What is SMB1001? The complete guide for Australian small businesses
SUMMARY
Somewhere in the last couple of years, a term started turning up in places it never used to appear. A client mentions it in an email. A cyber insurance renewal form asks about it by name. A tender document lists it as a requirement in the fine print: SMB1001. If you’ve landed on this guide because someone used that term and you nodded along without quite knowing what they meant, you’re in good company. Most small business owners hadn’t heard of it either, until fairly recently.
That’s the gap this guide exists to close. Not with a sales pitch or the kind of vague reassurance that cyber security content tends to lean on, but with a genuinely complete answer: what SMB1001 actually is, how it works, what it costs, who it suits and just as importantly, what it doesn’t guarantee. We hold SMB1001 Gold certification ourselves and have taken clients through every level of it, so this isn’t written from the outside looking in.
Cyber security has a reputation of feeling deliberately confusing, full of acronyms, tiers and maturity levels that seem designed for businesses that already have a security team on staff. SMB1001 was actually built to fix that problem, not add to it, and making sense of it doesn’t require a technical background. It just takes someone willing to walk through it properly, in plain language, without skipping the parts that matter. That’s what the rest of this guide sets out to do.
- SMB1001 is a five-tier cyber security certification standard, Bronze, Silver, Gold, Platinum and Diamond, built specifically for small and medium businesses and maintained by Dynamic Standards International (DSI)
- It isn’t named in the Cyber Security Act 2024 or the Security of Critical Infrastructure Act and it isn’t mandatory under any Australian law; certification is entirely voluntary
- Bronze, Silver and Gold are self-attested by a company director through the CyberCert platform; Platinum and Diamond require an independent external audit and cost considerably more
- The standard is updated annually and publishes control mappings to the Australian Essential Eight, UK Cyber Essentials, US CMMC and ISO 27001, though it isn’t formally adopted by any of those frameworks’ own governing bodies
- Most small businesses get the clearest, most defensible value from working toward Gold, with Platinum and Diamond generally suited to larger or higher-risk organisations
- The IT Agency is an SMB1001 Gold Certified MSP and uses the standard as a practical starting framework with small business clients, while being upfront about what it does and doesn’t guarantee
Questions answered
- What is SMB1001?
- What does SMB1001 stand for?
- Who developed SMB1001?
- Why was SMB1001 created?
- Is SMB1001 mandatory?
- Who needs SMB1001?
- What are the certification levels?
- How much does certification cost?
- How long does certification take?
- How do I become certified?
- Is SMB1001 better than Essential Eight?
- Is SMB1001 the same as ISO 27001?
What is SMB1001? The complete guide for Australian small businesses
SMB1001 is a cyber security certification standard built specifically for small and medium businesses, maintained by Dynamic Standards International. It works through five progressive levels, Bronze, Silver, Gold, Platinum and Diamond, each adding controls to the one before it, so a business can certify at a level that matches its size and budget rather than facing a single all-or-nothing audit. Bronze, Silver and Gold are self-attested by a company director through the CyberCert platform; Platinum and Diamond require an independent auditor and cost considerably more. It isn’t legally mandatory anywhere and it isn’t named in the Cyber Security Act 2024 or in any formal government procurement requirement. What it offers instead is a structured, affordable way for a business without a dedicated security team to build and demonstrate genuine cyber security controls, which is why we use it as a starting framework with most of our small business clients, alongside an honest picture of what the certificate does and doesn’t prove to a third party.
Understanding SMB1001
What is SMB1001?
Picture a certification built the way a small business owner would have designed it themselves, if they’d had the time. That’s roughly the idea behind SMB1001, a multi-tiered cyber security certification standard developed by Dynamic Standards International, a private standards body headquartered in Washington D.C. with an additional office in Canberra. Rather than treating security as a purely technical box-ticking exercise, it organises its requirements into five domains: technology management, access management, backup and recovery, policies and processes, and education and training. Every certification level is required to draw from all five, providing a breadth that separates it from a purely technical checklist. A business working through SMB1001 needs to show working policies and trained staff sitting around its technical controls, not just that the right software happens to be switched on.
What does SMB1001 stand for?
