SMB1001 certification proves your business meets a recognised Australian cyber security baseline, and closing the gap comes down to a specific sequence of technical and staff-facing fixes. This guide breaks down the tiers, the order of operations, and the mistakes that stall most applications in 2026.
TL;DR
- SMB1001 certification has four tiers — Bronze, Silver, Gold, Platinum — match the tier to what your contracts or insurer actually require.
- The self-assessment checks identity controls, backups, patching and staff awareness — training gaps stall more applications than technical gaps.
- Passing once doesn't finish the job: SMB1001 certification needs recurring evidence, not a one-time tick.
- Staff awareness training closes the human-layer controls fastest — prioritise it early in the sequence, not last.
Why this matters
SMB1001 exists because ISO 27001 is built for enterprises with a dedicated security team, not a twelve-person business running Xero and Microsoft 365. Insurers, procurement teams, and larger clients increasingly ask for proof of a cyber security baseline before they'll sign a contract. SMB1001 certification gives small and mid-sized businesses a way to answer that ask without hiring a security manager.
The framework runs on four tiers — Bronze, Silver, Gold, Platinum — each stacking more controls on top of the last. Bronze covers the fundamentals: multi-factor authentication, passphrases, patching, backups, and admin account separation. Higher tiers add depth in incident response, vendor risk, and staff evidence requirements.
Most businesses fail their first self-assessment attempt on staff-facing controls, not technical ones. Firewalls and backup schedules are one-time configuration jobs. Getting every staff member to stop reusing passwords and recognise a phishing email is a training problem, and it starts with a documented security awareness policy for audits, not ad hoc reminders in a team chat.
What you'll need
- Asset register — every device, account, and SaaS subscription tied to the business
- Admin access to your identity provider (Microsoft 365, Google Workspace) and endpoint management tools
- A named owner for the submission — SMB1001 certification doesn't get finished as a side project with nobody accountable
- Existing policy documents, even outdated ones, as a starting draft
- A security awareness training platform to generate staff completion records, because evaluators want dated evidence, not a verbal assurance that "everyone knows not to click links"
| Tier | Focus | Typical audience |
|---|---|---|
| Bronze | Core hygiene: MFA, passphrases, backups, patching | Sole traders, micro businesses |
| Silver | Adds access control depth and incident response basics | Growing SMBs with a handful of staff |
| Gold | Adds vendor risk and more rigorous staff evidence | Businesses handling client data at scale |
| Platinum | Full control set with the most rigorous verification | Businesses bidding on government or enterprise contracts |
The steps
1. Confirm your tier and read the actual control list
Picking a tier before reading the requirements wastes months. A sole trader chasing Platinum builds controls no client is asking for; a business bidding on government work at Bronze gets rejected at the tender stage.
Check what your biggest contract, insurer, or client actually specifies before committing to a tier. Read the published control list line by line — SMB1001 certification requirements are specific about MFA coverage, backup frequency, and account separation, not vague.
Expected outcome: a one-page checklist matched to your actual tier. Common mistake: guessing your tier based on headcount instead of what a contract or insurer specifies.
2. Run a gap assessment against every control
You can't fix what you haven't measured, and the self-assessment asks you to attest to specifics, not vibes. Go control by control and mark each one Met, Partial, or Not Met.
Don't skip controls that feel obviously fine. MFA is the classic one — businesses assume full coverage and find unenrolled accounts the moment they actually check the admin console.
Expected outcome: a gap list ranked by effort. Common mistake: treating the self-assessment as a checkbox exercise instead of pulling real evidence — screenshots, admin console exports, dated logs.
3. Fix identity and access controls first
Compromised credentials remain one of the most common entry points into small business systems, and it's the fastest gap to close on the whole list.
Enforce MFA on every account with zero exceptions, including the owner and any legacy shared logins. Move from passwords to passphrases where the platform supports it. Separate admin accounts from daily-use accounts so nobody browses the web or reads email while logged in as an administrator.
Expected outcome: every account under MFA, admin accounts isolated. Common mistake: leaving one exception "because it's annoying on their phone" — that single exception fails the whole control.
4. Lock down backups and patch cadence
Evaluators want proof backups actually restore, not just that a backup job runs on schedule. This step covers the recovery side of the framework, not only prevention.
Confirm backup jobs cover every critical system, test a restore, and document the date it worked. Set a patch window for operating systems and business applications and stick to it — assessors ask for evidence of a schedule, not a policy statement.
Expected outcome: a tested restore log and a patch cadence you can point to. Common mistake: backups exist but nobody has restored from them in over a year, so the first real test happens mid-incident.
5. Put a written security awareness policy in place
This turns "the team knows about phishing" into a document an assessor can actually check. SMB1001 certification wants evidence a policy exists and is followed, not a claim that staff are generally careful.
Write down what's expected: password behaviour, reporting suspicious emails, device use, and who owns the review cycle. Keep it to one or two pages — a forty-page policy nobody reads doesn't pass an audit either.
Expected outcome: a signed-off policy document with a review date. Common mistake: copying a template policy that references controls your business doesn't actually have.
6. Train staff and capture the evidence
A policy without training records is a document, not a control. This step generates the completion evidence SMB1001 certification checks for.
Run structured training through a certified cyber security awareness course rather than a one-off slide deck. Cyber Aware and similar platforms log completion timestamps automatically, which saves the manual chasing most businesses underestimate.
