Australia now has a cyber security standard written for businesses with no security team. Here is what the five tiers ask for, which one you should aim at, and what changed in the 2026 edition.
If you run a small or medium business in Australia, you have probably had one of these arrive in the last year: a supplier questionnaire from a large customer, an insurance renewal form with a security section, or a tender that asks how you protect client data. And you have probably had the same reaction — you know you do some of this, but you have no idea how to prove it.
That gap is what SMB1001 exists to close.
SMB1001 is a cyber security standard designed specifically for small and medium business. It is graduated: five tiers, each one adding a short, concrete list of controls to the one below it. You certify at the tier you can actually evidence, and you climb when a customer or an insurer gives you a reason to.
The reason that structure matters is that the alternatives do not fit. ISO 27001 assumes you have a compliance function. The ACSC Essential Eight is excellent guidance, but it is a framework rather than a certification — there is nothing to hand a customer when you finish. SMB1001 gives you a certificate, and it starts at a level a ten-person business can genuinely reach.
A firewall, anti-malware on every computer, automated backups, and a technical support arrangement that is actually engaged. If you cannot say yes to those four, nothing further down this page is relevant yet.
Bronze, plus multi-factor authentication, one account per person, patching on a schedule, staff security awareness training, a written backup plan, and SPF published for your email domain.
Silver is where most real-world break-ins get stopped. The attacks that hurt Australian SMBs are overwhelmingly credential-based — someone’s password, reused, appearing in a breach dump. Multi-factor authentication is the control that makes a stolen password worthless.
This is the tier behind most supplier questionnaires and insurance forms. Gold adds endpoint detection and response, DKIM signing with an enforced DMARC policy, continuous monitoring, a documented incident response plan, access control, cyber insurance, and — new in the 2026 edition — a written policy for responsible and secure AI use.
If your DMARC record is set to
p=none, you have email authentication switched on but nothing is being rejected. Under SMB1001:2026, that is not Gold.
Gold, plus managed detection and response, regular vulnerability assessment, a mature incident response capability, and an annual independent external audit. This is the first tier where an outsider verifies your evidence, which is what larger customers usually mean when they say “audited”.
Platinum, plus real-time security analytics through a SIEM or security operations centre, continuous auditing rather than an annual snapshot, and ongoing engagement with security professionals. Built for businesses whose contracts require security to be demonstrable at any moment.
The 2026 edition was released in September 2025 and is the most significant revision since the standard launched. Three changes matter for most businesses:
That AI policy requirement is the one catching people out. A great many businesses have staff pasting client information into public AI tools right now, with no policy at all. Under the current edition, writing that policy is not optional at Gold.
For most Australian SMBs the honest answer is Gold. It is the tier that answers the questionnaires you are actually receiving, it is still self-attested so there is no audit fee, and if you have a reasonably-run Microsoft 365 environment you are probably closer to it than you think.
In our experience the gaps between “a decent setup” and Gold are usually the same three: DMARC still set to monitoring rather than enforcement, no endpoint detection and response beyond built-in antivirus, and no written incident response plan.
Bronze through Gold are self-attested. That leads some people to conclude the certificate is meaningless. It isn’t — but it is worth precisely as much as the evidence sitting behind it.
Attesting to controls you do not have is a false representation. More practically, it is the first thing an insurer will examine when you make a claim. If you attested to enforced multi-factor authentication and a third of your accounts never enrolled, that is the conversation you will be having at the worst possible moment.
So build the evidence pack. Screenshots, configuration exports, the incident response plan, the restore test record. Assemble it once, keep it current, and the attestation is defensible.
The certification fee itself is modest — Bronze starts under a hundred dollars a year. The real cost is closing whatever gaps you have, and that varies enormously depending on where you start. A business already running managed endpoint detection and enforced MFA might reach Gold in two weeks of tidying. A business with shared logins and untested backups will take longer.
Which is why the first step is a gap assessment rather than a certification order: you find out the number before you commit to it.
A gap assessment takes about a week and ends with a findings register — every control, its status, and what closing it would take.
No obligation. We will tell you if you do not need us.