SMB1001 isn’t a formal acronym in the way some standards spell out a specific phrase. ‘SMB’ refers to small and medium businesses, the audience the standard was built for from the outset, and ‘1001’ functions more as a model or version identifier than an abbreviation with its own separate meaning, in the same way plenty of technical standards carry a numeric designation without it unpacking into words.
Who developed SMB1001?
The standard is maintained by Dynamic Standards International, known as DSI, which was formerly called Cyber Security Certification Australia. It was developed in Australia before becoming available for certification internationally from January 2025, and DSI has kept it moving ever since, updating the standard annually through a steering committee drawn from public and private sector experts. That’s the reasoning behind calling it a ‘dynamic’ standard rather than a fixed one. Certification itself sits with a separate organisation, CyberCert, whose platform businesses use to complete self-attestation or arrange an external audit, depending on the level they’re pursuing.
Why was SMB1001 created?
Every standard exists to solve a problem, and SMB1001’s problem was fairly specific. The Australian Signals Directorate’s Essential Eight and the international ISO 27001 standard are both credible, well-regarded frameworks, but neither was built with a five or fifteen-person business in mind. ISO 27001 typically demands a documented management system, a formal risk assessment process and an external audit, often running to tens of thousands of dollars and several months even for a modest-sized business. The Essential Eight, meanwhile, is narrowly technical
and has little to say about governance, documentation or staff training. SMB1001 was designed to sit in the gap between the two, giving smaller businesses a tiered, affordable pathway that scales with their size instead of assuming enterprise resourcing from day one.
What problem is SMB1001 solving for Australian businesses?
Most small business are serious about security, but lack a clear, affordable structure for implementing security standards or a credible way to prove these are in place. Before frameworks like SMB1001 existed, a small business really only had two options: attempt a scaled-down version of an enterprise standard that was never built for them, or fall back on a general assurance to clients and insurers with nothing concrete standing behind it. SMB1001 offers a genuine third path, a defined set of controls a business can implement in a matter of weeks at the entry levels, backed by a certificate that names exactly what was checked.
Why cyber security matters for small businesses
It’s tempting to assume attackers go looking for bigger prizes, but the numbers tell a different story. Small businesses remain a consistent target, not despite their size but partly because of it. According to the ASD Annual Cyber Threat Report 2024–25, small businesses reported average losses of $56,600 per cybercrime incident in the past financial year, an increase of 14 per cent on the year before, and the Australian Cyber Security Centre responded to more than 1,200 incidents while receiving a cybercrime report roughly every six minutes. Attackers favour small businesses because their defences tend to be lighter and because a single small business can offer a path into the larger organisations it supplies. A structured framework, whichever one a business ultimately chooses, is what turns good intentions into something that actually holds up under pressure.
We see the same pattern across almost every new client we bring on board. The technology gaps are rarely the hard part to close. What’s usually missing is the documentation and the accountability that ties the technology together, and that’s exactly what a framework like SMB1001 forces out into the open.
How SMB1001 works
How SMB1001 is structured
SMB1001 organises its requirements into five domains that repeat across every level: technology management, covering the tools and configuration that protect devices and networks; access management, covering who can reach what; backup and recovery, covering how data is protected and restored; policies, processes and plans, covering the documentation that makes expectations explicit; and education and training, covering the people using the systems day to day. A business doesn’t complete one domain and move to the next. Each certification level asks for a slice of all five, which is why the standard reads as a genuine security programme rather than a single technical checklist.
The five SMB1001 certification levels
SMB1001 uses five progressive levels, where each level builds on the controls established below it. The current edition is SMB1001:2026, released in September 2025 and certifiable from January 2026.
Level 1 – Bronze, basic cyber hygiene. The entry level, covering fundamental protections: engaging technical support, firewalls and antivirus software, automatic updates, basic password practices, and backups, which are required from Bronze and remain a requirement at every level above it. Most businesses with reasonably competent IT support already meet the bulk of Bronze without realising it. Worth noting honestly: Bronze’s routine password-change requirement sits at odds with current NIST guidance, which has moved away from forced periodic password rotation, so this is one area where the standard hasn’t fully kept pace.
