Skip to main content
Mino IT
SMB1001

What is SMB1001 Certification? A Plain-English Guide

SMB1001 is described by its publisher DSI as the world's first cybersecurity certification standard built specifically for small and medium businesses. Here is what it covers, how the tiers work, and why more small and medium businesses are pursuing Gold certification.

Mino IT TeamManaged IT Specialists6 min read

If you have been researching cybersecurity for your business recently, you may have come across the term SMB1001. Described by its publisher, Dynamic Standards International (DSI), as the world’s first cybersecurity certification standard built specifically for small and medium businesses, it was developed right here in Australia. This guide explains what SMB1001 actually covers, how the tier system works, and why growing businesses are increasingly pursuing Gold certification.

What SMB1001 Is and Where It Came From

SMB1001 was created by Dynamic Standards International (DSI), with certification delivered in Australia through CyberCert, in response to a clear gap in the market. Enterprise-grade frameworks like ISO 27001 and SOC 2 are comprehensive, but they are designed for large organisations with dedicated security teams and significant compliance budgets. For a 20 or 50-person business, they are impractical.

SMB1001 fills that gap. It provides a structured, achievable cybersecurity baseline for businesses that do not have an in-house security team but still need to demonstrate that their systems, data, and processes are being managed responsibly. The standard was designed to be implemented with the help of a managed IT provider, rather than requiring a dedicated CISO or security consultant.

Mino IT is SMB1001 Gold certified, which means we implement the same controls for our clients that we apply to our own environment. Learn more about our SMB1001 Gold certification service, or how we approach cybersecurity and compliance for Brisbane businesses.

The Five Tiers: Bronze Through Diamond

SMB1001 uses a five-tier model, with each level building on the controls of the previous one. The tiers are:

  • Bronze — The entry level, with 7 controls. Covers basic security hygiene: password policies, software updates, and basic access controls. Suitable for very small businesses just starting to formalise their security posture.
  • Silver — 17 controls. Adds multi-factor authentication on email, a password manager, email anti-spoofing, backups, and staff security awareness training. A meaningful step up that addresses the most common attack vectors.
  • Gold — The most widely pursued tier for growth-stage businesses. Covers 27 controls across the standard's five domains: technology management, access management, backup and recovery, policies and plans, and education and training. Gold adds endpoint detection and response, an incident response plan, a cybersecurity policy, a digital asset register, and cyber insurance. It is the benchmark that clients, insurers, and government procurement panels increasingly look for.
  • Platinum — 32 controls. Extends MFA across VPN, remote desktop, and data stores, adds vulnerability scanning of internet-facing systems, and is independently verified by a third party rather than self-assessed. Suited to businesses handling sensitive data or operating in regulated industries.
  • Diamond — The highest tier, with 39 controls including penetration, vulnerability, and social engineering testing. Intended for organisations with complex environments and significant regulatory obligations.

For most businesses in Brisbane, Gold is the target. It is the tier that provides demonstrable assurance to clients and insurers, without requiring an enterprise-scale security program.

Why More Businesses Are Pursuing Certification

Three forces are driving the uptake of SMB1001 certification among South East Queensland businesses:

1. Client and supply chain requirements

Larger organisations are increasingly asking their suppliers and subcontractors to demonstrate cybersecurity credentials before engaging them. This is particularly common in construction, professional services, and healthcare. A Gold certificate provides a clear, certified answer to the question “how are you managing cyber risk?”

2. Cyber insurance requirements

The cyber insurance market hardened significantly following the wave of major Australian breaches in 2022 and 2023. Insurers now ask more detailed underwriting questions, and businesses without documented security controls often face higher premiums, reduced coverage limits, or exclusions for specific attack types. SMB1001 Gold certification is a recognised signal that controls are in place.

3. Incident prevention

The certification process itself forces businesses to close the gaps that attackers exploit most commonly — weak passwords, missing MFA, unpatched software, no backup testing, and untrained staff. Most businesses pursuing Gold certification discover several significant vulnerabilities during the process that would otherwise have gone unnoticed.

What the Certification Process Looks Like

The path to SMB1001 Gold certification typically involves four stages:

  1. Gap assessment — Your current environment is measured against the 27 Gold controls to identify what is already in place and what needs to be addressed.
  2. Remediation — Missing controls are implemented. This typically includes deploying or configuring security tooling, updating policies, and running staff awareness training.
  3. Evidence collection — Documentation is gathered to demonstrate that each control is active and functioning. This is submitted through the CyberCert portal.
  4. Certification — CyberCert reviews the submission and issues the certificate, which is publicly verifiable and renewed annually.

With an experienced IT partner managing the process, Gold certification typically takes four to eight weeks. Mino IT manages the full pathway for clients, from gap assessment through to certification, as part of our cybersecurity and compliance service.

Not sure which level fits your business? Our free SMB1001 readiness check will tell you where you stand in a few minutes.

Frequently Asked Questions

What is SMB1001 and who created it?

SMB1001 is a cybersecurity certification standard published by Dynamic Standards International (DSI) and certified in Australia by CyberCert, specifically designed for small and medium businesses. Unlike enterprise frameworks such as ISO 27001, SMB1001 is built around the real constraints of SMBs — practical controls, achievable timelines, and affordable implementation.

How many tiers does SMB1001 have?

SMB1001 has five tiers: Bronze, Silver, Gold, Platinum, and Diamond. Each tier adds more controls and rigour. Gold is the most widely pursued tier for growth-stage businesses, covering 27 controls across areas including access management, asset tracking, incident response, staff training, and backup verification.

How long does SMB1001 certification take?

Achieving SMB1001 Gold typically takes four to eight weeks with the right IT partner managing the process, or up to three months for a business starting with very little in place. The timeline depends on how many controls are already in place and how quickly staff training can be completed. Mino IT manages the full certification pathway for clients.

Does SMB1001 certification help with cyber insurance?

Yes. Many cyber insurance providers recognise SMB1001 certification as evidence of proactive risk management. Certified businesses often receive more favourable terms, lower premiums, or faster claims processing compared to uncertified businesses with similar revenue. Always confirm specifics with your insurer.

Want to discuss how these insights apply to your business?