Business Connected — IT & CommunicationsBook an assessment
Home  /  Knowledge centre  /  Compliance
Compliance · 12 August 2026 · 8 min read

SMB1001 explained, for people who don’t work in IT

Australia now has a cyber security standard written for businesses with no security team. Here is what the five tiers ask for, which one you should aim at, and what changed in the 2026 edition.

If you run a small or medium business in Australia, you have probably had one of these arrive in the last year: a supplier questionnaire from a large customer, an insurance renewal form with a security section, or a tender that asks how you protect client data. And you have probably had the same reaction — you know you do some of this, but you have no idea how to prove it.

That gap is what SMB1001 exists to close.

What it is

SMB1001 is a cyber security standard designed specifically for small and medium business. It is graduated: five tiers, each one adding a short, concrete list of controls to the one below it. You certify at the tier you can actually evidence, and you climb when a customer or an insurer gives you a reason to.

The reason that structure matters is that the alternatives do not fit. ISO 27001 assumes you have a compliance function. The ACSC Essential Eight is excellent guidance, but it is a framework rather than a certification — there is nothing to hand a customer when you finish. SMB1001 gives you a certificate, and it starts at a level a ten-person business can genuinely reach.

The five tiers, in plain terms

Bronze — the floor

A firewall, anti-malware on every computer, automated backups, and a technical support arrangement that is actually engaged. If you cannot say yes to those four, nothing further down this page is relevant yet.

Silver — identity

Bronze, plus multi-factor authentication, one account per person, patching on a schedule, staff security awareness training, a written backup plan, and SPF published for your email domain.

Silver is where most real-world break-ins get stopped. The attacks that hurt Australian SMBs are overwhelmingly credential-based — someone’s password, reused, appearing in a breach dump. Multi-factor authentication is the control that makes a stolen password worthless.

Gold — what people are actually asking for

This is the tier behind most supplier questionnaires and insurance forms. Gold adds endpoint detection and response, DKIM signing with an enforced DMARC policy, continuous monitoring, a documented incident response plan, access control, cyber insurance, and — new in the 2026 edition — a written policy for responsible and secure AI use.

If your DMARC record is set to p=none, you have email authentication switched on but nothing is being rejected. Under SMB1001:2026, that is not Gold.

Platinum — someone else checks

Gold, plus managed detection and response, regular vulnerability assessment, a mature incident response capability, and an annual independent external audit. This is the first tier where an outsider verifies your evidence, which is what larger customers usually mean when they say “audited”.

Diamond — continuous assurance

Platinum, plus real-time security analytics through a SIEM or security operations centre, continuous auditing rather than an annual snapshot, and ongoing engagement with security professionals. Built for businesses whose contracts require security to be demonstrable at any moment.

What changed in SMB1001:2026

The 2026 edition was released in September 2025 and is the most significant revision since the standard launched. Three changes matter for most businesses:

  • Email authentication got stricter. SPF is required from Silver. DKIM signing and an enforced DMARC policy — quarantine or reject, not monitoring-only — are required from Gold.
  • Gold expanded from 23 controls to 27. The additions include endpoint detection and response, full email authentication, cyber insurance, and a written policy for the responsible and secure use of AI.
  • It now maps to other frameworks. SMB1001:2026 publishes mappings to the Essential Eight, UK Cyber Essentials, US CMMC and ISO 27001 — so if you are asked about a different framework, you can show your work translates.

That AI policy requirement is the one catching people out. A great many businesses have staff pasting client information into public AI tools right now, with no policy at all. Under the current edition, writing that policy is not optional at Gold.

Which tier should you aim at?

For most Australian SMBs the honest answer is Gold. It is the tier that answers the questionnaires you are actually receiving, it is still self-attested so there is no audit fee, and if you have a reasonably-run Microsoft 365 environment you are probably closer to it than you think.

In our experience the gaps between “a decent setup” and Gold are usually the same three: DMARC still set to monitoring rather than enforcement, no endpoint detection and response beyond built-in antivirus, and no written incident response plan.

A word about self-attestation

Bronze through Gold are self-attested. That leads some people to conclude the certificate is meaningless. It isn’t — but it is worth precisely as much as the evidence sitting behind it.

Attesting to controls you do not have is a false representation. More practically, it is the first thing an insurer will examine when you make a claim. If you attested to enforced multi-factor authentication and a third of your accounts never enrolled, that is the conversation you will be having at the worst possible moment.

So build the evidence pack. Screenshots, configuration exports, the incident response plan, the restore test record. Assemble it once, keep it current, and the attestation is defensible.

What it costs

The certification fee itself is modest — Bronze starts under a hundred dollars a year. The real cost is closing whatever gaps you have, and that varies enormously depending on where you start. A business already running managed endpoint detection and enforced MFA might reach Gold in two weeks of tidying. A business with shared logins and untested backups will take longer.

Which is why the first step is a gap assessment rather than a certification order: you find out the number before you commit to it.

Want to know which tier you could evidence today?

A gap assessment takes about a week and ends with a findings register — every control, its status, and what closing it would take.

No obligation. We will tell you if you do not need us.