Expected outcome: a completion register you can export as evidence. Common mistake: training office staff and forgetting remote, casual, or contractor accounts that still touch company systems.
7. Map evidence against each control and complete the self-assessment
This turns your gap list from step two into the actual submission. Incomplete evidence mapping is the single biggest reason self-assessments bounce back for rework.
Go line by line through the tier's control list and attach specific evidence — screenshots, logs, policy documents, training records — to each one. Where you're mapping into a broader framework like ISO 27001 Annex A, reuse that mapping work instead of duplicating it from scratch.
Expected outcome: a complete evidence pack ready to submit. Common mistake: submitting vague evidence like "staff are trained" instead of a dated completion export.
8. Submit, then set a recurring review cadence
SMB1001 certification isn't a one-time badge. Controls drift, staff turn over, and evidence goes stale, so this step keeps you certified after the certificate arrives.
Submit through the official SMB1001 process, then calendar a recurring internal review well ahead of your next reattestation window so gaps get caught early, not the week before renewal.
Expected outcome: certification confirmed, with a standing review date on the calendar. Common mistake: filing the certificate and forgetting about it until a client or insurer asks for a current one.
Get staff training-ready for SMB1001
Cyber Aware runs the awareness training and reporting evaluators check for.
Troubleshooting
- MFA rollout stalls on one legacy system that doesn't support it. Isolate it behind a VPN or conditional access rule and document the compensating control instead of leaving it unenrolled.
- A backup restore test reveals corrupted files. Fix the backup job immediately and re-test before you submit — a backup that doesn't restore isn't a backup, and evaluators will ask for the restore log.
- Staff complete training but click rates don't move. Completion isn't behaviour change. Run a phishing simulation after training to confirm the material actually landed, not just that a video was watched.
- The policy exists but nobody signed off on it. Get a named owner — usually the founder or ops lead — to date and sign the document before submission.
- Certification lapses because nobody tracked the renewal date. Set a calendar reminder at least two months ahead of the reattestation window, not the week it's due.
Tools and resources
- Identity console — your Microsoft 365 or Google Workspace admin panel for MFA enrolment and admin role review
- Backup platform — whatever you already run, verified with a documented restore log rather than assumed to work
- Staff awareness training and reporting — a platform like Cyber Aware that logs completion and simulation results by individual, not just by department
- Policy documentation — a plain-language security awareness policy reviewed at least once a year
- Evidence mapping — a spreadsheet or GRC tool tying each SMB1001 control to its supporting evidence file
What to do next
Once Bronze is locked in, the jump to Silver is mostly about depth — more rigorous evidence for the same categories, plus incident response basics you probably haven't documented yet. Businesses that already run ongoing security awareness training rather than a once-a-year session move through the higher tiers faster, because the evidence trail already exists instead of getting built the week before submission.
FAQ
What is SMB1001 certification?
SMB1001 certification is an Australian cyber security framework that lets small and mid-sized businesses prove they meet a baseline set of controls, without the cost of an ISO 27001 audit. It uses four tiers — Bronze, Silver, Gold, Platinum — so businesses can certify against the level clients or insurers actually ask for.
Which SMB1001 tier should my business target?
Match the tier to what your biggest client, insurer, or government contract actually specifies, not to your headcount. Most first-time applicants start at Bronze and move up once fundamentals like MFA and backups are fully in place.
Is SMB1001 certification mandatory in Australia?
SMB1001 certification is not a legal requirement, but it's increasingly requested by insurers, procurement teams, and larger clients as proof of a cyber security baseline. Businesses chasing government or enterprise contracts increasingly see it referenced in vendor risk questionnaires.
How much does SMB1001 certification cost?
Cost depends on the tier and whether you handle the self-assessment internally or bring in help closing control gaps. Check the current fee schedule on the official SMB1001 registration portal before budgeting, since pricing sits outside any individual vendor.
Is SMB1001 a self-assessment or an independent audit?
SMB1001 is built around a self-assessment model, where the business attests to meeting each control and provides supporting evidence. The rigour of evidence required increases at higher tiers.
How long does SMB1001 certification last before renewal?
SMB1001 certification isn't a one-time badge — it requires periodic reattestation to stay valid, since controls drift and staff turn over. Confirm the current reattestation cycle on the official SMB1001 site rather than assuming it matches another framework's schedule.
Does SMB1001 replace ISO 27001 or the Essential Eight?
SMB1001 doesn't replace either one. It's built specifically for businesses too small to run a full ISO 27001 program, while the Essential Eight is a technical control set designed for a different audience. Some businesses map evidence across all three frameworks to avoid duplicating work.
What's the fastest control gap to close for SMB1001 certification?
Staff awareness training is usually the fastest gap to close, since MFA and backup configuration take longer to roll out across every account and system. A platform like Cyber Aware can get training records generating within one training cycle, while technical controls like admin account separation take longer to verify.
One last thing
The controls businesses redo most often aren't the technical ones — a firewall rule or a backup schedule, once configured correctly, tends to stay configured. Staff behaviour drifts constantly: new hires join without training, someone reuses a passphrase across a personal account, a repeat clicker ignores three simulations in a row. Treat the staff-facing side of SMB1001 certification as an ongoing programme running through 2026 and beyond, not a folder of evidence you build once and file away.