SMB1001 certification for Australian businesses.
The only cybersecurity certification built specifically for Australian SMBs. Bronze through Diamond, issued by CyberCert, recognised in government tenders, enterprise vendor panels, and cyber insurance underwriting.
5 tiers. Designed around how small and medium businesses actually operate, not enterprise scale.
Specified in Australian government tenders, enterprise vendor onboarding, and insurer questionnaires.
Reissued annually. The 2026 edition tightened password and AI controls. You stay aligned without re-certifying.
Every Australian business should hold at least Silver. Customers are asking, insurers are tightening, and the Privacy Act and Cyber Security Act 2024 all point to the same expectation: current, documented evidence that you take security seriously.
Five Tiers · One Standard
SMB1001:2026
The world's only dynamic cybersecurity standard built for SMBs. Issued by CyberCert as the accredited Dynamic Standard Certifier.

Bronze

Silver

Gold

Platinum

Diamond
Published by Dynamic Standards International
Issued by CyberCert as accredited DSC
Aligned to ISAE 3402 and ISO 17021-1
Essential Eight, CMMC, Cyber Essentials, Cyber Trustmark
What is SMB1001 certification?
SMB1001 certification is an Australian cyber security certification built for small and medium businesses. It runs across five tiers, from Bronze through to Diamond, and each tier adds a defined set of controls you must have in place before a certificate is issued. Real Bytes is certified at Gold and runs the gap assessment, control implementation and certification process for businesses across Australia.
- What it is
- A five-tier cyber security certification standard for small and medium businesses, published by Dynamic Standards International.
- Who issues it
- CyberCert, the accredited Dynamic Standard Certifier, under procedures aligned to ISAE 3402 and ISO 17021-1.
- The tiers
- Bronze, Silver, Gold, Platinum and Diamond. Bronze to Gold are Director-attestable. Platinum and Diamond add an independent audit.
- Annual cost
- A$95 Bronze, A$195 Silver, A$395 Gold, A$595 Platinum, A$995 Diamond, plus audit fees of A$3,000 (Platinum) and A$5,000 (Diamond).
- How long it takes
- Bronze in 4 to 8 weeks, Silver 6 to 12 weeks, Gold 3 to 6 months, Platinum and Diamond 6 to 18 months.
- Why businesses do it
- Government tenders, enterprise vendor onboarding and cyber insurance underwriting increasingly ask for documented cyber security evidence.
From 1 January 2027, SMB1001 is permanently free for every small business.
This is the biggest change to the standard since it launched. DSI, the not-for-profit behind SMB1001 and an ACNC registered charity, is opening the full 2027 edition to the world at no cost. Any small business will be able to read the standard, work through the controls, and lift its security posture without paying for access.
What does not change: certification is still issued by CyberCert, external audits still apply at Platinum and Diamond, and the work to actually meet the controls is still the work. What changes is that cost is no longer a reason to put off finding out where you stand.
As one of the early backers of SMB1001, Real Bytes supports DSI's mission to build global cyber resilience. We hold a Commercial Use Licence, which means early access to the 2027 edition from September 2026. Our clients get prepared for the changes before they land.
1 September 2026
Early access opens
Commercial Use Licence holders get the 2027 edition of the standard four months ahead of public release, so implementation partners can prepare clients for the changes early.
1 January 2027
SMB1001 goes free
The full 2027 edition becomes free to access at smb1001.org for individuals, small businesses, and technical support specialists working with up to three client organisations.
Ongoing
Commercial Use Licence
A CUL is only needed by technical support specialists working with more than three clients, or organisations delivering SMB1001 commercially through products, services or platforms.

Real Bytes is Gold certified under SMB1001:2026.
Issued by CyberCert as the accredited Dynamic Standard Certifier. We have implemented these controls in our own business at every tier of the standard. When we help you certify, it is from direct hands-on experience, not consulting theory.
Five Tiers. One Clear Pathway.
SMB1001:2026 progresses from Bronze to Diamond. Start where you are and build at a pace that fits your business. Click each tier for the full controls breakdown.
Bronze, Silver, Gold - Director-attestable
A Director or Owner signs an Attestation Letter declaring conformity, evidenced through CyberCert's portal. Issued under CyberCert's accreditation as the Dynamic Standard Certifier and sufficient for the majority of supply chain and procurement requirements.
Platinum, Diamond - Externally audited
Director attested plus an independent external audit aligned to ISAE 3402 and ISO 17021-1. Platinum adds an A$3,000 audit fee, Diamond adds A$5,000, both in addition to the annual certification subscription. Carries the most weight in formal government procurement, defence supply chains and regulated industries.
Find Your Target Tier in 30 Seconds
Start with the free Gap Assessment if you are unsure, or jump to the tier that matches your situation. Each row shows the triggers we hear most often and what that tier delivers. Expand any tier to see exactly who it fits and where it is the wrong call.
Target
Free Gap Assessment
Start Here
If any of these apply
- IFYou are not sure which tier you need
- IFYou want a credible answer before spending
- IFYou have been asked but the questionnaire is unclear
What this tier delivers
The 20-minute CyberCert Gap Assessment baselines your business against all five tiers at once. You will know exactly which tier you currently meet, what gaps exist at each level, and the realistic next step before any commitment. No cost, no obligation.

