SMB1001 Cyber Security Certification
with a CyberCert Partner
SMB1001 is the Australian cyber security certification built for small and medium businesses. We achieved Gold ourselves, and as a CyberCert Certification Partner we take you through Bronze, Silver and Gold, doing the technical work and preparing the evidence.
- SMB1001 Gold achieved
- CyberCert Certification Partner
- Hands-on implementation

Achieved by SEQ IT through CyberCert. We run the same controls we set up for you.
Achieved through CyberCert
We take clients through Bronze, Silver and Gold
Current edition, reviewed annually
Businesses supported
A certification built for small and medium businesses
SMB1001 is an Australian cyber security standard from Dynamic Standards International, written for businesses without a security department. Certification is issued through CyberCert, so you end up with a recognised certificate rather than a promise in an email.
Each tier adds controls on top of the one before, so you start where you are and move up when clients, insurers or tenders ask for more.
SMB1001 is reviewed every year, and the current edition is SMB1001:2026. Certification is renewed annually too, so the controls have to keep working after the certificate arrives.

- Written for small and medium businesses
- Standard by Dynamic Standards International
- Certification issued through CyberCert
- Current edition SMB1001:2026, reviewed yearly
Why businesses are getting SMB1001 certified
Usually, the trigger is a question you couldn’t answer with evidence.
Tenders and panels
Government agencies and larger companies increasingly ask suppliers how they handle cyber security. A certificate answers that in one line of your response.
Supply chain questionnaires
Clients send long security questionnaires to their suppliers. With SMB1001 in place, most answers point to controls that are already documented.
Cyber insurance
Insurers ask about multi-factor authentication, EDR, patching and backups. Gold includes many of the controls they look for, with the evidence ready.
Client trust
A certificate and digital badge on your website, proposals and email signature show clients you take their data seriously.
Bronze, Silver and Gold: the path we take you along
Each tier builds on the one before. You don’t have to start at Gold. We work out where you are today and plan the route to the tier your clients and insurer care about.
Get the basics right
The foundations every business needs.
- A technical support specialist engaged
- A firewall installed and configured
- Antivirus on every device
- Automatic software patching
- Strong password habits
- A backup and recovery plan
- Cyber security awareness training for staff
Lock down accounts and email
Everything in Bronze, plus firmer control over who can do what.
- Multi-factor authentication on all email accounts
- Admin rights removed from staff accounts
- Individual accounts for every employee
- A business password manager
- Email authentication to stop spoofing
- Servers patched and websites on TLS certificates
- Confidentiality agreements, an invoice fraud policy and a visitor register
Monitor, plan and prove it
Everything in Silver, plus monitoring, written plans and governance. Where most businesses facing compliance pressure should aim.
- Endpoint detection and response (EDR)
- Multi-factor authentication on all business apps and social media
- Remote desktop only over a VPN
- Cyber insurance in place
- A cyber security policy and incident response plan
- An AI acceptable use policy
- An asset register, secure document destruction and device disposal
SMB1001 also includes Platinum and Diamond tiers, designed for defence supply chains and critical infrastructure. Our certification work covers Bronze, Silver and Gold.
Which tier are you closest to?
Our free cyber security assessment checks your devices, email, accounts and backups and shows where you stand against SMB1001. Valued at $2,500, with no obligation.
From first look to certificate
You get a timeline after the readiness assessment, based on how much needs fixing.
Readiness assessment
We check your setup against your target tier and show you what is already in place and what is missing.
Fix the gaps
We put the missing controls in place, such as multi-factor authentication, EDR, patching and email authentication. Urgent gaps go first.
Write the policies
We draft the documents your tier needs, such as the incident response plan and AI acceptable use policy, and go through them with you.
Collect evidence and submit
We gather the configuration reports, policies and training records, then lodge your application through CyberCert. Once approved, you receive your certificate and digital badge.
Stay certified
Certification is renewed annually. We keep the controls running and the documents current, so renewal is routine.
What we handle and what we need from you
Certification is shared work. We carry the technical load and the paperwork, and you make the business decisions.
What we do
- Assess your setup against your target tier
- Deploy and configure the technical controls
- Draft the policies and plans in plain English
- Run awareness training and simulated phishing, with completion tracked
- Collect the evidence and lodge the application through CyberCert
- Keep everything current for renewal
What you do
- Choose the tier you are aiming for, with our advice
- Nominate one person as our main contact
- Read, adjust and approve the policies
- Make sure staff finish their training
- Decide on business items such as cyber insurance and supplier agreements
- Tell us about new staff, systems or offices
We hold the certificate we help you earn
SEQ IT achieved SMB1001 Gold through CyberCert. We know which controls take time, what evidence has to be collected and where businesses usually get stuck, because we have been through it ourselves.

SMB1001 Gold

Certification Partner

Partner and Cloud Solution Provider (CSP)

Google Cloud Partner
SMB1001: common questions
What is SMB1001 certification?
SMB1001 is an Australian cyber security certification for small and medium businesses, written by Dynamic Standards International and issued through CyberCert. Tiers run from Bronze upwards, each adding controls to the one before. The standard is reviewed every year, and the current edition is SMB1001:2026.
Which SMB1001 level should my business aim for?
It depends on who is asking and what data you hold. Bronze covers the basics and Silver tightens accounts and email. Gold adds monitoring, written plans and governance, and suits most businesses facing client, tender or insurer requirements.
How long does SMB1001 certification take?
It depends on your starting point. A business with multi-factor authentication, patching and backups already in place moves much faster. After the readiness assessment we give you a timeline for your target tier and start on the most urgent gaps.
Should we do SMB1001 or the Essential Eight?
Often both. The Essential Eight is the ASD’s technical baseline, measured in maturity levels, and there is no certificate for it. SMB1001 overlaps with it, adds policies and training, and gives you a certificate to show clients and insurers.
What is the difference between SMB1001 and ISO 27001?
ISO 27001 is an international standard for information security management, built with larger organisations in mind. SMB1001 was written for small and medium businesses and uses tiers so you can start small. We refer ISO 27001 projects to trusted Australian GRC specialists.
Does SMB1001 help with cyber insurance?
It helps you answer the questions insurers ask. Gold includes controls they look for, such as multi-factor authentication, EDR, backups and an incident response plan, and certification backs your answers with evidence. Cover and premiums remain your insurer’s decision.
Do we have to renew SMB1001 every year?
Yes. Certification is renewed annually and the standard is updated each year. For clients we manage, we keep controls running, update policies as the standard changes and prepare renewal evidence before it is due, so certification doesn’t lapse.
How much does SMB1001 certification cost?
It depends on your target tier and how many gaps need closing. If you are already on our managed IT services, many controls are in place and the project is smaller. We quote before any work starts, and the first assessment is free.
Build on your certification
Cyber security services
Managed security that keeps your controls working.
Essential Eight
The ASD baseline, measured in maturity levels.
Cyber insurance readiness
Answer your insurer’s questions accurately, with evidence.
Governance and compliance
Policies, frameworks and evidence.
Healthcare IT support
Security for practices holding patient data.
Start your path to SMB1001 certification
Tell us what is driving the request: a tender, a client questionnaire or your insurer. We’ll tell you which tier makes sense and what it will take.
- The tier that fits your situation
- The gaps between you and that tier
- A quoted plan, with no lock-in contract
Rather talk it through? Call 1300 619 750, Monday to Friday.
Tell us what you need. We’ll get back to you within one business day.
