"What does SMB1001 certification cost, and how long will it take?" is usually the second question a business asks about the standard, right after "which level do we need?". This post answers it across all five levels, from Bronze to Diamond. If you already know Gold is your target and want the deep dive on that tier specifically, we have covered it in SMB1001 Gold: What It Costs and How to Get Certified. This one is the whole-of-standard view.
Mino IT holds SMB1001 Gold ourselves and manages certification for clients, so the numbers of weeks and the cost drivers below come from running the process, not from the brochure.
The three costs, at every level
Whatever level you certify at, the money goes to the same three places. What changes between levels is the size of each bucket.
- The certification fee. Paid to the certifier (CyberCert in Australia) and renewed annually. DSI, the standard's publisher, sets a maximum certification price for each level, so this fee is capped and published rather than quoted. Current pricing is listed at cybercert.ai. At every level this is the smallest of the three costs.
- Implementing the controls. This is the real investment, and it scales with the level: Bronze asks for 7 controls, Silver 17, Gold 27, Platinum 32, and Diamond 39. The higher levels do not just add controls, they upgrade earlier ones, so each level is a genuine superset of the one below.
- Verification, at the top two levels only. Bronze, Silver, and Gold are self-assessed and attested by a company director, so there is no auditor to pay. Platinum and Diamond require independent third-party verification, and Diamond adds penetration, vulnerability, and social engineering testing. That is a step change in both cost and effort, which is why the jump from Gold to Platinum is the biggest one in the standard.
What drives your implementation cost
Two businesses certifying at the same level can face very different bills, and the difference comes down to three factors:
- Your starting point. A business already on a managed IT service usually has the technical controls, patching, MFA, backups, and endpoint protection, largely in place. What is left is the people and process work: training, plans, registers, and documentation. A business with ad-hoc IT is buying tooling as well as time.
- Your headcount. Several controls scale with staff: awareness training, password manager licensing, and MFA rollout are per-person exercises. A 15-person business and a 100-person business do the same controls at very different sizes.
- The level you target. Bronze and Silver are mostly technical hygiene. Gold is where policies, incident response plans, asset registers, cyber insurance, and formal training enter. Platinum extends MFA across VPN, remote desktop, and data stores and adds vulnerability scanning. Diamond adds the testing regime.
How long each level takes
Timelines depend on the same starting-point question, but as a working guide from the certifications we run:
- Bronze: days to a couple of weeks. The 7 controls are foundational, and a small business with any managed IT in place may only need the attestation paperwork.
- Silver: two to four weeks. The additions, MFA on email, a password manager, email anti-spoofing, and staff training, are quick technically but the training takes calendar time.
- Gold: four to eight weeks with an IT partner and a reasonable starting point; allow up to three months from a standing start. The long poles are people and process: training completion, an incident response plan staff have actually read, and the documentation.
- Platinum and Diamond: months, not weeks. The controls themselves take longer, and scheduling independent verification (and for Diamond, penetration testing) adds external lead time you do not control.
One timeline note that surprises people: certification is valid for one year at every level, and DSI updates the standard annually. Renewal is far faster than first certification if the evidence was documented properly the first time, and painful if it was not.
Which level should you be costing?
Do not pick a level by price. The level that matters is the one your customers expect, and DSI publishes a Supplier Categorization Matrix that maps it: what information customers trust you with, what access you hold to their systems, and how quickly they need you back if you go down. A bookkeeping firm holding client financials and a florist delivering to reception sit at very different levels, whatever their budgets say. We walk through each level's profile in SMB1001 Levels Explained.
Certifying below what your customers expect saves little and usually means doing the process twice. Certifying above it buys rigour nobody asked for. For most Brisbane SMBs handling client data, the answer lands on Gold, which is why it is the tier insurers and tender panels increasingly treat as the baseline.
How to keep the cost down
- Start with a gap assessment, not a quote. The only honest cost number comes from knowing which controls you already have. Our free readiness check gives you a first pass in a few minutes: which level you need, and which controls you are missing for it.
- Lean on your managed service. If you pay for managed IT, a good share of the technical controls should already be covered by the service. Ask your provider to map what you are paying for against the level you are targeting before you buy anything new.
- Do the paperwork once, properly. Evidence and documentation are where self-managed certifications bleed time. Documented well, next year's renewal is an afternoon instead of a project.
The bottom line
The certification fee is capped and modest at every level. The real cost is closing the gap between your current controls and the level your customers expect, and that number is knowable before you spend anything. Start with the readiness check, read about our SMB1001 certification service, or book a discovery call and we will map your gap properly.