Level 2 – Silver, managed cyber security. Adds multi-factor authentication across email accounts, a published SPF record for outbound email and the removal of administrative privileges from standard user accounts. The rest of Silver is largely documentation, such as confidentiality agreements for staff and contractors, an invoice fraud policy, and a visitor register for businesses with a physical office.
Level 3 – Gold, organisational governance. The level where SMB1001 really starts to look like a developed security programme. The 2026 edition lifted Gold’s control count from 23 to 27, adding endpoint detection and response on every device, full email authentication with DKIM signing and an enforced DMARC policy, mandatory cyber insurance, a documented incident response plan, a digital asset register, and a responsible AI use policy. Gold does not require MFA on remote access tools such as RDP or VPN and it doesn’t include application control or blocking untrusted Office macros. Both of those wait until Diamond, so you can’t assume Gold is equivalent to Essential Eight Maturity Level One.
Level 4 – Platinum, mature cyber resilience. The first level that requires independent verification rather than director self-attestation, with an external audit organisation checking the work rather than taking the business’s word for it. Platinum adds regular vulnerability scanning of internet-facing systems, formal encryption requirements for data at rest and MFA extended to remote access tools. It’s generally appropriate for larger small businesses with more mature operations and is priced accordingly at roughly $3,595 per year based on current DSI pricing.
Level 5 – Diamond, leading practice. The most advanced level, adding penetration testing, rehearsed incident response drills, a systematic supplier due-diligence programme, application control and blocking untrusted Office macros. It’s the closest SMB1001 gets to ISO 27001 in spirit, without claiming equivalence, and at roughly $5,995 per year, it’s priced for businesses that genuinely need externally audited assurance rather than internal improvement.
Which SMB1001 level is right for your business?
Most businesses with nothing formal in place should start at Bronze and move to Silver quickly, since the jump is largely documentation rather than new technology. Businesses handling sensitive client data, or facing pressure from insurers or larger clients, should target Gold within six to twelve months. Platinum suits larger small businesses, often upward of 100 to 150 staff, with more mature internal operations, and Diamond is rarely necessary unless a business is specifically being asked for externally audited assurance by a large enterprise or government-adjacent client.
We generally steer clients toward Gold as the practical ceiling for most small businesses. Beyond that, the cost and audit burden start to outweigh the benefit unless there’s a specific reason, a large client, a government-adjacent contract, or a genuinely high-risk data holding, driving the decision.
Becoming certified
Who can become SMB1001 certified?
Any small or medium business can pursue SMB1001 and DSI’s intended audience in Australia generally means organisations with fewer than 200 employees. Sole traders and micro businesses can certify, though the value is clearest once a business has staff, customers or contractors whose access needs actual management. Charities and not-for-profits can use the standard in the same way as a commercial business, and it suits professional services firms, particularly law and accounting, well, since industry bodies in Queensland and increasingly Western Australia have pointed members toward SMB1001 Gold as a reasonable way to demonstrate cybersecurity due diligence to clients. Medical practices, which hold sensitive health information, and accountants, which hold financial and identity data, are both natural fits given the sensitivity of what they store.
Is SMB1001 mandatory?
No. SMB1001 isn’t written into Australian law. As of 2026 it isn’t named in the Cyber Security Act 2024, and it hasn’t been added to the Security of Critical Infrastructure Act’s Critical Infrastructure Risk Management Program rules. DSI, under its former name Cyber Security Certification Australia, made a submission in 2024 asking government to formally reference the standard, and that request didn’t land in the 2025 round of amendments. It also isn’t part of any formal Commonwealth government procurement requirement, unlike the Essential Eight, which non-corporate Commonwealth entities have been required to reach Maturity Level Two on since July 2022.
What’s genuinely changed is the practical pressure around it. Clients, tenders and professional bodies are asking for evidence of a recognised framework more often, and SMB1001 is one of the frameworks that comes up. But it’s worth being direct about the current limits of that recognition, particularly with insurers, which is covered further down.
What does the certification process involve?
For Bronze, Silver and Gold, certification runs through a structured self-attestation process on the CyberCert platform. A business, usually working with its IT provider, completes a gap assessment against the target level, closes whatever controls are missing, and then a company director logs in and formally attests that the required controls are genuinely in place. For Platinum and Diamond, an accredited external audit organisation verifies the controls independently before certification is issued. In every case, the certificate is tied to a specific edition of the standard, currently SMB1001:2026, and needs to be reassessed at each
How long does certification take?
