SMB1001 Certification: How to Get Certified in 2026

Get SMB1001 certification in 2026: tier structure, exact steps, common pitfalls, and how staff awareness training closes compliance gaps in Australia.

SMB1001 certification proves your business meets a recognised Australian cyber security baseline, and closing the gap comes down to a specific sequence of technical and staff-facing fixes. This guide breaks down the tiers, the order of operations, and the mistakes that stall most applications in 2026.

TL;DR

Why this matters

SMB1001 exists because ISO 27001 is built for enterprises with a dedicated security team, not a twelve-person business running Xero and Microsoft 365. Insurers, procurement teams, and larger clients increasingly ask for proof of a cyber security baseline before they'll sign a contract. SMB1001 certification gives small and mid-sized businesses a way to answer that ask without hiring a security manager.

The framework runs on four tiers — Bronze, Silver, Gold, Platinum — each stacking more controls on top of the last. Bronze covers the fundamentals: multi-factor authentication, passphrases, patching, backups, and admin account separation. Higher tiers add depth in incident response, vendor risk, and staff evidence requirements.

Most businesses fail their first self-assessment attempt on staff-facing controls, not technical ones. Firewalls and backup schedules are one-time configuration jobs. Getting every staff member to stop reusing passwords and recognise a phishing email is a training problem, and it starts with a documented security awareness policy for audits, not ad hoc reminders in a team chat.

What you'll need

TierFocusTypical audience
BronzeCore hygiene: MFA, passphrases, backups, patchingSole traders, micro businesses
SilverAdds access control depth and incident response basicsGrowing SMBs with a handful of staff
GoldAdds vendor risk and more rigorous staff evidenceBusinesses handling client data at scale
PlatinumFull control set with the most rigorous verificationBusinesses bidding on government or enterprise contracts

The steps

1. Confirm your tier and read the actual control list

Picking a tier before reading the requirements wastes months. A sole trader chasing Platinum builds controls no client is asking for; a business bidding on government work at Bronze gets rejected at the tender stage.

Check what your biggest contract, insurer, or client actually specifies before committing to a tier. Read the published control list line by line — SMB1001 certification requirements are specific about MFA coverage, backup frequency, and account separation, not vague.

Expected outcome: a one-page checklist matched to your actual tier. Common mistake: guessing your tier based on headcount instead of what a contract or insurer specifies.

2. Run a gap assessment against every control

You can't fix what you haven't measured, and the self-assessment asks you to attest to specifics, not vibes. Go control by control and mark each one Met, Partial, or Not Met.

Don't skip controls that feel obviously fine. MFA is the classic one — businesses assume full coverage and find unenrolled accounts the moment they actually check the admin console.

Expected outcome: a gap list ranked by effort. Common mistake: treating the self-assessment as a checkbox exercise instead of pulling real evidence — screenshots, admin console exports, dated logs.

3. Fix identity and access controls first

Compromised credentials remain one of the most common entry points into small business systems, and it's the fastest gap to close on the whole list.

Enforce MFA on every account with zero exceptions, including the owner and any legacy shared logins. Move from passwords to passphrases where the platform supports it. Separate admin accounts from daily-use accounts so nobody browses the web or reads email while logged in as an administrator.

Expected outcome: every account under MFA, admin accounts isolated. Common mistake: leaving one exception "because it's annoying on their phone" — that single exception fails the whole control.

4. Lock down backups and patch cadence

Evaluators want proof backups actually restore, not just that a backup job runs on schedule. This step covers the recovery side of the framework, not only prevention.

Confirm backup jobs cover every critical system, test a restore, and document the date it worked. Set a patch window for operating systems and business applications and stick to it — assessors ask for evidence of a schedule, not a policy statement.

Expected outcome: a tested restore log and a patch cadence you can point to. Common mistake: backups exist but nobody has restored from them in over a year, so the first real test happens mid-incident.

5. Put a written security awareness policy in place

This turns "the team knows about phishing" into a document an assessor can actually check. SMB1001 certification wants evidence a policy exists and is followed, not a claim that staff are generally careful.

Write down what's expected: password behaviour, reporting suspicious emails, device use, and who owns the review cycle. Keep it to one or two pages — a forty-page policy nobody reads doesn't pass an audit either.

Expected outcome: a signed-off policy document with a review date. Common mistake: copying a template policy that references controls your business doesn't actually have.

