Winner, TechNews Fast 50 | ARN Innovation

SMB1001 Certification Services Australia

CyberPulse helps Australian small and medium businesses achieve SMB1001 certification, the tiered Australian cyber security standard built specifically for SMBs. We provide end-to-end support across all five tiers, from Bronze through to Diamond, covering readiness assessment, control implementation, and attestation or independent audit through CyberCert. Our fixed-price engagements give you a clear, achievable path to a recognised cyber security certificate that customers, partners, and insurers understand.

Trusted by leading Australian organisations

CyberPulse clients include Minter Ellison, Veolia, Sydney Roosters, Utopia Digital and Meshed.

Minter Ellison - CyberPulse clientVeolia - CyberPulse clientSydney Roosters - CyberPulse clientUtopia Digital - CyberPulse clientMeshed - CyberPulse client

SMB1001 Certification Support for Australian Businesses

SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses, published by Dynamic Standards International and certified through CyberCert. Rather than a single pass or fail, it offers five graded tiers, so a business can certify at the level that matches its size, risk, and customer requirements, and step up over time. It is a realistic alternative for SMBs that find enterprise frameworks such as ISO 27001 too heavy, or the ASD Essential Eight hard to evidence on their own.
CyberPulse delivers SMB1001 readiness and certification support end to end, applying the same fixed-price, evidence-led model we use across our ISO 27001 and Essential Eight engagements. We help you choose the right tier, implement the controls it requires, and complete either the self-attestation at Bronze, Silver and Gold or the independent audit at Platinum and Diamond, so certification is straightforward rather than another project that stalls.

Free readiness checklist
The SMB1001 Tier and Controls Readiness Checklist
✓  All five tiers (Bronze to Diamond) and what each requires, in plain English
✓  Which tier your customers and insurers are likely to expect
✓  How to map your existing IT and security practices across the controls
Get your copy
No spam. Unsubscribe anytime.

Why SMB1001?

For a small or medium business, SMB1001 turns cyber security from an all-or-nothing project into a clear, staged path. It gives you a recognised certificate to show customers and insurers, at a level and cost that fits your business.

Built for small and medium businesses

SMB1001 is designed around the reality of businesses without a dedicated security team, so its requirements are practical and achievable rather than assuming enterprise resources.

Certify at the right level for you

Five tiers from Bronze to Diamond let you certify at a level that matches your size, risk, and customer needs, and move up as your business grows.

Answer supply chain and tender questions

A recognised certificate lets you demonstrate a security baseline to larger customers and partners without completing a lengthy, bespoke questionnaire every time.

A realistic step before ISO 27001

For businesses that find ISO 27001 too heavy, SMB1001 provides a graded, lower-cost path that still builds genuine security maturity.

Build on what you already have

Much of what SMB1001 asks for aligns with good IT practice and the ASD Essential Eight. We map your existing controls across so you certify efficiently.

Independent assurance at the top tiers

Platinum and Diamond require an independent audit, giving higher-risk businesses and their customers stronger, externally verified assurance.

Our track record in numbers

350+
Satisfied clients
500+
Certifications achieved
400+
Security assessments conducted

Why SMB1001 Matters Now for Australian SMBs

Cyber risk for small and medium businesses keeps rising, and larger customers, insurers, and government buyers increasingly ask suppliers to demonstrate a security baseline. SMB1001 gives SMBs a way to answer that demand without the cost and complexity of enterprise certification. The standard is revised annually to stay current, and the SMB1001:2026 edition added requirements such as mandatory cyber insurance at the Gold tier, according to the standard’s publisher. Certifying now gives you a credential to put in front of customers and insurers today, and a clear path to raise your tier as expectations grow.

Some of the frameworks we support

ISO 27001ISO 42001AICPA SOC 2PCI DSSACSC Essential EightAPRA CPS 234NIST

Value of SMB1001

SMB1001 gives small and medium businesses something enterprise frameworks rarely offer: a security certificate that is achievable, affordable, and recognised. It lets you prove a baseline to customers and insurers at a tier that fits your business today, backed by a standard whose development steering group includes the Australian Signals Directorate, the Insurance Council of Australia, and major Australian firms. CyberPulse helps you certify at the right level and step up as your needs grow.

CyberPulse’s SMB1001 Approach

Assess | Implement | Certify

We make SMB1001 certification clear and achievable with fixed-cost engagements and award-winning expertise.

Control Implementation

  • Implement the controls the tier requires, such as backups, updates, MFA and EDR at Gold

  • Put the required policies and registers in place

  • Deliver staff awareness where the tier requires it

  • Assemble the evidence for attestation or audit

Certification | Attestation or Audit

  • Complete self-attestation for Bronze, Silver or Gold

  • Coordinate independent audit via CyberCert for Platinum or Diamond

  • Support you through evidence and any findings

  • Plan annual recertification and tier progression

The SMB1001 Certification Process

SMB1001 certification follows a clear path from choosing the right tier through to attestation or independent audit. For most small and medium businesses the lower tiers can be achieved quickly once the controls are in place, while the higher tiers involve an independent audit through CyberCert. CyberPulse manages the journey end to end, so you certify at the right level with evidence that stands up.

