Cybersecurity

SMB1001 certification for Australian businesses

SMB1001 is the Australian cyber security standard written for businesses under two hundred people. Five tiers, a defined control set at each one, and certification you can show a client or an insurer. This page covers what each tier requires, what it costs in effort, and how to reach it without turning it into a project nobody finishes.

What it is

Four things to understand about SMB1001

SMB1001 exists because the two options either side of it do not fit a smaller Australian business. The Essential Eight is a government maturity model with no certificate at the end. ISO 27001 is an enterprise management system that costs more than most small businesses will spend on security in total.

01

Five tiers, and you pick your entry point

Bronze, Silver, Gold, Platinum and Diamond. Each tier adds controls, and you certify at the level that matches your size, your risk and what your clients are asking for. Starting at Bronze and moving up is the normal path rather than a compromise, and it means the first certificate arrives in weeks rather than never.

02

It produces a certificate, which is the point

The Essential Eight gives you a maturity level you assert about yourself. SMB1001 gives you third party certification you can attach to a tender response, a client security questionnaire or an insurance renewal. For most businesses asking us about cyber, that document is the actual requirement behind the question.

03

It is built for under two hundred people

The standard is maintained by Dynamic Standards International and scoped deliberately at Australian small and medium business. The controls assume you do not have a security team, which is the assumption most frameworks get wrong.

04

It is updated every year

The current version is SMB1001:2026. Annual revision keeps the control set current, and it means certification is a cycle rather than a one-off. Budget for the renewal at the outset.

Which standard

SMB1001, Essential Eight or ISO 27001

The three get discussed as if they compete. They answer different questions, and the right one depends on who is asking you for it.

SMB1001 suits you when

You are under two hundred people, a client or an insurer has asked for evidence, and you need something defensible without a twelve month programme. It is the only one of the three that gives a smaller business a certificate at a cost proportional to its size.

Evidence, proportionate effort

Look at the others when

You are bidding for government work or handling government data, where the Essential Eight and IRAP are the language used. Or you are selling to enterprise and large customers who name ISO 27001 in their procurement. Those are different requirements, and meeting SMB1001 first makes both of them easier rather than wasted.

Government or enterprise buyers

How to get certified

From nothing to a certificate

We are vendor funded, so the service costs your business nothing. This is the sequence, and most of it is faster than businesses expect.

01

Work out which tier you actually need

Driven by what your clients ask for rather than by ambition. Certifying at Gold when your customers want Bronze spends money for no commercial return, and it is the most common way this goes wrong.

02

Find out what you already have

Most businesses already own more controls than they have turned on, usually inside Microsoft 365 or Google Workspace. A gap assessment against the tier tells you what is genuinely missing rather than what a vendor would like to sell you.

03

Close the gaps

Multi-factor authentication, patching, backups, access control and the rest of the tier requirements. Most of this is configuration rather than purchase.

04

Evidence it

The certification needs proof rather than assertion. We use platform tooling to collect the evidence continuously, so the audit is a report rather than a scramble, and so the renewal next year is not a repeat of the whole exercise.

05

Certify, then keep it

The certificate is issued against the standard. Because the standard revises annually, we set up the monitoring that keeps you compliant between renewals rather than letting it lapse quietly.

Getting it right

What to check before you start on SMB1001

These are the items that decide whether certification is worth the effort or becomes a filing exercise.

What your clients are actually asking for

Read the security questionnaire or the tender clause rather than guessing. Some name SMB1001, some name the Essential Eight, some name ISO 27001, and some just ask whether you have MFA. The wording tells you the tier.

Whether you need a certificate or a maturity level

The Essential Eight produces a maturity level you assert. SMB1001 produces third party certification. If the requirement is evidence for somebody else, that difference is the whole decision.

What you already own

Microsoft 365 Business Premium and Google Workspace both include most of the controls at the lower tiers. Paying for a separate product to meet a control you already licence is common and avoidable.

Who maintains it after the certificate

Annual revision means this is a cycle. Establish who owns evidence collection month to month before you certify, or the second year costs as much as the first.

The real cost, including your own time

The certification fee is rarely the largest number. Internal effort to close gaps and gather evidence usually is. Get both estimated before committing.

Whether the tier can grow with you

Certifying at Bronze is a sound start and moving to Silver later should reuse the evidence rather than restart. Confirm the upgrade path before you pick a starting tier.

Common questions

Questions about SMB1001

What Australian businesses ask before certifying

What is SMB1001?

It is an Australian cyber security standard for small and medium businesses, maintained by Dynamic Standards International. It has five certification tiers, Bronze through to Diamond, each with a defined control set. It sits between the Essential Eight, which is a government maturity model, and ISO 27001, which is an enterprise management system.

What are the SMB1001 tiers?

Bronze, Silver, Gold, Platinum and Diamond. Each adds controls to the one below it. You certify at the tier matching your size, risk and what clients are asking for, then move up over time. Most smaller businesses start at Bronze or Silver.

How is SMB1001 different from the Essential Eight?

The Essential Eight is an Australian Signals Directorate maturity model, self-assessed and aimed at reducing risk from common attacks. It does not produce a certificate. SMB1001 is a certification standard, so it produces a document a third party has issued. If a client or insurer is asking you to prove something, that distinction matters.

Do we need SMB1001 or ISO 27001?

ISO 27001 is the answer when enterprise or overseas customers name it in procurement, and it is a substantially larger undertaking. SMB1001 is the answer for a business under two hundred people that needs credible evidence at proportionate cost. Meeting SMB1001 first makes a later ISO 27001 project shorter rather than duplicated.

How long does SMB1001 certification take?

It depends on the tier and on how much you already have configured. Businesses that already run Microsoft 365 or Google Workspace properly are often closer than they expect, because the lower tier controls are largely configuration rather than purchase. The gap assessment is what turns this from a guess into a timeline.

Can you help us get certified?

Yes. We run the gap assessment, tell you which tier fits what your clients are asking for, and provide the platform tooling that collects the evidence continuously so the audit and the annual renewal are not manual exercises. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Find out which tier your clients are actually asking for.

Certifying at the wrong tier is the most expensive mistake available here, and it takes one conversation to avoid. Answer six questions about what triggered this and what you already have, and we will tell you the tier, the gaps and what your licences already cover.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.