SMB1001 has quietly become the certification Australian small businesses are most likely to be asked for. It is tiered, it starts at a level a ten-person business can genuinely reach, and the lower tiers are self-attested rather than audited, which is exactly why it spread.
The standard moved to a new edition. SMB1001:2026 became certifiable in January 2026, and it is not a cosmetic refresh. The Gold tier in particular picked up controls that cost real money and take real time, and if you certified under the 2025 edition you will meet them at your next renewal rather than at your leisure.
Here is what changed, and what it means depending on where you already sit.
The short version
Gold goes from 23 controls to 27. The additions are not paperwork. They are:
- Endpoint Detection and Response on every device. Continuous telemetry, behavioural detection and automated response. Traditional antivirus does not satisfy this, and neither does the free tier of most products.
- Full email authentication. SPF, DKIM and DMARC, with DMARC set to quarantine or reject.
- A current cyber insurance policy. Mandatory at Gold, which is unusual for a security standard and worth pausing on.
- An AI governance policy. Written rules covering data governance, risk and security for AI use in the business.
- Extended confidentiality agreements. Now reaching contractors and third parties, not just employees.
- Invoice fraud controls. Prescriptive requirements including dual verification and dual sign-off.
Several existing controls also tightened. Password management now expects a centrally managed solution with MFA and auditing rather than any password manager. Remote Desktop Protocol needs a business-grade VPN or an application proxy in front of it. Awareness training moved to ongoing campaigns with annual review, and server patching moved down from Gold to Silver, which means some businesses at Silver picked up a requirement they did not have before.
The one that catches people: DMARC
Most businesses we assess already have SPF. A good number have DKIM. Almost none have DMARC set to anything other than p=none, which is monitoring mode and provides no protection at all. It reports on abuse of your domain and blocks precisely nothing.
SMB1001:2026 requires quarantine or reject. That is a meaningful piece of work, not a setting change. Moving to enforcement without first identifying every legitimate system that sends email as your domain, meaning your accounting package, your CRM, your marketing platform, your booking system, is how businesses accidentally stop their own invoices reaching customers.
The sequence that works is: publish DMARC at p=none, collect reports for several weeks, fix the legitimate senders that are failing, then tighten to quarantine, then to reject. Done properly it is a month or two of elapsed time and very little disruption. Done in an afternoon because an auditor is coming, it is a bad week.
The one that is genuinely new thinking: mandatory cyber insurance
Requiring businesses to hold a cyber insurance policy is an unusual move for a security standard, and it produces a neat circularity worth understanding. Insurers have spent the last few years tightening what they expect before they will quote: MFA, EDR, offline backups, email authentication, an incident response plan. Gold now requires nearly all of the same controls, plus the policy itself.
In practice that means the work you do for Gold is largely the work that gets you a better premium, and the policy you buy for Gold is easier to obtain because you did the work. If you are weighing up the cost of certification, that overlap is the part to count. We wrote about what underwriters actually ask for in cyber insurance in Adelaide.
What to do, depending on where you are
If you are already certified under SMB1001:2025
Nothing breaks today, but your renewal will be assessed against the current edition. Work out your renewal date, then work backwards. EDR deployment and DMARC enforcement are the two items with real lead time. The AI policy and the confidentiality agreement changes are document work that can be done in a fortnight. Do not leave DMARC until last because it is the one that cannot be rushed safely.
If you are certifying for the first time
Certify against the 2026 edition directly rather than chasing the old one. Start at the tier your obligations actually require. A great many businesses being asked for certification by a customer or an insurer need Bronze or Silver, not Gold, and Gold at the 2026 edition is a genuine programme of work rather than a weekend of form-filling. Bronze also picked up awareness training in this edition, which moved down from a higher tier.
If you are already at Essential Eight Maturity Level 2
You have done most of Gold without calling it that. The gaps are usually the email authentication piece, the insurance policy, and the AI governance document, because none of those are Essential Eight concerns. If you are choosing between the two frameworks rather than stacking them, Essential Eight versus ISO 27001 covers the wider decision.
The AI policy is not a formality
The new AI governance control asks for written rules on acceptable and secure AI use, aimed at data leakage, intellectual property loss and privacy breaches. It is tempting to treat this as a template to download and file.
The reason not to is that the risk it addresses is already live in most businesses. Staff are pasting client data into consumer AI tools right now, at businesses whose leadership would say confidently that they do not use AI. A policy that nobody has read does not change that, but the exercise of writing one usually surfaces what is actually happening, which is the useful part.
Gold at the 2026 edition is a programme, not a form.
EDR on every device and DMARC at enforcement are the two controls with real cost and real lead time. If your renewal is inside six months, those are the two to start now. Everything else in the update can be done in weeks.
We take businesses through SMB1001 from first assessment to certification, and we hold ISO 27001 ourselves, so we are not recommending a process we have not been through. See SMB1001 certification, try the self-assessment to see roughly where you sit, or book a 30-minute call.