For a business with reasonable IT practices already in place, secure email, basic access control, some form of backup, reaching Bronze or Silver can take a matter of weeks. Gold typically takes longer, since it now requires Endpoint Detection and Response (EDR), full email authentication and a documented incident response plan, so most businesses bring in a managed provider to help close those gaps. Platinum and Diamond add the time needed to schedule and complete an external audit on top of the implementation work.
How much does SMB1001 certification cost?
As of 2026, DSI’s listed certification pricing for the self-attested levels, Bronze through Gold, runs from roughly $135 to $1,413 depending on the licence option selected. That figure covers the certification fee itself, not the work needed to close control gaps beforehand, which varies enormously depending on what a business already has in place. Platinum and Diamond, which require an external audit, are priced considerably higher, at roughly $3,595 and $5,995 per year respectively. For most small businesses, the certification fee is a small fraction of the total cost. The bulk of the investment goes into implementing the underlying controls, MFA, EDR, backups and documentation, that the certificate is confirming.
How often do you need to renew certification?
Every year, against whichever edition of the standard happens to be current at the time. Because SMB1001 is deliberately refreshed annually, a certificate earned against an older edition doesn’t carry forward. A business that certified under SMB1001:2025, for example, needs to demonstrate the additional Gold controls introduced in the 2026 edition before its next renewal goes through. Think of it less like a one-off exam and more like an annual check-up your business needs to keep booking in.
What evidence is required?
The level of evidence scales with the certification level. At Bronze, Silver and Gold, the evidence sits with the business, records showing MFA is enabled, backups are tested, policies are documented and staff have completed training, with a director personally attesting that it’s accurate. There’s no external party checking the underlying evidence at these levels, which is worth understanding clearly: a Bronze or Gold certificate reflects director attestation, not independent verification. At Platinum and Diamond, an external auditor reviews that same evidence directly and confirms it before certification is issued.
We tell clients not to treat self-attestation as a formality. Anyone can sign off on paper, but a director attesting to controls that aren’t genuinely in place is making a claim they’d need to stand behind if a client, insurer or regulator ever asked to see the evidence.
Business benefits
Why businesses are adopting SMB1001
Three forces are driving adoption. Clients and supply chain partners are asking small suppliers to demonstrate a recognised framework more often than they used to. Cyber insurance underwriters are tightening their requirements and want concrete evidence rather than a verbal assurance. And business owners themselves are recognising that a specific, verifiable statement, ‘we hold SMB1001 Gold’, carries more weight than a general claim of taking security seriously.
Can SMB1001 help win government contracts?
Many Australian Government agencies reference the Essential Eight when setting cyber security requirements, but the Essential Eight is a technical framework rather than a certification. SMB1001 maps its controls to the Essential Eight, giving businesses a structured way to implement and demonstrate many of the same security measures. If a government contract requires alignment with the Essential Eight, achieving the equivalent level through SMB1001 can provide both evidence of alignment and a recognised cyber security certification. Where a tender specifies a particular framework or maturity level, those requirements should always take precedence.
Can SMB1001 reduce cyber insurance costs?
Yes, it can. Some Australian insurers recognise SMB1001 certification when assessing cyber risk and may offer lower premiums or more favourable policy terms to businesses with stronger cyber security controls. While the level of rrecognition varies between insurers, SMB1001 provides independent evidence of your cyber maturity that can support insurance applications, renewals and discussions with your broker.
Does SMB1001 build customer trust?
A specific, named certification is a more credible statement to a customer than a general assurance and it gives a business a point of reference when a client asks how their data is protected. For business-to-business relationships in particular, it’s beneficial to specify exactly which controls are in place, such as EDR, enforced email authentication, or a documented incident response plan.
Can SMB1001 improve compliance?
SMB1001’s control set was built in consideration of the Privacy Act 1988’s requirement to take reasonable steps to protect personal information, and to ensure the kind of preparedness the Notifiable Data Breaches scheme expects if something goes wrong. Working through SMB1001 doesn’t discharge those legal obligations on its own, since they exist independently of any certification, but the practical work of knowing what data you hold, controlling who can access it and having a documented breach response, overlaps heavily with what the Privacy Act actually expects in practice.
