A cyber standard sized for small business
SMB1001 is an Australian certification standard written for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it is revised every year; the current edition is SMB1001:2026. Rather than one big pass-or-fail audit, it has five levels, Bronze through to Diamond. You certify at the level that fits your size and risk, and move up when you need to.
The first three levels are self-attested: once the controls are in place, a director signs off in the CyberCert portal and the certificate is issued. Platinum and Diamond are checked by an independent auditor. A certificate is valid for twelve months, so it is renewed each year against whatever the current edition asks for.
The controls themselves are the same fundamentals you will find in the Essential Eight and the UK's Cyber Essentials, just packaged so a business without a security team can actually get there. Two things changed in the 2026 edition worth knowing about: endpoint detection and response is now required at Gold rather than a higher level, and there is a new control on how staff use AI tools with company and client data. If you certified under an earlier edition, your next renewal will be marked against these.
Who is asking you to prove it
Cyber security used to be something you did quietly in the background. Now other people want to see it.
Cyber insurers
Renewal questionnaires now ask for evidence of specific controls. A current certificate answers most of them in one line.
Larger clients and tenders
Corporates, government and industry bodies increasingly require suppliers to demonstrate their security. SMB1001 is built to be that proof.
Professional obligations
Accounting, legal and healthcare practices hold sensitive client data and are expected to show due care, not just claim it.
Your own peace of mind
Certifying against a recognised standard replaces "I think we are OK" with a checked list of what is actually in place.
Law firms: the Queensland Law Society recommends Gold
The Queensland Law Society has formally endorsed SMB1001 and recommends member practices work towards Gold certification as a reasonable standard for robust cyber security and professional assurance. It sits alongside a solicitor's ethical duty to take reasonable steps to protect client confidentiality, and QLS notes improved insurability as one of the benefits.
Practices insured through Lexon should also note that cyber cover benefits can reduce where minimum data-protection obligations are not met, which makes a current certificate a sensible thing to hold. Read the QLS guidance.
- Endpoint detection and response on every device
- Multi-factor authentication and access control
- Tested, separate backups
- Email security and staff awareness training
- Documented policies, incident response and governance
Start where you are, climb as you grow
Each tier builds on the one below it. Most businesses start at Bronze or Silver and work up to the level their clients and insurers expect.
Bronze
Foundational hygiene: backups, endpoint protection, multi-factor authentication and basic policies. The entry point for businesses just starting out.
Silver
Formalises your practices with access controls, email security and documented policies your team actually follows.
Gold
Endpoint detection and response (EDR), monitoring, governance and incident response. Where most compliance-driven SMBs aim.
Platinum
Mature security operations, with an independent auditor verifying that your controls are real and operating.
Diamond
The highest tier: penetration testing, supply-chain trust and enterprise-grade governance.
Tier requirements, control counts and certification fees are set by Dynamic Standards International and CyberCert and may change. This page is general information, not compliance advice.
We do the work, you get certified
Most of the controls SMB1001 asks for are things we already deliver, so certification reflects real, operating security, not paperwork.
- 01
Pick the right tier
We look at who is asking, what they expect and where you are today, and recommend a tier that fits. There is no prize for over-reaching.
- 02
Gap assessment
We benchmark your accounts, devices, email, backups and policies against your target tier and hand you a short, plain-English list of what needs to change.
- 03
Close the gaps
Most controls are ones we already deliver, largely through Microsoft 365 Business Premium: conditional access so only managed, compliant devices reach company data, EDR on every endpoint, tested backups, email security and awareness training.
- 04
Evidence and attestation
We prepare the evidence and documentation, then walk your director through sign-off in the CyberCert portal (or the independent audit for Platinum and Diamond).
- 05
Maintain and progress
Certification lasts 12 months. We keep the controls operating all year, re-certify you against the current edition, and map the path to the next tier as you grow.
Talk to us about SMB1001 certification
Tell us a little about your business and who is asking for certification, and a Brisbane technician will come back to you, usually within one business day, with a recommended tier and next steps. No obligation.
SMB1001, answered plainly
What is SMB1001?
SMB1001 is an Australian-developed cyber security certification standard for small and medium businesses, published by Dynamic Standards International (DSI) and certified through the CyberCert platform. It has five progressive tiers (Bronze, Silver, Gold, Platinum and Diamond) so a business can certify at a level that matches its size and risk, then climb as it grows.
Which tier does my business need?
It depends on who is asking. Most small businesses start at Bronze or Silver and work up to Gold, which is where most insurers, larger clients and tenders are comfortable. Platinum and Diamond are for businesses with higher-risk data or contractual obligations that call for independent audit. We recommend a tier as part of the gap assessment rather than guessing.
Our law firm is a QLS member. Which tier should we aim for?
The Queensland Law Society has formally endorsed SMB1001 and recommends member practices work towards Gold certification as a reasonable standard for robust cyber security and professional assurance. Gold is self-attested, so no external audit is required, but it does call for endpoint detection and response, incident response planning and documented governance. We help Brisbane law firms close those gaps and prepare the evidence for the principal to sign off.
How long does it take to get certified?
It comes down to the size of the gap. A business already on a well-run managed IT plan is often most of the way to Silver or Gold before we start, so the work is mainly documentation and evidence. A business starting from scratch needs the controls put in place first, which takes longer. The gap assessment gives you a realistic timeline before you commit to anything.
What does SMB1001 certification cost?
There are two parts: the certification fee itself, which is set by CyberCert and varies by tier, and the cost of any controls you do not yet have in place. For most of our managed IT clients the second part is small, because the controls are already running. We quote the work after the gap assessment so there are no surprises.
Is SMB1001 the same as the Essential Eight?
No, but they overlap heavily. The Essential Eight is the Australian Cyber Security Centre's set of mitigation strategies; it is a framework you align to, not a certificate you can show a client. SMB1001 draws on the same controls but packages them into a tiered, certifiable standard. Many businesses do both: Essential Eight as the engineering baseline, SMB1001 as the proof.
Does the certification expire?
Yes. An SMB1001 certificate is valid for 12 months, and the standard itself is revised each year (the current edition is SMB1001:2026). Re-certifying annually against the current edition is part of how we maintain it for you.
We already have cyber insurance. Do we still need this?
Increasingly, yes. Insurers are asking more detailed questions at renewal about the controls you have in place, and some are declining or loading policies where the answers are vague. A current SMB1001 certificate is clear evidence of your posture and can make renewal considerably smoother.
Go deeper on SMB1001
Getting SMB1001 certified in 2026: a step-by-step guide
How certification actually works, from choosing a tier to attesting and maintaining it.
Read the article →SMB1001 vs Essential Eight: which does your business need?
The two Australian standards compared, and why many businesses end up using both.
Read the article →5 ways to reduce your cyber insurance premium
What insurers are actually looking for, and the controls that move the needle.
Read the article →