
SMB1001 Certification: What It Actually Proves
SMB1001 is an Australian cyber security certification standard built for small and medium business, with five levels running Bronze, Silver, Gold, Platinum and Diamond. The first three levels are self attested: a director signs to say the controls are in place and a certificate is issued, with no auditor checking. Platinum and Diamond require independent verification. It is a private market certification published by Dynamic Standards International, not an Australian Standard, and no Australian law requires it.
That distinction is worth understanding before you buy, because SMB1001 certificates are now appearing in Australian supply chains and tender responses, and what a certificate proves depends entirely on which level it is. Here is what each level means, what it is genuinely useful for, and when your money is better spent elsewhere.
What is SMB1001?
SMB1001 is a tiered cyber security standard aimed at businesses too small to carry ISO 27001. It is published by Dynamic Standards International, an Australian not for profit that was previously named Cyber Security Certification Australia. Certification against it is issued by an approved certifier rather than by the standards body itself. The edition listed at the time of writing is SMB1001:2026, and the standard is revised regularly, so check the publisher’s site for the current edition before you start.
The design idea behind SMB1001 is sensible. Most Australian small businesses will never implement an information security management system, but they can plausibly do multi factor authentication, backups, patching, staff awareness and an incident plan. SMB1001 packages those into levels a business can climb one step at a time, and gives them something to show a customer at the end of each step.
What are the SMB1001 levels?
SMB1001 has five levels, each adding controls to the one below it:

- Level 1, Bronze. Basic preventive controls, the sort of baseline a business should have regardless of any certificate.
- Level 2, Silver. More advanced preventive measures layered onto the Bronze baseline.
- Level 3, Gold. A broader set covering people, process and technology rather than technology alone.
- Level 4, Platinum. Formal governance and risk management, with independent verification.
- Level 5, Diamond. Best practice risk management, with independent verification.
Control counts per level differ between the sources that write about SMB1001, and they have changed between editions, so treat any number you see in a blog post, including a competitor’s, as indicative only. The publisher’s own documentation is the version that counts.
Which SMB1001 levels are independently audited?
Only Platinum and Diamond. SMB1001 Bronze, Silver and Gold are attested by an executive officer, owner or senior executive of the certified business. You complete a self assessment, an officer of the company signs to confirm it is accurate, and the certificate is issued and listed. Nobody external tests the controls.
This is not a scandal, and it is not hidden. Self attestation is what makes the lower levels cheap and fast enough for a ten person business, and a signed director’s attestation carries real weight, because signing a false one is a problem of a different order. But it does change what a Bronze, Silver or Gold certificate means when you receive one from a supplier. It tells you the supplier says they do these things. It does not tell you that anyone checked.
If you are the one doing the checking, ask which level the certificate is, and for anything below Platinum, treat it as you would treat a completed vendor security questionnaire: useful, honest in most cases, and unverified.
What does SMB1001 certification cost?
SMB1001 certification is paid for in two places: a licence or subscription for access to the standard and the certification platform, and, at Platinum and Diamond, the cost of the independent assessment on top. Published figures differ depending on whether you are looking at a per level price or a price banded by business size, and they have moved between editions, so check the publisher’s and the certifier’s current pricing pages rather than a third party summary.
What is safe to say is the shape of it. The lower levels are priced to be an easy decision for a small business making its first move on cyber security. The audited levels cost materially more because someone has to do the work of verifying. The bigger cost at every level is the internal time to actually implement the controls, which is the same for any framework.
Is SMB1001 an Australian Standard, and does any law require it?
No on both counts. SMB1001 has no AS or AS/NZS designation from Standards Australia, and it is not named in the Cyber Security Act 2024 or in the Security of Critical Infrastructure risk management rules. It is a private market certification scheme, which is a normal and legitimate thing to be, but it is not the same thing as a national standard.
Be careful with the surrounding claims too. We could not verify a published Australian insurer discount tied to SMB1001, or a named prime contractor that requires it by name. If a reseller tells you a particular customer or insurer demands SMB1001, ask them to show you where that customer or insurer says so. Certification also does nothing to change your obligations under the Privacy Act, including the Notifiable Data Breaches scheme, which apply whether or not you hold a certificate.
SMB1001 vs the Essential Eight: which should you do?
Do the Essential Eight work either way. The ASD Essential Eight is free, published by the Australian Signals Directorate, self assessed against maturity levels, and it is the framework Australian government buyers and regulators actually reference. It costs nothing but effort, and the effort is the part that improves your security.

