CyberCertThe cybersecurity standard built for Australian SMBs

SMB1001 certification for Australian businesses.

The only cybersecurity certification built specifically for Australian SMBs. Bronze through Diamond, issued by CyberCert, recognised in government tenders, enterprise vendor panels, and cyber insurance underwriting.

Built for SMBs

5 tiers. Designed around how small and medium businesses actually operate, not enterprise scale.

Recognised Here

Specified in Australian government tenders, enterprise vendor onboarding, and insurer questionnaires.

Stays Current

Reissued annually. The 2026 edition tightened password and AI controls. You stay aligned without re-certifying.

Every Australian business should hold at least Silver. Customers are asking, insurers are tightening, and the Privacy Act and Cyber Security Act 2024 all point to the same expectation: current, documented evidence that you take security seriously.

ACSC Network Partner
CyberCert Gold Certified
Bronze to Diamond
No Lock-In
Last updated:
Standard

Published by Dynamic Standards International

Certifier

Issued by CyberCert as accredited DSC

Audit Basis

Aligned to ISAE 3402 and ISO 17021-1

Maps To

Essential Eight, CMMC, Cyber Essentials, Cyber Trustmark

What is SMB1001 certification?

SMB1001 certification is an Australian cyber security certification built for small and medium businesses. It runs across five tiers, from Bronze through to Diamond, and each tier adds a defined set of controls you must have in place before a certificate is issued. Real Bytes is certified at Gold and runs the gap assessment, control implementation and certification process for businesses across Australia.

What it is
A five-tier cyber security certification standard for small and medium businesses, published by Dynamic Standards International.
Who issues it
CyberCert, the accredited Dynamic Standard Certifier, under procedures aligned to ISAE 3402 and ISO 17021-1.
The tiers
Bronze, Silver, Gold, Platinum and Diamond. Bronze to Gold are Director-attestable. Platinum and Diamond add an independent audit.
Annual cost
A$95 Bronze, A$195 Silver, A$395 Gold, A$595 Platinum, A$995 Diamond, plus audit fees of A$3,000 (Platinum) and A$5,000 (Diamond).
How long it takes
Bronze in 4 to 8 weeks, Silver 6 to 12 weeks, Gold 3 to 6 months, Platinum and Diamond 6 to 18 months.
Why businesses do it
Government tenders, enterprise vendor onboarding and cyber insurance underwriting increasingly ask for documented cyber security evidence.
SMB1001 UnlockedAnnounced by Dynamic Standards International, August 2026

From 1 January 2027, SMB1001 is permanently free for every small business.

This is the biggest change to the standard since it launched. DSI, the not-for-profit behind SMB1001 and an ACNC registered charity, is opening the full 2027 edition to the world at no cost. Any small business will be able to read the standard, work through the controls, and lift its security posture without paying for access.

What does not change: certification is still issued by CyberCert, external audits still apply at Platinum and Diamond, and the work to actually meet the controls is still the work. What changes is that cost is no longer a reason to put off finding out where you stand.

As one of the early backers of SMB1001, Real Bytes supports DSI's mission to build global cyber resilience. We hold a Commercial Use Licence, which means early access to the 2027 edition from September 2026. Our clients get prepared for the changes before they land.

1 September 2026

Early access opens

Commercial Use Licence holders get the 2027 edition of the standard four months ahead of public release, so implementation partners can prepare clients for the changes early.

1 January 2027

SMB1001 goes free

The full 2027 edition becomes free to access at smb1001.org for individuals, small businesses, and technical support specialists working with up to three client organisations.

Ongoing

Commercial Use Licence

A CUL is only needed by technical support specialists working with more than three clients, or organisations delivering SMB1001 commercially through products, services or platforms.

Visit smb1001.org
SMB1001 Gold
Implementation partner

Real Bytes is Gold certified under SMB1001:2026.

Issued by CyberCert as the accredited Dynamic Standard Certifier. We have implemented these controls in our own business at every tier of the standard. When we help you certify, it is from direct hands-on experience, not consulting theory.

