SMB1001 certification takes 2-4 weeks at the Bronze tier and 4-8 weeks at Gold for most small businesses, with Platinum and Diamond taking 2-6 months because they require an independent external audit. The driver is your starting posture: a business that already has MFA, backups and patching in place moves through the control work in days, while one starting from scratch adds weeks of implementation before any attestation. Most small Australian businesses can hold a Bronze or Silver SMB1001 certificate within one to two months of starting.
TL;DR
- Bronze SMB1001: 2-4 weeks typical, self-attested.
- Gold SMB1001: 4-8 weeks typical, also self-attested but with 27 controls.
- Platinum and Diamond: 2-6 months, because an independent external audit is required.
- Certification renews annually against the current standard edition.
- Staff awareness training is a required control from Silver upward.
Why this matters
SMB1001 is the tiered cyber security certification built by Dynamic Standards International (DSI) specifically for small and medium businesses, certified through the CyberCert platform. Unlike ISO 27001, which routinely takes six months or more of enterprise-grade documentation, SMB1001 lets a business certify at the tier matching its current maturity and climb later — so the honest answer to "how long" depends entirely on which tier you target.
The tier structure is what keeps the timeline short. Bronze requires seven controls, and the levels climb from there: Silver adds staff awareness training, MFA and documented processes, Gold reaches 27 controls, and Platinum and Diamond require external audit and 32-39 controls.
Timeline by tier
| Tier | Controls | Verification | Typical timeline |
|---|---|---|---|
| Bronze | 7 | Self-attestation | 2-4 weeks |
| Silver | 17 | Self-attestation | 2-4 weeks (adds policy work) |
| Gold | 27 | Self-attestation | 4-8 weeks |
| Platinum | 32 | Independent external audit | 2-3 months |
| Diamond | 39 | Independent external audit | 3-6 months |
These ranges reflect published guidance from implementation partners working against SMB1001:2026. A Bronze self-attestation can move faster still when the controls — firewall, anti-malware, backups and engaged technical support — are already running and only need evidencing.
What drives the timeline up or down
- Starting posture — a business with an MSP managing MFA, patching and backups skips most of the implementation phase.
- Tier chosen — Gold's 27 controls take roughly twice the Bronze effort; Platinum and Diamond add assessor scheduling.
- Evidence readiness — self-attestation goes quickly when completion records exist; hunting for proof of training and backups is the usual delay.
- External audit availability — Platinum and Diamond wait on an accredited assessor's calendar, which adds weeks independent of your readiness.
- Existing certifications — businesses already mapped to the Essential Eight or ISO 27001 inherit most Gold controls.
How staff training fits the timeline
Staff cyber security awareness training is a named Silver-tier control, and it is the one most businesses cannot produce evidence for on day one. Enrollment takes minutes on a platform like Cyber Aware, but assessors look for completion records and recurring phishing simulations rather than a one-off session — so start training in week one of the certification project, not week five.
A gap assessment before you begin tells you which controls already pass, which shaves weeks off the implementation phase because you only remediate what is actually missing.
Is annual renewal a second timeline?
Yes — SMB1001 certification is valid for one year, and recertification runs against the current edition of the standard. The second year is faster in every case: the controls are already operating and documented, so the renewal cycle is mostly evidence refresh rather than new implementation. Platinum and Diamond holders repeat the external audit each year.
FAQ
How long does SMB1001 Bronze certification take? Bronze typically takes 2-4 weeks: it is self-attested, covers seven baseline controls, and moves quickly when backups, anti-malware and an engaged IT provider are already in place.
How long does SMB1001 Gold certification take? Gold usually takes 4-8 weeks, covering 27 controls including EDR, email authentication and documented incident response — still self-attested, so no external audit wait applies.
Why do Platinum and Diamond take longer? They require an independent external audit, so the timeline includes assessor availability and findings remediation — typically 2-3 months for Platinum and 3-6 months for Diamond.
Does SMB1001 certification expire? Yes — certification is valid for 12 months, with annual recertification against the current edition of the standard. Renewals are faster because the controls are already operating.