What happens if you don’t have a recognised cyber security framework?
Nothing happens immediately, which is part of the problem. Most small businesses operate for years without a framework and without incident, right up until the point an insurer tightens a renewal, a client asks a security question nobody can answer confidently, or an incident happens and there’s no documented response plan to fall back on. The cost of not having a framework tends to be invisible until exactly the moment it becomes very visible, by which point the fix is reactive rather than planned.
We’d rather have this conversation with a client before any of those moments arrive. A framework doesn’t prevent every incident, but it consistently shortens the gap between something going wrong and the business knowing what to do about it.
SMB1001 compared
SMB1001 vs Essential Eight
The Essential Eight is the Australian Signals Directorate’s cyber security framework, setting out eight technical mitigation strategies measured across four maturity levels. It is widely referenced by Australian Government agencies and many organisations when assessing cyber security.
SMB1001 is a broader cyber security framework designed specifically for small and medium businesses. In addition to technical controls, it covers areas such as governance, policies, access management, backup and recovery, and staff awareness through a staged certification pathway.
SMB1001 maps its controls to the Essential Eight, helping businesses implement many of the same technical security measures while providing a recognised certification that demonstrates their cyber maturity. If a customer or government tender requires alignment with the Essential Eight, businesses should assess their requirements against the specified maturity level, as some higher-level Essential Eight controls extend beyond the requirements of earlier SMB1001 certification levels.
For many small businesses, SMB1001 provides a practical starting point. It strengthens cyber security, provides recognised certification and establishes a foundation that can support future Essential Eight maturity requirements where needed.
SMB1001 vs ISO 27001
ISO 27001 is the international standard for information security management systems, requiring a documented management system, a formal risk assessment process and certification through an accredited third-party auditor. For larger organisations working with enterprise, government or international clients, ISO 27001 is often the standard specified in contracts, procurement requirements and supplier assessments.
SMB1001 shares many of the same underlying security principles, and its higher certification levels align closely with ISO 27001 through published control mappings. This provides small businesses with a practical pathway to implement recognised security controls before progressing to ISO 27001 if a client or contract later requires it. While SMB1001 is designed specifically for small and medium businesses and doesn’t replace ISO 27001 where it is explicitly required, it provides a strong foundation for organisations that may pursue ISO 27001 in the future.
For most Australian small businesses, SMB1001 is the practical starting point, with ISO 27001 becoming relevant when enterprise customers, government contracts or international clients specifically require certification against the ISO standard.
SMB1001 vs Cyber Wardens
These two are easy to confuse but solve different problems. Cyber Wardens is a free, government-funded training program run by the Council of Small Business Organisations of Australia (COSBOA), supported by Telstra, CommBank and the Australian Cyber Security Centre. It’s staff education, not a business certification: owners and employees complete short online modules covering the basics, phishing recognition, password hygiene, device security, and can earn a badge showing a Cyber Warden has been trained within the business. SMB1001 is a certification that assesses and verifies actual technical and organisational controls across the whole business. The training and certification work well together, where Cyber Wardens builds staff awareness at no cost and SMB1001 certifies the underlying controls those staff are meant to be following.
Which framework is right for your business?
If a tender, insurer or client has already named a specific framework then that’s the one to pursue. If nothing specific has been requested, SMB1001 Bronze or Silver is a sensible, low-cost starting point for most small businesses, since it addresses the fundamentals with self-attestation and no external audit required. Businesses supplying government or expecting to need Essential Eight language should run a self-assessment alongside SMB1001 rather than substituting one for the other. Businesses with enterprise or international clients that specifically require ISO 27001 should treat SMB1001 as useful groundwork, not a replacement. And every business, regardless of which certification path it chooses, gets genuine value from putting staff through Cyber Wardens, since it costs nothing and directly addresses the human error that causes most incidents in the first place.
We don’t sell any one of these as the universal answer, because there isn’t one. The starting question is always the same: who is actually asking, and what have they asked for by name?
