Compliance · SMB1001

SMB1001: cyber certification built for small business

SMB1001 is an affordable, tiered cyber security certification made for small and medium businesses: a practical way to prove your security to clients, insurers and regulators, without the cost and complexity of ISO 27001.

Get certified with Itopia Our compliance service
What it is

A cyber standard sized for small business

SMB1001 is an Australian certification standard written for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it is revised every year; the current edition is SMB1001:2026. Rather than one big pass-or-fail audit, it has five levels, Bronze through to Diamond. You certify at the level that fits your size and risk, and move up when you need to.

The first three levels are self-attested: once the controls are in place, a director signs off in the CyberCert portal and the certificate is issued. Platinum and Diamond are checked by an independent auditor. A certificate is valid for twelve months, so it is renewed each year against whatever the current edition asks for.

The controls themselves are the same fundamentals you will find in the Essential Eight and the UK's Cyber Essentials, just packaged so a business without a security team can actually get there. Two things changed in the 2026 edition worth knowing about: endpoint detection and response is now required at Gold rather than a higher level, and there is a new control on how staff use AI tools with company and client data. If you certified under an earlier edition, your next renewal will be marked against these.

Why now

Who is asking you to prove it

Cyber security used to be something you did quietly in the background. Now other people want to see it.

Cyber insurers

Renewal questionnaires now ask for evidence of specific controls. A current certificate answers most of them in one line.

Larger clients and tenders

Corporates, government and industry bodies increasingly require suppliers to demonstrate their security. SMB1001 is built to be that proof.

Professional obligations

Accounting, legal and healthcare practices hold sensitive client data and are expected to show due care, not just claim it.

Your own peace of mind

Certifying against a recognised standard replaces "I think we are OK" with a checked list of what is actually in place.

Industry guidance

Law firms: the Queensland Law Society recommends Gold

The Queensland Law Society has formally endorsed SMB1001 and recommends member practices work towards Gold certification as a reasonable standard for robust cyber security and professional assurance. It sits alongside a solicitor's ethical duty to take reasonable steps to protect client confidentiality, and QLS notes improved insurability as one of the benefits.

Practices insured through Lexon should also note that cyber cover benefits can reduce where minimum data-protection obligations are not met, which makes a current certificate a sensible thing to hold. Read the QLS guidance.

What Gold asks of a practice
  • Endpoint detection and response on every device
  • Multi-factor authentication and access control
  • Tested, separate backups
  • Email security and staff awareness training
  • Documented policies, incident response and governance
Talk to us about Gold for your firm
The five tiers

Start where you are, climb as you grow

Each tier builds on the one below it. Most businesses start at Bronze or Silver and work up to the level their clients and insurers expect.

Level 1

Bronze

Self-attested

Foundational hygiene: backups, endpoint protection, multi-factor authentication and basic policies. The entry point for businesses just starting out.

Level 2

Silver

Self-attested

Formalises your practices with access controls, email security and documented policies your team actually follows.

Most aim here
Level 3

Gold

Self-attested

Endpoint detection and response (EDR), monitoring, governance and incident response. Where most compliance-driven SMBs aim.

Level 4

Platinum

Independently audited

Mature security operations, with an independent auditor verifying that your controls are real and operating.

Level 5

Diamond

Independently audited

The highest tier: penetration testing, supply-chain trust and enterprise-grade governance.

Tier requirements, control counts and certification fees are set by Dynamic Standards International and CyberCert and may change. This page is general information, not compliance advice.

How we help

We do the work, you get certified

Most of the controls SMB1001 asks for are things we already deliver, so certification reflects real, operating security, not paperwork.

  1. 01

    Pick the right tier

    We look at who is asking, what they expect and where you are today, and recommend a tier that fits. There is no prize for over-reaching.

  2. 02

    Gap assessment

    We benchmark your accounts, devices, email, backups and policies against your target tier and hand you a short, plain-English list of what needs to change.

  3. 03

    Close the gaps

    Most controls are ones we already deliver, largely through Microsoft 365 Business Premium: conditional access so only managed, compliant devices reach company data, EDR on every endpoint, tested backups, email security and awareness training.

  4. 04

    Evidence and attestation

    We prepare the evidence and documentation, then walk your director through sign-off in the CyberCert portal (or the independent audit for Platinum and Diamond).

  5. 05

    Maintain and progress

    Certification lasts 12 months. We keep the controls operating all year, re-certify you against the current edition, and map the path to the next tier as you grow.

Get started

Talk to us about SMB1001 certification

Tell us a little about your business and who is asking for certification, and a Brisbane technician will come back to you, usually within one business day, with a recommended tier and next steps. No obligation.

We only use your details to respond to your enquiry. No marketing lists, no spam, and we never share your information. See our privacy policy.

Common questions

SMB1001, answered plainly

What is SMB1001?

SMB1001 is an Australian-developed cyber security certification standard for small and medium businesses, published by Dynamic Standards International (DSI) and certified through the CyberCert platform. It has five progressive tiers (Bronze, Silver, Gold, Platinum and Diamond) so a business can certify at a level that matches its size and risk, then climb as it grows.

Which tier does my business need?

It depends on who is asking. Most small businesses start at Bronze or Silver and work up to Gold, which is where most insurers, larger clients and tenders are comfortable. Platinum and Diamond are for businesses with higher-risk data or contractual obligations that call for independent audit. We recommend a tier as part of the gap assessment rather than guessing.

Our law firm is a QLS member. Which tier should we aim for?

The Queensland Law Society has formally endorsed SMB1001 and recommends member practices work towards Gold certification as a reasonable standard for robust cyber security and professional assurance. Gold is self-attested, so no external audit is required, but it does call for endpoint detection and response, incident response planning and documented governance. We help Brisbane law firms close those gaps and prepare the evidence for the principal to sign off.

How long does it take to get certified?

It comes down to the size of the gap. A business already on a well-run managed IT plan is often most of the way to Silver or Gold before we start, so the work is mainly documentation and evidence. A business starting from scratch needs the controls put in place first, which takes longer. The gap assessment gives you a realistic timeline before you commit to anything.

What does SMB1001 certification cost?

There are two parts: the certification fee itself, which is set by CyberCert and varies by tier, and the cost of any controls you do not yet have in place. For most of our managed IT clients the second part is small, because the controls are already running. We quote the work after the gap assessment so there are no surprises.

Is SMB1001 the same as the Essential Eight?

No, but they overlap heavily. The Essential Eight is the Australian Cyber Security Centre's set of mitigation strategies; it is a framework you align to, not a certificate you can show a client. SMB1001 draws on the same controls but packages them into a tiered, certifiable standard. Many businesses do both: Essential Eight as the engineering baseline, SMB1001 as the proof.

Does the certification expire?

Yes. An SMB1001 certificate is valid for 12 months, and the standard itself is revised each year (the current edition is SMB1001:2026). Re-certifying annually against the current edition is part of how we maintain it for you.

We already have cyber insurance. Do we still need this?

Increasingly, yes. Insurers are asking more detailed questions at renewal about the controls you have in place, and some are declining or loading policies where the answers are vague. A current SMB1001 certificate is clear evidence of your posture and can make renewal considerably smoother.

Ready to prove your cyber security?

We'll help you pick the right tier and get you certified, without the enterprise overhead.

Start with a gap assessment Call 07 3063 2211