Target
Bronze
SMB1001 Level 1
If any of these apply
- IFYou have nothing formal in place and want a credible starting point
- IFYou are a sole trader or micro-business beginning your security journey
- IFYou want a documented foundation before chasing larger contracts
What this tier delivers
Bronze covers the seven foundational controls every SMB should have regardless of size or industry: firewall, antivirus, patching, password hygiene, backup, awareness training, and an asset register. It is the right tier when there is no existing baseline to build from. Director-attestable.

Target
Silver
SMB1001 Level 2
If any of these apply
- IFYour cyber insurer is asking for evidence of controls at renewal
- IFAn enterprise customer has sent a vendor onboarding questionnaire
- IFYou want the recommended baseline every Australian SMB should hold
What this tier delivers
Silver introduces MFA on email, password managers, SPF / DKIM / DMARC, named user accounts, and an invoice fraud prevention policy. This is the threshold most Australian underwriters now look for to offer cover or hold premiums, and it satisfies many private-sector vendor onboarding requirements. Director-attestable.

Target
Gold
SMB1001 Level 3
If any of these apply
- IFA government tender or Commonwealth supplier panel has specified cybersecurity evidence
- IFYou hold sensitive client data: legal, accounting, health, or financial advice
- IFYour enterprise customer requires more than a basic vendor questionnaire
What this tier delivers
Gold introduces EDR, MFA across all business apps (not just email), RDP restricted to VPN, a written and tested incident response plan, cyber insurance, and an AI acceptable use policy. This is the level Privacy Act-exposed firms typically aim for, and it is the most common requirement on Australian government panels and large enterprise vendor onboarding. Director-attestable.

Target
Platinum
SMB1001 Level 4
If any of these apply
- IFYou supply the Commonwealth or large enterprises that require independent verification
- IFYou are an APRA CPS 234-aligned organisation needing third-party assurance
- IFYour contract specifies an external audit on top of attestation
What this tier delivers
Platinum adds an external audit on top of the A$595 certification subscription (A$3,000 audit fee), performed against ISAE 3402 and ISO 17021-1 aligned procedures. Introduces phishing-resistant MFA, vulnerability scanning, cloud secrets management and formal MSP SLAs. Required where independent third-party assurance is specified in the contract.

