SMB1001:2026 · Level 3SMB1001 Gold certification for Australian businesses.
Level 3 of the SMB1001:2026 standard. 27 controls, Director-attestable, and the tier enterprise vendor panels, government tenders, and cyber insurers most often ask for. Real Bytes holds CyberCert Gold and runs the full certification engagement.
The short answer
SMB1001 Gold is the certification level most Australian businesses actually need.
Silver gets you cyber-insurable. Gold gets you through procurement. Gold (Level 3) introduces Endpoint Detection and Response, application-wide MFA, a tested incident response plan, formal cybersecurity policy, a digital asset register, and secure AI use policy. It is Director-attestable, so no external audit fee applies, and it carries real weight in vendor onboarding, government tenders, and insurance underwriting.
Cost
A$395/yr
CyberCert subscription, plus tax if applicable. Labour to meet controls is separate.
Timeline
3 to 6 months
Typical with Real Bytes support. Shorter if you already run MFA and EDR.
Attestation
Director-attestable
No external audit. External audits begin at Platinum.
Why Gold, not Silver or Platinum
The tier enterprise vendor panels and government tenders ask for
Gold (Level 3) is the level most often specified as a threshold in enterprise vendor onboarding questionnaires and government supplier panels. It is the point where certification moves from differentiator to entry requirement for compliance-heavy supply chains.
Structured evidence for cyber insurance underwriters
Gold gives underwriters a documented, predictable answer to their questionnaire: EDR in place, MFA across applications, a tested incident response plan, and a formal cybersecurity policy. It can move a declined risk to insurable and often reduces excess.
Real technical maturity, not a paperwork exercise
Gold introduces EDR, application-wide MFA, RDP restrictions, device disposal standards, a digital asset register, and a tested incident response plan. The controls survive the audit and keep protecting the business afterwards.
Director-attestable, no external audit required
Gold is Director-attestable. A Director or Owner signs an Attestation Letter through the CyberCert portal declaring conformity with the 27 controls. No external audit fee applies at this tier (those begin at Platinum).
What Gold requires
The 27 controls at Gold (Level 3)
Gold builds on the 17 Silver controls. The list below shows the additional controls introduced at Gold, plus the Silver baseline you must maintain. We implement every one of these as part of the certification engagement.
- Endpoint Detection and Response (EDR) deployed across all endpoints
- Multi-factor authentication on all business applications and social media
- RDP only permitted over VPN connections
- Cyber or business insurance in place
- Documented cybersecurity policy maintained
- Incident response plan for cyber-related incidents
- Secure physical document destruction
- Secure disposal of devices storing sensitive data
- Digital asset register maintained
- Responsible and secure AI use policy in place
- All Silver controls maintained (MFA on email, password manager, SPF, named accounts, invoice fraud policy and more)
Full control lists are published in the SMB1001:2026 standard. We confirm the exact control set against the current edition in your gap assessment.
How we run a Gold certification
Free gap assessment
We baseline your current controls against the 27 Gold controls. You see exactly which you already meet, which are partial, and which are missing. No cost, no commitment.
Fixed-scope proposal
We produce a plain-English implementation roadmap with a fixed price. You know the cost, sequence, and timeline before any work begins. No scope creep.
Control implementation
Our engineers deploy EDR, enforce application MFA, lock down RDP, build the asset register, draft the cybersecurity and incident response policies, and stand up the secure AI use policy.
Attestation support
We walk your Director through the CyberCert portal Attestation Letter and evidence each control. Gold is Director-attestable, so no external audit is required.
Ongoing compliance
Certification is annual. We maintain the controls, review your posture as the standard updates each year, and keep you ready for re-certification without it becoming a distraction.

Remote Support