How long does SMB1001 certification take to achieve?

SMB1001 certification takes 2-4 weeks at Bronze and 4-8 weeks at Gold; Platinum and Diamond add an external audit. See the full 2026 timeline by tier.

SMB1001 certification takes 2-4 weeks at the Bronze tier and 4-8 weeks at Gold for most small businesses, with Platinum and Diamond taking 2-6 months because they require an independent external audit. The driver is your starting posture: a business that already has MFA, backups and patching in place moves through the control work in days, while one starting from scratch adds weeks of implementation before any attestation. Most small Australian businesses can hold a Bronze or Silver SMB1001 certificate within one to two months of starting.

TL;DR

Why this matters

SMB1001 is the tiered cyber security certification built by Dynamic Standards International (DSI) specifically for small and medium businesses, certified through the CyberCert platform. Unlike ISO 27001, which routinely takes six months or more of enterprise-grade documentation, SMB1001 lets a business certify at the tier matching its current maturity and climb later — so the honest answer to "how long" depends entirely on which tier you target.

The tier structure is what keeps the timeline short. Bronze requires seven controls, and the levels climb from there: Silver adds staff awareness training, MFA and documented processes, Gold reaches 27 controls, and Platinum and Diamond require external audit and 32-39 controls.

Timeline by tier

TierControlsVerificationTypical timeline
Bronze7Self-attestation2-4 weeks
Silver17Self-attestation2-4 weeks (adds policy work)
Gold27Self-attestation4-8 weeks
Platinum32Independent external audit2-3 months
Diamond39Independent external audit3-6 months

These ranges reflect published guidance from implementation partners working against SMB1001:2026. A Bronze self-attestation can move faster still when the controls — firewall, anti-malware, backups and engaged technical support — are already running and only need evidencing.

What drives the timeline up or down

How staff training fits the timeline

Staff cyber security awareness training is a named Silver-tier control, and it is the one most businesses cannot produce evidence for on day one. Enrollment takes minutes on a platform like Cyber Aware, but assessors look for completion records and recurring phishing simulations rather than a one-off session — so start training in week one of the certification project, not week five.

A gap assessment before you begin tells you which controls already pass, which shaves weeks off the implementation phase because you only remediate what is actually missing.

Is annual renewal a second timeline?

Yes — SMB1001 certification is valid for one year, and recertification runs against the current edition of the standard. The second year is faster in every case: the controls are already operating and documented, so the renewal cycle is mostly evidence refresh rather than new implementation. Platinum and Diamond holders repeat the external audit each year.

FAQ

How long does SMB1001 Bronze certification take? Bronze typically takes 2-4 weeks: it is self-attested, covers seven baseline controls, and moves quickly when backups, anti-malware and an engaged IT provider are already in place.

How long does SMB1001 Gold certification take? Gold usually takes 4-8 weeks, covering 27 controls including EDR, email authentication and documented incident response — still self-attested, so no external audit wait applies.

Why do Platinum and Diamond take longer? They require an independent external audit, so the timeline includes assessor availability and findings remediation — typically 2-3 months for Platinum and 3-6 months for Diamond.

Does SMB1001 certification expire? Yes — certification is valid for 12 months, with annual recertification against the current edition of the standard. Renewals are faster because the controls are already operating.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.