an independent audit.

  • Bronze covers the basics every business should already have: a named IT support provider, a firewall, antivirus, automatic software updates and backups. The 2026 edition moved cyber awareness training down into Bronze as well.
  • Silver tightens access and email security, including SPF records, which tell other mail servers which systems are allowed to send email on your behalf.
  • Gold is where most businesses aim. It now covers 27 controls. The 2026 edition brought endpoint detection and response (EDR), full email authentication (DKIM plus a DMARC policy set to quarantine or reject) and a formal AI use policy into Gold.
  • Platinum adds independent verification and further controls, such as multi factor authentication on remote access.
  • Diamond is the top tier and brings in controls such as application control and restrictions on Office macros.

These are examples, not the full control list. If you are working towards certification, work from the current edition of the standard, because controls move between tiers from one year to the next.

What does SMB1001 certification cost?

There are two costs: the certification fee and the work to meet the controls. The fee is the small one.

At the time of writing, CyberCert's fees start at $95 a year for Bronze and sit at around $395 a year for Gold. Platinum and Diamond were listed at roughly $3,600 and $6,000 a year (excluding GST, April 2026 pricing). Check cybercert.ai for current fees. There have also been free offers at the lower tiers, including free Bronze certification for the first 50,000 businesses in late 2025, and free Bronze and Silver for small businesses coming through the Cyber Wardens program.

The real cost is the uplift. If you already have MFA on every account, EDR on every device, tested backups and managed patching, getting to Gold is mostly a matter of closing a few gaps, writing down the policies you already follow and collecting evidence. If you are starting from a flat network, a shared admin password and backups nobody has tested, expect a few months of work and some new licensing before a director can sign in good conscience.

Certificates last 12 months. Because the standard changes every year, renewal means checking your controls against the new edition, not just paying the fee again.

What a certificate proves, and what it does not

This is the part most SMB1001 marketing skips.

What it proves. From Bronze to Gold, a director has put their name to a specific set of controls being in place. At Platinum and Diamond, an independent auditor has checked. It gives you a short, credible answer to the cyber question in questionnaires and tenders, and a structured path to follow instead of a vague instruction to "improve security". Industry bodies are starting to point members to it. The Queensland Law Society supports SMB1001 and recommends its members work towards Gold.

What it does not prove. Gold is self attested, so nobody outside the business checks the controls unless something goes wrong. It is also not a substitute for the Essential Eight. Application control and Office macro restrictions are both Essential Eight Maturity Level 1 strategies, and in SMB1001 they do not appear until Diamond. A Gold certificate does not mean you meet Maturity Level 1. As of April 2026, no Australian insurer was publicly listing SMB1001 as a premium discount, although a certificate is useful evidence when you fill in an insurance questionnaire. Even the Queensland Law Society is careful to say certification does not create a safe harbour.

Our view: treat the director's attestation like a statutory declaration. A certificate signed over controls that are not in place is worse than no certificate, because it is one of the first documents anyone will ask for after an incident.

SMB1001 vs Essential Eight vs ISO 27001

SMB1001Essential EightISO 27001
Who writes itDynamic Standards International, a private Australian standards bodyAustralian Signals Directorate (Australian Government)International Organization for Standardization
What you end up withA certificate at your chosen tierAn assessed maturity level (ML1 to ML3), no certificateA certificate after an external audit
Who checks itA director self attests up to Gold; an independent auditor at Platinum and DiamondSelf assessment or an independent assessorAn accredited certification body, with yearly surveillance audits
What it coversA practical set of controls sized for smaller businessesEight technical strategies against the most common attacksA full information security management system: risk, governance, policies and continual improvement
Typical costFrom $95 to around $6,000 a year in fees, plus the uplift workFree to assess against; the cost is the uplift workUsually tens of thousands of dollars for first certification
Who tends to ask for itClients and supply chains wanting a simple answer; some industry bodiesCyber insurers, boards, government and enterprise clientsEnterprise, government, defence and overseas clients

We went through ISO 27001 certification ourselves in 2026, so we have a clear sense of the difference in effort. ISO 27001 certifies a management system: how you identify risk, choose controls, review them and improve. SMB1001 certifies a set of controls. The Essential Eight focuses on eight technical strategies that stop the most common attacks. They are different tools more than competitors, and plenty of businesses will end up using two of them.

Do you need SMB1001? A quick way to decide

  1. A client, head contractor or tender has asked for a recognised cyber certification and ISO 27001 is out of reach for now. Gold is a sensible target, and Bronze or Silver can be a quick first answer while you work towards it.
  2. You are a law firm or professional services firm holding confidential client data. Gold gives you a documented baseline, and in Queensland the law society is already pointing firms at it.
  3. Your insurer or a government client is asking about the Essential Eight. Work on Maturity Level 1 first. An SMB1001 certificate will not answer that question.
  4. You are in or near the defence supply chain. DISP membership is assessed against government security requirements, not SMB1001. It can be a stepping stone but it is not the destination.
  5. Nobody is asking yet, but you want a plan. Use the Bronze and Silver controls as a checklist and certify if and when someone asks.

How to get SMB1001 certified without a scramble

  1. Run a gap check against the current edition, tier by tier, and pick your target tier.
  2. Fix the high value controls first: MFA on every account, EDR on every device, email authentication (SPF, DKIM and DMARC at quarantine or reject) and backups that are kept separate from your network and tested.
  3. Write policies that match what you do. Incident response, access, acceptable use and now AI use. Keep them short enough that people read them.
  4. Collect evidence as you go: configuration screenshots, backup restore reports and training completion records. It keeps the attestation honest and makes renewal quick.
  5. Attest through CyberCert, or book your audit if you are going for Platinum or Diamond.
  6. Put the renewal in the calendar and check what changed in the new edition each year.

Where Austin Technology fits

Our SecureShield cyber security plans are built around the same controls. The Gold and Platinum plans put in place what the higher SMB1001 tiers ask for, alongside Essential Eight Maturity Level 1 or 2, and we help you pull the evidence together. The certificate itself is issued independently. If you want to know where you stand first, a cyber security audit shows your gaps against SMB1001 and the Essential Eight, written in plain English.

SMB1001 questions we get asked

Is SMB1001 a government standard?

No. It is published by Dynamic Standards International, a private Australian standards body. The Australian Government's own baseline for businesses is the Essential Eight, published by ASD.

Is SMB1001 Gold the same as Essential Eight Maturity Level 1?

No. There is plenty of overlap, but two of the eight strategies, application control and Office macro restrictions, only appear at Diamond. If an insurer or client asks for Maturity Level 1, a Gold certificate will not answer it on its own.

How long does SMB1001 certification last?

Twelve months. DSI releases a new edition each year, so each renewal is a chance to check what has changed.

Can we get certified without an IT provider?

Bronze, probably yes. From Silver up, most controls are technical, such as email authentication, EDR and MFA configuration, and the evidence has to come out of your systems. That is where an IT partner earns their keep.

Sources

Next step

Want a hand putting
this into practice?

Talk to an engineer, not a sales script. We will look at how your business runs today and tell you what matters, or tell you if we are not the right fit.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.
Scroll to Top