Skip to main content

The IT Agency

Cyber Security, Compliance

Should I use a managed service provider to implement SMB1001, or can I do it internally?

Whether SMB1001 is implemented internally or with the support of a managed service provider is only part of the decision. More important is understanding what the implementation actually involves.

SMB1001 spans five core domains: technology management, access management, backup and recovery, policy and process and staff training. Each domain requires technical controls, documented governance and evidence that those controls are operating effectively. The question is less about who performs the work and more about whether the business has the capability, time and experience to complete it thoroughly and maintain it over time.

  • SMB1001 implementation covers five domains, technology, access, backup, policy and training, and all five require attention regardless of who carries out the work
  • Internal implementation is achievable at Bronze and Silver for a business with existing IT capability, though the governance and documentation requirements typically take longer than the technical controls
  • Certain implementation failure points recur consistently, like an SPF record published without DMARC enforcement, an endpoint detection deployed with default settings or an incident response plan drafted once and never tested
  • SMB1001 is reassessed annually against the current edition of the standard, so the work continues well after the first certificate is issued
  • A business would need to produce the evidence behind each control, including dated configuration records, policy documents and training logs, if its security posture were ever formally questioned
  • Which approach suits a given business depends on its existing technical capability, the time available internally and the certification level it is targeting

Questions answered

  • Should I use a managed service provider to help me implement SMB1001, or can I do it internally?

Should I use a managed service provider to implement SMB1001, or can I do it internally?

SMB1001 can be implemented internally, particularly at the Bronze and Silver levels, by businesses with capable IT staff and enough time to dedicate to the project. The technical controls at these levels, such as multi-factor authentication, secure backups and access management, are generally well within the capability of an experienced internal IT team.

The governance requirements often prove more challenging than the technology itself. Documenting policies, maintaining evidence, recording staff training and preparing for annual re-attestation require ongoing discipline rather than technical expertise alone. Businesses that work with an experienced managed service provider often

complete the process more efficiently because the common implementation pitfalls are already well understood and the ongoing certification cycle is built into the way they operate.

The right approach depends on the technical capability already within the business, the time available internally and the certification level being pursued. What does SMB1001 implementation actually involve?

Implementing SMB1001 involves much more than configuring security software. Every certification level covers five core areas: technology management, access management, backup and recovery, policy and process and staff training. Success depends on all five working together, supported by evidence that the required controls are operating effectively.

Technology management

The technical controls become more comprehensive as certification levels increase. Bronze focuses on the fundamentals, including firewalls, antivirus, automatic updates and secure backups. Silver introduces controls such as multi-factor authentication and sender policy framework (SPF) records. Gold expands to endpoint detection and response, DKIM signing and enforced DMARC. Platinum and Diamond add more advanced controls including vulnerability management, encryption and application control.

Implementing these controls individually is rarely the difficult part. The challenge lies in configuring them correctly, ensuring they work together and maintaining them over time. A poorly configured security control can create as many problems as not having one at all.

Policies and governance

In addition to having the technology in place, SMB1001 requires documented policies that explain how cyber security is managed within the business. As certification levels increase, businesses are expected to document areas such as password management, access control, incident response, acceptable use and responsible AI. These documents need to reflect how the business actually operates rather than existing simply to satisfy a checklist.

For many organisations, governance becomes the most time-consuming part of implementation because policies need to be maintained as the business changes.

Evidence and record keeping

Certification is supported by evidence rather than declarations. Businesses need to be able to demonstrate that security controls are operating as intended through configuration records, backup restoration testing, training records, policy documents and other supporting evidence. If a customer, insurer or regulator ever asks how a business manages cyber security, this evidence becomes far more valuable than the certificate itself.

Staff awareness and training

Cyber security depends on people as much as technology. Staff need regular training to recognise phishing attacks, payment redirection scams and other emerging threats. Because attack techniques continue to evolve, SMB1001 treats staff awareness as an ongoing activity rather than a one-off induction session.

Annual reviews and continuous improvement

SMB1001 is an ongoing certification that requires annual renewal. The SMB1001 standard is constantly evolving to reflect changes in the threat landscape, so businesses need to re-attest annually against the current version. Maintaining certification requires businesses to review their controls, refresh documentation and ensure evidence remains current throughout the year.

Can I implement SMB1001 internally?

Yes. Many businesses successfully implement SMB1001 Bronze and Silver internally, particularly where they already have capable IT staff and sufficient time to dedicate to the project. The technical requirements at these levels are generally well within the capability of an experienced internal IT team, however the greater challenge is maintaining the governance, documentation and evidence needed to support certification. Internal implementation works best when someone within the business has clear ownership of the project and enough capacity to see it through.

When does using a managed service provider make sense?

Many businesses choose to work with a managed service provider because implementation involves much more than configuring technology. An experienced provider has already worked through the certification process many times and understands where projects typically slow down. Documentation is completed alongside the technical work, evidence is gathered as controls are implemented and the annual certification cycle is planned from the beginning rather than becoming an afterthought.

For businesses with limited internal resources or higher certification goals, this experience can significantly reduce implementation time and avoid common mistakes.

