The SMB1001 Bronze requirements checklist is shorter than most business owners expect. Where the Essential Eight asks for eight mitigation strategies across three maturity levels, SMB1001's entry tier asks for four things, self-attested by a director, with no external audit. That's the point of Bronze. It's the on-ramp, not the destination, and it's deliberately achievable in weeks rather than months.
This is a plain walk-through of what Bronze actually requires under the current SMB1001:2026 standard, who it's realistically for, how the self-attestation process works, and which tools tick each box without over-buying for a tier that doesn't ask for them yet.
Who Bronze is for
Bronze (Level 1) is built for businesses with little or no formal cyber security in place: the sole trader running a laptop and a phone, the five-person office with a shared Gmail login, the trades business that's never had an IT conversation beyond "is the wifi working". Dynamic Standards International (DSI) publishes SMB1001 with five progressive tiers precisely so a business this size isn't handed the same bar as a bank. You don't need Bronze if you're already running MFA, individual logins and a documented backup plan. You'd clear Silver on day one, and Bronze would just be a slower way to get there.
Where Bronze earns its keep is as a forcing function. A director has to personally attest that the controls are in place, which turns "we should probably sort out backups" from a vague intention into a signed statement with their name on it. That alone gets more SMBs over the basic-hygiene line than a security audit report nobody reads.
The SMB1001 Bronze requirements checklist, item by item
The current edition of the standard, SMB1001:2026, was released in September 2025 and is the version CyberCert now certifies against. Tier structures have shifted release to release, so treat anything referencing SMB1001:2025 control counts as dated. Bronze itself asks for four things:
- Engage technical support. In-house IT or an external provider or MSP. The standard just wants someone accountable for keeping the environment maintained, rather than nobody.
- Install and configure a firewall. A properly configured firewall on the network, not just whatever shipped switched on by default.
- Run antivirus or anti-malware on every device. Reputable, active, and covering every endpoint that touches business data, not a subset.
- Implement an automated backup and recovery process. Not a manual copy someone remembers to run, but a process that happens on a schedule and that someone could actually recover from.
Notice what's missing: no MFA requirement, no individual-account mandate, no written policy. Those arrive at Silver, along with a regular update cadence and staff awareness training. Bronze is intentionally narrow. It covers the four controls that stop the most common opportunistic attacks (an unpatched exposed service, a phished shared login, a ransomware note with no backup to fall back on) without asking a five-person business to run an access-management programme it doesn't have the headcount for.
Self-attestation: how it actually works
Bronze, Silver and Gold are all self-attested rather than externally audited, which is what keeps them fast and cheap. In practice, a company director logs into the CyberCert certification portal (CyberCert is the body DSI appointed to issue certificates against the standard) and personally signs off that each control is genuinely in place. It has to be a director. Not the IT manager, not the MSP managing the environment on the business's behalf. The person with legal accountability for the business puts their name to the claim.
That detail matters more than it sounds. It means a director can't outsource the risk of a false attestation to whoever happens to manage the firewall. If you're a director about to attest, walk your environment against the four items above yourself before you sign, even if an IT provider tells you it's covered.
External audits don't start until Platinum, so Bronze and Silver both run on the honour system. That's also why they're achievable in days to a few weeks once the underlying controls are actually in place, rather than the months an audited tier takes.
Tools that tick each control
You don't need enterprise security spend to clear Bronze, but the right platform saves a lot of manual admin, especially once you're maintaining evidence for the attestation. For the antivirus and technical-support controls, a unified MSP-delivered platform like Guardz covers managed antivirus on every plan (with SentinelOne-grade EDR available on the higher tiers) alongside the "someone accountable" requirement, since it's delivered and monitored by the MSP running it. It's built for MSPs to run across their client base rather than something a business installs itself, so it's most relevant if you're already working with, or looking to appoint, a managed provider.
For the backup and recovery control, the requirement is deliberately unspecific about the tool. It just has to be automated and it has to actually restore. If your business runs on Microsoft 365 or Google Workspace, native retention isn't backup (it's designed for accidental deletion inside a short window, not ransomware or a departing employee wiping a mailbox). That's the gap a dedicated SaaS backup platform like Keepit is built to close: automated, scheduled, and independent of the platform it's protecting. We've covered the broader case for that distinction in our Essential Eight backup requirements guide, which maps the same "is a copy actually a backup" question against the ASD's framework.
Firewall and technical support are more environment-specific. What you run depends on whether you're on-prem, cloud, or hybrid, and whether IT is in-house or outsourced. The standard doesn't mandate a vendor for either, only that they're in place and someone owns them.
Path to Silver
Bronze is the floor, not a resting point. SMB1001 is built to be climbed, and Silver is a meaningfully bigger step than Bronze was from nothing. Where Bronze asks for a firewall, antivirus, backups and someone accountable, Silver adds individual user accounts (shared logins stop qualifying), multi-factor authentication on email and other key accounts, a regular and timely update and patch cadence, staff cyber security awareness training, and a documented, not just implemented, backup and recovery plan.
The jump matters because it closes the two breach vectors Bronze doesn't touch at all: credential theft (shared logins, no MFA) and human error (no training, no documented process for anyone to follow when the person who set it up is on leave). If you're attesting to Bronze today with half an eye on Silver next quarter, MFA and individual accounts are the two items worth starting early, since they tend to take longer to roll out across a team than the technical controls do.
Bronze certification is self-attested and, at the time of writing, priced by CyberCert at roughly AUD $95 a year. The certificate itself is cheap; the real cost is whatever work it takes to get the four controls genuinely in place first. For most small businesses starting from nothing, that's a firewall check, an antivirus rollout, and a proper automated backup, all achievable well inside the "days to a few weeks" window the self-attestation model is designed around. When you're ready, our SMB1001 Silver requirements checklist walks through the five controls that tier adds.
Sources: SMB1001:2026 changes explained, SMB1001 in 2026: what the certificate actually proves, SMB1001 & CyberCert: how it all hangs together.
