If you have been researching cybersecurity for your business recently, you may have come across the term SMB1001. Described by its publisher, Dynamic Standards International (DSI), as the world’s first cybersecurity certification standard built specifically for small and medium businesses, it was developed right here in Australia. This guide explains what SMB1001 actually covers, how the tier system works, and why growing businesses are increasingly pursuing Gold certification.
What SMB1001 Is and Where It Came From
SMB1001 was created by Dynamic Standards International (DSI), with certification delivered in Australia through CyberCert, in response to a clear gap in the market. Enterprise-grade frameworks like ISO 27001 and SOC 2 are comprehensive, but they are designed for large organisations with dedicated security teams and significant compliance budgets. For a 20 or 50-person business, they are impractical.
SMB1001 fills that gap. It provides a structured, achievable cybersecurity baseline for businesses that do not have an in-house security team but still need to demonstrate that their systems, data, and processes are being managed responsibly. The standard was designed to be implemented with the help of a managed IT provider, rather than requiring a dedicated CISO or security consultant.
Mino IT is SMB1001 Gold certified, which means we implement the same controls for our clients that we apply to our own environment. Learn more about our SMB1001 Gold certification service, or how we approach cybersecurity and compliance for Brisbane businesses.
The Five Tiers: Bronze Through Diamond
SMB1001 uses a five-tier model, with each level building on the controls of the previous one. The tiers are:
- Bronze — The entry level, with 7 controls. Covers basic security hygiene: password policies, software updates, and basic access controls. Suitable for very small businesses just starting to formalise their security posture.
- Silver — 17 controls. Adds multi-factor authentication on email, a password manager, email anti-spoofing, backups, and staff security awareness training. A meaningful step up that addresses the most common attack vectors.
- Gold — The most widely pursued tier for growth-stage businesses. Covers 27 controls across the standard's five domains: technology management, access management, backup and recovery, policies and plans, and education and training. Gold adds endpoint detection and response, an incident response plan, a cybersecurity policy, a digital asset register, and cyber insurance. It is the benchmark that clients, insurers, and government procurement panels increasingly look for.
- Platinum — 32 controls. Extends MFA across VPN, remote desktop, and data stores, adds vulnerability scanning of internet-facing systems, and is independently verified by a third party rather than self-assessed. Suited to businesses handling sensitive data or operating in regulated industries.
- Diamond — The highest tier, with 39 controls including penetration, vulnerability, and social engineering testing. Intended for organisations with complex environments and significant regulatory obligations.
For most businesses in Brisbane, Gold is the target. It is the tier that provides demonstrable assurance to clients and insurers, without requiring an enterprise-scale security program.
Why More Businesses Are Pursuing Certification
Three forces are driving the uptake of SMB1001 certification among South East Queensland businesses:
1. Client and supply chain requirements
Larger organisations are increasingly asking their suppliers and subcontractors to demonstrate cybersecurity credentials before engaging them. This is particularly common in construction, professional services, and healthcare. A Gold certificate provides a clear, certified answer to the question “how are you managing cyber risk?”
2. Cyber insurance requirements
The cyber insurance market hardened significantly following the wave of major Australian breaches in 2022 and 2023. Insurers now ask more detailed underwriting questions, and businesses without documented security controls often face higher premiums, reduced coverage limits, or exclusions for specific attack types. SMB1001 Gold certification is a recognised signal that controls are in place.
3. Incident prevention
The certification process itself forces businesses to close the gaps that attackers exploit most commonly — weak passwords, missing MFA, unpatched software, no backup testing, and untrained staff. Most businesses pursuing Gold certification discover several significant vulnerabilities during the process that would otherwise have gone unnoticed.
What the Certification Process Looks Like
The path to SMB1001 Gold certification typically involves four stages:
- Gap assessment — Your current environment is measured against the 27 Gold controls to identify what is already in place and what needs to be addressed.
- Remediation — Missing controls are implemented. This typically includes deploying or configuring security tooling, updating policies, and running staff awareness training.
- Evidence collection — Documentation is gathered to demonstrate that each control is active and functioning. This is submitted through the CyberCert portal.
- Certification — CyberCert reviews the submission and issues the certificate, which is publicly verifiable and renewed annually.
With an experienced IT partner managing the process, Gold certification typically takes four to eight weeks. Mino IT manages the full pathway for clients, from gap assessment through to certification, as part of our cybersecurity and compliance service.
Not sure which level fits your business? Our free SMB1001 readiness check will tell you where you stand in a few minutes.
