Back to Blog
Backup & DR11 August 2026

SMB1001 Silver Requirements: The Step Up From Bronze

Cloud Ready SolutionsGuardz, Keepit

The SMB1001 Silver requirements pick up exactly where Bronze leaves off, and the step is bigger than the jump from nothing to Bronze was. Where Bronze asks for four basic hygiene controls, Silver (Level 2) closes the two breach vectors Bronze doesn't touch at all: stolen credentials and human error. It's still self-attested, still signed off by a director, and there's still no external audit, but it asks a business to actually change how people log in and how backups are documented, not just confirm that something is switched on.

This is a plain walk-through of what the SMB1001 Silver requirements actually cover under the current standard, who's genuinely ready for the step up, how self-attestation compares to Bronze, and which tools tick each control without over-buying for a tier you're not at yet.

Who Silver is for

Silver suits a business that's already cleared Bronze, or one that was never really at Bronze's level to begin with because it already runs individual logins and reasonably current software. It's the tier for an established small business with a handful of staff, a mix of cloud and on-prem systems, and enough structure that "who owns the admin password" has an actual answer.

It's not the right starting point for a business that's still sharing one login across the team or running whatever antivirus came free with the laptop. That's Bronze territory, and our Bronze requirements checklist covers the floor you need before Silver makes sense. Silver also isn't Gold: it doesn't ask for endpoint detection and response, email authentication, or a written incident response plan. Those arrive at the next tier up. Silver sits in the middle, past basic hygiene and short of active threat detection.

The SMB1001 Silver requirements, item by item

Silver carries everything Bronze asks for (a firewall, antivirus on every device, an accountable technical support arrangement, and automated backups) plus five additional controls:

  1. Multi-factor authentication on email and other key accounts. Not just email: anywhere a compromised password alone could get someone in, MFA needs to be switched on.
  2. Individual user accounts, no shared logins. Every person gets their own credentials. A shared "office@" or "admin" login that three staff members all know stops qualifying.
  3. Regular, timely system and software updates. Patches applied on a defined cadence, not whenever someone remembers or a machine finally forces a restart.
  4. Staff cyber security awareness training. Everyone with access to business systems has been through some form of training on phishing, password hygiene and reporting suspicious activity, not just the person who set up the network.
  5. A documented backup and recovery plan. Bronze only asked for automated backups to exist. Silver asks for that process to be written down: what's backed up, how often, where it lives, and who's responsible for checking it actually restores.

That last point catches businesses out more than any other on this list. Plenty of small businesses have backups running that nobody has actually tested, and "documented" specifically means someone could hand the plan to a new hire and they'd know what to do without guessing.

Self-attestation: what changes and what doesn't

The attestation mechanics are identical to Bronze. A company director logs into the CyberCert certification portal and personally signs off that each control is genuinely in place. (CyberCert is the body Dynamic Standards International, DSI, appointed to issue certificates against the SMB1001 standard.) It still has to be a director, not the IT manager or the MSP running the environment day to day, and there's still no independent audit. External verification doesn't start until Platinum.

What changes is the size of the claim being made. Five additional controls means five additional things a director is personally vouching for, several of which (individual accounts, MFA rollout, a written plan) take longer to genuinely implement across a team than the more binary Bronze items did. A director who rushes a Silver attestation without walking the environment first is signing off on more surface area than they were at Bronze, which is worth remembering before clicking submit.

Tools that tick each Silver control

The access and awareness controls are where a unified MSP-delivered platform earns its keep at Silver in a way it didn't need to at Bronze. Guardz covers MFA enforcement, individual account visibility, patch and update status, and built-in staff security awareness training as part of the same platform already handling managed antivirus for the Bronze controls. That's useful specifically because Silver asks for several controls to work together (MFA plus individual accounts plus training) rather than one control in isolation. It's delivered and monitored by the MSP running it, so it's most relevant if you're already working with, or looking to appoint, a managed provider. Our MSP partner programme is the starting point if you're an MSP building that stack out for clients.

The documented backup and recovery plan is really two things: the backup itself (unchanged from Bronze, and still best served by a platform independent of what it's protecting) and the document describing it. For Microsoft 365 or Google Workspace environments, Keepit provides the automated, scheduled backup layer; the documentation on top of it just needs to record what Keepit is backing up, how often, and who checks the restore reports. We covered the broader "why native retention isn't backup" case in our Essential Eight backup requirements guide, and the same distinction applies here.

Patching and updates are more environment-specific than the other four controls. What "regular and timely" looks like depends on whether devices are managed centrally or not, and most MSP toolsets already report on patch compliance as a baseline function.

Cost and effort reality check

Certification fees step up with the tier. At the time of writing, Bronze is priced by CyberCert at roughly AUD $95 a year and Silver at roughly AUD $195 a year, both ex GST: a modest jump for a meaningfully bigger set of controls. As with Bronze, the certificate itself is the smaller cost. The real spend is whatever work it takes to roll out MFA and individual accounts across a team that's used to shared logins, plus the time to actually write the backup plan down.

Because Silver is still self-attested, it doesn't take dramatically longer than Bronze to certify once the controls are genuinely in place. Weeks rather than months is still realistic. The variable is almost always the access-control rollout: swapping a team off shared logins and onto individual, MFA-protected accounts is a change-management exercise as much as a technical one, and it's worth starting before you're ready to attest rather than in the same week.

Path to Gold

SMB1001 keeps climbing from here. Gold (Level 3) adds endpoint detection and response, email authentication (DMARC, SPF and DKIM), continuous system monitoring, a documented incident response plan, and formal access control and privilege management, still self-attested, but noticeably closer to what a mature security programme looks like. If you're attesting to Silver with Gold already in view, the incident response plan and email authentication setup are the two items worth scoping early, since neither is a quick toggle — our SMB1001 Gold requirements checklist covers all 27 controls in detail.

Silver is the tier where SMB1001 stops being purely about hygiene and starts asking a business to demonstrate some actual security discipline: who has access, whether they're trained, and whether the backup plan would survive someone other than its author trying to follow it.

Sources: SMB1001 Certification Guide for Australian SMBs, SMB1001 in 2026: what the certificate actually proves, SMB1001 & CyberCert: how it all hangs together.

Related Vendors

GuardzKeepit