What are the most common implementation mistakes?

Several implementation issues appear repeatedly across small businesses.

  • Publishing a DMARC record but never moving it from monitoring mode to enforcement.
  • Deploying endpoint detection and response using default settings without ongoing tuning.
  • Writing an incident response plan that is never tested or updated.
  • Allowing digital asset registers to become outdated as systems change.
  • Completing staff training once and assuming it remains effective indefinitely.
  • Failing to remove access promptly when employees leave the business.
  • Treating documentation as something to complete at the end rather than throughout the project.

Most of these problems occur because cyber security competes with other business priorities and no one has clear responsibility for maintaining the framework.

What’s the biggest difference between internal and specialist implementation?

The biggest difference is experience rather than technical expertise. Businesses implementing SMB1001 for the first time naturally discover challenges as they arise. Organisations that implement the framework regularly have already encountered those issues and have established processes to prevent them. Experience helps avoid common mistakes, keeps projects moving and ensures evidence is collected as controls are implemented rather than recreated later.

Which approach is right for my business?

The right approach depends on the technical capability already within the business, the time available internally and the certification level being pursued. Businesses with experienced IT staff and sufficient capacity may consider implementing Bronze or Silver successfully themselves, while many organisations find it beneficial to enlist the support from a team with specialist expertise who can make the process smoother and faster.

Businesses targeting higher certification levels, working to tight deadlines or looking for ongoing governance support often benefit from working with an experienced cyber security service provider.

Your situation Internal implementation Managed services provider
Existing, capable cyber team
Bronze or Silver certification level
Limited internal resources
Gold, Platinum or Diamond
certification
Customer or insurer deadline
Ongoing governance and annual
re-attestation support

Key takeaways

SMB1001 can be implemented internally or with the support of a managed service provider. The deciding factor is rarely whether the technology can be configured. It is whether the business has the time, capability and governance to implement the framework thoroughly and maintain it year after year.

For businesses with experienced internal IT capability, Bronze and Silver may be achievable without external assistance. For organisations seeking faster implementation, higher certification levels or ongoing support, an experienced managed services provider can reduce risk by bringing proven processes, practical implementation experience and a structured approach to long-term cyber security governance.

Frequently asked questions

Which SMB1001 controls are commonly implemented but not properly tested?

Backups and incident response plans are the two most common examples. A backup that runs on schedule but has never been restored, and an incident response plan that exists as a document but hasn’t been tested against a realistic scenario, both satisfy the letter of the requirement without necessarily working when actually needed.

How much of SMB1001 implementation is technical versus documentation?

At Bronze and Silver, the balance leans technical. From Gold onward, documentation and governance, an incident response plan, a digital asset register, a responsible AI use policy, make up a larger share of the work, and these typically take longer to get right than the technical controls sitting alongside them.

What is the most commonly underestimated part of implementation?

Keeping evidence current after the initial certification. Configuration records, access reviews and training logs that were accurate at the time of certification tend to age as a business changes, and evidence that isn’t refreshed becomes a liability rather than a safeguard.

Does SMB1001 require an external audit at every level?

No. Bronze, Silver and Gold are self-attested by a company director through the CyberCert platform. Platinum and Diamond require an independent external audit rather than self-attestation.

How does the annual recertification cycle work in practice?

SMB1001 is reassessed each year against whatever edition of the standard is current at the time. Editions have introduced new requirements at Gold level in recent years, so a business needs to review what has changed before assuming a previous year’s attestation still applies.

What happens if a self-attested control turns out not to be accurate?

The business has made a formal claim that may not hold up if a client, insurer or regulator later asks to see the evidence behind it. Self-attestation places the responsibility for accuracy directly on the business, which is a material consideration regardless of who carried out the implementation work.

Is there a minimum size of business SMB1001 is designed for?

SMB1001 targets small and medium businesses generally defined in Australia as having fewer than 200 employees, though the standard is used by organisations of varying sizes within that range, including sole traders with limited data holdings through to larger operations with more complex environments.

Continue reading

Is your small business at risk of a cyber attack?
Do Australian small businesses need cyber security certification?
What is a cyber security framework, and what does implementing one involve?
What’s the easiest way for a small business to become cyber compliant?
What is SMB1001? The complete guide for Australian small businesses
Essential Eight vs SMB1001 vs ISO/IEC 27001: Which cyber security framework is right for your business?
How much does SMB1001 cost? Is it worth the investment?
SMB1001 implementation roadmap: from assessment to certification
Cyber governance for Australian small businesses: Building resilience and trust
Why choose The IT Agency for SMB1001? How to choose the right implementation partner

About The IT Agency

The IT Agency is a Microsoft Solutions Partner and SMB1001 Gold Certified MSP, helping Australian businesses assess their current cyber maturity, prepare for certification and implement practical security improvements aligned with recognised frameworks. This article draws on direct experience implementing SMB1001 across a range of small business environments.

References

https://dsi.org/smb1001
https://cybercert.ai

The IT Agency

The IT Agency

SMB1001 GoldMicrosoft Solutions PartnerCyber and IT Experts

The IT Agency helps businesses stay connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions.