SMB1001 is the Australian cyber security standard designed specifically for businesses under 200 staff. We guide you through gap analysis, remediation and certification, with a clear outcome you can show clients, insurers and procurement teams.
Most security frameworks available to small businesses are either too shallow to mean anything or too demanding to be realistic. SMB1001 sits in the middle. Developed by Dynamic Standards International for businesses without a dedicated security function, it gives you a structured, certifiable path to improving your security posture at a pace that works for a business your size. The controls are practical, the certification is recognised, and annual renewal means it reflects where you actually stand.
SMB1001 organises its controls into five coverage areas. Every engagement addresses all five. We assess where you currently stand across each area, close the gaps, and build the evidence that supports your certification.
SMB1001 certification gives you a shareable certificate and digital badge, something concrete to show clients during procurement, insurers during policy renewal, and partners who ask about your security posture. It's not a framework on a shelf. It's evidence.
We keep your compliance documentation proportionate, enough to satisfy the standard and hold up under review, without creating paperwork that nobody reads or maintains.
We don't disappear after you earn your certificate. Ongoing support covers control monitoring, annual renewal preparation, and progression planning toward higher tiers.
SMB1001 aligns with the UK's Cyber Essentials scheme and ISO 27001:2022 control domains, so progressing to higher frameworks later doesn't mean starting from scratch. We build controls that work across standards.
SMB1001 uses a five-tier model: Bronze through Diamond. Most Adelaide businesses start with Bronze or Silver, achieve a real certification outcome quickly, and build from there. You don't have to reach Diamond to demonstrate a credible security posture.
Self-assessed. Covers foundational controls: MFA, patching, backups, access controls, security awareness. Most businesses can reach Bronze certification in 8–12 weeks. The most common entry point, and a real, certifiable outcome from day one.
Builds on Bronze with additional technical and procedural controls, moving toward independent review. The right target for businesses that have established their baseline and want to demonstrate a more mature programme to clients and insurers.
Gold requires third-party assessment. Platinum and Diamond add higher assurance requirements and independent certification. For businesses in sensitive supply chains or with significant security obligations, demonstrating a genuinely mature programme.
Unlike the Essential Eight's uniform maturity requirements, where every control must reach the same level before moving up, SMB1001 lets you progress tier by tier. Each certification is a complete, usable outcome. You're not waiting until everything is done before you can demonstrate anything.
“Most Adelaide businesses have more controls in place than they realise. The gap is usually documentation and evidence, not the technology itself.”
Every SMB1001 engagement follows the same structured path. You always know where you are and what comes next.
We assess your current controls across all five SMB1001 areas and produce a prioritised gap report. You know exactly where you stand, and what your realistic path to certification looks like, before any remediation work begins.
We work alongside your team to implement controls, document policies and processes, configure technical settings, and build the evidence library that supports your certification. We do as much or as little of the hands-on work as you need.
We prepare your self-assessment (Bronze) or coordinate independent review (Silver and above), ensuring your evidence package is complete and accurate. You receive your certificate and digital badge, ready to share with clients, insurers and partners.
SMB1001 certification renews annually, keeping it meaningful and current. We manage the renewal cycle as part of our ongoing programme, so reassessment doesn't sneak up on you and your certification never lapses without warning.
SMB1001 is an Australian cyber security standard developed by Dynamic Standards International (DSI) for businesses under 200 staff that don't have a dedicated security function. It uses a five-tier certification model, Bronze, Silver, Gold, Platinum, and Diamond, designed to be achievable at each level without enterprise-scale resources. SMB1001:2025 is the current version of the standard.
Typically 8–12 weeks from initial gap analysis to certification-ready, depending on how many controls are already in place. Bronze is self-assessed, so you don't need to wait for an external assessor. Businesses that already have basic security hygiene, regular backups, some form of MFA, documented processes, will move through the remediation phase faster. The timeline is wide because starting points vary significantly; the gap analysis tells you where you realistically sit.
SMB1001 was designed for businesses under 200 staff without a dedicated security function. It's intentionally more accessible than the Essential Eight for that environment. The Essential Eight is better suited to organisations in government supply chains, financial services, or larger enterprise contexts where the ACSC's maturity model is the expected standard. Both frameworks cover many of the same fundamental controls; the difference is in the depth and complexity of implementation required at each level. If you're unsure which is right for your business, that's the first conversation we have.
Bronze, Silver and Gold are self-assessed. You document your controls, complete the assessment questionnaire, and declare your certification level. Platinum and Diamond require independent third-party assessment, where an accredited assessor verifies your controls and evidence before certification is issued. Most businesses targeting their first SMB1001 certification start at Bronze and work toward Gold before considering higher tiers. We guide you through the self-assessment process for the lower tiers and coordinate independent assessment when you're ready to progress.
Yes. SMB1001 certification requires annual renewal to remain current. This keeps your certification meaningful. It reflects your actual security posture, not where you were twelve months ago. The renewal process involves reassessing your controls against the standard and updating your evidence. We manage this as part of our ongoing cyber security programme so it doesn't sneak up on you.
SMB1001:2025 is designed for small and medium-sized businesses that lack a dedicated security function but still need a credible, certifiable security programme. If your business handles customer data, uses cloud services, or needs to demonstrate security credentials to clients or insurers, SMB1001 is the most practical starting point available to Australian businesses under 200 staff.
SMB1001:2025 covers both technical measures and organisational practices. On the technical side: multi-factor authentication, patch management, secure backups, network segmentation, and access controls. On the organisational side: cybersecurity policies, staff security awareness, incident response planning, and vendor management. The mix of technical versus organisational requirements increases in depth as you progress through the Bronze to Gold tiers.
SMB1001:2025 recognises that not all controls may be relevant or feasible for every small business. Organisations are encouraged to prioritise controls based on their specific context and risk profile. The gap analysis we run in Phase 1 maps exactly where you stand and sequences remediation so you're working on the highest-impact items first, not trying to achieve everything at once. We've helped businesses start from very low baselines and work methodically to certification.
Beyond the direct security improvements, certification delivers tangible business benefits: competitive advantage when tendering for contracts where security credentials are assessed, improved positioning for cyber insurance renewal, and demonstrated commitment to clients and stakeholders. Certification also builds an evidenced security foundation that makes progression to more demanding frameworks, such as the ACSC Essential Eight or ISO 27001, significantly faster, since much of the documentation and control work carries over.
SMB1001 gives Australian small businesses a practical, tiered path to improving their security posture, without the complexity of the Essential Eight. Cameron Weymouth explains how it works.
Read the article →For businesses in government supply chains or regulated sectors, the Essential Eight is the Australian standard that applies. We run maturity level assessments from ML1 baselines through to ML2 and ML3 targets.
Learn more →Book a free 30-minute discovery call. We'll run through where you currently sit against SMB1001 controls and what your path to Bronze looks like, no obligation, no pressure.