Skip to main content
Mino IT
SMB1001

SMB1001 Gold: What It Costs and How to Get Certified

SMB1001 Gold covers 27 controls and most businesses certify in four to eight weeks. Here is what certification costs, what the controls cover, and the exact pathway, from a provider that holds Gold itself.

Mino IT TeamManaged IT Specialists7 min read

SMB1001 Gold is the certification tier most Australian small and medium businesses aim for, and the two questions we hear most often are the same two this post answers: what does it cost, and how do you get certified. The short version: the certification fee itself is modest, the real investment is implementing the 27 controls Gold requires, and with an IT partner managing the process most businesses get there in four to eight weeks.

Mino IT holds SMB1001 Gold certification ourselves, and we manage the certification pathway for clients. Everything below comes from having done it, not from reading the brochure.

What is SMB1001 Gold?

SMB1001 is a cybersecurity certification standard published by Dynamic Standards International (DSI) and certified in Australia through CyberCert. It has five tiers: Bronze, Silver, Gold, Platinum, and Diamond. Each tier adds controls and rigour on top of the one below it.

Gold sits at tier three. It covers 27 controls across technology, process, and people, and it is the tier that insurers, larger customers, and tender panels increasingly treat as the credible baseline for a small or medium business. We have covered the standard itself in detail in What is SMB1001 Certification?, so this post stays focused on cost and the path to getting certified.

How do the SMB1001 tiers compare?

Understanding where Gold sits helps explain the cost, because each tier is a superset of the one below it.

  • Bronze (tier 1) is the entry point: a small set of foundational controls a very small business can implement in days. It signals intent more than maturity.
  • Silver (tier 2) adds more technical controls and is a reasonable target for a micro business with no dedicated IT support.
  • Gold (tier 3) is where the standard starts covering people and process as well as technology: staff training, an incident response plan, and the documentation that proves controls are managed. This is why Gold is the tier insurers and tender panels take seriously, and why it is the tier we recommend for any business with staff and customer data.
  • Platinum and Diamond (tiers 4 and 5) add further rigour and verification requirements. For most SMBs they are a later decision, driven by a specific contract or regulatory requirement rather than general good practice.

The practical takeaway: certifying at Bronze or Silver when your customers and insurer care about Gold saves little and usually means doing the process twice. Most businesses we work with go straight to Gold.

What does SMB1001 Gold certification cost?

There are three cost components, and they are very different sizes.

  1. The certification fee. This is paid to CyberCert when you certify, and it renews annually. It is the smallest of the three costs.
  2. Implementing the 27 controls. This is where the real money and effort go, and it varies enormously depending on where you start. A business that already has multi-factor authentication, managed backups, and endpoint protection in place may only need process and documentation work. A business starting from scratch is buying tooling as well: a password manager, backup coverage, security software across every device, and staff training. For most businesses in the 15 to 150 staff range the gap is somewhere in the middle.
  3. Someone to run the process. You can self-manage the certification, and some businesses do. Most use their IT provider because the provider already controls half the evidence the standard asks for: patching, backups, access management, and endpoint security. If your provider runs a managed service, a good portion of the Gold controls should already be covered by the service you pay for today.

The honest answer on total cost is that it depends on your gap. That is not a dodge. It is why the right first step is a gap assessment rather than a quote. Our SMB1001 readiness check takes a few minutes and tells you roughly how far off Gold you are before you spend anything.

What do the 27 Gold controls actually cover?

The controls group into five areas. None of them are exotic. They are the things a well-run business should be doing anyway, written down as a checklist you can be certified against.

  • Technology management: firewalls, security software on every device, automatic patching, and multi-factor authentication on business-critical accounts.
  • Access management: a password manager, unique accounts per person, and a process for removing access the day someone leaves.
  • Asset and data management: knowing what devices and systems you own, and backing up the data that matters with backups you have tested.
  • People: cybersecurity awareness training for staff, so the most common attack type (someone clicking something) gets harder.
  • Process: an incident response plan, a digital asset register, and the policies that prove the controls are managed rather than accidental.

How do you get SMB1001 Gold certified?

