Gold is where SMB1001 stops feeling like a checklist and starts asking a business to run something closer to a real security programme. The jump from Bronze's four essentials to Silver's access controls was already a step up; the jump from Silver to Gold (Level 3) is bigger again, because the SMB1001:2026 edition expects 27 controls at Gold, not five headline items, and several of them come with a technical bar that "installed and switched on" doesn't clear.
This is a plain walk-through of what the SMB1001 Gold requirements actually ask for under the current standard, who's ready to attempt it, how self-attestation holds up against a materially more technical set of controls, and which tools cover the ground without over-buying for a tier you're not at yet.
Who Gold is for
Gold suits a business that has genuinely cleared Silver, not one hoping to skip ahead. That means individual accounts and MFA are already the norm, staff have been through security awareness training, and the backup plan is written down and tested rather than assumed. Gold adds detection and response on top of that foundation, so a business still running shared logins or unpatched software has Silver-level gaps to close first, and Gold will only expose them rather than fix them.
It's the tier for an established SMB that's outgrown "we have antivirus and a firewall" as an answer to "what's our security posture," and wants a certificate that reflects active monitoring rather than passive hygiene. It's also, realistically, the tier where a business without an existing MSP relationship starts to feel the gap, since several Gold controls — EDR with behavioural detection, 24/7 monitoring, an incident response plan someone has actually thought through — are hard to run well without a managed platform behind them. A business trying to self-manage Gold with an internal generalist IT person is possible, but it's a materially bigger lift than self-managing Bronze or Silver was.
The SMB1001 Gold requirements, item by item
Gold carries everything Silver asks for (MFA, individual accounts, patching, awareness training, a documented backup plan) plus five categories of new control that SMB1001:2026 expanded into 27 individual items overall, up from 23 in the 2025 edition:
- Endpoint Detection & Response (EDR) on every device. This is the control most businesses under-deliver on without meaning to. The 2026 standard is explicit that antivirus alone doesn't qualify — Gold expects continuous telemetry, behavioural detection and automated response on workstations, laptops and servers, not a signature-based scanner that only catches what it already recognises.
- Email authentication — SPF, DKIM and DMARC, actively enforced. The detail that trips people up: DMARC has to be set to quarantine or reject forged mail, not left on monitor-only, which reports on spoofing without stopping any of it. A lot of businesses that think they've "done DMARC" have only done the reporting half.
- Continuous system monitoring. Something is actually watching the environment day to day, not just generating alerts nobody reads.
- A documented incident response plan. Not a folder of good intentions — a plan that names who does what, in what order, when something goes wrong, and that's been thought through rather than templated and filed.
- Access control and privilege management. Beyond individual accounts (a Silver control), Gold asks who has admin rights and why, whether that access is reviewed on a schedule rather than accumulated by default over time, and whether departing staff actually lose access on their last day rather than weeks later.
Why the standard got heavier
SMB1001 is revised periodically by Dynamic Standards International, and the 2026 edition's expansion of Gold from 23 to 27 controls tracks a broader pattern across cyber security standards generally: baseline "have a tool" requirements are being replaced with "the tool is configured correctly" requirements, because the gap between the two is exactly where a lot of real breaches happen. Antivirus that's installed but not managed, or DMARC that's present but set to monitor-only, satisfied an older, more permissive reading of "have email authentication." The 2026 tightening closes that gap deliberately.
Self-attestation: a bigger claim than it looks
The mechanics haven't changed since Bronze: a company director logs into the CyberCert portal and personally attests that the controls are in place. There's still no external audit at Gold — that starts at Platinum. What's changed is the size and specificity of the claim. Attesting "we have antivirus" at Bronze was close to binary. Attesting that DMARC is set to reject rather than monitor, or that EDR includes behavioural detection rather than signature matching, requires a director to actually know those distinctions exist, not just that a product with the right name is installed somewhere. A director signing off on Gold without checking the DNS records and the EDR console configuration is vouching for more than they've verified.
Tools that tick each Gold control
The email authentication control is worth calling out specifically, because DMARC, SPF and DKIM are notoriously easy to half-implement. Cibecs SendMarc is a purpose-built platform for exactly this: it automates the SPF flattening and DKIM key management most IT teams find painful to maintain by hand, and it guarantees a move to full DMARC enforcement — not just monitoring — within 90 days, which lines up precisely with what Gold expects the policy to actually do.
EDR, continuous monitoring and access-and-privilege visibility sit naturally with a unified MSP-delivered platform. Guardz covers SentinelOne-based EDR from its Control tier upward, 24/7 AI-plus-human MDR for the continuous monitoring control, and identity-tier detection across Entra ID and Google Workspace that feeds directly into an access-control review. The incident response plan is the one control no product ships pre-written — it has to reflect the actual business, its actual systems and its actual escalation contacts — but a platform already coordinating detection and response across endpoint, email and identity makes the plan easier to write, because there's one console the plan can point to, not five.
Cost, effort, and the cyber insurance angle
CyberCert prices the Gold certificate at roughly AUD $395 a year, ex GST, up from Silver's roughly $195 and Bronze's roughly $95. As with the tiers below it, the certificate fee is the smaller number. Businesses that already have Silver's foundation in place commonly certify Gold in four to eight weeks; a business starting from further back — no EDR, DMARC left on monitor-only, no written incident response plan — should expect that window to stretch, since standing up behavioural EDR and moving DMARC to a reject policy safely (a misconfigured DMARC record can silently block legitimate mail) both take genuine testing time, not just a purchase.
It's also the tier where the cyber insurance conversation tends to get more concrete. Insurers increasingly want evidence of active detection and email authentication specifically, not just a general statement that "security is in place," and Gold's control set maps closely onto what a renewal questionnaire actually asks. A certificate doesn't guarantee cover or pricing, but it removes a lot of the back-and-forth an insurer would otherwise need to chase down control by control.
Path to Platinum
SMB1001 changes shape entirely at the next tier. Platinum (Level 4) is where self-attestation ends: an independent external audit is required, with a certificate fee of roughly AUD $3,595 plus a separate audit fee — commonly $3,000 to $8,000 or more depending on business size — paid to an accredited verification body. Ongoing threat monitoring and regular vulnerability assessments also move from "have a plan" to "prove it's being tested." If Gold is where SMB1001 starts asking a business to run real detection and response, Platinum is where it stops taking the business's word for it.
Gold is the tier where the SMB1001 certificate stops being a hygiene checklist and starts resembling an actual security programme: active detection, enforced email authentication, and a plan for the day something gets through anyway. Our SMB1001 Silver requirements checklist covers the foundation Gold builds on, and the Bronze checklist is the place to start if neither tier is in place yet.
Sources: SMB1001:2026 Changes Explained for Perth Businesses, SMB1001 Gold: What It Costs and How to Get Certified, SMB1001 Gold Certification (Tier 3), SMB1001 in 2026: What the Cyber Certificate Actually Proves
