Skip to searchSkip to main content
  • SMB1001 certification for Australian small business

    Five levels, from Bronze to Diamond. One fixed price with the certification platform fee included. We'll tell you which level you actually need — usually it's lower than you think.

What is SMB1001?

SMB1001 is an Australian cyber security standard designed for small and medium businesses. It sets out five certification levels — Bronze, Silver, Gold, Platinum and Diamond — so a business can certify at the level its customers, insurers or contracts actually require, rather than committing to a single all-or-nothing standard.


It exists because larger organisations increasingly need proof that their suppliers are secure, and standards like ISO 27001 are out of reach for a business with twenty staff. SMB1001 gives you a recognised way to demonstrate that without a six-month project.


Certification is valid for 12 months and renewed annually.

The five SMB1001 levels

Bronze

Bronze is the entry point — the foundational hygiene any business should have regardless of who's asking. Antivirus, regular updates, backups, sensible password practice and reliable IT support. It suits a business that needs a defensible baseline before supplier onboarding or an insurance review, and it proves the fundamentals aren't being left to chance.

Silver

Silver builds on that with stronger identity and access controls — multi-factor authentication and password managers being the substantive additions. Most businesses with decent IT hygiene already in place can reach Silver without major change.

Gold

Gold is where SMB1001 starts to carry real weight, and it's the level most supply-chain and customer requirements land on. The 27 controls cover endpoint detection and response, full email authentication, cyber insurance, an incident response plan, a digital asset register and a responsible AI use policy. This is no longer a configuration exercise — it's a program across people, process and technology. Achieving Gold typically requires either a strong internal IT team or a managed cybersecurity provider running it for you.

Platinum

Platinum is the first independently audited level, adding vulnerability scanning, secure remote access and formal audits. It suits larger SMBs with mature operations, and the external audit carries noticeably more weight with enterprise procurement teams.

Diamond

Diamond is the top tier, adding encryption, zero-trust controls and real-time monitoring. It's built for businesses handling regulated data or operating as a high-value target. At larger sizes the gap from Platinum to Diamond is small, and the cost difference is modest relative to the credibility gain.

SMB1001 isn't legally mandatory for private Australian businesses, but it's increasingly requested by enterprise customers, government contractors and cyber insurers.

Which level do you actually need?

Usually lower than you think. Here's how to work it out.

Someone named a level

Then that's your level — but check what they've actually asked for. "Cyber security certification" and "SMB1001 Gold" are very different requirements, and we see businesses over-buy on a vague request more often than under-buy on a specific one. Send us the email or contract clause and we'll confirm it.

They asked for certification but didn't specify

Gold is usually the answer. It's the highest level a director can attest to without an independent audit, and it satisfies most supply-chain and customer requirements. Be realistic about the work, though — Gold's 27 controls include EDR, email authentication, cyber insurance and an incident response plan. Most businesses need either a capable internal IT team or a provider running it. If that's a stretch right now, Silver certifies quickly and you step up at renewal.

Nobody's asked yet

Start at Bronze or Silver. The levels are cumulative and designed to be climbed — certifying at Bronze now costs little, gets you a recognised credential, and means the next level is an increment rather than a project. There's no advantage to waiting until someone demands it.

Do you need Platinum or Diamond?

Probably not. These are the independently audited levels, and they're built for larger SMBs with mature operations, regulated data, or enterprise procurement teams who want third-party verification. If nobody has specifically asked for an audited level, Gold is where to stop.

Pricing & Getting Started