Five Tiers. One Clear Pathway.

SMB1001:2026 progresses from Bronze to Diamond. Start where you are and build at a pace that fits your business. Click each tier for the full controls breakdown.

Bronze, Silver, Gold - Director-attestable

A Director or Owner signs an Attestation Letter declaring conformity, evidenced through CyberCert's portal. Issued under CyberCert's accreditation as the Dynamic Standard Certifier and sufficient for the majority of supply chain and procurement requirements.

Platinum, Diamond - Externally audited

Director attested plus an independent external audit aligned to ISAE 3402 and ISO 17021-1. Platinum adds an A$3,000 audit fee, Diamond adds A$5,000, both in addition to the annual certification subscription. Carries the most weight in formal government procurement, defence supply chains and regulated industries.

Which Tier Do I Actually Need?

Find Your Target Tier in 30 Seconds

Start with the free Gap Assessment if you are unsure, or jump to the tier that matches your situation. Each row shows the triggers we hear most often and what that tier delivers. Expand any tier to see exactly who it fits and where it is the wrong call.

Start Free

Target

Free Gap Assessment

Start Here

If any of these apply

  • IFYou are not sure which tier you need
  • IFYou want a credible answer before spending
  • IFYou have been asked but the questionnaire is unclear

What this tier delivers

The 20-minute CyberCert Gap Assessment baselines your business against all five tiers at once. You will know exactly which tier you currently meet, what gaps exist at each level, and the realistic next step before any commitment. No cost, no obligation.

SMB1001 Bronze badge

Target

Bronze

SMB1001 Level 1

If any of these apply

  • IFYou have nothing formal in place and want a credible starting point
  • IFYou are a sole trader or micro-business beginning your security journey
  • IFYou want a documented foundation before chasing larger contracts

What this tier delivers

Bronze covers the seven foundational controls every SMB should have regardless of size or industry: firewall, antivirus, patching, password hygiene, backup, awareness training, and an asset register. It is the right tier when there is no existing baseline to build from. Director-attestable.

SMB1001 Silver badge

Target

Silver

SMB1001 Level 2

If any of these apply

  • IFYour cyber insurer is asking for evidence of controls at renewal
  • IFAn enterprise customer has sent a vendor onboarding questionnaire
  • IFYou want the recommended baseline every Australian SMB should hold

What this tier delivers

Silver introduces MFA on email, password managers, SPF / DKIM / DMARC, named user accounts, and an invoice fraud prevention policy. This is the threshold most Australian underwriters now look for to offer cover or hold premiums, and it satisfies many private-sector vendor onboarding requirements. Director-attestable.

Most Common Target
SMB1001 Gold badge

Target

Gold

SMB1001 Level 3

If any of these apply

  • IFA government tender or Commonwealth supplier panel has specified cybersecurity evidence
  • IFYou hold sensitive client data: legal, accounting, health, or financial advice
  • IFYour enterprise customer requires more than a basic vendor questionnaire

What this tier delivers

Gold introduces EDR, MFA across all business apps (not just email), RDP restricted to VPN, a written and tested incident response plan, cyber insurance, and an AI acceptable use policy. This is the level Privacy Act-exposed firms typically aim for, and it is the most common requirement on Australian government panels and large enterprise vendor onboarding. Director-attestable.

SMB1001 Platinum badge

Target

Platinum

SMB1001 Level 4

If any of these apply

  • IFYou supply the Commonwealth or large enterprises that require independent verification
  • IFYou are an APRA CPS 234-aligned organisation needing third-party assurance
  • IFYour contract specifies an external audit on top of attestation

What this tier delivers

Platinum adds an external audit on top of the A$595 certification subscription (A$3,000 audit fee), performed against ISAE 3402 and ISO 17021-1 aligned procedures. Introduces phishing-resistant MFA, vulnerability scanning, cloud secrets management and formal MSP SLAs. Required where independent third-party assurance is specified in the contract.

