A business owner’s guide to SMB1001 Gold requirements
SUMMARY
- SMB1001 Gold is a Level 3 cyber security certification designed for Australian small and medium businesses
- SMB1001:2026 requires 27 controls covering technology, access management, backups, policies and staff training
- Key requirements include EDR, MFA, DMARC email protection, an incident response plan and a responsible AI use policy
- Business directors must personally attest that required controls are in place before certification is issued
If someone has told you that your business needs SMB1001 Gold certification and you have no idea what that means, you are in the right place.
Many business owners first hear about SMB1001 during a tender process, an insurance review or a client security questionnaire. Suddenly there is a certification requirement sitting on a checklist and nobody has explained what it actually involves.
The good news is that SMB1001 is not designed for large enterprises. It was built specifically for small and medium businesses and focuses on practical controls that reduce real-world cyber risk.
What is SMB1001 Gold?
SMB1001 is a cyber security certification standard built specifically for small and medium businesses. It comes in five tiers: Bronze, Silver, Gold, Platinum and Diamond.
Gold sits at Level 3 and is widely considered the minimum standard for businesses that handle sensitive information, operate in regulated industries or work with clients who increasingly expect evidence of cyber security controls.
The standard is maintained by Dynamic Standards International and updated annually. The current version is SMB1001:2026, which became certifiable in January 2026. Certification is issued through the CyberCert platform.
What does SMB1001 Gold actually require?
Gold level certification now requires 27 controls in the 2026 edition, up from 23 in 2025.
Those controls are grouped across five areas:
Technology management
Can you see, protect and manage the technology your business relies on?
This area covers the security of devices, software and business systems. Gold requires businesses to maintain visibility of their technology environment and implement controls that help detect and respond to threats.
In practical terms, this includes things like:
- Endpoint Detection and Response (EDR) on business devices
- Security updates and patch management
- Approved and supported software
- Visibility of business assets and systems
The goal is simple. If a laptop, server or application becomes compromised, your business should have a way to identify the issue and respond quickly.
Access management
Can you control who has access to your systems and data?
Many cyber incidents start because attackers gain access using stolen or weak credentials. Access management focuses on reducing that risk.
At Gold level, businesses are expected to implement stronger controls around user access, including:
- Multi-factor authentication (MFA)
- Secure password practices
- Controlled administrator access
- Protection for remote access services
- Security for key cloud platforms and business applications
The principle is straightforward. People should only have access to what they need, and access should be difficult for attackers to misuse.
Backup and recovery
Could your business recover if systems were lost, encrypted or damaged?
Backups remain one of the most important cyber security controls for small and medium businesses.
Gold requires businesses to maintain reliable backup processes and ensure information can be recovered when needed.
This generally includes:
- Regular data backups
- Secure storage of backup data
- Recovery procedures
- Testing that backups can actually be restored
Many businesses discover during an incident that backups existed but could not be recovered. This section is designed to avoid that situation.
Policies and processes
Would your team know what to do if something went wrong?
Technology alone is not enough. Businesses also need documented processes that guide decision-making and response activities.
Gold includes requirements such as:
- An incident response plan
- Asset registers
- Documented security processes
- Responsible AI usage policies
- Governance and accountability measures
These documents do not need to be complex. They simply need to provide clarity around responsibilities, expectations and response procedures.
Education and training
Do your staff know how to recognise common cyber threats?
Cyber criminals often target people rather than technology. Phishing emails, invoice scams and social engineering attacks continue to be common entry points into businesses.
Gold requires organisations to provide security awareness training so staff can recognise and respond appropriately to suspicious activity.
This includes helping employees understand:
- Phishing and email scams
- Password security
- Safe use of business systems
- Data handling responsibilities
- Emerging risks such as AI misuse
A well-trained team often prevents incidents before technology ever needs to step in.
How SMB1001 Gold certification works
For Bronze, Silver and Gold, there is no external auditor.
Instead, a company director must personally log into the CyberCert platform and attest that all required controls are in place. Their name becomes part of the certification record which makes preparation important. Before signing off, directors should be confident the controls are genuinely operating within the business and not simply assumed to exist.
Most organisations work through the requirements with their IT provider or managed service provider, address any gaps and then complete the attestation process. Some operators, like The IT Agency, can provide a structured review and roadmap that outline the gaps and can be implemented by existing IT teams or by The IT Agency.
How long it takes and what it costs
Gold is a meaningful security uplift project rather than a simple paperwork exercise.
For businesses upgrading from Silver or with existing controls already in place, implementation can take as little as one to two weeks. For businesses starting from a lower baseline, the process typically runs longer.
The CyberCert certification fee is separate and relatively modest. Most of the investment goes towards improving your security posture, which provides value whether certification is ultimately required or not.
Why it matters beyond the certificate
Cyber security questions are appearing more frequently in procurement processes, insurance applications and supplier reviews.
Many organisations now want evidence that their suppliers take security seriously. SMB1001 Gold provides a recognised and independently administered certification that helps answer those questions.
More importantly, the controls required by Gold address common causes of cyber incidents, including ransomware, business email compromise and data breaches.
What happens after you certify
SMB1001 certification is renewed annually against the current version of the standard.
Treating certification as an annual business process makes it easier to maintain compliance and budget appropriately for future requirements.
The annual review also creates a useful checkpoint to confirm that security controls remain effective and relevant as the business evolves.
The IT Agency helps keep businesses connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions. As a Microsoft Solutions Partner and SMB1001 Gold Certified MSP, we help businesses simplify IT, implement technology securely and strengthen resilience. Talk to us about building a more secure and future-ready business.
Frequently asked questions
No. SMB1001 is a voluntary certification. However, some clients, tenders, industry programs and supply chains may require or strongly encourage certification.
Certification is renewed annually. Businesses must recertify against the current version of the standard each year.
No. Gold certification uses a director attestation process through CyberCert. External audits apply at higher certification levels.
Gold introduces additional controls, including mandatory EDR, stricter email authentication requirements, broader MFA coverage and more formal governance requirements.
Yes. SMB1001 was specifically designed for small and medium businesses and scales far more effectively than enterprise-focused standards.
Many businesses work with an IT provider experienced in cyber security and compliance. The process typically starts with a gap assessment, followed by remediation and certification preparation.
References
https://cybercert.ai
https://www.cyber.gov.au
The IT Agency
The IT Agency helps businesses stay connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions.