SMB1001 certification
SMB1001 certification, at the level you need
SMB1001 is the Australian cyber security certification written for small and medium businesses. We find the gaps against the level you need, put the controls in place, prepare the evidence and keep it all running, so your certificate reflects how your business really works.

- 5Levels, from Bronze to Diamond
- ISO27001 certified ourselves, audited every year
- Top 50MSP in Australia, 2024 to 2026
- 300+Businesses supported by our team
01Why businesses get certified
When someone asks you to prove it
Most businesses look at SMB1001 because someone outside the business wants evidence. These are the four situations we see most.
- 01
A client or tender asks for it
Larger clients now send supplier security questionnaires, and some tenders ask for a named certification. Without one you can lose points or miss the shortlist.
FixA certificate at the level they ask for, and evidence you can attach to your reply.
- 02
Your cyber insurance form got harder
Renewal forms ask about multi factor authentication, backups, endpoint protection and incident response. The answers have to match what is really in place.
FixControls that match your answers, and a certificate that backs them up.
- 03
ISO 27001 is more than you need
ISO 27001 is a big commitment in time, cost and paperwork, and it was not written with a 20 person business in mind.
FixSMB1001 gives you a recognised certificate sized for your business, and a path up the levels as you grow.
- 04
You have done the work but cannot show it
Many businesses already have good controls through their IT provider, but nothing independent to show a client or a board.
FixWe map what you have against the standard, close what is missing and turn it into a certificate.
02The five levels
Bronze to Diamond, in plain English
Each level builds on the one below it. You start at the level that fits your business rather than working through all five, and move up when a client or insurer asks for more.
| Level | What it covers | How it is checked | Who it usually suits |
|---|---|---|---|
| Bronze | The basics: protected and updated devices, backups, a firewall and security awareness training for staff | Self attested by a director | Sole traders and small teams starting out |
| Silver | Stronger sign in: multi factor authentication, an account for each person, fewer admin rights and a password manager | Self attested by a director | Most small businesses, often at a client's request |
| Gold | Written policies, an incident response plan, endpoint detection and response, email protected from spoofing and a policy on AI use | Self attested by a director | Businesses handling client data or answering supplier questionnaires |
| Platinum | Controls that are tested: stronger multi factor authentication, vulnerability scanning, restore tests and regular access reviews | Independent audit | Businesses in regulated work or large supply chains |
| Diamond | The highest level: application control, encryption, penetration testing and managed detection and response, monitored all the time | Independent audit | Businesses whose clients expect the strongest evidence |
Swipe the table sideways to see every column.
A plain English summary of SMB1001:2026. The standard sets the exact controls for each level, and we map every one of them against your business in the gap review.
03How we get you certified
From gap review to certificate
You know the level, the gaps and the cost before any work starts. Most of the effort sits with us, not your team.
- Review
Free gap review
We check your setup against the level you need and show you what is in place, what is missing and what it will take to close each gap.
- Fix
Close the gaps
Our engineers put the missing controls in place, from multi factor authentication and email protection to backups, policies and an incident response plan.
- Certify
Evidence and sign off
We prepare the evidence for each control. At Bronze to Gold your director signs the declaration. At Platinum and Diamond we get you ready for the independent audit.
- Keep
Stay certified
The standard changes every year and certificates are renewed each year. With SecureShield we keep the controls current and the evidence ready.
04SMB1001 and SecureShield
Certification built into your security plan
A certificate only means something if the controls keep running after the paperwork is done. SecureShield keeps them running, and the higher plans are built to the higher SMB1001 levels.
The security base
24/7 managed detection and response on devices, identity threat detection for Microsoft 365, security awareness training and a password manager for every user.
Pairs withThe lower SMB1001 levels, with any gaps closed after the review.
Visibility and governance
Everything in Bronze plus centralised security logging, end user policy management and an incident response plan tested every year.
Aligned toSMB1001 Platinum, with the evidence prepared for the audit.
Strategy and vCISO
Everything in Gold as a full security program, with Essential Eight Maturity Level Two, an ongoing virtual CISO and board ready reviews.
Aligned toSMB1001 Diamond, the highest level.
SecureShield Bronze starts from $25 per user per month excluding GST. Gold and Platinum are quoted after your assessment.