6. Train staff and capture the evidence

A policy without training records is a document, not a control. This step generates the completion evidence SMB1001 certification checks for.

Run structured training through a certified cyber security awareness course rather than a one-off slide deck. Cyber Aware and similar platforms log completion timestamps automatically, which saves the manual chasing most businesses underestimate.

Expected outcome: a completion register you can export as evidence. Common mistake: training office staff and forgetting remote, casual, or contractor accounts that still touch company systems.

7. Map evidence against each control and complete the self-assessment

This turns your gap list from step two into the actual submission. Incomplete evidence mapping is the single biggest reason self-assessments bounce back for rework.

Go line by line through the tier's control list and attach specific evidence — screenshots, logs, policy documents, training records — to each one. Where you're mapping into a broader framework like ISO 27001 Annex A, reuse that mapping work instead of duplicating it from scratch.

Expected outcome: a complete evidence pack ready to submit. Common mistake: submitting vague evidence like "staff are trained" instead of a dated completion export.

8. Submit, then set a recurring review cadence

SMB1001 certification isn't a one-time badge. Controls drift, staff turn over, and evidence goes stale, so this step keeps you certified after the certificate arrives.

Submit through the official SMB1001 process, then calendar a recurring internal review well ahead of your next reattestation window so gaps get caught early, not the week before renewal.

Expected outcome: certification confirmed, with a standing review date on the calendar. Common mistake: filing the certificate and forgetting about it until a client or insurer asks for a current one.

Get staff training-ready for SMB1001

Cyber Aware runs the awareness training and reporting evaluators check for.

Explore Cyber Aware

Troubleshooting

Tools and resources

What to do next

Once Bronze is locked in, the jump to Silver is mostly about depth — more rigorous evidence for the same categories, plus incident response basics you probably haven't documented yet. Businesses that already run ongoing security awareness training rather than a once-a-year session move through the higher tiers faster, because the evidence trail already exists instead of getting built the week before submission.

FAQ

What is SMB1001 certification?

SMB1001 certification is an Australian cyber security framework that lets small and mid-sized businesses prove they meet a baseline set of controls, without the cost of an ISO 27001 audit. It uses four tiers — Bronze, Silver, Gold, Platinum — so businesses can certify against the level clients or insurers actually ask for.

Which SMB1001 tier should my business target?

Match the tier to what your biggest client, insurer, or government contract actually specifies, not to your headcount. Most first-time applicants start at Bronze and move up once fundamentals like MFA and backups are fully in place.

Is SMB1001 certification mandatory in Australia?

SMB1001 certification is not a legal requirement, but it's increasingly requested by insurers, procurement teams, and larger clients as proof of a cyber security baseline. Businesses chasing government or enterprise contracts increasingly see it referenced in vendor risk questionnaires.

How much does SMB1001 certification cost?

Cost depends on the tier and whether you handle the self-assessment internally or bring in help closing control gaps. Check the current fee schedule on the official SMB1001 registration portal before budgeting, since pricing sits outside any individual vendor.

Is SMB1001 a self-assessment or an independent audit?

SMB1001 is built around a self-assessment model, where the business attests to meeting each control and provides supporting evidence. The rigour of evidence required increases at higher tiers.

How long does SMB1001 certification last before renewal?

SMB1001 certification isn't a one-time badge — it requires periodic reattestation to stay valid, since controls drift and staff turn over. Confirm the current reattestation cycle on the official SMB1001 site rather than assuming it matches another framework's schedule.

Does SMB1001 replace ISO 27001 or the Essential Eight?

SMB1001 doesn't replace either one. It's built specifically for businesses too small to run a full ISO 27001 program, while the Essential Eight is a technical control set designed for a different audience. Some businesses map evidence across all three frameworks to avoid duplicating work.

What's the fastest control gap to close for SMB1001 certification?

Staff awareness training is usually the fastest gap to close, since MFA and backup configuration take longer to roll out across every account and system. A platform like Cyber Aware can get training records generating within one training cycle, while technical controls like admin account separation take longer to verify.

One last thing

The controls businesses redo most often aren't the technical ones — a firewall rule or a backup schedule, once configured correctly, tends to stay configured. Staff behaviour drifts constantly: new hires join without training, someone reuses a passphrase across a personal account, a repeat clicker ignores three simulations in a row. Treat the staff-facing side of SMB1001 certification as an ongoing programme running through 2026 and beyond, not a folder of evidence you build once and file away.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.