Free tool · SMB1001

SMB1001 Readiness Check
Bronze, Silver or Gold?

Find out which SMB1001 tier your business is closest to, and exactly which controls are missing. 21 quick questions, about three minutes, and no email needed.

  • No email needed
  • Result in three minutes
  • Answers stay private
SEQ IT technician helping a client with her laptop at her desk
SMB1001 Gold certification badge
SMB1001 Gold

Achieved by SEQ IT through CyberCert. The questions come from the controls we run ourselves.

The readiness check

Which tier are you closest to?

Three short steps, one for each tier. For each item, tell us whether your business already has it in place. You reach a tier when everything in it, and in the tiers before it, is in place.

3 short stepsAbout 3 minutesNo email needed

Step 1 of 3Bronze: the basics every business needs

For each item, tell us whether your business has it in place today, across the whole business and not just most of it. Not sure? That's fine: choose Not sure and we'll show you what to check.

An IT provider or technical specialist is engaged to look after your systems.

A firewall is installed and configured on your office network.

The box your internet comes through usually has a basic one. A business firewall is set up and looked after on purpose.

Every computer has antivirus installed and kept up to date.

Windows or Mac updates, and updates for your software, install automatically.

Software means programs like Office, Chrome and Adobe Reader.

Staff use long, unique passwords and never share or reuse them.

Your important data is backed up, and there is a plan for restoring it.

Staff have had cyber security awareness training.

For example, short online lessons on spotting scam emails and fake invoices.

Step 2 of 3Silver: lock down accounts and email

Silver builds on Bronze. Again, tell us what is in place today.

Multi-factor authentication (MFA) is on for every email account.

MFA means entering a code from your phone or an app as well as your password.

Everyday staff accounts don't have admin rights on their computers.

If staff can install software on their own computers, the answer is probably no.

Every employee has their own account, with no shared logins.

The business uses a password manager for work passwords.

An app that stores passwords securely and shares them with the right people, instead of a spreadsheet or notebook.

Your email is set up so criminals can't send email that looks like it came from your business (SPF, DKIM and DMARC).

Not sure? Our free SPF, DKIM and DMARC check tells you in seconds (opens in a new tab, so you keep your answers here).

Any servers are kept up to date, and your website shows a padlock in the browser (HTTPS).

No servers in the office? Just answer for your website.

Staff sign confidentiality agreements, you have an invoice fraud policy, and visitors sign in.

All three for a yes. An invoice fraud policy says how staff check a change of bank details before paying anyone.

Step 3 of 3Gold: monitor, plan and prove it

Gold builds on Silver. These are the items in the certification SEQ IT achieved.

Every computer has endpoint detection and response (EDR), not just antivirus.

EDR is a step up from antivirus: it spots suspicious behaviour and can stop an attack in progress. Your IT provider will know if you have it.

MFA is on for all your business apps and social media accounts, not just email.

Think accounting software, online banking, your website login and social media.

Remote desktop is only reachable over a VPN, or not used at all.

This is about logging in to an office computer from home. If nobody does that, answer yes.

You hold a current cyber insurance policy.

You have a written cyber security policy and a written incident response plan.

Both need to be written down for a yes.

You have an AI acceptable use policy that tells staff how AI tools can be used.

You keep an asset register, shred sensitive documents and wipe old devices before disposal.

An asset register is a list of every computer, phone and device the business owns. All three for a yes.

Your answers stay in your browser. Nothing is stored or sent unless you choose to add your result to the enquiry form.

Indicative only. This check is not an SMB1001 assessment and does not grant or predict certification, which is issued through CyberCert. Questions summarise the SMB1001:2026 Bronze, Silver and Gold controls in plain English. Reviewed October 2026.

How it works

How the check works out your tier

It follows the same logic as certification, in plain English.

Questions

One question per control

The 21 questions cover the Bronze, Silver and Gold controls in SMB1001:2026, grouped by tier and written without the jargon.

