SMB1001 is the Australian standard written for businesses that do not have a security team. Five tiers, each a short list of controls you either have or you don’t. We assess where you sit, close the gaps, and take you through certification.
ISO 27001 assumes a compliance function. The Essential Eight is a framework, not a certification — there is nothing to hand a customer at the end of it. SMB1001 fills the gap: a graduated, certifiable standard that starts at a level a ten-person business can genuinely reach, and climbs to independent annual audit if your contracts require it.
The current edition is SMB1001:2026, released in September 2025. It tightened email authentication, expanded the Gold control set to twenty-seven, and added a requirement most businesses have not thought about yet: a written policy for responsible and secure AI use. It also publishes mappings to the Essential Eight, UK Cyber Essentials, US CMMC and ISO 27001 — so the work counts more than once.
Bronze through Gold are self-attested — you declare compliance and hold the evidence. Platinum and Diamond require an independent auditor.
Which entity is certifying, and to which tier. Usually driven by a customer questionnaire, an insurer, or a tender you want to be eligible for. Most businesses should aim at Gold.
We test each control against what is actually configured — not what the policy says. You get a findings register with every gap, its effort, and its cost.
We close the technical gaps and write the documents the standard asks for: backup plan, incident response plan, access control policy, AI use policy.
Screenshots, exports and configuration records assembled into a single pack, so the attestation is defensible if anyone ever asks.
Attestation lodged and certificate issued. For Platinum and Diamond we prepare you for the independent audit and sit in it with you.
Certification is annual and controls drift. Managed clients get it monitored as part of the ordinary reporting.
No. You certify at the tier you can evidence. Most businesses with a decent Microsoft 365 setup are closer to Gold than they expect — usually missing DMARC enforcement, EDR, or a written incident response plan.
They overlap heavily. SMB1001:2026 publishes a mapping. If you have done Essential Eight uplift, most of the Gold control set is already met — you just need the evidence assembled and attested.
It is worth exactly as much as the evidence behind it. Attesting to controls you do not have is a false representation, and it is the first thing an insurer will examine at claim time. We build the evidence pack for that reason.
The certification fee is paid to the certifying body and starts under a hundred dollars a year at Bronze. The real cost is closing the gaps. Our assessment tells you that number before you commit to anything.
A gap assessment takes about a week and ends with a findings register: every control, its status, and what it would take to close. No certification commitment required.
No obligation. We will tell you if you do not need us.