Target
Diamond
SMB1001 Level 5
If any of these apply
- IFYou are a critical infrastructure operator under SOCI Act obligations
- IFYou are a defence supply chain or intelligence-adjacent contractor
- IFYou operate a mature ISMS and want SMB-aligned independent validation
What this tier delivers
Diamond is the highest tier and adds MDR, application allowlisting, data encryption at rest, Office macro controls, annual penetration and social engineering testing, a digital trust programme with suppliers, police vetting of privileged staff and live IRP testing. A$995 subscription plus A$5,000 audit fee. Rarely a procurement requirement below 200 staff.
Still unsure? Send us the questionnaire, tender clause, or insurer letter and we will tell you which tier satisfies it. No obligation.
The Five Control Domains
SMB1001:2026 organises controls into five domains. Higher tiers do not invent new domains, they deepen the controls within each one.
Technology Management
Firewall, antivirus and EDR, automatic patching, server hardening, vulnerability scanning, encryption at rest, application allowlisting, MDR.
Examples
- Firewall hardening
- EDR + MDR
- Automatic patching
- TLS on public sites
- Application control
Access Management
Strong passwords, individual accounts, password managers, MFA on email and apps, phishing-resistant MFA, RDP and VPN protection, SPF / DKIM / DMARC.
Examples
- MFA enforcement
- Phishing-resistant MFA at higher tiers
- Password manager
- RDP via VPN only
- SPF, DKIM, DMARC
Backup and Recovery
Documented backup strategy with offline copies, asset-aligned coverage, retention windows, annual restore testing, and active cyber insurance from Gold up.
Examples
- Offline / immutable copy
- 6 months retention
- Annual restore test
- Cyber insurance from Gold
Policies, Processes and Plans
Written cyber policy, invoice fraud policy, AI acceptable use, incident response plan, asset register, secure disposal, supplier digital trust programme.
Examples
- Cyber policy
- Invoice fraud controls
- Incident response plan
- AI acceptable use
- Digital asset register
Education and Training
Annual security awareness training at Bronze and Silver. Ongoing simulated phishing and policy reviews from Gold. Annual IRP testing at Diamond.
Examples
- Awareness training
- Phishing simulation
- BEC and vishing scenarios
- Annual IRP exercise at Diamond
What Each Tier Actually Includes
A side-by-side comparison of the controls required at each tier of SMB1001:2026. "Strong" indicates phishing-resistant MFA. "Director" tiers are Director-attestable through CyberCert. Platinum and Diamond add an independent external audit aligned to ISAE 3402 and ISO 17021-1.
| Control area | Bronze | Silver | Gold | Platinum | Diamond |
|---|---|---|---|---|---|
| Engaged technical support | SLA | SLA | |||
| Firewall and antivirus / EDR | |||||
| Automatic OS and app patching | |||||
| Server patching routine | |||||
| Vulnerability scanning (external) | |||||
| Endpoint Detection and Response (EDR) | |||||
| Managed Detection and Response (MDR) | |||||
| Application allowlisting | |||||
| Office macro hardening | |||||
| Encryption at rest | |||||
| MFA on email | Strong | Strong | |||
| MFA on business apps | Strong | ||||
| Password manager (privileged users) | |||||
| Password manager (all users) | |||||
| RDP and VPN behind MFA | Strong | ||||
| SPF, DKIM, DMARC enforcement | SPF | ||||
| Backup with offline / immutable copy | Tested | Tested | |||
| Annual restore test | |||||
| Cyber insurance | |||||
| Cyber policy + invoice fraud policy | |||||
| Incident response plan | Enhanced | ||||
| AI acceptable use policy | |||||
| Digital asset register | PII tagged | ||||
| Security awareness training | Continuous | Continuous | Continuous | ||
| Annual IRP testing (red/blue/purple) | |||||
| Penetration test (annual) | |||||
| Police vetting (privileged) | |||||
| Supplier digital trust programme | |||||
| Assessment | Director | Director | Director | External audit | External audit |
From National Strategy to Your Certificate
Why SMB1001 sits at the centre of Australian cyber policy, why your business should pursue it, how Real Bytes delivers the work, and what real outcomes look like across Australian industries.
SMB1001 sits inside Australia's national cyber strategy
The Australian Government published the Australian Cyber Workforce Playbook in October 2025 under Shield 5 of the 2023-2030 Australian Cyber Security Strategy. Section 3.5 specifically addresses protecting small business. SMB1001 is the practical, certifiable standard that maps to that intent.
Read the Playbook (Home Affairs, Oct 2025)Protecting small business
Section 3.5 of the Playbook directly addresses the cyber capability gap in Australian SMBs and recognises tiered, certifiable standards as a practical pathway.
Sovereign cyber capability
Shield 5 of the 2023-2030 Strategy targets a sovereign workforce and supply chain. Local certifications and Australian-aligned controls feed directly into this objective.
A workforce gap, not just a tools gap
The Playbook acknowledges ongoing shortages of cyber professionals. For most Australian SMBs, this is exactly why an MSP partnership is more practical than hiring in-house.
Aligned to a national strategy
Real Bytes implements controls that align to Essential Eight and SMB1001, so the work compounds against current and future government and enterprise expectations.
Source: Department of Home Affairs, Australian Cyber Workforce Playbook (V.10, October 2025). Real Bytes is not affiliated with the Department of Home Affairs and references the Playbook as publicly available policy context only.
Issued and Recognised By

Bronze

Silver

Gold

Platinum

Diamond
SMB1001:2026 is published by Dynamic Standards International. CyberCert is the accredited Dynamic Standard Certifier (DSC) and issues certificates under procedures aligned with ISAE 3402 and ISO 17021-1.
Start With a Free Gap Assessment
The gap assessment takes about 20 minutes and shows you exactly where your business sits against the SMB1001 framework right now. You will see which tier you currently meet, what gaps exist at each level, and what a realistic path to your target certification looks like.
There is no cost, no commitment, and no sales pressure attached. If you are not ready to certify yet, the assessment is still useful for understanding your current security posture.
"Real Bytes guided us through SMB1001 Gold certification in just over 3 months. It has opened doors with enterprise clients who now require evidence of cybersecurity maturity before onboarding vendors."
Already have a requirement to certify?
If a tender, client, or insurer has specified SMB1001 as a requirement, call us directly. We can usually give you a clear scope and timeline within 24 hours.
07 3114 2808Why SMB1001 is calibrated for the real attack pattern
SMB1001 was built around the controls that the breach data keeps pointing to: MFA on every account that matters, credential discipline, patching velocity on edge devices, and people awareness. The Verizon 2026 DBIR validates that those controls remain the highest-leverage moves for small and medium businesses in Australia.
Read the Verizon 2026 DBIR96%
96% of ransomware victims in the DBIR dataset are small or medium businesses
Attackers run a volume model. Smaller operators are the easier mark, not the safer one.
38%
38% of SMB breaches started with compromised credentials
MFA on every account that matters is the highest-leverage control left for SMBs.
29%
29% of SMB breaches started with an unpatched edge device
Firewall, VPN and NAS patching needs an SLA, not a calendar reminder.
Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.
SMB1001 and CyberCert: Common Questions

Bronze to Diamond. Start where you are.
We have implemented SMB1001 in our own business at every tier, and now run the same engagement for clients across Australia. Start with the free gap assessment and know exactly where you stand against every level of the framework.
CyberCert Gold certified. ACSC Network Partner. No lock-in.

Remote Support