Gold is a self-assessed tier. There is no external auditor walking your office. You implement the controls, attest that they are in place, and CyberCert issues the certificate. That makes the process fast, but it also means the value of your certificate rests on doing the work properly. The pathway we run for clients looks like this:

  1. Gap assessment. Map the 27 controls against what you already have. Under a managed service, many controls are typically already in place, which is why the timeline is weeks and not months.
  2. Remediation. Close the gaps. In our experience the common ones are the process items: the incident response plan, the asset register, and formal staff training. The technical controls are usually further along than the paperwork.
  3. Evidence and documentation. Write down what is in place and where the proof lives. This is the step businesses skip when they self-manage, and it is the step that makes renewal painless a year later.
  4. Attestation and certification. Complete the attestation through CyberCert, receive the certificate and badge, and put them where your customers and insurer can see them.

When we certified Mino IT, the useful surprise was how much of the effort was documentation rather than technology.

How long does SMB1001 Gold take?

With an IT partner managing the process and a reasonable starting point, four to eight weeks is typical. A business starting with very little in place should allow up to three months, mostly because staff training and process changes take calendar time even when the technical work is quick. The certificate renews annually, and the renewal is far faster than the first certification if the documentation was done properly the first time.

What are the common mistakes when going for Gold?

Three patterns cause most of the pain we see:

  • Treating it as a tick-box exercise. Because Gold is self-assessed, it is possible to attest to controls that are half-implemented. Nothing stops you until the incident does. If the controls are not real, the certificate will not protect the business and it will not survive an insurer's scrutiny after a claim.
  • Underestimating the people controls. Buying security software is a purchase order. Getting every staff member through awareness training and writing an incident response plan people have actually read takes weeks of calendar time. Start those first, not last.
  • Skipping the documentation. The businesses that treat evidence as an afterthought pay for it twice: once at certification and again at every renewal. Documented properly the first time, renewal becomes an afternoon.

Is SMB1001 Gold worth it?

For most growth-stage businesses, yes, for three practical reasons. Insurers increasingly ask what controls you have before they price your cyber policy, and certification is clean evidence. Larger customers and tender panels are starting to ask for it, particularly in construction, health, and anywhere government money flows. And the controls themselves genuinely reduce the chance of the incident that costs real money. The certificate is the receipt; the security is the product.

If you want to know where you stand, start with the readiness check or read about our SMB1001 certification service. If you would rather talk it through, book a discovery call and we will start with the gap assessment.

Frequently Asked Questions

How much does SMB1001 Gold certification cost?

The certification fee paid to CyberCert is the smallest component and renews annually. The larger investment is implementing the 27 Gold controls, which depends entirely on your starting point: a business with MFA, managed backups, and endpoint protection already in place mainly needs process and documentation work, while a business starting from scratch also needs tooling and staff training. A gap assessment tells you the real number before you commit.

Is SMB1001 Gold independently audited?

No. Gold is a self-assessed tier: you implement the 27 controls, attest they are in place, and CyberCert issues the certificate. That keeps the process fast and affordable for SMBs, but it means the value of the certificate rests on implementing the controls properly rather than on paper.

How long does it take to get SMB1001 Gold certified?

Four to eight weeks is typical with an IT partner managing the process and a reasonable starting point. A business starting with very little in place should allow up to three months, mostly because staff training and process changes take calendar time. Renewal each year is much faster if the documentation was done properly the first time.

Can we get SMB1001 Gold without an IT provider?

Yes, the standard is designed so an SMB can self-manage it. In practice most businesses use their IT provider because the provider already controls much of the evidence the standard asks for: patching, backups, access management, and endpoint security. If you are on a managed service, a good portion of the Gold controls should already be covered.

Does SMB1001 Gold help win contracts and tenders?

Increasingly, yes. Larger customers and tender panels are starting to ask suppliers for evidence of cybersecurity management, particularly in construction, health, and government-adjacent work. SMB1001 Gold certification is a recognised, checkable answer to that question, and insurers view it the same way when pricing cyber cover.

Want to discuss how these insights apply to your business?