SMB1001 Diamond badge

Target

Diamond

SMB1001 Level 5

If any of these apply

  • IFYou are a critical infrastructure operator under SOCI Act obligations
  • IFYou are a defence supply chain or intelligence-adjacent contractor
  • IFYou operate a mature ISMS and want SMB-aligned independent validation

What this tier delivers

Diamond is the highest tier and adds MDR, application allowlisting, data encryption at rest, Office macro controls, annual penetration and social engineering testing, a digital trust programme with suppliers, police vetting of privileged staff and live IRP testing. A$995 subscription plus A$5,000 audit fee. Rarely a procurement requirement below 200 staff.

Still unsure? Send us the questionnaire, tender clause, or insurer letter and we will tell you which tier satisfies it. No obligation.

Control Domains

The Five Control Domains

SMB1001:2026 organises controls into five domains. Higher tiers do not invent new domains, they deepen the controls within each one.

Technology Management

Firewall, antivirus and EDR, automatic patching, server hardening, vulnerability scanning, encryption at rest, application allowlisting, MDR.

Examples

  • Firewall hardening
  • EDR + MDR
  • Automatic patching
  • TLS on public sites
  • Application control

Access Management

Strong passwords, individual accounts, password managers, MFA on email and apps, phishing-resistant MFA, RDP and VPN protection, SPF / DKIM / DMARC.

Examples

  • MFA enforcement
  • Phishing-resistant MFA at higher tiers
  • Password manager
  • RDP via VPN only
  • SPF, DKIM, DMARC

Backup and Recovery

Documented backup strategy with offline copies, asset-aligned coverage, retention windows, annual restore testing, and active cyber insurance from Gold up.

Examples

  • Offline / immutable copy
  • 6 months retention
  • Annual restore test
  • Cyber insurance from Gold

Policies, Processes and Plans

Written cyber policy, invoice fraud policy, AI acceptable use, incident response plan, asset register, secure disposal, supplier digital trust programme.

Examples

  • Cyber policy
  • Invoice fraud controls
  • Incident response plan
  • AI acceptable use
  • Digital asset register

Education and Training

Annual security awareness training at Bronze and Silver. Ongoing simulated phishing and policy reviews from Gold. Annual IRP testing at Diamond.

Examples

  • Awareness training
  • Phishing simulation
  • BEC and vishing scenarios
  • Annual IRP exercise at Diamond
Tier Comparison

What Each Tier Actually Includes

A side-by-side comparison of the controls required at each tier of SMB1001:2026. "Strong" indicates phishing-resistant MFA. "Director" tiers are Director-attestable through CyberCert. Platinum and Diamond add an independent external audit aligned to ISAE 3402 and ISO 17021-1.

Control areaBronzeSilverGoldPlatinumDiamond
Engaged technical support
SLA
SLA
Firewall and antivirus / EDR
Automatic OS and app patching
Server patching routine
Vulnerability scanning (external)
Endpoint Detection and Response (EDR)
Managed Detection and Response (MDR)
Application allowlisting
Office macro hardening
Encryption at rest
MFA on email
Strong
Strong
MFA on business apps
Strong
Password manager (privileged users)
Password manager (all users)
RDP and VPN behind MFA
Strong
SPF, DKIM, DMARC enforcement
SPF
Backup with offline / immutable copy
Tested
Tested
Annual restore test
Cyber insurance
Cyber policy + invoice fraud policy
Incident response plan
Enhanced
AI acceptable use policy
Digital asset register
PII tagged
Security awareness training
Continuous
Continuous
Continuous
Annual IRP testing (red/blue/purple)
Penetration test (annual)
Police vetting (privileged)
Supplier digital trust programme
Assessment
Director
Director
Director
External audit
External audit
Required Not required at this tierLabel Stronger or specialised variant of the control
The Full Picture

From National Strategy to Your Certificate

Why SMB1001 sits at the centre of Australian cyber policy, why your business should pursue it, how Real Bytes delivers the work, and what real outcomes look like across Australian industries.