What the Essential Eight does not give you is a certificate. There is no Essential Eight certification body and no badge to send a customer, only your own maturity assessment. That gap is exactly the space SMB1001 sells into. The two overlap but are not interchangeable, and an SMB1001 certificate at a lower level should not be read as evidence that you meet Essential Eight Maturity Level One.
When do you outgrow SMB1001?
You outgrow SMB1001 the first time a customer asks for something it cannot answer. In Australia that moment usually arrives as an enterprise procurement pack asking for ISO 27001 certification, a SOC 2 report, or a hundred question security assessment that assumes you have a documented management system. SMB1001 is not designed to answer any of those, and no amount of climbing its levels will make it do so.
Stepping up to ISO 27001 or SOC 2 means keeping evidence against every control and handing it to an auditor in a form they can review. There are three usual ways to do that. A spreadsheet and a shared drive costs nothing and works until it does not. A consultant can run the evidence process for you. Or you use a tool: enterprise platforms such as Vanta and Drata automate collection through deep integrations, while a lighter option like CertAssist runs at a flat US$375 a month and does not connect to your systems at all. The trade off is automation on one side and simplicity on the other.
Whichever route you pick, start with a gap analysis rather than a tool subscription. Knowing the size of the job is worth more than software at that stage.
Should your business get SMB1001 certified?
SMB1001 certification is worth it if a customer or a tender has asked for it, if you want a structured ladder to climb rather than an open ended improvement project, or if you need something concrete to show the market and ISO 27001 is years away. Those are real reasons and they apply to a lot of Australian small businesses.
It is not worth it if you are buying a certificate to skip the work, if your customers have never mentioned it, or if you are already heading for ISO 27001 or SOC 2 within the year. In that last case the certification spend is better pointed at the standard your customers will ask for next.
| Your situation | Sensible next step |
|---|---|
| A customer or tender has named SMB1001 | Certify at the level they asked for |
| You want a structured starting point and have no framework | Essential Eight first, then SMB1001 if you want the certificate |
| Enterprise customers are asking security questionnaires | ISO 27001 or SOC 2, not SMB1001 |
| You sell to Australian government or Defence | Essential Eight, IRAP readiness or DISP, depending on the contract |
| Nobody has asked for anything yet | Fix multi factor authentication, backups and patching first |
Common questions
What is SMB1001?
SMB1001 is an Australian tiered cyber security certification standard designed for small and medium business. It has five levels, Bronze through Diamond, each adding controls covering areas such as multi factor authentication, backups, patching, staff awareness and incident response. It is published by Dynamic Standards International, an Australian not for profit, and certification is issued by an approved certifier.
What is SMB1001 certification?
SMB1001 certification is a certificate confirming your business meets the controls at a given SMB1001 level. At Bronze, Silver and Gold it is granted on a self assessment attested by a company officer. At Platinum and Diamond it requires independent verification. Certificates are listed publicly, so a customer can confirm one exists and check which level it is.
Who created SMB1001?
SMB1001 is published by Dynamic Standards International, an Australian not for profit organisation previously named Cyber Security Certification Australia. The standards body publishes the standard, and certification against it is carried out by an approved certifier, which is a separate organisation. It is not published by the Australian Government or by Standards Australia.
SMB1001 vs Essential 8: what is the difference?
The Essential Eight is a free set of eight mitigation strategies published by the Australian Signals Directorate, self assessed against maturity levels zero to three, with no certificate. SMB1001 is a paid, five level certification scheme published by a private not for profit, which does produce a certificate. They overlap in subject matter but neither substitutes for the other.
SMB1001 vs ISO 27001: which should we get?
Get SMB1001 if a customer has asked for it and ISO 27001 is out of reach this year. Get ISO 27001 if you sell to enterprise or overseas buyers, because it is independently audited, internationally recognised and the one named in serious procurement. ISO 27001 costs far more in money and time, and it answers questions SMB1001 cannot.
Is SMB1001 mandatory in Australia?
No. No Australian law or regulation requires SMB1001 certification. It is a voluntary, private market scheme. Individual customers are free to require it in a contract, in the same way they might require ISO 27001, and that commercial pressure is the only thing that makes it mandatory for any particular business.
Where to go next
If a customer has asked you for SMB1001, get the request in writing and find out which level they want before you buy anything, because the answer changes the cost by an order of magnitude. If nobody has asked and you are choosing a starting point, the honest advice is to fix the fundamentals first and let the certificate follow. We help Australian businesses work out which framework their customers will actually accept. See our SMB1001 services, our cyber security advisory work, or get in touch.