Preparing your business
How to prepare for SMB1001 certification
Preparation follows a consistent pattern regardless of which level a business is targeting. Start with a gap assessment against the target level, identifying which controls already exist and which are missing. Close the technical gaps first, MFA, backups, endpoint protection, since these are usually the fastest wins. Write the required policies once the technical work is underway, rather than treating documentation as an afterthought. Train staff on what’s actually expected of them under the new controls. Then complete the self-attestation, or schedule an external audit for Platinum and Diamond, once everything is genuinely in place rather than partially implemented.
Common gaps found before certification
- No multi-factor authentication on email or admin accounts, even where the platform supports it at no extra cost
- Backups that run automatically but have never been tested for actual recovery
- Administrative privileges left on everyday user accounts rather than restricted to a small number of dedicated logins
- No documented incident response plan, so nobody has a defined role in the first hour of a suspected breach
- Missing email authentication records, particularly an enforced DMARC policy, which is now required from Gold
- No AI use policy, despite staff already using tools such as ChatGPT or Copilot informally
What documentation will you need?
- A password and access control policy setting out how accounts and credentials are managed
- An incident response plan outlining who does what in the first hour of a suspected breach
- A digital asset register listing the systems and data the business is responsible for protecting
- A responsible AI use policy from Gold level onward, covering acceptable use, data handling and staff training
- Confidentiality agreements for staff and contractors, and an invoice fraud policy from Silver level onward
What technology is commonly required?
- Multi-factor authentication across email, admin and remote access accounts
- A modern backup solution with tested, verifiable recovery, not just an automated job that runs unmonitored
- Endpoint detection and response software from Gold level, replacing basic antivirus
- Email authentication records, SPF from Silver, DKIM and an enforced DMARC policy from Gold
- Automatic patching for operating systems and business-critical software
Common mistakes businesses make
- Trying to jump straight to Gold or Platinum instead of working through Bronze and Silver first, which usually stalls momentum
- Buying security tools before fixing basic processes, leaving expensive software poorly configured around gaps the standard was designed to close
- Treating self-attestation as a formality, rather than genuinely confirming the controls are in place before a director signs off
- Assuming Gold certification is equivalent to Essential Eight Maturity Level One, when several core Essential Eight strategies don’t appear in SMB1001 until Diamond
- Letting certification lapse by missing the annual renewal against the current edition of the standard
Avoiding these is less about extra effort and more about working through the levels in order and being honest about what each one actually proves.
Key takeaways
SMB1001 exists because small businesses needed a cyber security standard built for their actual size, budget and resourcing, not a scaled-down version of something designed for a government department or a multinational. It works through five levels that a business can move through at its own pace, starting with self-attested fundamentals at Bronze and building toward the audited rigour of Platinum and Diamond if the business genuinely needs it. It isn’t mandatory anywhere, and its recognition among insurers and government procurement is less established than MSP marketing sometimes suggests. What it reliably offers is a structured, affordable way to build genuine controls and describe them specifically, rather than vaguely, to a client, an insurer or a regulator. For most Australian small businesses, working toward SMB1001 Gold remains one of the clearest and most achievable ways to do that, provided it’s pursued with a clear-eyed view of what the certificate does and doesn’t guarantee.
Frequently asked questions
SMB1001 is a five-tier cyber security certification standard built specifically for small and medium businesses, maintained by Dynamic Standards International. It covers technology, access, backup, policy and training controls across Bronze, Silver, Gold, Platinum and Diamond levels.
It isn’t a formal acronym. SMB refers to small and medium businesses, and 1001 functions as a model or version identifier rather than an abbreviation with an expanded meaning.
No. SMB1001 is a voluntary cyber security framework and certification standard. No Australian law currently requires businesses to achieve SMB1001 certification.
SMB1001 was developed by Dynamic Standards International (DSI), formerly Cyber Security Certification Australia. Certification is administered through the CyberCert platform.
SMB1001 was developed to give Australian small and medium businesses a practical, affordable cyber security framework and certification pathway. It provides an alternative to enterprise-focused standards such as ISO 27001 while covering broader business controls than technical frameworks such as the Essential Eight.
