SMB1001 · SMB1001:2026 · Bronze to Diamond

SMB1001 certification, explained and delivered.

SMB1001 is the tiered cyber security certification built for Australian small and medium businesses: five levels, a certificate and badge at each, and a director's attestation rather than an ISO-style audit for the first three.

This guide covers what the standard asks for, what it costs and how CyberCert certification works. If you want it done rather than read about, we close your gaps and take you through certification at the tier your customers and insurer expect, for a fixed fee.

Australian team, no offshoring
ISO 27001 certified practice
Fixed-fee path to certification

The standard

What SMB1001 is, in plain terms.

SMB1001 is a cyber security standard written for businesses of roughly five to two hundred people. It was launched in September 2023 by Dynamic Standards International (DSI), the private standards body that traded as Cyber Security Certification Australia until 2023, and it is revised every year. The current edition is SMB1001:2026, certifiable since January 2026.

Where ISO 27001 asks for a management system most small businesses cannot staff, SMB1001 asks for concrete controls across five domains (technology management, access management, backup and recovery, policies and processes, education and training), scaled across five levels. A five-person firm and a two-hundred-person firm can both certify honestly, at different tiers.

Certification is issued by CyberCert, DSI's sister certification body. Bronze, Silver and Gold are attested by a company director through the CyberCert portal; Platinum and Diamond are independently audited. Each certificate runs for twelve months and comes with a badge and certificate you can put in front of customers, insurers and procurement teams. It is the thing an Essential Eight assessment alone cannot give you, because the Essential Eight has no certificate.

At a glance

Published by
Dynamic Standards International (formerly CSCAU)
Certified by
CyberCert
Current edition
SMB1001:2026 (released Sept 2025, certifiable from Jan 2026)
Levels
Bronze, Silver, Gold, Platinum, Diamond
Verification
Director attestation (Bronze to Gold); independent audit (Platinum, Diamond)
Validity
12 months, then renew or step up
Who recommends it
Queensland Law Society (aim for Gold), insurers, Cyber Wardens

The five levels

Certify where you are. Step up when you're ready.

Bronze

Director self-attestation

The basics every business needs in place

  • A technical support arrangement, in-house or outsourced
  • A firewall protecting the network and devices
  • Anti-malware on every device
  • Automatic software updates turned on

Sole traders, very small businesses, or anyone starting from zero who needs a credible first badge quickly.

Silver

Director self-attestation

Identity and email hardening

  • Individual accounts for every person, no shared logins
  • Multi-factor authentication on email and key accounts
  • Restricted administrator access
  • SPF published for your email domain

Small professional firms that hold client data. A common landing point for a first certification year.

Gold

Director self-attestation

Detection, response and governance

  • Endpoint detection and response (EDR) on all devices
  • DKIM signing and an enforced DMARC policy for your email domain
  • A documented incident response plan
  • A register of your digital assets

27 controls in the 2026 edition, up from 23 in 2025.

Most SMBs with client, financial or health data. The tier the Queensland Law Society advises legal practices to work towards.

Platinum

Independent external audit

Independently verified and actively tested

  • Everything in Gold, checked by an independent auditor rather than self-declared
  • Regular vulnerability scanning of internet-facing systems
  • Encryption of data at rest
  • Ongoing threat monitoring

Businesses whose customers, regulators or tenders want third-party assurance rather than a director's signature.

Diamond

Independent external audit

Continuous assurance

  • Everything in Platinum
  • Continuous monitoring and real-time security analytics, SOC or SIEM style
  • Continuous compliance monitoring
  • Active engagement with cyber security professionals

SMBs competing on trust in sensitive supply chains. The rigour approaches ISO 27001 without the management-system overhead.

Examples only, drawn from the published standard and public guidance. The full control list lives in SMB1001:2026 and changes each year, so we re-check it against your target tier during the gap review.

Why certify

Who is asking for SMB1001, and why it is growing.

Customers and procurement teams

Supply-chain security questionnaires are now routine in Australian procurement. A current SMB1001 certificate answers most of them in one line, with a badge and a certificate number they can check.

Your insurer

Cyber insurers reward demonstrable controls. Gold in the 2026 edition includes having cyber insurance, and the certificate gives your broker something concrete to take to underwriters.

Professional bodies

The Queensland Law Society formally recommends SMB1001 to its members and advises practices to work towards Gold. Other industry bodies and programs, including Cyber Wardens, point small businesses at it too.

Your own board or owners

A tier is a plain-English answer to "how secure are we?". Certify where you are, then step up a level when the business is ready, instead of arguing about an abstract maturity score.

Read the Queensland Law Society's SMB1001 resource for legal practices, or our own SMB1001 for law firms guide.

What it costs

Two numbers, not one.

The CyberCert fee is modest at Bronze to Gold (listed from about $95 a year at entry level at the time of writing). The real number is the uplift to close your gaps, which is why we quote it fixed-fee after a gap review.

SMB1001 cost, explained →

SMB1001 vs Essential Eight

Framework or credential?

The Essential Eight is the government's control baseline with no certificate. SMB1001 is the certificate. Take the five-question selector or read the comparison.

Compare the two →

SMB1001 vs ISO 27001

Proportionate, or the global standard?

Diamond approaches ISO 27001 in rigour, but ISO is still what enterprise and government tenders name. When each one is the right call, from a practice that holds ISO 27001 itself.

Read the comparison →

How it works

From “which tier?” to a certificate on the wall.

