SMB1001 certification for Australian law firms.
Privacy Act obligations, AML/CTF Tranche 2 from 1 July 2026, Legal Professional Privilege, and enterprise legal panel onboarding all point to the same thing: documented evidence that your firm takes client data security seriously. SMB1001 Gold is how Australian law firms show it.
Why law firms need SMB1001
The obligations have arrived. SMB1001 is the documented answer.
No regulator mandates SMB1001 by name for law firms. But the obligations behind it now apply, and clients, panels, and insurers are asking for evidence. Gold gives you a single, defensible answer.
Privacy Act and client data obligations
Law firms hold sensitive client data subject to the Australian Privacy Act and the Notifiable Data Breaches scheme. SMB1001 Gold gives you documented evidence that reasonable steps are taken to protect personal information, which is what the Privacy Act now requires.
AML/CTF obligations from 1 July 2026
Tranche 2 AML/CTF reforms bring lawyers and conveyancers into the reporting regime. SMB1001 controls (named accounts, MFA, EDR, incident response) map directly to the information security obligations AML/CTF-regulated entities must meet.
Legal Professional Privilege protection
Privileged material is a target. Gold requires EDR, MFA across applications, RDP restrictions, secure device disposal, and a tested incident response plan. These controls protect privilege from credential theft, ransomware, and insider risk.
Enterprise and government client onboarding
Corporate legal panels, government legal panels, and financial institution vendor questionnaires increasingly ask for SMB1001 evidence. Gold is the tier most often specified as a threshold for legal supplier onboarding.
What we implement for a law firm
A Gold certification engagement tailored to legal practice risk. Every control mapped to your Privacy Act, AML/CTF, and privilege exposure, implemented by engineers who understand how law firms actually work.
- Gap assessment against the SMB1001 Gold control set, mapped to your Privacy Act and AML/CTF exposure
- Endpoint Detection and Response deployed across all firm devices, including partner and associate laptops
- Multi-factor authentication enforced across email, practice management, and all business applications
- Password manager rollout for every staff member, with shared vaults for matter credentials
- Email authentication hardening (SPF, DKIM, DMARC) to protect against invoice fraud and BEC
- Documented cybersecurity policy and incident response plan tailored to legal practice risk
- Secure device disposal process for retired hardware holding client data
- Digital asset register covering devices, accounts, and matter repositories
- Secure AI use policy covering Copilot, ChatGPT, and the risk of privileged material entering external AI tools
- Director attestation support through the CyberCert portal, with evidence packaged and ready
AML/CTF Tranche 2
Lawyers and conveyancers enter the AML/CTF regime from 1 July 2026.
Tranche 2 brings lawyers, conveyancers, and trust account service providers into AUSTRAC reporting. The information security obligations under AML/CTF Part B programmes require documented controls over access, logging, and incident response. SMB1001 Gold controls map directly onto those obligations, so one certification gives you evidence for both.
Read our managed IT for law firms guide
Remote Support