Thirteen controls. How many can you prove?
SMB1001 and the Essential Eight are what your insurer, your auditor and your largest customer measure you against. Assess yourself honestly. Your answers stay in this browser and nothing is sent unless you choose to.
Each control shows the SMB1001:2026 clause and tier that first requires it, plus the Essential Eight strategy it maps to. All eight Essential Eight strategies are covered. Start with Bronze and work up.
Stays in your browser
Nothing is stored on our servers. Clear it any time.
About five minutes
Thirteen controls, three answers each. Come back later and it remembers.
Mapped to the standards
Every control cites its SMB1001 clause and Essential Eight strategy.
Bronze
Tier 1Regular, isolated backups
Are backups running daily, held somewhere ransomware cannot reach, and has a restore actually been tested in the last three months?
Patch operating systems and applications
Are workstations, servers, browsers and Office patched automatically, with critical fixes applied within days rather than months?
Endpoint protection on every device
Does every laptop, desktop and server run actively updated anti-malware or EDR, including the ones that rarely come into the office?
Security awareness training
Do all staff complete cyber awareness training with attendance recorded, not just a slide deck at induction?
Silver
Tier 2MFA on email and admin accounts
Is MFA enforced by policy on every email account and every admin account, not just switched on for whoever opted in?
Restrict administrative privileges
Are admin rights limited to people who need them, reviewed regularly, and kept separate from day-to-day logins?
Centrally managed password vault
Do privileged users keep credentials in a managed password vault with MFA and auditing, rather than browsers or spreadsheets?
Gold
Tier 3SPF, DKIM and DMARC enforcement
Are SPF, DKIM and DMARC published on every sending domain, with DMARC set to quarantine or reject rather than none?
Cyber policy and incident response plan
Is there a written cyber security policy staff have signed, and an incident response plan with named contacts you could open tonight?
Platinum
Tier 4Phishing-resistant MFA
Are SMS, voice and email codes disabled as MFA methods, leaving authenticator apps or hardware keys only, even as a backup?
Diamond
Tier 5Application control
Is there anything stopping an unapproved program, downloaded or emailed, from simply running on a staff laptop?
Office macros blocked by policy
Are Microsoft Office macros blocked by default across the fleet, with only vetted, signed macros allowed to run?
User application hardening
Are browsers, Office and PDF readers hardened by policy: web ads and Java blocked in browsers, Office child processes and OLE restricted, and Internet Explorer 11 removed?
Step two
Score yourself against the full SMB1001 control set
This tracker covers 13 controls. CyberCert's gap assessment scores every control across all five tiers and returns a prioritised roadmap. Real Bytes is a CyberCert Gold MSSP, so the output maps straight onto work we can do with you.
0 of 13 answered
Opens on CyberCert. Third-party tool, no cost to you.
Where this leads
Turn a tier readout into a certificate
SMB1001 certification is the fastest way for an Australian business to prove its posture to a supply chain. Real Bytes is a CyberCert Gold MSSP and works through each tier's controls with you, from Bronze to Diamond.
Frequently asked
Questions about the tracker, before you start ticking.
No. Your answers stay in your browser only. Nothing is stored on our servers and nothing is sent unless you choose to submit the enquiry form, in which case your answers and contact details go to our helpdesk by email so the follow-up call already knows the gaps. We do not keep a database record of the enquiry.

Remote Support