SMB1001 certification · CyberCert Partner

SMB1001 Cyber Security Certification
with a CyberCert Partner

SMB1001 is the Australian cyber security certification built for small and medium businesses. We achieved Gold ourselves, and as a CyberCert Certification Partner we take you through Bronze, Silver and Gold, doing the technical work and preparing the evidence.

  • SMB1001 Gold achieved
  • CyberCert Certification Partner
  • Hands-on implementation
SEQ IT technician reviewing a laptop setup with a client
Gold

Achieved by SEQ IT through CyberCert. We run the same controls we set up for you.

SMB1001 Gold

Achieved through CyberCert

3 tiers

We take clients through Bronze, Silver and Gold

SMB1001:2026

Current edition, reviewed annually

300+

Businesses supported

What is SMB1001?

A certification built for small and medium businesses

SMB1001 is an Australian cyber security standard from Dynamic Standards International, written for businesses without a security department. Certification is issued through CyberCert, so you end up with a recognised certificate rather than a promise in an email.

Each tier adds controls on top of the one before, so you start where you are and move up when clients, insurers or tenders ask for more.

SMB1001 is reviewed every year, and the current edition is SMB1001:2026. Certification is renewed annually too, so the controls have to keep working after the certificate arrives.

SEQ IT helpdesk technician on a support call
SMB1001 at a glance
  • Written for small and medium businesses
  • Standard by Dynamic Standards International
  • Certification issued through CyberCert
  • Current edition SMB1001:2026, reviewed yearly
Why get certified

Why businesses are getting SMB1001 certified

Usually, the trigger is a question you couldn’t answer with evidence.

01

Tenders and panels

Government agencies and larger companies increasingly ask suppliers how they handle cyber security. A certificate answers that in one line of your response.

02

Supply chain questionnaires

Clients send long security questionnaires to their suppliers. With SMB1001 in place, most answers point to controls that are already documented.

03

Cyber insurance

Insurers ask about multi-factor authentication, EDR, patching and backups. Gold includes many of the controls they look for, with the evidence ready.

04

Client trust

A certificate and digital badge on your website, proposals and email signature show clients you take their data seriously.

The path

Bronze, Silver and Gold: the path we take you along

Each tier builds on the one before. You don’t have to start at Gold. We work out where you are today and plan the route to the tier your clients and insurer care about.

Bronze

Get the basics right

The foundations every business needs.

  • A technical support specialist engaged
  • A firewall installed and configured
  • Antivirus on every device
  • Automatic software patching
  • Strong password habits
  • A backup and recovery plan
  • Cyber security awareness training for staff
Silver

Lock down accounts and email

Everything in Bronze, plus firmer control over who can do what.

  • Multi-factor authentication on all email accounts
  • Admin rights removed from staff accounts
  • Individual accounts for every employee
  • A business password manager
  • Email authentication to stop spoofing
  • Servers patched and websites on TLS certificates
  • Confidentiality agreements, an invoice fraud policy and a visitor register
Gold

Monitor, plan and prove it

Everything in Silver, plus monitoring, written plans and governance. Where most businesses facing compliance pressure should aim.

  • Endpoint detection and response (EDR)
  • Multi-factor authentication on all business apps and social media
  • Remote desktop only over a VPN
  • Cyber insurance in place
  • A cyber security policy and incident response plan
  • An AI acceptable use policy
  • An asset register, secure document destruction and device disposal

Which tier are you closest to?

Our free cyber security assessment checks your devices, email, accounts and backups and shows where you stand against SMB1001. Valued at $2,500, with no obligation.

How it works

From first look to certificate

You get a timeline after the readiness assessment, based on how much needs fixing.

01

Readiness assessment

We check your setup against your target tier and show you what is already in place and what is missing.

02

Fix the gaps

We put the missing controls in place, such as multi-factor authentication, EDR, patching and email authentication. Urgent gaps go first.

03

Write the policies

We draft the documents your tier needs, such as the incident response plan and AI acceptable use policy, and go through them with you.

04

Collect evidence and submit

We gather the configuration reports, policies and training records, then lodge your application through CyberCert. Once approved, you receive your certificate and digital badge.

05

Stay certified

Certification is renewed annually. We keep the controls running and the documents current, so renewal is routine.

Who does what

What we handle and what we need from you

Certification is shared work. We carry the technical load and the paperwork, and you make the business decisions.

SEQ IT

What we do

  • Assess your setup against your target tier
  • Deploy and configure the technical controls
  • Draft the policies and plans in plain English
  • Run awareness training and simulated phishing, with completion tracked
  • Collect the evidence and lodge the application through CyberCert
  • Keep everything current for renewal
Your business

What you do

  • Choose the tier you are aiming for, with our advice
  • Nominate one person as our main contact
  • Read, adjust and approve the policies
  • Make sure staff finish their training
  • Decide on business items such as cyber insurance and supplier agreements
  • Tell us about new staff, systems or offices
Our own certification

We hold the certificate we help you earn

SEQ IT achieved SMB1001 Gold through CyberCert. We know which controls take time, what evidence has to be collected and where businesses usually get stuck, because we have been through it ourselves.

SMB1001 Gold certification badge

SMB1001 Gold

CyberCert logo

Certification Partner

Microsoft logo

Partner and Cloud Solution Provider (CSP)

Google Cloud logo

Google Cloud Partner

FAQ

SMB1001: common questions

SMB1001 is an Australian cyber security certification for small and medium businesses, written by Dynamic Standards International and issued through CyberCert. Tiers run from Bronze upwards, each adding controls to the one before. The standard is reviewed every year, and the current edition is SMB1001:2026.

It depends on who is asking and what data you hold. Bronze covers the basics and Silver tightens accounts and email. Gold adds monitoring, written plans and governance, and suits most businesses facing client, tender or insurer requirements.

It depends on your starting point. A business with multi-factor authentication, patching and backups already in place moves much faster. After the readiness assessment we give you a timeline for your target tier and start on the most urgent gaps.

Often both. The Essential Eight is the ASD’s technical baseline, measured in maturity levels, and there is no certificate for it. SMB1001 overlaps with it, adds policies and training, and gives you a certificate to show clients and insurers.

ISO 27001 is an international standard for information security management, built with larger organisations in mind. SMB1001 was written for small and medium businesses and uses tiers so you can start small. We refer ISO 27001 projects to trusted Australian GRC specialists.

It helps you answer the questions insurers ask. Gold includes controls they look for, such as multi-factor authentication, EDR, backups and an incident response plan, and certification backs your answers with evidence. Cover and premiums remain your insurer’s decision.

Yes. Certification is renewed annually and the standard is updated each year. For clients we manage, we keep controls running, update policies as the standard changes and prepare renewal evidence before it is due, so certification doesn’t lapse.

It depends on your target tier and how many gaps need closing. If you are already on our managed IT services, many controls are in place and the project is smaller. We quote before any work starts, and the first assessment is free.

Get started

Start your path to SMB1001 certification

Tell us what is driving the request: a tender, a client questionnaire or your insurer. We’ll tell you which tier makes sense and what it will take.

  • The tier that fits your situation
  • The gaps between you and that tier
  • A quoted plan, with no lock-in contract

Rather talk it through? Call 1300 619 750, Monday to Friday.

Talk to us

Tell us what you need. We’ll get back to you within one business day.