SMB1001 sits inside Australia's national cyber strategy

The Australian Government published the Australian Cyber Workforce Playbook in October 2025 under Shield 5 of the 2023-2030 Australian Cyber Security Strategy. Section 3.5 specifically addresses protecting small business. SMB1001 is the practical, certifiable standard that maps to that intent.

Read the Playbook (Home Affairs, Oct 2025)

Protecting small business

Section 3.5 of the Playbook directly addresses the cyber capability gap in Australian SMBs and recognises tiered, certifiable standards as a practical pathway.

Sovereign cyber capability

Shield 5 of the 2023-2030 Strategy targets a sovereign workforce and supply chain. Local certifications and Australian-aligned controls feed directly into this objective.

A workforce gap, not just a tools gap

The Playbook acknowledges ongoing shortages of cyber professionals. For most Australian SMBs, this is exactly why an MSP partnership is more practical than hiring in-house.

Aligned to a national strategy

Real Bytes implements controls that align to Essential Eight and SMB1001, so the work compounds against current and future government and enterprise expectations.

Source: Department of Home Affairs, Australian Cyber Workforce Playbook (V.10, October 2025). Real Bytes is not affiliated with the Department of Home Affairs and references the Playbook as publicly available policy context only.

Issued and Recognised By

SMB1001 Bronze

Bronze

SMB1001 Silver

Silver

SMB1001 Gold

Gold

SMB1001 Platinum

Platinum

SMB1001 Diamond

Diamond

SMB1001:2026 is published by Dynamic Standards International. CyberCert is the accredited Dynamic Standard Certifier (DSC) and issues certificates under procedures aligned with ISAE 3402 and ISO 17021-1.

Start With a Free Gap Assessment

The gap assessment takes about 20 minutes and shows you exactly where your business sits against the SMB1001 framework right now. You will see which tier you currently meet, what gaps exist at each level, and what a realistic path to your target certification looks like.

There is no cost, no commitment, and no sales pressure attached. If you are not ready to certify yet, the assessment is still useful for understanding your current security posture.

Baseline against all 5 certification tiers simultaneously
See your current tier and what is needed to advance
Get a clear remediation priority list
Understand your certification timeline before committing
No lock-in - we provide the roadmap, you decide what to do with it
Google Reviews

"Real Bytes guided us through SMB1001 Gold certification in just over 3 months. It has opened doors with enterprise clients who now require evidence of cybersecurity maturity before onboarding vendors."

Brisbane professional services client

Already have a requirement to certify?

If a tender, client, or insurer has specified SMB1001 as a requirement, call us directly. We can usually give you a clear scope and timeline within 24 hours.

07 3114 2808
What the 2026 breach data shows

Why SMB1001 is calibrated for the real attack pattern

SMB1001 was built around the controls that the breach data keeps pointing to: MFA on every account that matters, credential discipline, patching velocity on edge devices, and people awareness. The Verizon 2026 DBIR validates that those controls remain the highest-leverage moves for small and medium businesses in Australia.

Read the Verizon 2026 DBIR

96%

96% of ransomware victims in the DBIR dataset are small or medium businesses

Attackers run a volume model. Smaller operators are the easier mark, not the safer one.

38%

38% of SMB breaches started with compromised credentials

MFA on every account that matters is the highest-leverage control left for SMBs.

29%

29% of SMB breaches started with an unpatched edge device

Firewall, VPN and NAS patching needs an SLA, not a calendar reminder.

Source: Verizon 2026 Data Breach Investigations Report. Dataset window Oct 2024 to Nov 2025. 31,000+ incidents and 22,000+ confirmed breaches across 145 countries.

SMB1001 and CyberCert: Common Questions

SMB1001 Gold badge
Get certified

Bronze to Diamond. Start where you are.

We have implemented SMB1001 in our own business at every tier, and now run the same engagement for clients across Australia. Start with the free gap assessment and know exactly where you stand against every level of the framework.

CyberCert Gold certified. ACSC Network Partner. No lock-in.