SMB1001 implementation roadmap: from assessment to certification
SUMMARY
- SMB1001 implementation follows five stages: a cyber maturity assessment, certification tier selection, remediation, evidence collection and director attestation through the CyberCert platform.
- A cyber maturity assessment measures your business against SMB1001’s five domains and provides the roadmap for implementation. Completing the assessment before selecting a certification tier helps avoid unnecessary cost and delays.
- Implementation time depends on your starting point. Bronze can often be completed within hours, Silver typically takes a week and Gold generally takes less than a month, depending on your existing cyber security maturity.
- For Bronze, Silver and Gold, evidence is just as important as the technical controls. Directors self-attest that the required controls are operating, making documented evidence a key part of the certification process.
- SMB1001 certification is renewed annually against the current version of the standard, making cyber security an ongoing business process rather than a one-off project.
Questions answered
- How long does it take to implement SMB1001 certification?
- What happens during SMB1001 implementation?
- What is a cyber maturity assessment?
- What happens after certification?
- What order should SMB1001 implementation steps happen in?
- What evidence is needed for SMB1001 certification?
SMB1001 implementation roadmap: from assessment to certification
Implementing SMB1001 is less about installing new technology and more about following a structured process. Every business starts from a different level of cyber security maturity, so the time, effort and investment required will vary. The implementation journey, however, is remarkably consistent.
Whether you’re working towards Bronze, Silver or Gold, the process begins with understanding your current security posture, identifying any gaps against the standard and prioritising the work needed to close them. From there, the focus shifts to implementing technical controls, documenting policies, gathering evidence and completing director attestation through the CyberCert platform.
This guide explains each stage of the SMB1001 implementation process, how long certification typically takes, how to choose the right certification level, what evidence is required and what happens after certification. It also highlights the common mistakes that delay projects and the practical steps businesses can take to avoid them.
As an SMB1001 Gold Certified Managed Service Provider, The IT Agency has helped Australian businesses implement Bronze, Silver and Gold certification. The roadmap below reflects the approach we’ve developed through real-world implementation experience.
What are the stages of SMB1001 implementation?
SMB1001 implementation follows five stages:
- Complete a cyber maturity assessment against the five SMB1001 domains.
- Select the certification tier that best aligns with your current maturity and business requirements.
- Remediate the technical, governance and documentation gaps identified during the assessment.
- Gather evidence demonstrating that each required control is operating effectively.
- Complete director attestation through the CyberCert platform and prepare for annual renewal.
Each stage builds on the one before it. Businesses that complete the process in sequence generally achieve certification more efficiently than those that skip directly to implementation or choose a certification level before understanding their current maturity.
What is a cyber maturity assessment?
A cyber maturity assessment measures your existing cyber security practices against SMB1001’s five domains:
- Technology management
- Access management
- Backup and recovery
- Policies and processes
- Education and training
Rather than producing a simple pass or fail result, the assessment identifies which controls are already operating effectively, which require improvement and which are missing altogether. It reviews both technical controls, such as multi-factor authentication, endpoint protection and backups, and governance controls including policies, procedures and staff awareness. For many businesses, it provides the first complete picture of their cyber security maturity and creates a clear roadmap for certification.
Without a maturity assessment, choosing a certification level becomes guesswork and implementation lacks a defined scope.
How do you choose the right SMB1001 certification level?
SMB1001 includes five certification levels: Bronze, Silver, Gold, Platinum and Diamond. The right certification level depends on your current cyber maturity, customer expectations, contractual obligations and business objectives.
Many organisations assume they need Gold because it appears in a customer contract or tender document, while cyber maturity assessments often show that achieving Silver first provides a faster and more cost-effective pathway for progressing to Gold.
Each certification level builds on the previous one. Gold under the 2026 standard includes 27 controls across the five domains, making it significantly more comprehensive than Bronze or Silver. Businesses that already have strong technical controls and governance in place are often much closer to Gold than they initially expect.
How long does it take to implement SMB1001?
Implementation time depends far more on your starting point than on the certification level itself.
Businesses with strong cyber security foundations can often achieve Bronze within a matter of hours. Silver commonly takes 3-10 days because it introduces additional governance, documentation and access management requirements.
Gold is usually a more substantial project. Businesses already operating with endpoint detection and response, comprehensive multi-factor authentication, tested backups and documented governance can sometimes complete Gold within a few weeks. Organisations starting from a lower baseline may require longer to implement the necessary technical controls, governance and supporting evidence.
The biggest influence on project duration is usually remediation work rather than certification itself.
What happens during SMB1001 implementation?
Implementation typically runs across three parallel workstreams:
- Technical remediation focuses on strengthening security controls such as access management, endpoint protection, email security and backup processes.
- Governance develops the policies, procedures and documentation required by the framework, including incident response planning, acceptable use policies and asset registers.
- Evidence collection runs alongside both workstreams, ensuring each implemented control is supported by documentation, configuration records, screenshots, training records or other evidence required for director attestation.
Running these activities together produces a smoother implementation than leaving documentation or evidence until the end of the project.
What evidence is required for SMB1001 certification?
For Bronze, Silver and Gold, certification relies on director self-attestation rather than an external audit, which makes evidence particularly important.
