SMB1001 Certification · CyberCert Authorised Partner

Get certified.
Know it's real.

A fixed-fee, independent SMB1001 readiness assessment for Australian businesses. We assess your controls, close the gaps, and prepare you for certification — through CyberCert, the official certification body.

Fixed fee. No scope creep.
CyberCert authorised partner
Independent — no MSP conflict
CyberCert Silver certified
What is SMB1001

The cyber standard built
for businesses like yours

SMB1001 is a five-tier cybersecurity certification standard published by Dynamic Standards International and certified by CyberCert. It was designed specifically for small and medium businesses — not repurposed from government or enterprise frameworks.

It covers the controls that matter for your risk profile: patching, MFA, backups, email authentication, staff awareness, incident response, and policy fundamentals. Updated annually. Endorsed by the Queensland Law Society for member law firms.

Built for SMBs

Controls are scaled for 5–100 person businesses. No dedicated security team required. No six-figure implementation budget.

Recognised and growing

Formally endorsed by the Queensland Law Society. Increasingly cited in procurement and insurance conversations across professional services, healthcare, and legal.

Annual revision cycle

Updated every year — faster than the Essential Eight and far faster than ISO 27001. Controls reflect current threats, not a 2018 threat landscape.

The five tiers

Five tiers. One honest picture.

SMB1001 certifications run from Bronze (essential hygiene) to Diamond (pen tested, audited, supplier-governed). The tier you pursue depends on what you need to prove, and to whom.

Important: Bronze, Silver, and Gold are director self-attested — a company director signs a declaration that controls are in place. Platinum and Diamond require an independent external audit. Most certificate requests in the market are at Gold or below. Know what you're showing before you show it.
Tier 1 Bronze
7 controls Director self-attestation
Bronze certification badge

Firewall, anti-malware, patching, password hygiene, backup with offline copy, awareness training.

Good for: Getting started. Internal discipline. First step on the ladder.

Tier 2 Silver
17 controls Director self-attestation
Silver certification badge

Adds: Server patching, MFA on email, SPF email authentication, password manager, individual accounts, confidentiality agreements, invoice fraud policy.

Good for: Small professional services firms, sole traders, businesses under procurement pressure to show basic hygiene.

Tier 3 Gold
~27 controls Director self-attestation
Gold certification badge

Adds: MFA on all business apps, EDR on all devices, DKIM and DMARC, incident response plan, digital asset register, cyber security policy, regular staff training.

Good for: Most SMBs. The practical target for businesses wanting to satisfy insurer and client expectations. QLS-endorsed tier for law firms.

Tier 4 Platinum
~35 controls External audit required
Platinum certification badge

Adds: Vulnerability scanning, MFA on RDP and VPN, cloud IAM, cyber insurance requirement, enhanced backup with annual restore test, MSP SLA requirement.

Good for: Businesses with active insurer or procurement requirements. The first tier where an independent auditor has verified the controls — not just a director's word.

Tier 5 Diamond
~40 controls External audit required
Diamond certification badge

Adds: Encryption at rest, application control, annual penetration testing, IR tabletop exercises, supplier due diligence programme, police vetting for privileged staff.

Good for: Businesses approaching ISO 27001 maturity. Supply chain requirements. High-value data environments.

What we do

What Coastal Cyber does —
and what we don't

Our role is advisory. We assess your controls against the target tier, identify gaps, and prepare you for certification. We do not implement technical controls — that's your IT provider's job. We do not issue the certificate — that's CyberCert's job.

What that independence gives you: an honest, unbiased picture of where you stand. No one at Coastal Cyber benefits from certifying you before you're ready, or from selling you technology to close the gaps.

We assess

Independent gap analysis against your target tier. Evidence review. Structured interviews. Plain-English findings.

We advise

Prioritised remediation roadmap. We tell you what to fix, in what order, and what good looks like. Your MSP implements.

We prepare

Certification readiness brief. Pre-attestation review. CyberCert discount link so you can complete certification at 35% off the standard fee.

What's included

What's included

Inquire now

Book a 20-minute call to discuss scope, target tier, and whether a Readiness Assessment is right for you. Certification subscription fees are charged separately by CyberCert via our partner discount link.

How it works

How it works

Six steps from introductory call to certificate in hand.

01

Discovery call (free, 20 minutes)

We establish your target tier, your timeline, and whether a Readiness Assessment is the right starting point. No obligation.

02

Kick-off and scoping (week 1)

Engagement letter signed. Kick-off call with you (and your IT provider if relevant). We confirm scope, evidence to gather, and interview schedule.

