SMB1001 certification costs about $95 per year at Bronze, $195 per year at Silver, $495 at Gold, and $1,995 plus audit fees at Platinum and Diamond, with certification issued through the CyberCert platform. Budget realistically, though, and the total spend is wider than the annual fee: Bronze's minimum control set assumes you already run a firewall, anti-malware and automated backups, and the higher tiers expect multi-factor authentication on every account, patch management, and staff awareness training with completion evidence.
How much does SMB1001 certification cost, at a glance
| Tier | Annual licence (AUD, ex GST) | Audit requirement | Best for |
|---|---|---|---|
| Bronze | $95 | Self-assessment | A first cyber baseline for any small business |
| Silver | $195 | Self-assessment | Businesses facing client or supply-chain security questions |
| Gold | $495 | Self-assessment | SMBs with an IT manager or an MSP on retainer |
| Platinum | $1,995 | Independent audit | Businesses bidding for regulated or enterprise work |
| Diamond | $1,995 + audit | Independent audit | Managed service providers and larger SMB estates |
The fees above are the certification cost from DSI's own published pricing. What the table does not show is the cost of the controls behind the certificate, which is where most of the real budget sits.
What you get at each tier
Bronze ($95/year, 7 controls) covers the non-negotiables: firewall, anti-malware, patching, backups, MFA, a password standard and staff awareness. If your IT already does these things, certification is a paperwork exercise. If it does not, the certification cost is the small part — fixing the gaps is the project.
Silver ($195/year) adds individual user accounts, documented policies and procedures, and the operational layer that turns a security plan into daily practice. This is the tier most small businesses with enterprise clients aim for, because it is the first level where the answer to a client security questionnaire starts to carry weight.
Gold ($495/year) tightens the screws: formal asset registers, incident response planning, and controls that assume a dedicated person or MSP owns security rather than whoever has spare time on a Friday.
Platinum and Diamond ($1,995/year plus audit fees) require an independent external audit, and that is where the certificate earns teeth for larger deals — the audit is what turns a self-attested claim into third-party evidence. Audit fees vary by assessor and scope, so they sit outside the published tier price.
Diamond is written with managed service providers and larger SMB estates in mind: multi-site or multi-client environments where an auditor needs evidence of controls operating across every tenant, not just head office. MSPs that already run recurring security programmes — monthly awareness training, phishing simulations and human risk reporting — usually hold most of the Diamond evidence as a by-product, which is why the audit, not the build, dominates the cost at this tier.
The hidden costs that decide whether the fee is worth it
- Remediation before certification. If Bronze's seven controls are not already in place, the cost of getting there — licences, backup tooling, an MFA rollout — usually outweighs the certification fee by a wide margin.
- Staff awareness training. Awareness training is a named control across the standard, and assessors want completion records and recurring phishing simulations, not a one-off session. A platform that maps to SMB1001 and generates that evidence automatically costs a per-seat subscription (Cyber Aware's pricing is published on its training page), which is a real but small line item next to the remediation spend.
- Time. A self-assessment tier still takes someone internal a few days to gather evidence, document policies and answer the assessment honestly. Budget the hours, because a rushed self-assessment is the single most common way a Bronze or Silver certificate ends up meaning nothing.
- Audit fees at the top tiers. Platinum and Diamond add an independent auditor's fee on top of the $1,995 tier price, and the audit cost depends on the assessor and the size of the estate. Get a quote before you commit to those tiers.
How SMB1001 compares with ISO 27001
ISO 27001 certification typically runs to tens of thousands of dollars once you add the gap assessment, implementation, audit and surveillance costs — a realistic spend for a mid-sized company, not for a 12-person firm. SMB1001 was built by Dynamic Standards International specifically to close that gap: the Bronze entry point is roughly $95 a year, and the climb from there is incremental rather than a single project. Some enterprise buyers will still ask for ISO 27001, and in that case SMB1001 is the stepping stone — but for the security questionnaire from your largest client, Bronze or Silver is usually the answer that costs two orders of magnitude less.
How to budget the certification in 2026
- Run a gap assessment first — Cyber Aware's gap assessment shows which controls already pass before you commit to a tier, and costs nothing but time.
- Pick the tier you can evidence today, not the one you aspire to. A Bronze certificate that is real beats a Silver application that stalls.
- Fix the baseline before the paperwork. Firewall, anti-malware and automated backups are Bronze requirements and stop most opportunistic attacks on their own.
- Stand up staff training in week one. It is a control at every tier worth having, and the completion evidence Cyber Aware generates is exactly what assessors ask for.
- Recertify annually against the current edition. Renewals at the same tier are mostly an evidence refresh, not a new project.
FAQ
How much does SMB1001 certification cost in 2026? Bronze costs $95 per year, Silver $195, Gold $495, and Platinum and Diamond $1,995 each plus independent audit fees, issued through the CyberCert platform.
Is SMB1001 cheaper than ISO 27001? Yes, by a wide margin — ISO 27001 typically costs tens of thousands of dollars once implementation and audit are included, while SMB1001's Bronze tier starts at $95 per year.
Do the SMB1001 fees include an audit? Bronze, Silver and Gold are self-assessed, so there is no separate audit fee. Platinum and Diamond require an independent external audit, which is quoted separately by the assessor.
What extra costs should a small business budget for? The main ones are remediation work to close control gaps, a staff awareness training platform with completion evidence, and the internal hours to document policies and complete the self-assessment.
Which SMB1001 tier should a small business start at? Start at the tier whose controls you can evidence today — usually Bronze if you have not formalised security before, Silver once MFA, patching, backups and staff training are demonstrably running.
Can a business jump straight to Platinum or Diamond? Technically yes, but assessors will expect the Gold-level controls — asset registers, incident response, documented ownership — to already operate across the whole estate, so most businesses certify up tier by tier rather than skipping.
Does the annual fee cover recertification? The tier fee covers the annual cycle; recertification at the same tier is mostly an evidence refresh rather than a new implementation, so the cost stays at the published rate rather than restarting.
One last thing
The cheapest way to make a $95 Bronze certificate worthless is to attest "MFA enabled" without checking every account. The fee buys the certificate; the controls are what protect the business — and a self-assessed tier only carries weight if the answers behind it are true.