Skip to main content
Mino IT
SMB1001

SMB1001 Levels Explained: Bronze to Diamond

SMB1001 has five certification levels, and the right one is set by what your customers trust you with, not your company size. Here is every level, the controls each adds, how DSI's Supplier Categorization Matrix decides where you sit, and an honest note on attested versus audited.

Mino IT TeamManaged IT Specialists8 min read

SMB1001 has five certification levels, badged Bronze through Diamond, and the most common mistake businesses make is treating them like belt colours: start at the bottom, work your way up. That is not how the standard thinks about it. The right level is determined by what your customers trust you with, and DSI publishes a framework, the Supplier Categorization Matrix, that spells it out. This post walks through all five levels and how to work out where your business sits.

Mino IT holds SMB1001 Gold certification and manages the pathway for clients, so where this post makes judgement calls, they come from experience with the standard rather than the marketing.

The five levels at a glance

SMB1001 is published by Dynamic Standards International (DSI) and certified in Australia through CyberCert. Internally the standard uses Level 1 to Level 5; the metal names are the certifier branding. Each level is a superset of the one below it, adding controls and upgrading existing ones.

LevelControlsAssessmentTypical supplier profile
Bronze (L1)7Director attestedHandles only public or non-sensitive information
Silver (L2)17Director attestedReceives internal business information, standard user access
Gold (L3)27Director attestedHolds confidential or personal information, elevated access
Platinum (L4)32Independently verifiedAdmin access to systems customers depend on daily
Diamond (L5)39Independently verifiedPrivileged access to core infrastructure, mission-critical service

How DSI decides which level you need

The Supplier Categorization Matrix rates a supplier on three dimensions, and your level is set by the highest one you trigger:

  • Confidentiality: what information do you hold? From public information (Bronze) through internal business information (Silver), confidential or personal information under privacy obligations (Gold), restricted and proprietary information (Platinum), to highly sensitive, mission-critical data (Diamond).
  • Integrity: what access do you have? From no digital access (Bronze) through standard user access (Silver), elevated access (Gold), administrator access to systems daily operations depend on (Platinum), to privileged, system-level access to core infrastructure (Diamond). Physical access to customer facilities and secure sites also pushes suppliers into the top two levels.
  • Availability: how fast do they need you back? The matrix assigns recovery time expectations per level: 30+ days at Bronze, 7 to 30 days at Silver, 24 hours to 7 days at Gold, 8 to 24 hours at Platinum, and 0 to 8 hours at Diamond.

Notice what is missing: your company size and your budget. A five-person bookkeeping practice holding client financials rates higher than a fifty-person landscaping business that only ever receives purchase orders. Our readiness check asks exactly these questions and tells you which level your profile maps to.

What each level actually asks of you

  • Bronze: the foundations. Seven controls: engage technical support, a firewall, antivirus on every device, automatic patching, password hygiene, a backup and recovery strategy, and staff awareness training. A well-run business with any IT support likely has most of this today.
  • Silver: closing the common attack paths. Seventeen controls. The additions that matter: MFA on all staff email, a password manager, individual accounts without admin privileges, email authentication and anti-spoofing (SPF, DKIM, DMARC), server patching, TLS on public websites, and first policy work including confidentiality agreements and invoice fraud procedures.
  • Gold: a managed security program. Twenty-seven controls. Gold is where the standard stops being purely technical: endpoint detection and response (EDR), MFA extended to business applications, RDP only over VPN, cyber insurance, a cybersecurity policy, an incident response plan, a digital asset register, secure disposal, and an AI use policy. This is the tier that reads like a security program rather than a checklist, which is exactly why insurers and tender panels anchor on it.
  • Platinum: hardened and verified. Thirty-two controls. MFA everywhere it matters (VPN, RDP, wherever important data is stored), vulnerability scanning of everything internet-facing, managed remote-access credentials, and, the real step change, independent third-party verification instead of self-assessment.
  • Diamond: proven under attack. Thirty-nine controls. Adds penetration, vulnerability, and social engineering testing plus further governance rigour, independently verified. Built for suppliers whose failure would be catastrophic for their customers.

Attested vs audited: an honest note

Bronze, Silver, and Gold are self-assessed: a company director attests the controls are in place, and CyberCert issues the certificate. There is no auditor. Platinum and Diamond require independent third-party verification. We are upfront about this because it cuts both ways: it is what makes certification achievable for an SMB in weeks rather than months, and it means the value of a Bronze-to-Gold certificate rests entirely on the controls genuinely being implemented. Our own Gold certification is director-attested, like everyone else's, and the controls behind it are the same ones we run for clients every day. If a supplier tells you their Gold certificate was independently audited, they are mistaken about their own certification.

Which level should your business target?

Run the matrix on yourself with three questions. Do you hold customer information that is confidential or personal? Do you have logins to customer systems beyond a basic portal? If your service stopped, would customers need you back inside a week? Each yes pushes you toward Gold or above. For most established SMBs that handle client data, the answer lands on Gold, which also happens to be the tier procurement panels and cyber insurers increasingly expect. Bronze and Silver are legitimate levels for genuinely low-risk suppliers, and Platinum and Diamond are usually driven by a specific contract or regulatory requirement rather than general good practice.

Cost scales with the level and your starting point; we have broken that down separately in How Much Does SMB1001 Certification Cost?. And if you are weighing SMB1001 against the Essential Eight, see SMB1001 vs Essential Eight.

Moving up a level later

Because every level is a superset of the one below, nothing you implement is wasted if your requirements grow. A Gold-certified business pursuing Platinum keeps all 27 controls and adds the extensions plus independent verification. The standard is also updated annually by DSI (it is a "dynamic standard"), and certification renews each year, so treat whatever level you choose as a program you maintain rather than a plaque for the wall.

The fastest way to find your level and your gaps is the free SMB1001 readiness check: thirteen questions, no obligation. Or read about our SMB1001 certification service and book a discovery call when you are ready to map it properly.

Frequently Asked Questions

What are the five levels of SMB1001?

Bronze (Level 1, 7 controls), Silver (Level 2, 17 controls), Gold (Level 3, 27 controls), Platinum (Level 4, 32 controls), and Diamond (Level 5, 39 controls). Each level is a superset of the one below it. The standard itself uses Level 1 to 5; the metal names are the certifier's branding.

How do I know which SMB1001 level my business needs?

DSI's Supplier Categorization Matrix sets your level by what customers trust you with across three dimensions: the sensitivity of the information you hold, the depth of access you have to their systems, and how quickly they need your service restored if it fails. The highest dimension you trigger sets your level. Company size and budget are not factors.

Is SMB1001 Gold independently audited?

No. Bronze, Silver, and Gold are self-assessed tiers attested by a company director, with the certificate issued through CyberCert. Independent third-party verification applies at Platinum and Diamond, and Diamond adds penetration, vulnerability, and social engineering testing.

Can we start at a lower level and move up later?

Yes, and nothing is wasted: every level is a superset of the one below, so a Gold-certified business pursuing Platinum keeps all 27 controls and adds the extensions plus independent verification. That said, certifying below the level your customers expect usually means running the process twice, so most businesses go straight to the level their supplier profile maps to.

Want to discuss how these insights apply to your business?