Tiers

Every control counts

Certification needs every control in a tier, plus the tiers before it. One missing Bronze control holds the result at “not yet”, even if you run most of Gold.

Not sure

Not sure is a real answer

It counts as a gap and is flagged in your result, because certification needs evidence for each control. Not knowing is a finding in itself.

Want the evidence checked, not just the answers?

Our free cyber security assessment looks at your actual settings and shows where you stand against SMB1001. Valued at $2,500, with no obligation.

About SMB1001

SMB1001 in two minutes

SMB1001 is an Australian cyber security standard from Dynamic Standards International, written for small and medium businesses rather than large enterprises. Certification is issued through CyberCert, and the standard is reviewed every year. The current edition is SMB1001:2026.

Businesses usually look at it when a tender, a client questionnaire or an insurer starts asking for proof. Instead of a long list of answers in an email, you can point to a certificate. Read more on our SMB1001 certification page.

What each tier focuses on
  • Bronze: support, firewall, antivirus, patching, passwords, backups and training
  • Silver: multi-factor authentication on email, admin rights, individual accounts and email authentication
  • Gold: EDR, wider multi-factor authentication, written plans and policies, and cyber insurance
Common gaps

Where businesses usually get stuck

These controls take the most work to put in place and prove.

01

Shared logins

Reception, a shared inbox or an old admin account that several people use. Every person needs their own account.

02

Admin rights

Staff who install their own software usually have admin rights. Removing them needs a quick way to approve installs.

03

Multi-factor authentication beyond email

Accounting, banking and social media accounts are often missed once email is done.

04

Written plans

An incident response plan and a cyber security policy have to exist on paper, not just in someone’s head.

05

AI acceptable use

Most teams already use AI tools. Gold expects written rules on how.

06

Asset register and disposal

A list of every device, and proof that old laptops and paper records were wiped or destroyed.

Our own certification

We achieved Gold before we offered it

SEQ IT achieved SMB1001 Gold through CyberCert, and we are a CyberCert Certification Partner. The controls in this check are the same ones we run in our own business.

SMB1001 Gold certification badge

SMB1001 Gold

CyberCert logo

Certification Partner

Microsoft logo

Partner and Cloud Solution Provider (CSP)

Google Cloud logo

Google Cloud Partner

FAQ

SMB1001 readiness check: common questions

No. It is a free self-check that gives an indicative result. It doesn’t look at your systems or evidence, and it can’t grant or predict certification. Certification is issued through CyberCert after the evidence for each control is checked.

No. Your result appears on the page straight away. Your answers stay in your browser, and nothing reaches us unless you choose to send your result through the enquiry form at the bottom of the page.

It is as accurate as your answers. Each question matches one control from the Bronze, Silver and Gold lists, and a tier only counts when every control in it is in place. Answering “not sure” is often the most useful thing the check turns up.

It depends on who is asking and what data you hold. Bronze covers the basics and Silver tightens accounts and email. Gold adds monitoring, written plans and governance, and suits most businesses facing tender, client or insurer requirements.

Yes. SMB1001 also has Platinum and Diamond tiers, designed for defence supply chains and critical infrastructure. This check covers Bronze, Silver and Gold, the tiers we take clients through.

Fix what you can, or ask us to. Our free cyber security assessment checks your actual settings against SMB1001 and gives you a plain-English report. If you go ahead, we close the gaps, write the policies and prepare the evidence for certification.

It depends on how many gaps there are. A business with multi-factor authentication, patching and backups already in place moves much faster. After a readiness assessment we give you a timeline and start with the most urgent gaps.

Get started

Get your SMB1001 gaps checked for free

Send us your result, or just tell us what is driving the question. We’ll check your settings and show you what it takes to reach your target tier.

  • Your actual settings checked, not just your answers
  • A plain-English report on the gaps
  • No obligation and no lock-in contract

Prefer to talk? Call 1300 619 750, Monday to Friday.

Request your free assessment

If you used the check, your result is already in the message box. We’ll get back to you within one business day.