SMB1001 certification is an internationally recognised cyber security certification built specifically for small and medium businesses — a five-tier standard (Bronze, Silver, Gold, Platinum, Diamond) that proves your basic cyber controls are in place, to a level your clients, insurers and supply chain can actually verify.
Key takeaways
- SMB1001 is developed by Dynamic Standards International (DSI) and certified through its accredited bodies such as CyberCert — it is designed for SMEs, not enterprises.
- The standard has five levels: Bronze (7 controls), Silver (17), Gold (27), Platinum (32) and Diamond (39).
- Bronze, Silver and Gold are self-attested with supporting evidence; Platinum and Diamond require an independent assessor to verify controls.
- The average self-reported cost of cybercrime to Australian small business rose 14% to $56,600 in FY2024–25 (ASD's ACSC Annual Cyber Threat Report) — the risk the certification is designed to reduce and evidence.
- Security awareness training and phishing simulation records are among the controls SMB1001 asks about, and they are the easiest for a small business to evidence continuously.
What is SMB1001 certification?
SMB1001 answers a problem most certification frameworks ignore: ISO 27001 and similar standards were built for enterprises with security teams and budgets to match. A 20-person accounting firm still needs to prove to a client, an insurer or a tender panel that it takes security seriously — but has nobody full-time to run a certification programme.
SMB1001 is the answer built for that business. It is developed by Dynamic Standards International, a standards body focused on SMB security, and certified through DSI-accredited certification bodies such as CyberCert. The standard is organised into five progressive tiers, each building on the last:
| Level | Badge | Controls | Focus | Certification method |
|---|---|---|---|---|
| 1 | Bronze | 7 | Basic preventive controls: firewall, antivirus, updates, backups | Self-attested with evidence |
| 2 | Silver | 17 | More advanced preventive measures | Self-attested with evidence |
| 3 | Gold | 27 | Holistic risk management across people, process and technology | Self-attested with evidence |
| 4 | Platinum | 32 | Formal governance, policy and verification | Independent assessment |
| 5 | Diamond | 39 | Full maturity across all domains | Independent assessment |
A business does not certify at all five levels — it picks the tier that matches its risk, its customers and its contracts. Gold is the most common target for small businesses: it is the level where security becomes genuinely demonstrable, with full MFA, endpoint protection, a cyber security policy, an incident response plan and evidence of staff training. Platinum and Diamond add independent verification and are typically pursued by organisations with regulated clients or larger contracts.
What SMB1001 actually requires
The controls are deliberately practical — things a small business can implement with its IT provider rather than a project team. Across the tiers, they cover:
- Basic hygiene — firewalls, antivirus, automatic updates, secure backups.
- Access control — MFA, password policy, managing admin accounts.
- People controls — cyber security awareness training, phishing awareness, and a way to prove staff completed it.
- Process — a written cyber security policy, an incident response plan, vendor and remote access management.
- Evidence — records showing each control is operating, not just planned.
That last point is where most small businesses stumble. The control often exists — the backup runs, the training happened — but nothing was recorded. Certification turns "we do that" into "here is the evidence".
How certification works, step by step
- Assess your current state against the controls of your target level. Most businesses start with a gap assessment rather than a guess.
- Close the gaps — implement the missing controls with your IT provider or MSP.
- Gather evidence for every control: screenshots, logs, policies, training records.
- Engage a DSI-accredited certification body and submit for your tier. At Bronze, Silver and Gold you self-attest with supporting evidence; at Platinum and Diamond an independent assessor verifies the controls.
- Maintain and recertify on the certification body's cycle — controls have to keep operating, not just exist once.
Certification timelines scale with tier: the lower tiers are commonly achieved in weeks, Gold in one to two months, and the independently verified tiers in a quarter or more.
Why small businesses certify
Three drivers show up again and again:
- Winning and keeping contracts. Client and tender questionnaires increasingly carry security clauses; a recognised certification turns a slow questionnaire cycle into a checkbox.
- Insurance. Cyber insurers scrutinise controls more closely every year, and demonstrable certification supports both eligibility and pricing.
- Actual risk reduction. The threat is not hypothetical. ASD's ACSC received more than 84,700 cybercrime reports in FY2024–25 — one every 6 minutes — and the average self-reported cost to small business rose 14% to $56,600. Business email compromise fraud alone was 15% of business cybercrime reports.
At the global end, IBM's 2026 Cost of a Data Breach Report puts the average breach at USD 4.99 million — a figure no small business will ever see, but the direction is the same: prevention and evidence cost less than response.
SMB1001 vs the Essential Eight
| SMB1001 | Essential Eight | |
|---|---|---|
| Built for | SMBs anywhere | Australian organisations, esp. government-adjacent |
| Structure | 5 progressive tiers, certification issued | 8 mitigation strategies, maturity levels 0–3 |
| Certification | Yes — via accredited bodies | Assessment/self-assessment; no formal certificate |
| Best fit | Client contracts, tenders, insurers | Government supply chains, uplift programmes |
They are complements, not rivals. The Essential Eight is the Australian government's mitigation framework; SMB1001 wraps a certified, market-facing proof of the same hygiene. Many businesses map both from the same evidence base.
The control small businesses fail most: people evidence
Technology gaps get closed with a purchase order. The people control is harder — it needs ongoing, dated evidence that staff are trained and tested, which is why annual slide decks do not survive certification. A monthly programme of short training plus phishing simulations generates exactly the evidence trail the standard asks for, automatically.
Cyber Aware's security awareness training and phishing simulations produce per-person completion and click data every month, human risk reporting turns it into a monthly evidence pack, and the gap assessment maps your position against Essential Eight and SMB1001 out of the box. If you are weighing the standard itself, the SMB1001 overview covers how the platform supports each tier.
FAQ
What is SMB1001 certification? An internationally recognised, five-tier cyber security certification built for small and medium businesses by Dynamic Standards International, proving your controls are in place at the level you certify.
What are the SMB1001 levels? Bronze (7 controls), Silver (17), Gold (27), Platinum (32) and Diamond (39). Bronze to Gold are self-attested with evidence; Platinum and Diamond are independently verified.
What level of SMB1001 should a small business aim for? Gold is the common target — it satisfies most procurement, insurer and supply chain requirements. Bronze is a legitimate first step if you are starting from a low base.
Is SMB1001 a legal requirement in Australia? No. It is a voluntary, market-facing certification — its value comes from clients, insurers and tender panels recognising it, not from legislation.
How long does SMB1001 certification take? The lower tiers are commonly achieved in weeks, Gold in one to two months, and the independently verified tiers in a quarter or more, depending on how many gaps you start with.
How much does SMB1001 certification cost? It depends on tier and certification body. Check current pricing with an accredited certification body before committing; the control implementation often costs more than the certification itself.
Does SMB1001 require staff cyber security training? Yes — awareness training and phishing awareness are among the controls across the tiers, and evidence of completed, current training is part of the certification pack.
One last thing
Certification is a snapshot; the behaviours behind it are a habit. The businesses that keep their SMB1001 status (and keep winning the contracts) are the ones whose training records, phishing results and control evidence stay current month after month — which is exactly what an automated programme produces without anyone chasing spreadsheets.