Evidence commonly includes:
- configuration records demonstrating technical controls
- screenshots showing multi-factor authentication and endpoint protection
- documented policies and procedures
- completed staff training records
- backup testing and restoration records
- asset registers and governance documentation
Collecting evidence throughout implementation is considerably easier than attempting to recreate it immediately before certification.
What happens after SMB1001 certification?
SMB1001 certification is renewed annually against the current version of the standard. As the framework evolves, businesses are expected to maintain existing controls and implement any additional requirements introduced in future editions.
Treating cyber security as an ongoing business process rather than a once-off project makes annual certification significantly easier. Regular reviews of technical controls, policies, training and evidence help ensure the business remains prepared throughout the year rather than scrambling before renewal.
What are the most common SMB1001 implementation mistakes?
Several issues consistently delay certification projects.
- Choosing a certification level before completing a maturity assessment.
- Leaving documentation until late in the project.
- Treating staff awareness training as a final task instead of an ongoing requirement.
- Collecting evidence only when certification is approaching.
- Assuming director attestation is simply an administrative step rather than a declaration supported by evidence.
Most implementation delays are caused by governance and project sequencing rather than technical complexity.
The IT Agency perspective
The businesses that implement SMB1001 most efficiently are rarely those with the most sophisticated IT environments. They are the ones that understand their current maturity before deciding where they want to finish.
We regularly work with organisations that believe they are ready for Gold because their technology is modern, only to discover during the assessment that governance, documentation or evidence collection are the areas requiring the greatest attention. Addressing those gaps early keeps projects moving and prevents unexpected delays later in the implementation.
We also encourage businesses to collect evidence as each control is implemented rather than waiting until certification is due. That simple change consistently shortens implementation time and gives directors greater confidence when completing their attestation.
Key takeaways
SMB1001 implementation follows a clear and repeatable process: assess your current maturity, select the right certification level, remediate identified gaps, collect evidence and complete certification through director attestation.
The businesses that achieve certification most efficiently are not necessarily the most technically advanced. They are the ones that understand their starting point, follow the implementation roadmap in sequence and treat cyber security as an ongoing business discipline rather than a one-off compliance exercise.
Frequently asked questions
It depends on the target tier and the business’s starting maturity. Bronze can sometimes be completed within days. Silver typically takes six to twelve weeks. Gold usually takes four to twelve months, with the range reflecting how much of the required technical, policy and training controls already exist before the project begins.
The first step is a cyber maturity assessment against the standard’s five domains: technology management, access management, backup and recovery, policies and processes and education and training. Choosing a target tier before this step usually leads to a longer and more expensive project.
A cyber maturity assessment is a structured review of your business’s existing cyber security controls against SMB1001’s five domains. It identifies which controls are already in place, which need improvement and which are missing, creating a clear roadmap for implementation and certification.
Yes, particularly at Bronze and Silver, where the self-attestation process is designed to be manageable without a provider. Gold is achievable internally too, though many businesses engage an IT provider for the technical remediation while keeping the director attestation internal.
Configuration screenshots showing controls such as MFA and endpoint protection are active, dated policy documents, staff training records and backup test logs confirming a successful restore rather than just a completed backup job. Collecting this evidence throughout implementation is faster than reconstructing it before attestation.
Yes. Certification is renewed annually against the current edition of the standard, not the edition originally certified against. Businesses need to keep the implemented controls operating and refresh their evidence each year rather than treating certification as a one-off achievement.
There is no penalty for identifying a gap between renewal cycles, but it should be remediated before the next attestation. Since the director is personally attesting that controls are in place, an internal review ahead of each annual renewal is the best way to catch and close gaps before they affect certification.
The director. Regardless of who performs the technical remediation, the attestation is a personal statement from a company director confirming the required controls are in place, and that responsibility cannot be delegated to an external provider.
Yes, and it is a common approach. Many businesses build maturity progressively, using Silver as a foundation and moving to Gold in a subsequent certification cycle once the additional controls, such as broader MFA coverage and more formal governance documentation, are in place.
Underestimating policy and documentation requirements, particularly an incident response plan and a responsible AI use policy and leaving staff training until the final weeks of the project. Technical controls are usually faster to close than businesses expect, but documentation and training take longer than businesses budget for.
Not necessarily. The right starting point depends on your current cyber security maturity and business requirements. Some organisations begin at Bronze to establish the fundamentals, while others already have enough controls in place to work towards Silver or Gold after completing a cyber maturity assessment.
Continue reading
Is your small business at risk of a cyber attack?
Do Australian small businesses need cyber security certification?
What is a cyber security framework, and what does implementing one involve?
What’s the easiest way for a small business to become cyber compliant?
What is SMB1001? The complete guide for Australian small businesses
Essential Eight vs SMB1001 vs ISO/IEC 27001: Which cyber security framework is right for your business?
Should I use a managed service provider to implement SMB1001, or can I do it internally?
How much does SMB1001 cost? Is it worth the investment?
Cyber governance for Australian small businesses: Building resilience and trust
Why choose The IT Agency for SMB1001? How to choose the right implementation partner
About The IT Agency
The IT Agency helps keep businesses connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions. As a Microsoft Solutions Partner and SMB1001 Gold Certified MSP, we help businesses simplify IT, implement technology securely and strengthen resilience. Talk to us about building a more secure and future-ready business.
References
https://cybercert.ai
https://dsi.org/smb1001
The IT Agency
The IT Agency helps businesses stay connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions.