Back to Blog
Backup & DR16 August 2026

SMB1001 Diamond Requirements: What Changes at the Top Tier

Cloud Ready SolutionsGuardz, Keepit

Diamond is the last stop on the SMB1001 ladder, and it looks less like a heavier version of Platinum than a different kind of certificate altogether. Where Platinum swaps self-attestation for a once-a-year external audit, the SMB1001 Diamond requirements keep that audit and add something Platinum does not ask for: continuous, real-time verification that the controls are still working between audits, not just on the day the auditor visited.

This is a plain walk-through of what Diamond (Level 5) adds on top of Platinum, who genuinely needs it, what changes mechanically compared to a periodic audit, and what it costs — closing out the series that started with Bronze and worked up through Silver, Gold and Platinum.

Who Diamond is for

Diamond is not the natural next step for most businesses that have cleared Platinum. It is built for organisations carrying genuinely elevated risk or obligations that flow down from someone else's compliance programme — a supplier in a defence or critical-infrastructure supply chain, a business whose enterprise or government customers are themselves running ISO 27001, Essential Eight or APRA CPS 234 and pushing security requirements down to vendors, or a business handling data sensitive enough that a once-a-year audit snapshot is not reassurance enough for the people relying on it.

For a typical 10-to-100-person SMB, Platinum is usually the practical ceiling. Diamond suits the smaller set of businesses where a customer's procurement team, a regulator, or a prime contractor is asking a harder question than "were you compliant on audit day" — they want ongoing evidence that the controls are still standing months later, under continuous review rather than a point-in-time check. A managed services provider selling security services on the strength of its own certification is a common example, since its own customers are effectively trusting Diamond's continuous-verification claim on faith unless it is genuinely being lived, not just renewed once a year.

The SMB1001 Diamond requirements, item by item

Diamond carries everything Platinum asks for — phishing-resistant MFA, internet-facing vulnerability scanning, tested recovery, stronger monitoring commitments, independent audit — and adds a further set of controls that push from "audited periodically" to "monitored continuously":

  1. Continuous auditing and compliance monitoring. Instead of a point-in-time audit that is revisited annually, Diamond expects ongoing evidence that controls remain in place between formal audit cycles — closer to a live compliance posture than a snapshot.
  2. Real-time security analytics (SIEM/SOC). Genuine security information and event management, correlating activity across the environment as it happens, not log review after the fact.
  3. Application control. Whitelisting what is allowed to run rather than only blacklisting what is known-bad — a materially more restrictive and more operationally demanding control than anything below Platinum.
  4. Full encryption at rest. Data encrypted wherever it is stored, not only in transit, closing a gap that lower tiers do not explicitly require.
  5. Penetration testing and social engineering exercises. Adversary simulation — someone actively trying to get in, including testing staff against phishing and pretexting — rather than automated vulnerability scanning alone.
  6. Formal supplier assurance. Documented arrangements — some sources describe these as Digital Trust Agreements — with key suppliers, extending the business's own security expectations down its own supply chain rather than stopping at its own perimeter.
  7. Active collaboration with cyber security professionals, plus mature, regularly exercised response and recovery. The incident response and recovery-testing controls from Platinum, expected to be genuinely embedded and practised rather than demonstrated once for an auditor.

What changes: continuous, not periodic

The mechanical shift from Platinum to Diamond keeps the same audit model — a CyberCert-approved Independent Verification Organisation still has to assess the environment — but the standard it is assessed against is no longer "prove it was true on the day of the audit." Diamond expects governance and monitoring embedded in the way the business actually runs: control review, remediation and leadership oversight as part of the operating rhythm, not an annual fire drill timed to the audit booking.

That is a genuinely different commitment, not just a longer control list. A business can pass a Platinum audit with strong preparation in the weeks beforehand. Diamond is much harder to prepare for late, because the evidence an auditor wants is continuity — logs and reports that show the SIEM was live and the compliance monitoring was running months earlier, not just in the week before the assessor arrived. A business that stands up a SOC tool the month before its Diamond renewal has nothing to show for the eleven months before that, and an auditor assessing continuous controls will notice the gap in the record even if the tool itself is configured correctly on the day.

Tools that tick each Diamond control

The continuous monitoring and real-time analytics controls map directly onto Guardz Managed Detection & Response — its 24/7 agentic-AI-plus-human-SOC model runs across identity, endpoint and email in one playbook, which is closer to the continuously watched, not periodically reviewed, evidence Diamond is actually looking for than a traditional endpoint-only tool. The same platform's incident reporting also feeds the active-collaboration-with-cyber-security-professionals control, since a managed SOC relationship is that collaboration in practice, not just a purchased licence.

Recovery testing carries over unchanged from Platinum: Keepit's independent, immutable backup still needs a real restore run and documented, and Diamond's "mature, regularly exercised" language makes a one-off test from the Platinum audit insufficient — it needs to keep happening on a schedule, with each run adding to the evidence trail rather than replacing the last one. Application control, full encryption at rest, penetration testing and formal supplier assurance agreements are not capabilities any single CRS vendor owns outright — they are organisational and procurement decisions (which endpoint platform enforces whitelisting, which storage layer encrypts at rest by default, which firm runs the penetration test, what a supplier contract actually requires) that sit above the product layer, and are worth scoping with an MSP or security partner before booking a Diamond audit rather than assuming a product purchase closes them.

Cost, effort, and the reality check

CyberCert's reported Diamond certificate fee runs to roughly AUD $5,995 a year, ex GST, up from Platinum's roughly $3,595. The external audit fee sits on top of that again, in the same broad $3,000–$8,000-plus range Platinum draws on, though a Diamond-scope audit — covering continuous monitoring evidence and supplier assurance on top of everything Platinum checks — is realistically toward the upper end of that range rather than the lower one for most environments.

The bigger cost most businesses underestimate is not the certificate or the audit — it is standing up genuinely continuous monitoring, application control and a real penetration-testing cadence where none existed before, none of which are quick to implement or cheap to run indefinitely. Businesses moving straight from a fresh Platinum pass should expect Diamond readiness to take months rather than weeks, and should treat the first few months of continuous monitoring as evidence-gathering before even approaching an Independent Verification Organisation for a quote. This is not a tier to attempt as a badge exercise. If nothing in the "who Diamond is for" section above actually describes the business — no defence or critical-infrastructure supply chain obligation, no enterprise customer demanding continuously verified security — Platinum, kept genuinely current, is very likely the better use of the budget.

That closes out the SMB1001 tier series. Bronze through Diamond each add a distinct layer, from self-attested essentials to continuously verified, audited maturity — SMB1001 itself has the full tier comparison if you are deciding where to start rather than where to finish.

Sources: What Are the SMB1001 Requirements? Every Tier Explained, SMB1001 Diamond Certification (Tier 5), SMB1001:2026 Changes Explained for Perth Businesses, SMB1001 in 2026: What the Cyber Certificate Actually Proves

Related Vendors

GuardzKeepit