SMB1001 certification is designed to be affordable for small businesses. Certification fees for the self-attested Bronze, Silver and Gold levels currently range from approximately $135 to $1,413 per year. Platinum and Diamond require an independent audit and have higher certification fees. Businesses should also budget for implementing any security controls needed before certification.
SMB1001 Bronze or Silver can often be reached within a matter of weeks for a business with reasonable IT practices already in place. Gold typically takes longer given its expanded control set, and Platinum and Diamond add the time needed for an external audit.
Yes. Sole traders can achieve SMB1001 certification, although the benefits generally increase as a business grows, employs staff or manages larger amounts of customer information.
Yes. SMB1001 can be used by any eligible small or medium organisation, including charities and not-for-profit organisations, to implement and demonstrate recognised cyber security controls.
Yes, and the sensitivity of health information makes it a particularly good fit, though practices should confirm how SMB1001 sits alongside any specific health-sector privacy obligations that already apply to them.
Yes. Accounting firms hold sensitive financial and identity data, and professional bodies in some states have pointed members in adjacent professions, including law, toward SMB1001 Gold as a reasonable benchmark.
No. SMB1001 shares some structural thinking with ISO 27001 and DSI publishes a control mapping between the two, but ISO 27001 remains the credential that carries weight with enterprise and international procurement teams specifically asking for it by name.
SMB1001 aligns many of its controls with the Australian Signals Directorate’s Essential Eight, but the two are not identical. Businesses that need to demonstrate a specific Essential Eight maturity level should assess their controls directly against the Essential Eight framework.
Not necessarily. Some businesses can achieve SMB1001 Bronze certification using their existing IT support. Many businesses engage a managed IT or cyber security provider when working towards higher certification levels because of the additional technical and governance requirements.
For Bronze, Silver and Gold, the business itself self-attests through the CyberCert platform, with a company director confirming the controls are in place. For Platinum and Diamond, an independent external audit organisation verifies the controls directly.
Annually, against whichever edition of the standard is current. Businesses need to demonstrate any new controls introduced in a given year’s edition at their next renewal, not just repeat their previous attestation.
Australian Government agencies commonly reference the Essential Eight rather than SMB1001 when specifying cyber security requirements. Because SMB1001 maps many of its controls to the Essential Eight, it can provide a practical pathway for businesses preparing to meet government cyber security expectations.
Some Australian insurers recognise SMB1001 certification when assessing cyber risk and may offer improved policy terms or premium discounts. Recognition varies between insurers, so businesses should confirm how their insurer or broker assesses cyber security certification.
Most businesses beginning their cyber security journey start with Bronze before progressing to Silver and Gold. Businesses responding to customer, insurer or tender requirements may choose to target a higher certification level sooner.
For Bronze, Silver and Gold, there’s no pass or fail moment as such, since the business controls the pace of its own self-attestation and only attests once the controls are genuinely in place. For Platinum and Diamond, an external audit that identifies gaps typically results in a remediation period before certification is issued, rather than an outright rejection.
Continue reading
Is your small business at risk of a cyber attack?
Do Australian small businesses need cyber security certification?
What is a cyber security framework, and what does implementing one involve?
What’s the easiest way for a small business to become cyber compliant?
Essential Eight vs SMB1001 vs ISO/IEC 27001: Which cyber security framework is right for your business?
Should I use a managed service provider to implement SMB1001, or can I do it internally?
How much does SMB1001 cost? Is it worth the investment?
SMB1001 implementation roadmap: from assessment to certification
Cyber governance for Australian small businesses: Building resilience and trust
Why choose The IT Agency for SMB1001? How to choose the right implementation partner
About The IT Agency
The IT Agency helps keep businesses connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions. As a Microsoft Solutions Partner and SMB1001 Gold Certified MSP, we help businesses simplify IT, implement technology securely and strengthen resilience. Talk to us about building a more secure and future-ready business.
References
https://dsi.org/smb1001
https://cybercert.ai
https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/essential-eight/essential-eight-maturity-model
https://www.homeaffairs.gov.au
https://www.oaic.gov.au/privacy/notifiable-data-breaches
https://www.iso.org/standard/27001
https://cyberwardens.com.au
https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025
The IT Agency
The IT Agency helps businesses stay connected, protected, productive and supported through cyber governance, compliance, AI and managed IT solutions.