SMB1001 certification

SMB1001 certification, at the level you need

SMB1001 is the Australian cyber security certification written for small and medium businesses. We find the gaps against the level you need, put the controls in place, prepare the evidence and keep it all running, so your certificate reflects how your business really works.

Austin Technology engineer reviewing a client's security setup with a colleague
SecureShieldGold aligns to Platinum, Platinum to Diamond
  • 5Levels, from Bronze to Diamond
  • ISO27001 certified ourselves, audited every year
  • Top 50MSP in Australia, 2024 to 2026
  • 300+Businesses supported by our team

01Why businesses get certified

When someone asks you to prove it

Most businesses look at SMB1001 because someone outside the business wants evidence. These are the four situations we see most.

  1. A client or tender asks for it

    Larger clients now send supplier security questionnaires, and some tenders ask for a named certification. Without one you can lose points or miss the shortlist.

    FixA certificate at the level they ask for, and evidence you can attach to your reply.

  2. Your cyber insurance form got harder

    Renewal forms ask about multi factor authentication, backups, endpoint protection and incident response. The answers have to match what is really in place.

    FixControls that match your answers, and a certificate that backs them up.

  3. ISO 27001 is more than you need

    ISO 27001 is a big commitment in time, cost and paperwork, and it was not written with a 20 person business in mind.

    FixSMB1001 gives you a recognised certificate sized for your business, and a path up the levels as you grow.

  4. You have done the work but cannot show it

    Many businesses already have good controls through their IT provider, but nothing independent to show a client or a board.

    FixWe map what you have against the standard, close what is missing and turn it into a certificate.

02The five levels

Bronze to Diamond, in plain English

Each level builds on the one below it. You start at the level that fits your business rather than working through all five, and move up when a client or insurer asks for more.

The five SMB1001 levels, what each covers, how it is checked and who it usually suits
LevelWhat it coversHow it is checkedWho it usually suits
BronzeThe basics: protected and updated devices, backups, a firewall and security awareness training for staffSelf attested by a directorSole traders and small teams starting out
SilverStronger sign in: multi factor authentication, an account for each person, fewer admin rights and a password managerSelf attested by a directorMost small businesses, often at a client's request
GoldWritten policies, an incident response plan, endpoint detection and response, email protected from spoofing and a policy on AI useSelf attested by a directorBusinesses handling client data or answering supplier questionnaires
PlatinumControls that are tested: stronger multi factor authentication, vulnerability scanning, restore tests and regular access reviewsIndependent auditBusinesses in regulated work or large supply chains
DiamondThe highest level: application control, encryption, penetration testing and managed detection and response, monitored all the timeIndependent auditBusinesses whose clients expect the strongest evidence

Swipe the table sideways to see every column.

A plain English summary of SMB1001:2026. The standard sets the exact controls for each level, and we map every one of them against your business in the gap review.

03How we get you certified

From gap review to certificate

You know the level, the gaps and the cost before any work starts. Most of the effort sits with us, not your team.

  1. Review

    Free gap review

    We check your setup against the level you need and show you what is in place, what is missing and what it will take to close each gap.

  2. Fix

    Close the gaps

    Our engineers put the missing controls in place, from multi factor authentication and email protection to backups, policies and an incident response plan.

  3. Certify

    Evidence and sign off

    We prepare the evidence for each control. At Bronze to Gold your director signs the declaration. At Platinum and Diamond we get you ready for the independent audit.

  4. Keep

    Stay certified

    The standard changes every year and certificates are renewed each year. With SecureShield we keep the controls current and the evidence ready.

04SMB1001 and SecureShield

Certification built into your security plan

A certificate only means something if the controls keep running after the paperwork is done. SecureShield keeps them running, and the higher plans are built to the higher SMB1001 levels.

SecureShield Bronze

The security base

24/7 managed detection and response on devices, identity threat detection for Microsoft 365, security awareness training and a password manager for every user.

Pairs withThe lower SMB1001 levels, with any gaps closed after the review.

SecureShield Gold

Visibility and governance

Everything in Bronze plus centralised security logging, end user policy management and an incident response plan tested every year.

Aligned toSMB1001 Platinum, with the evidence prepared for the audit.

SecureShield Platinum

Strategy and vCISO

Everything in Gold as a full security program, with Essential Eight Maturity Level Two, an ongoing virtual CISO and board ready reviews.

Aligned toSMB1001 Diamond, the highest level.

SecureShield Bronze starts from $25 per user per month excluding GST. Gold and Platinum are quoted after your assessment.

Compare SecureShield plans

05Choosing a framework

SMB1001, Essential Eight or ISO 27001

All three come up in tenders and insurance forms. They overlap a lot, so work towards one usually helps with the others. This is how they differ.

