SMB1001 Gold badgeSMB1001:2026 · Level 3

SMB1001 Gold certification for Australian businesses.

Level 3 of the SMB1001:2026 standard. 27 controls, Director-attestable, and the tier enterprise vendor panels, government tenders, and cyber insurers most often ask for. Real Bytes holds CyberCert Gold and runs the full certification engagement.

CyberCert Gold MSSP
27 controls
Director-attestable
No lock-in

The short answer

SMB1001 Gold is the certification level most Australian businesses actually need.

Silver gets you cyber-insurable. Gold gets you through procurement. Gold (Level 3) introduces Endpoint Detection and Response, application-wide MFA, a tested incident response plan, formal cybersecurity policy, a digital asset register, and secure AI use policy. It is Director-attestable, so no external audit fee applies, and it carries real weight in vendor onboarding, government tenders, and insurance underwriting.

Cost

A$395/yr

CyberCert subscription, plus tax if applicable. Labour to meet controls is separate.

Timeline

3 to 6 months

Typical with Real Bytes support. Shorter if you already run MFA and EDR.

Attestation

Director-attestable

No external audit. External audits begin at Platinum.

Why Gold, not Silver or Platinum

The tier enterprise vendor panels and government tenders ask for

Gold (Level 3) is the level most often specified as a threshold in enterprise vendor onboarding questionnaires and government supplier panels. It is the point where certification moves from differentiator to entry requirement for compliance-heavy supply chains.

Structured evidence for cyber insurance underwriters

Gold gives underwriters a documented, predictable answer to their questionnaire: EDR in place, MFA across applications, a tested incident response plan, and a formal cybersecurity policy. It can move a declined risk to insurable and often reduces excess.

Real technical maturity, not a paperwork exercise

Gold introduces EDR, application-wide MFA, RDP restrictions, device disposal standards, a digital asset register, and a tested incident response plan. The controls survive the audit and keep protecting the business afterwards.

Director-attestable, no external audit required

Gold is Director-attestable. A Director or Owner signs an Attestation Letter through the CyberCert portal declaring conformity with the 27 controls. No external audit fee applies at this tier (those begin at Platinum).

What Gold requires

The 27 controls at Gold (Level 3)

Gold builds on the 17 Silver controls. The list below shows the additional controls introduced at Gold, plus the Silver baseline you must maintain. We implement every one of these as part of the certification engagement.

  • Endpoint Detection and Response (EDR) deployed across all endpoints
  • Multi-factor authentication on all business applications and social media
  • RDP only permitted over VPN connections
  • Cyber or business insurance in place
  • Documented cybersecurity policy maintained
  • Incident response plan for cyber-related incidents
  • Secure physical document destruction
  • Secure disposal of devices storing sensitive data
  • Digital asset register maintained
  • Responsible and secure AI use policy in place
  • All Silver controls maintained (MFA on email, password manager, SPF, named accounts, invoice fraud policy and more)

Full control lists are published in the SMB1001:2026 standard. We confirm the exact control set against the current edition in your gap assessment.

How we run a Gold certification

01

Free gap assessment

We baseline your current controls against the 27 Gold controls. You see exactly which you already meet, which are partial, and which are missing. No cost, no commitment.

02

Fixed-scope proposal

We produce a plain-English implementation roadmap with a fixed price. You know the cost, sequence, and timeline before any work begins. No scope creep.

03

Control implementation

Our engineers deploy EDR, enforce application MFA, lock down RDP, build the asset register, draft the cybersecurity and incident response policies, and stand up the secure AI use policy.

04

Attestation support

We walk your Director through the CyberCert portal Attestation Letter and evidence each control. Gold is Director-attestable, so no external audit is required.

05

Ongoing compliance

Certification is annual. We maintain the controls, review your posture as the standard updates each year, and keep you ready for re-certification without it becoming a distraction.

SMB1001 Gold: common questions

SMB1001 Gold badge

Start with a free gap assessment.

See exactly where you sit against the 27 Gold controls right now, what is missing, and what a realistic path to Gold certification looks like. No cost, no commitment.

CyberCert Gold MSSP. Brisbane-based engineers. No lock-in.