Platinum is where SMB1001 stops taking a business's word for it. Bronze, Silver and Gold are all self-attested: a director confirms the controls exist and CyberCert issues the certificate on that confirmation. Platinum (Level 4) removes that option entirely. An independent, CyberCert-approved auditor has to look at the environment and confirm the controls are actually in place, actually configured correctly, and actually working — not just present.
This is a plain walk-through of what the SMB1001 Platinum requirements add on top of Gold, who should attempt it, what the audit process actually involves, where audits commonly fail, and what it costs once the audit fee is added to the certificate fee.
Who Platinum is for
Platinum suits a business that has already cleared Gold and needs a certificate an outside party will trust without follow-up questions. That's usually a business bidding for government or enterprise contracts with a security-attestation clause, a regulated business whose own compliance obligations expect independently verified controls, or an MSP that wants Platinum on its own environment as proof before selling security services to others. Self-attestation is a reasonable bar for a 20-person business proving it isn't negligent; it stops being a sufficient bar once a counterparty's own risk team is the one asking.
It's not the tier to attempt casually. Where Gold assumes a director who understands the controls well enough to attest to them honestly, Platinum assumes an environment mature enough to survive an outsider testing it, not just describing it. A business that scraped through Gold's self-attestation with some controls half-configured will find that gap exposed, not hidden, at audit. If Gold hasn't been genuinely lived in for a few months first — patches actually current, EDR actually alerting on something occasionally, the incident response plan actually referenced once — Platinum is premature.
The SMB1001 Platinum requirements, item by item
Platinum carries everything Gold asks for (EDR, enforced email authentication, monitoring, an incident response plan, access control) and adds a set of higher-assurance controls that move from "have it" to "prove it, tested":
- Phishing-resistant MFA. Standard MFA (an SMS code or a push notification) is no longer sufficient at this tier — Platinum expects authentication methods that resist real-time phishing, such as hardware security keys or passkeys, on the accounts that matter most.
- Regular vulnerability scanning of internet-facing systems. Not a one-off check — an ongoing scan schedule covering anything the business exposes to the internet, with findings tracked to resolution rather than filed and forgotten.
- Recovery testing, not just recovery planning. Gold asks for a documented incident response plan. Platinum asks for evidence the recovery side of that plan has actually been exercised — a restore that was tried, not just described.
- Stronger support and monitoring commitments. The "ongoing threat monitoring" control from Gold is expected to be more rigorous and more consistently evidenced at Platinum, with clearer accountability for who's watching and how fast they respond.
- Independent verification of everything above it. This is the control that changes the tier's character: an external auditor checks the other four, plus everything inherited from Bronze through Gold, against evidence — configuration exports, scan reports, test logs — rather than a director's word.
What changes: audited, not attested
The mechanics are genuinely different from every tier below. A CyberCert-approved Independent Verification Organisation is engaged to assess the environment against the Platinum control set. That audit checks evidence, not intentions: whether MFA is configured the way it's claimed to be, whether the vulnerability scan actually ran on schedule, whether the "tested" recovery plan has a test log behind it. A business that talks a good game at Gold can still fail a Platinum audit if the underlying configuration doesn't match the story.
This is also where the certificate stops being purely a compliance exercise and starts functioning like an actual security assessment. The auditor isn't there to help the business pass — they're there to confirm, independently, that it already has.
Where audits commonly stumble
The gap between "we do this" and "here's the evidence" is where most first-time Platinum audits lose points. A business that genuinely runs vulnerability scans but never kept the reports has nothing to show. A recovery plan that's never been rehearsed produces no test log, even if the backup itself is sound. Individual MFA rollouts that stalled at 80% coverage because a handful of legacy accounts were awkward to migrate are a common, entirely avoidable finding. None of these are hard problems to fix — they're evidence-hygiene problems, and they're far cheaper to fix before the audit is booked than to explain during it.
Tools that tick each Platinum control
The vulnerability-scanning control maps closely to Guardz's External Footprint Monitoring, which continuously checks open ports, exposed services and SSL drift on internet-facing infrastructure — exactly the kind of ongoing, evidenced scanning an auditor expects to see logs for, rather than a single point-in-time report. Guardz's 24/7 AI-plus-human MDR also carries the weight of the stronger monitoring commitment, since "who's watching and how fast they respond" is precisely what that service exists to answer with an audit trail behind it.
Recovery testing is the control worth taking seriously early, because it can't be retrofitted the week before an audit. Keepit's restore process needs to actually be run against a real (or realistic test) scenario, with the result documented, well before an auditor asks for evidence rather than a policy document. Phishing-resistant MFA is largely a configuration decision inside Microsoft 365, Google Workspace or the relevant identity provider — hardware keys or platform passkeys rather than SMS — and isn't something a third-party platform can retroactively fix if the rollout hasn't happened.
Cost, effort, and the audit reality check
CyberCert's Platinum certificate fee runs to roughly AUD $3,595 a year, ex GST — a substantial step up from Gold's ~$395. On top of that sits the audit fee itself, typically $3,000 to $8,000 depending on the size and complexity of the environment being assessed, paid to the Independent Verification Organisation rather than to CyberCert. Total cash cost for a straightforward audit therefore lands somewhere in the $6,500–$11,500 range before any implementation spend, and that's before accounting for the vulnerability-scanning tooling and hardware MFA keys some businesses will need to buy to close gaps the audit would otherwise find.
Timeline is the other real difference. Self-attested tiers can move in weeks once the controls exist. Platinum needs an audit booked, evidence gathered, and — realistically — a pre-audit gap check first, because failing a paid external audit is a worse outcome than delaying it. Businesses attempting Platinum straight after clearing Gold should budget months, not weeks, and shouldn't book the audit until the phishing-resistant MFA rollout and at least one documented recovery test are already done.
Path to Diamond
SMB1001 has one tier left above this. Diamond (Level 5) keeps the external audit model but pushes further into continuous, real-time verification — ongoing analytics and compliance monitoring rather than a periodic audit cycle, with certificate fees reported around AUD $5,995 a year on top of a larger audit scope. It's built for businesses with genuinely elevated risk or supply-chain obligations, not a default next step for most Platinum-certified SMBs.
Platinum is the tier where SMB1001 stops asking a business to describe its security programme and starts requiring proof of it, checked by someone with nothing to gain from a generous reading. Our SMB1001 Gold requirements checklist covers the self-attested foundation Platinum builds on and audits.
Sources: SMB1001 Certification Guide for Australian SMBs, What Are the SMB1001 Requirements? Every Tier Explained, SMB1001:2026 Changes Explained for Perth Businesses, SMB1001 CyberCert Certification, Bronze to Diamond