SMB1001 compared with the Essential Eight and ISO 27001
CompareSMB1001Certification for SMBsEssential EightAustralian Signals DirectorateISO 27001International standard
Written forSmall and medium businessesAustralian organisations of every sizeOrganisations of every size, worldwide
What you getA certificate at one of five levelsA maturity level assessment. No government certificateA certificate for your information security management system
How it is checkedDirector declaration at Bronze to Gold, independent audit at Platinum and DiamondAssessment by your provider or an independent assessorExternal certification audits every year
EffortWeeks at the lower levels, months at the higher onesMonths to reach Maturity Level One or TwoThe biggest commitment of the three
Who usually asksClients, supply chains and insurersInsurers, government and resources clientsEnterprise and overseas clients

Swipe the table sideways to compare all three.

Not sure which one you are being asked for? Send us the request and we will tell you.

Compliance management

06Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
Austin Technology engineers at work on the service desk in Subiaco
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

07Questions

SMB1001 questions

What owners and IT managers ask before they start. Anything else, call 1300 787 429.

01

What is SMB1001?

SMB1001 is an Australian cyber security standard written for small and medium businesses. It sets out five levels of controls, from Bronze to Diamond, and gives you a certificate for the level you reach, so you can show clients, insurers and staff that your security has been checked against a standard.

It is published by Dynamic Standards International and updated every year. For the background, read SMB1001 explained.

02

Which SMB1001 level do we need?

Start with whoever is asking. If a client, tender or insurer names a level, aim for that. If nobody has asked yet, most small businesses start at Bronze or Silver and move up once the basics are working. You do not have to work through every level in order.

The free gap review tells you which level fits and what is missing for it.

03

How long does SMB1001 certification take?

It depends on the level and on what you already have in place. The lower levels are usually a matter of weeks. Platinum and Diamond take longer because the controls are deeper and an independent auditor has to check them. After the gap review you get a realistic timeline for your business.

04

How much does SMB1001 certification cost?

There are three parts: the certification fee paid to the certification body, the work to close any gaps and keeping the controls running. We quote the gap work after the review. The ongoing controls usually sit inside a SecureShield plan, which starts from $25 per user per month excluding GST.

05

Do you issue the SMB1001 certificate?

No. We prepare your business for certification: we put the controls in place, collect the evidence and help you through the process. The certificate is issued by an independent certification body. At Bronze, Silver and Gold a director signs a declaration through the certification body's portal. At Platinum and Diamond an independent auditor checks the evidence first.

06

How often do we renew SMB1001?

Certificates are renewed each year, and the standard itself is updated each year. The 2026 edition, for example, added email authentication, endpoint detection and response and an AI use policy. If your controls sit inside SecureShield, we keep them current and have the evidence ready for renewal.

07

Is SMB1001 better than the Essential Eight?

They do different jobs. The Essential Eight is a set of controls from the Australian Signals Directorate, measured in maturity levels, and the government does not issue a certificate for it. SMB1001 gives you a certificate at a level sized for your business. Many of the controls overlap, so work on one helps the other. See Essential Eight.

08

Will SMB1001 lower our cyber insurance premium?

It helps you answer the insurer's questions accurately and show evidence for each answer. Whether it changes your premium or cover is a decision for your insurer and broker, so check with them before you rely on it.

Client feedback

What our clients say

800+ reviews from the people who call our Perth service desk every day.

  • Simplesat700+
  • Cloudtango30+
  • Google70+
01 / 09
  • “Turns every IT problem into a non-issue”

    Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.

    Bronte J.Indian Ocean Hotel
  • “Patient, capable and a genuine listener”

    The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.

    Peter MidgleyPowertech
  • “Steady, thoughtful and stress free”

    Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.

    Jason CavallaroCallidus Process Solutions
  • “Resolved the issue within minutes”

    The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.

    Kirk LentonPilbara Construction
  • “The extra guidance made it more valuable”

    Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.

    Tony YoungOptimus Real Estate
  • “Resolved quickly, with none of my work lost”

    They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.

    Warner PriestInterContinental Energy
  • “Calm, patient and always willing to help”

    Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.

    Peter AlexanderKoch Solutions
  • “A calm and methodical engineer”

    Chris Wade is a great engineer and I have a lot of respect for his professionalism. He approaches every issue with a calm and methodical attitude and communicates clearly so I always understand what is happening. His steady approach and reliability make a real difference to our team, and his support is always appreciated.

    Paul GreenGlobal Cardiology
  • “Refreshing after two unreliable IT providers”

    After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.

    Mark HutchisonLifewood
Trusted by 300+ organisations
Thyssenkrupp FLSmidth InterContinental Energy Global Cardiology Koch Solutions Callidus Process Solutions Carers WA Powertech Acclaim Visagio Roshana OGS Global Genus Lifewood

08SMB1001 certification

Find out what stands
between you and the certificate.

Book a free SMB1001 gap review. We check your setup against the level you need and give you the gaps, the timeline and the cost in writing.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.
Scroll to Top