  1. 01

    Tier selection

    A short call to work out which tier your contracts, insurer and risk profile require, not just the one that is easiest to sell.

  2. 02

    Gap review

    We assess your current controls against your target tier and give you a fixed-fee plan for whatever is missing.

  3. 03

    Uplift

    Our engineers implement the gaps with your IT team: identity, backups, patching, EDR, email authentication, training, and the policies to match.

  4. 04

    Certification

    We take you through the CyberCert attestation (or the independent audit at Platinum and Diamond) and you receive your certificate and badge.

  5. 05

    Stay certified

    SMB1001 certificates run for twelve months. We keep your controls current so renewal is a formality, not a project.

Certification itself is issued by CyberCert. Our job is everything before and around it, and the CyberCert page explains the portal, the attestation and the audit route.

Common questions

SMB1001, answered.

Not in this list? The tier-selection call is free and takes twenty minutes.

  1. What is SMB1001?

    SMB1001 is a multi-tiered cyber security certification standard written for small and medium businesses. It is published by Dynamic Standards International (which traded as Cyber Security Certification Australia, CSCAU, until 2023) and certification is issued through CyberCert. It was launched in September 2023, is revised every year, and the current edition is SMB1001:2026. It has five levels, Bronze, Silver, Gold, Platinum and Diamond, each adding stronger controls, so a business can certify at a level that matches its size and risk and step up over time.

  2. How is SMB1001 different from the Essential Eight?

    The Essential Eight is the Australian Signals Directorate's mitigation framework: free, self-assessed, referenced in government supply chains, and it produces no certificate. SMB1001 produces an actual certification you can show customers and insurers, at a tier scaled to your size. Many businesses do both: Essential Eight as the control baseline, SMB1001 as the credential. Our comparison page and five-question selector walk through which fits you.

  3. How much does SMB1001 certification cost?

    Two costs. The CyberCert certification fee itself is modest at the lower tiers: at the time of writing Bronze is listed from about $95 a year, with Silver and Gold in the low hundreds, and Platinum and Diamond adding an independent audit. Eligible small businesses can also access Bronze and Silver certification credits at no cost through the Cyber Wardens program. The real cost is closing any control gaps before you attest, which depends on where you are today. Our gap review gives you a fixed-fee number for your target tier before you commit to anything.

  4. How long does it take to get certified?

    A business with reasonable IT hygiene can reach Bronze or Silver in a few weeks. Gold typically takes one to three months depending on gaps, because it adds EDR, enforced email authentication, an incident response plan and several policies. Platinum and Diamond add an external audit, so allow a quarter. The tier-selection call gives you a realistic timeline for your situation.

  5. Which tier does my business need?

    It depends on who is asking. If a customer questionnaire or insurer wants evidence of baseline hygiene, Bronze or Silver may be enough. If you hold sensitive client data (legal, financial, health), Gold is the sensible target and is the tier the Queensland Law Society advises legal practices to aim for. If certification is a competitive differentiator in your tenders, Platinum or Diamond's external audit carries the most weight.

  6. Is SMB1001 self-assessed?

    Bronze, Silver and Gold are self-attested: a company director confirms through the CyberCert portal that each control is in place, and the certificate is issued on that attestation. Platinum and Diamond are independently verified by an external auditor. Self-attested does not mean casual: the director is putting their name to it, and an insurer or customer can ask you to evidence any control.

  7. Is SMB1001 recognised by the Australian Government?

    It is not government-mandated the way the Essential Eight is referenced in some sectors, and it is not an ASD or ACSC standard. Its recognition comes from industry: insurers, procurement teams and professional bodies such as the Queensland Law Society, plus small-business programs like Cyber Wardens. For government-adjacent work we usually pair an SMB1001 certification with an Essential Eight maturity assessment so both audiences are covered.

  8. Does SMB1001 replace ISO 27001?

    For most SMBs it is the more proportionate choice, and Diamond approaches ISO 27001 in rigour. But ISO 27001 remains the certification large enterprises and governments ask for in tenders, and it certifies a management system rather than a checklist of controls. If your customers name ISO 27001, you need ISO 27001. Our SMB1001 vs ISO 27001 page goes through the decision.

  9. What changed in SMB1001:2026?

    The 2026 edition, released in September 2025 and certifiable from January 2026, made email authentication mandatory (SPF from Silver, DKIM and an enforced DMARC policy from Gold) and expanded Gold from 23 to 27 controls, adding endpoint detection and response, cyber insurance, a digital asset register and a responsible-AI-use policy. DSI also published mappings to the Essential Eight, ISO 27001, UK Cyber Essentials and US CMMC.

  10. Can IronSights certify us directly?

    Certification is issued by CyberCert, not by consultancies. What we do is get you there: the tier decision, the gap review, the control uplift with your IT team, the evidence, and the attestation or audit preparation. For Platinum and Diamond the audit is performed by an independent auditor; we prepare you for it and sit alongside you through it.

First step

Find out which tier you could certify at this quarter.

A twenty-minute tier-selection call, then a fixed-fee gap review against your target tier. You get a number and a timeline before you commit to anything, and CyberCert's own fee stays exactly what it is.

SMB1001 is a standard of Dynamic Standards International and certification is issued by CyberCert, an independent certification body; IronSights prepares you for it and does not issue certificates. Prices and control counts quoted are from public sources at the time of writing (August 2026) and should be confirmed at cybercert.ai.