Information Security · SMB1001:2025 · Small Business Certification

Cyber security certification built for your size of business.

SMB1001 is the Australian cyber security standard designed specifically for businesses under 200 staff. We guide you through gap analysis, remediation and certification, with a clear outcome you can show clients, insurers and procurement teams.

The right framework for the right-sized business

Achievable controls. A real certificate.
Not just good intentions.

Most security frameworks available to small businesses are either too shallow to mean anything or too demanding to be realistic. SMB1001 sits in the middle. Developed by Dynamic Standards International for businesses without a dedicated security function, it gives you a structured, certifiable path to improving your security posture at a pace that works for a business your size. The controls are practical, the certification is recognised, and annual renewal means it reflects where you actually stand.

Standard by
Dynamic Standards International
Back to Cyber Security →
SMB1001:2025

Five control areas, structured, practical, certifiable.

SMB1001 organises its controls into five coverage areas. Every engagement addresses all five. We assess where you currently stand across each area, close the gaps, and build the evidence that supports your certification.

Control areas covered in every SMB1001 engagement
  • Technology Management: Devices, software and systems kept current and securely configured
  • Access Management: MFA enforcement, privilege reviews and access control
  • Backup & Recovery: Tested, ransomware-resilient backups that restore your business
  • Policies & Processes: Security policies, incident response and supplier requirements
  • Education & Training: Building genuine security habits across your team

A certificate you can actually use

SMB1001 certification gives you a shareable certificate and digital badge, something concrete to show clients during procurement, insurers during policy renewal, and partners who ask about your security posture. It's not a framework on a shelf. It's evidence.

We keep your compliance documentation proportionate, enough to satisfy the standard and hold up under review, without creating paperwork that nobody reads or maintains.

We don't disappear after you earn your certificate. Ongoing support covers control monitoring, annual renewal preparation, and progression planning toward higher tiers.

SMB1001 aligns with the UK's Cyber Essentials scheme and ISO 27001:2022 control domains, so progressing to higher frameworks later doesn't mean starting from scratch. We build controls that work across standards.

Certification tiers

Start at Bronze. Progress at your own pace.

SMB1001 uses a five-tier model: Bronze through Diamond. Most Adelaide businesses start with Bronze or Silver, achieve a real certification outcome quickly, and build from there. You don't have to reach Diamond to demonstrate a credible security posture.

Bronze tier
Bronze

The right starting point

Self-assessed. Covers foundational controls: MFA, patching, backups, access controls, security awareness. Most businesses can reach Bronze certification in 8–12 weeks. The most common entry point, and a real, certifiable outcome from day one.

Silver tier
Silver

Deeper controls, reviewed

Builds on Bronze with additional technical and procedural controls, moving toward independent review. The right target for businesses that have established their baseline and want to demonstrate a more mature programme to clients and insurers.

Gold tier
Gold & beyond

Third-party assessed

Gold requires third-party assessment. Platinum and Diamond add higher assurance requirements and independent certification. For businesses in sensitive supply chains or with significant security obligations, demonstrating a genuinely mature programme.

Gradual progression

Unlike the Essential Eight's uniform maturity requirements, where every control must reach the same level before moving up, SMB1001 lets you progress tier by tier. Each certification is a complete, usable outcome. You're not waiting until everything is done before you can demonstrate anything.

InterIntra security team

“Most Adelaide businesses have more controls in place than they realise. The gap is usually documentation and evidence, not the technology itself.”

InterIntra
Cyber Security Practice · Adelaide
How we work

Four stages from gap analysis to certification day.

Every SMB1001 engagement follows the same structured path. You always know where you are and what comes next.

Gap analysis
Stage 01

Gap analysis

We assess your current controls across all five SMB1001 areas and produce a prioritised gap report. You know exactly where you stand, and what your realistic path to certification looks like, before any remediation work begins.

Remediation plan
Stage 02

Remediation

We work alongside your team to implement controls, document policies and processes, configure technical settings, and build the evidence library that supports your certification. We do as much or as little of the hands-on work as you need.

Certification
Stage 03

Certification

We prepare your self-assessment (Bronze) or coordinate independent review (Silver and above), ensuring your evidence package is complete and accurate. You receive your certificate and digital badge, ready to share with clients, insurers and partners.

Annual renewal
Stage 04

Annual renewal

SMB1001 certification renews annually, keeping it meaningful and current. We manage the renewal cycle as part of our ongoing programme, so reassessment doesn't sneak up on you and your certification never lapses without warning.

Frequently Asked Questions

Got questions? We have answers.

From the Blog

Related insights.

From the Blog
What Is SMB1001? The Cyber Security Standard Built for Australian Small Business

SMB1001 gives Australian small businesses a practical, tiered path to improving their security posture, without the complexity of the Essential Eight. Cameron Weymouth explains how it works.

Cameron Weymouth · 8 May 2026
Read the article →
Related Service
ACSC Essential Eight

For businesses in government supply chains or regulated sectors, the Essential Eight is the Australian standard that applies. We run maturity level assessments from ML1 baselines through to ML2 and ML3 targets.

Assessment · Remediation · Evidence
Learn more →
Get Started

Ready to turn your security posture into something certifiable?

Book a free 30-minute discovery call. We'll run through where you currently sit against SMB1001 controls and what your path to Bronze looks like, no obligation, no pressure.

Book a Discovery Call
Trusted Partners & Certifications