Cyber Security Certification for Australian SMBs

SMB1001 Explained: The Complete Guide to Australia’s SMB Cyber Security Standard

SMB1001 is the tiered cyber security certification built for small and medium businesses — five levels from Bronze to Diamond that let you prove your security maturity without the cost and complexity of enterprise frameworks. Here’s how it works, what each tier requires, and how to get certified.

Last reviewed June 2026 • Based on SMB1001:2025 • Reviewed by the Cloud Ready Solutions cyber security team

What is SMB1001?

SMB1001 is a multi-tiered cyber security certification standard for small and medium businesses, maintained by Dynamic Standards International (DSI). The current version is SMB1001:2025. Instead of a single, all-or-nothing audit, it uses five progressive tiers so a business can start small, certify quickly, and build up real cyber maturity over time.

It exists because the established frameworks — ISO 27001, the Essential Eight — were built for large or government organisations. For a 15-person accounting firm or a regional manufacturer, they’re often too expensive, too complex, or both. SMB1001 gives those businesses an achievable path to demonstrate they take security seriously: to customers, to supply-chain partners, and to insurers.

Built for
Small & medium businesses
Maintained by
Dynamic Standards International
Certified via
CyberCert platform

The five SMB1001 tiers explained

Each tier builds on the one below it. You don’t skip levels — you climb them, adding controls as your business matures.

Level 1

Bronze

Cyber security essentials

Verification
Self-attestation

The foundational tier. Covers the basic hygiene every business should have in place — the controls that stop the overwhelming majority of opportunistic attacks.

Typical controls at this tier:

  • Engage technical support (in-house or an IT provider / MSP)
  • Install and configure a firewall
  • Run reputable antivirus / anti-malware on all devices
  • Implement an automated backup and recovery process

Controls shown are representative of SMB1001:2025. The standard is updated periodically — confirm the current requirements with CyberCert before certifying.

SMB1001 vs Essential Eight vs ISO 27001

Three names you’ll hear constantly. Here’s how they actually differ for a small business.

SMB1001Essential EightISO 27001
Built forSmall & medium businessesGovernment & larger orgsAny size, enterprise-leaning
Structure5 progressive tiers3 maturity levelsSingle certification
Entry effortLow — start at BronzeModerate to highHigh
CertifiableYes — issued via CyberCertNo (a framework, not a cert)Yes — accredited auditor
Typical costFrom ~$95/yr (Bronze)Implementation cost onlyTens of thousands
Best for SMBsYes — purpose-builtPartial — can be heavyUsually overkill

The short version: ISO 27001 is the gold standard for enterprises, the Essential Eight is the government baseline, and SMB1001 is the one actually designed for businesses that don’t have a dedicated security team. For most SMBs, it’s the sensible starting point.

The SMB1001 readiness checklist

Work through this before you certify. Free — no sign-up required.

BronzeLevel 1Self-attestation
  • Engage technical support (in-house or an IT provider / MSP)
  • Install and configure a firewall
  • Run reputable antivirus / anti-malware on all devices
  • Implement an automated backup and recovery process
SilverLevel 2Self-attestation
  • Multi-factor authentication (MFA) on email and key accounts
  • Individual user accounts (no shared logins)
  • Regular, timely system and software updates
  • Staff cyber security awareness training
  • Documented backup and recovery plan
GoldLevel 3Self-attestation
  • Endpoint Detection & Response (EDR) on devices
  • Email authentication (DMARC, SPF, DKIM)
  • Continuous system monitoring
  • A documented incident response plan
  • Access control and privilege management
PlatinumLevel 4Independent external audit
  • Ongoing threat monitoring (managed detection & response)
  • Regular vulnerability assessments
  • Sophisticated, tested incident response
  • Annual external audit and continuous oversight
DiamondLevel 5Real-time monitoring + external audit
  • Continuous auditing and compliance monitoring
  • Real-time security analytics (SIEM / SOC)
  • Active collaboration with cyber security professionals
  • Mature, regularly exercised response and recovery

How to get SMB1001 certified

1

Choose your starting tier

Most businesses begin at Bronze or Silver. Pick the tier that matches the controls you already have — you can climb later.

2

Implement the controls

Close the gaps for your chosen tier: MFA, backups, EDR, email authentication, awareness training. This is where your IT provider or MSP does the work.

3

Attest or audit

Bronze, Silver and Gold use self-attestation by a business owner or director. Platinum and Diamond require an independent external audit.

4

Certify through CyberCert

Register on the CyberCert platform, complete the workbook for your tier, and receive your certificate and badge.

For MSPs & IT providers

How MSPs deliver SMB1001 — and the tooling that gets clients there

SMB1001 is a genuine revenue and retention play for MSPs: every tier maps to security services your clients need anyway. The trick is having a stack that covers the controls without bolting together six separate tools per client.

SMB1001 controlCovered by
MFA, identity & access protectionGuardz (ITDR)
Managed antivirus & EDRGuardz (SentinelOne EDR)
Email security & DMARCGuardz email protection + Cibecs DMARC
Awareness training & phishing simulationGuardz
Continuous monitoring & MDRGuardz 24/7 MDR
Backup & recovery — SaaS (M365 / Google Workspace)Keepit
Backup & recovery — VMs, servers & physicalNAKIVO
Backup & recovery — endpoints / devicesCibecs

Backup & recovery is required from Bronze (Level 1) — every single tier. It’s the one control no business escapes, and the gap most SMBs fail on. CRS covers the full picture: Keepit for SaaS data (Microsoft 365, Google Workspace, Entra ID), NAKIVO for virtual machines, servers and physical workloads, and Cibecs for endpoints — so whatever your client runs, the recovery control is covered.

See where your clients stand today

Run a free external cyber risk scan on any client domain — a fast way to show where they sit against SMB1001 controls and open the certification conversation.

To issue certificates, MSPs join the CyberCert Partner Program (free to join). CRS supplies the security and backup tooling — Guardz, Keepit, NAKIVO and Cibecs — that satisfies the controls behind each tier.

SMB1001 frequently asked questions

SMB1001 is a multi-tiered cyber security certification standard built specifically for small and medium businesses. It is maintained by Dynamic Standards International (DSI), with the current version published as SMB1001:2025. Rather than a single pass/fail audit, it offers five progressive tiers — Bronze, Silver, Gold, Platinum and Diamond — so a business can certify at a level that matches its size, risk and budget, then move up over time.

Authoritative sources

This guide is provided for general information by Cloud Ready Solutions, an Australian IT distributor supporting MSPs across Australia and the Pacific Islands. It is not legal or compliance advice. Certification requirements and fees are set by Dynamic Standards International and CyberCert and may change. Last reviewed June 2026.