SMB1001 Gold Certification
for Brisbane Businesses
The cybersecurity certification standard built for small and medium businesses. What it is, how to achieve it, and what it means for your business, from a certified provider.
SMB1001 Gold Certified, issued by CyberCertTHE PROBLEM
Is this your IT reality?
Enterprise frameworks like ISO 27001 were not built for a 20 or 50-person business. They require dedicated security teams, large budgets, and months of consulting work. Yet leaving security entirely unstructured creates real risk: ransomware, data breaches, and growing pressure from clients and insurers to demonstrate that your systems are being managed responsibly. SMB1001 fills the gap: a structured, achievable certification standard built specifically for small and medium businesses, designed to be implemented with your managed IT provider.
No Verified Security Credentials to Show Clients
Missing Supply Chain and Government Contracts
No Documented Access or Security Controls
Staff Without Formal Security Awareness Training
No Visibility Over Your Security Posture
Reactive Security With No Structured Framework
THE SHIFT
From unverified to Gold certified.
OUR MANAGED IT SERVICES
Three pillars. One foundation.
Every service works together so nothing falls through the cracks.
THE OUTCOME
What this looks like after 12 months.
After achieving SMB1001 Gold with Mino IT, Brisbane businesses have a Gold certificate issued by CyberCert, 27 controls implemented and documented, clear evidence for cyber insurance underwriting, and the credentials to pursue government and enterprise supply chain contracts, with ongoing compliance maintained as part of their managed IT service.
- SMB1001 Gold certificate issued by CyberCert.
- 27 controls implemented across access management, patching, backups, email security, and incident response.
- Documented evidence of controls ready for cyber insurance underwriting and client due diligence.
- Eligible for government and enterprise procurement panels requiring verified cybersecurity credentials.
- Ongoing compliance maintained by Mino IT. No separate compliance program to run.
- A clear path to Platinum certification if your requirements grow.
CLIENT VOICES
Don't take our word for it.
Service was top drawer again as always. Issue resolved quickly, efficiently with the urgency appreciated. Thank you Mino IT, please keep up the great service.
- Client, Manufacturing
FREQUENTLY ASKED QUESTIONS
Common questions answered.
SMB1001 is a cybersecurity certification standard designed specifically for small and medium businesses, described by its developer Dynamic Standards International (DSI) as the world's first of its kind. It was developed by DSI and is certified in Australia by CyberCert, in response to a clear gap in the market: enterprise frameworks like ISO 27001 and SOC 2 are impractical for most SMBs, yet leaving security unstructured creates significant risk. SMB1001 provides a structured, achievable baseline that can be implemented with a managed IT provider rather than requiring an in-house security team.
SMB1001 has five tiers: Bronze (basic security hygiene), Silver (adds MFA, asset management, and incident response planning), Gold (27 controls across access, patching, backups, email security, and incident response), Platinum (advanced threat detection, penetration testing, third-party risk management), and Diamond (enterprise-aligned, for complex regulated environments). For most Brisbane businesses, Gold is the right target. It provides demonstrable assurance to clients and insurers without requiring an enterprise-scale program, and it is the tier that procurement panels and cyber insurers increasingly look for.
No. Gold is a self-assessed tier: the business certifies its own compliance against the 27 controls, and CyberCert issues the certificate. Independent third-party assessment applies at the higher tiers, Platinum and Diamond. What matters is that the controls are genuinely in place. We implement and document every control as part of your managed IT service, so your certification is backed by real security work, not a checkbox.
The process has four stages. First, a gap assessment: we audit your current environment against all 27 Gold controls and identify what is in place and what needs to be implemented. Second, remediation: we implement the missing controls as part of your managed IT service. This typically takes four to eight weeks, or up to three months if you are starting with very little in place. Third, evidence collection: we compile the documentation and evidence required by CyberCert to demonstrate each control is in place. Fourth, certification: we submit your application to CyberCert, who process the application and issue the certificate. Mino IT manages the entire process on your behalf.
The cost has two components: the CyberCert certification fee (a fixed fee payable directly to CyberCert, publicly listed on their website) and the implementation cost, which depends on how many of the 27 controls are already in place at your business. For most businesses that engage Mino IT as their managed IT provider, the majority of Gold controls are implemented as part of the standard service, meaning the incremental cost of reaching certification is often lower than expected. We provide a clear picture of where you stand and what it will cost after the initial gap assessment.
SMB1001 Gold certification is not a one-time achievement. It requires annual recertification to confirm controls remain in place. For Mino IT clients, this is managed as part of your ongoing service: we maintain the controls, keep the documentation current, and manage the renewal process with CyberCert each year. For businesses that want to go further, Platinum is the next tier, adding penetration testing, advanced threat detection, and more rigorous third-party risk management. We advise on when Platinum makes sense based on your industry, client requirements, and risk profile.
Ready to achieve SMB1001 Gold certification for your Brisbane business?
Get in Touch
Have a question or ready to get started? Drop us a message and we'll be in touch within one business day.