03

Gap assessment (weeks 2–3)

Structured review of controls across all five domains: Technology Management, Access Management, Backup & Recovery, Policies & Procedures, Education & Training. Evidence-based, not a tick-box.

04

Findings and roadmap (weeks 3–4)

You receive the gap register and remediation roadmap. We walk you through it. Your IT provider implements the outstanding items.

05

Pre-attestation review

Once your IT provider has closed the gaps, we review the CyberCert workbook with you before you sign. You attest with confidence.

06

Certification

You complete the attestation via CyberCert's platform and receive your certificate. We provide the partner discount link (35% off).

Who it's for

Who pursues SMB1001

SMB1001 is particularly relevant for businesses facing procurement, insurer, or regulatory pressure to demonstrate cyber maturity — or those that simply want a structured path to better security.

Legal & professional services

The Queensland Law Society formally endorsed SMB1001:2025 as a recommended standard for member law firms. Gold certification provides documented evidence of cybersecurity due diligence — relevant to PII obligations, PI insurance, and client expectations.

Healthcare & allied health

Private clinics, allied health practices, and aged care providers handle highly sensitive personal and health information. SMB1001 Gold covers the operational controls most relevant to APP compliance and OAIC expectations — and gives insurers and referring hospitals something concrete to review.

Technology & SaaS

B2B technology companies are increasingly asked to complete security questionnaires by enterprise customers. SMB1001 Gold is an efficient way to demonstrate baseline cyber maturity without the overhead of ISO 27001 — and creates a clear pathway toward it.

General SME

Any business facing supply chain scrutiny, cyber insurance pressure, or a board asking "what are we doing about cybersecurity?" can use SMB1001 as a structured starting point and a defensible answer.

K-12 independent schools

Independent schools handle sensitive student records, health information, and staff data under Privacy Act obligations — and face increasing pressure from school boards, insurers, and parent communities to demonstrate structured cyber governance. SMB1001 Gold provides an achievable certification pathway sized for school budgets, with controls directly relevant to EdTech vendor risk, identity management, and incident response. Government schools typically operate under state-level frameworks; this pathway suits independent and Catholic schools with governance boards accountable for cyber risk.

Frequently asked

The questions everyone asks,
answered honestly.

Does SMB1001 satisfy the Essential Eight?
Not fully, and it's worth being clear about this. SMB1001 Gold covers significant Essential Eight ML1 ground — patching, MFA, backups, awareness training. However, application control and macro disabling don't appear in SMB1001 until Diamond (Level 5). If you need Essential Eight ML1 compliance specifically — for government contracts or sector requirements — you need an E8 assessment. If you want a structured framework that builds toward it, SMB1001 is a practical starting point.
Does the certificate guarantee a cyber insurance discount?
Insurers are increasingly looking for evidence of structured cybersecurity controls at renewal — and SMB1001 certification gives underwriters documented confirmation that controls are in place. Many brokers report that structured evidence of this kind improves underwriting conversations. Whether that translates to a formal premium reduction depends on your specific insurer and policy. Check with your broker about what certification evidence they'll accept and how they factor it into their assessment.
Is SMB1001 government-mandated?
No. As of mid-2026, SMB1001 is not named in Australian legislation, including the Cyber Security Act 2024 or the SOCI Act. It is a private market certification with growing professional body and industry recognition. We'll give you an honest picture of what the certificate does and doesn't prove — that's the point of the advisory engagement.
What's the difference between the three lower tiers and the top two?
Bronze, Silver, and Gold are director self-attested — a company director signs a declaration that the controls are in place. No independent auditor has verified this. Platinum and Diamond require external audit by CyberCert's approved auditors. Most certificates in the market sit at Gold or below. The recipient of your certificate can't tell which tier you hold unless you tell them, so be clear about what you're presenting and to whom.
Can Coastal Cyber also implement the technical controls?
No — and that's deliberate. Our value is independence. We assess and advise; your existing IT provider or MSP implements. If you don't have an IT provider, we can recommend suitable partners for the Sunshine Coast and South East Queensland region.
What tier should we target?
Most businesses without an existing structured programme should target Silver as the starting point — it's achievable quickly and demonstrates meaningful hygiene. Gold is the right target for businesses facing procurement or insurer pressure, or professional services firms responding to sector expectations (law, healthcare). The discovery call will help us work this out together.

Ready to find out
where you stand?

Start with a free 20-minute call. No obligation. We'll tell you whether a Readiness Assessment is the right fit, which tier makes sense, and what the process looks like.

Free 20-minute call

No sales pitch. We'll tell you whether a Readiness Assessment is the right fit and what to expect.

Book a 20-minute chat