Compare SecureShield plans05Choosing a framework
SMB1001, Essential Eight or ISO 27001
All three come up in tenders and insurance forms. They overlap a lot, so work towards one usually helps with the others. This is how they differ.
| Compare | SMB1001Certification for SMBs | Essential EightAustralian Signals Directorate | ISO 27001International standard |
|---|---|---|---|
| Written for | Small and medium businesses | Australian organisations of every size | Organisations of every size, worldwide |
| What you get | A certificate at one of five levels | A maturity level assessment. No government certificate | A certificate for your information security management system |
| How it is checked | Director declaration at Bronze to Gold, independent audit at Platinum and Diamond | Assessment by your provider or an independent assessor | External certification audits every year |
| Effort | Weeks at the lower levels, months at the higher ones | Months to reach Maturity Level One or Two | The biggest commitment of the three |
| Who usually asks | Clients, supply chains and insurers | Insurers, government and resources clients | Enterprise and overseas clients |
Swipe the table sideways to compare all three.
Not sure which one you are being asked for? Send us the request and we will tell you.
Compliance management06Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
07Questions
SMB1001 questions
What owners and IT managers ask before they start. Anything else, call 1300 787 429.
01What is SMB1001?
SMB1001 is an Australian cyber security standard written for small and medium businesses. It sets out five levels of controls, from Bronze to Diamond, and gives you a certificate for the level you reach, so you can show clients, insurers and staff that your security has been checked against a standard.
It is published by Dynamic Standards International and updated every year. For the background, read SMB1001 explained.
02Which SMB1001 level do we need?
Start with whoever is asking. If a client, tender or insurer names a level, aim for that. If nobody has asked yet, most small businesses start at Bronze or Silver and move up once the basics are working. You do not have to work through every level in order.
The free gap review tells you which level fits and what is missing for it.
03How long does SMB1001 certification take?
It depends on the level and on what you already have in place. The lower levels are usually a matter of weeks. Platinum and Diamond take longer because the controls are deeper and an independent auditor has to check them. After the gap review you get a realistic timeline for your business.
04How much does SMB1001 certification cost?
There are three parts: the certification fee paid to the certification body, the work to close any gaps and keeping the controls running. We quote the gap work after the review. The ongoing controls usually sit inside a SecureShield plan, which starts from $25 per user per month excluding GST.
05Do you issue the SMB1001 certificate?
No. We prepare your business for certification: we put the controls in place, collect the evidence and help you through the process. The certificate is issued by an independent certification body. At Bronze, Silver and Gold a director signs a declaration through the certification body's portal. At Platinum and Diamond an independent auditor checks the evidence first.
06How often do we renew SMB1001?
Certificates are renewed each year, and the standard itself is updated each year. The 2026 edition, for example, added email authentication, endpoint detection and response and an AI use policy. If your controls sit inside SecureShield, we keep them current and have the evidence ready for renewal.
07Is SMB1001 better than the Essential Eight?
They do different jobs. The Essential Eight is a set of controls from the Australian Signals Directorate, measured in maturity levels, and the government does not issue a certificate for it. SMB1001 gives you a certificate at a level sized for your business. Many of the controls overlap, so work on one helps the other. See Essential Eight.
08Will SMB1001 lower our cyber insurance premium?
It helps you answer the insurer's questions accurately and show evidence for each answer. Whether it changes your premium or cover is a decision for your insurer and broker, so check with them before you rely on it.
What our clients say
800+ reviews from the people who call our Perth service desk every day.
700+
30+
70+
-
“Turns every IT problem into a non-issue”
Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.
Bronte J.Indian Ocean Hotel
-
“Patient, capable and a genuine listener”
The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.
Peter MidgleyPowertech
-
“Steady, thoughtful and stress free”
Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.
Jason CavallaroCallidus Process Solutions
-
“Resolved the issue within minutes”
The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.
Kirk LentonPilbara Construction
-
“The extra guidance made it more valuable”
Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.
Tony YoungOptimus Real Estate
-
“Resolved quickly, with none of my work lost”
They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.
Warner PriestInterContinental Energy
-
“Calm, patient and always willing to help”
Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.
Peter AlexanderKoch Solutions
-
“A calm and methodical engineer”
Chris Wade is a great engineer and I have a lot of respect for his professionalism. He approaches every issue with a calm and methodical attitude and communicates clearly so I always understand what is happening. His steady approach and reliability make a real difference to our team, and his support is always appreciated.
Paul GreenGlobal Cardiology
-
“Refreshing after two unreliable IT providers”
After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.
Mark HutchisonLifewood
08SMB1001 certification
Find out what stands
between you and the certificate.
Book a free SMB1001 gap review. We check your setup against the level you need and give you the gaps, the timeline and the cost in writing.