1

Tier Selection and Scoping

We work out which tier fits: what your customers, insurers and tenders expect, and what is realistic for you now. We define what is in scope so the assessment is accurate and efficient.

2

Gap Assessment

We assess your current practices against the chosen tier's controls, identify the gaps, and produce a prioritised remediation plan with clear owners and timeframes.

3

Control Implementation and Evidence

We implement or strengthen the required controls and gather the evidence the certification needs. Depending on the tier, this spans backups, updates, multi-factor authentication, access control, endpoint protection, incident response, and staff awareness.

4

Attestation or Independent Audit

For Bronze, Silver and Gold, a business owner or director attests that the controls are in place. For Platinum and Diamond, we coordinate an independent audit through CyberCert and support you through it.

5

Certification and Annual Renewal

On success, the certificate is issued. We hand over an evidence pack and a plan to maintain the controls, support annual recertification, and help you step up a tier when your customers or growth call for it.

CyberPulse supports Australian small and medium businesses through every stage of this process, from tier selection through to certification and ongoing managed compliance. Our fixed-cost delivery model gives you predictable budgets and clear milestones at each phase.

Find out more about our SMB1001 services

Book a free 30-minute SMB1001 readiness call

The SMB1001 Tiers Explained

SMB1001 is a graded standard with five tiers. Each builds on the one below, so you can start where you are and step up over time. The right tier depends on your size, risk, and what your customers and insurers expect. Exact control requirements are set by the current SMB1001 edition and confirmed through CyberCert.

Bronze

Foundational controls covering everyday hygiene: engaging IT support, firewalls and antivirus, automatic updates, sound password practices, and regular data backups. A practical entry point for the smallest businesses, achieved by self-attestation.

Silver

Builds on Bronze with additional baseline controls, raising the bar on core security hygiene for businesses that need to show a little more. Achieved by self-attestation.

Gold

A substantial step up: endpoint detection and response across devices, email authentication, a written incident response plan, an asset register, staff training, and, in the 2026 edition, mandatory cyber insurance. A common target where customers or insurers expect real assurance.

Platinum

Introduces independent verification: external audit, vulnerability scanning of internet-facing systems, and formal data-protection requirements, for businesses handling higher-risk data.

Diamond

The highest tier: penetration testing, rehearsed incident-response exercises, and structured supplier due diligence, for SMBs that need to demonstrate strong, externally verified security.

Not sure which tier you need? CyberPulse helps you choose the right SMB1001 tier for your customers, insurers and risk, then implement the controls and certify. We map your existing IT and Essential Eight practices across so you reach your target tier efficiently.

Why CyberPulse?

Expertise

Award-winning consultants with deep ISO 27001, SOC 2 and Essential Eight expertise, applied to help SMBs certify against SMB1001

Fixed-Price

Fixed-price delivery model with predictable costs and timelines

Support

End-to-end support, from tier selection through attestation or audit and annual renewal

What They Say About Us

The managed service model delivers that, while freeing my team from the bulk of compliance coordination effort and lifting the quality of both controls and supporting evidence. The outcome is a programme with the capacity to mature further and to take on new certification frameworks proactively, ahead of client and regulatory triggers.
Sunil SaaleChief Information Security Officer, MinterEllison
What stands out is the depth of expertise. CyberPulse brings real command of the standards and the threat landscape, and applies it with judgement rather than box-ticking. Year on year they strengthen our security and compliance maturity and give leadership confidence that risk is genuinely understood, not just documented.
Raghu GandhyChief Information Security Officer, Veolia
CyberPulse gave us clarity we didn't have before, not just on where we stood but a practical path forward. The roadmap they delivered has become the foundation of how we think about security investment.
Jimmy O'ReganHead of IT, Major NRL Club & Hospitality Group
Their guidance was practical, clear, and always grounded in what actually mattered for our business. They didn't just help us tick boxes; they helped us build a security posture we're genuinely proud of. If you're serious about enterprise-grade security, I can't recommend Cyber Pulse highly enough.
Aaron TraylenCo-Founder, Utopia Digital

SMB1001 Certification Cost

SMB1001 is designed to be affordable for small and medium businesses. The total cost has two parts: the certification fee, which depends on the tier, and the readiness and implementation work to meet that tier's controls. CyberPulse delivers the second part on a fixed price.

1

Tier Selection and Readiness

Choosing the right tier, assessing current controls against it, and planning remediation. This scales with the tier you target and how far current practices sit from it.

2

Control Implementation

Implementing the controls the tier requires. Lower tiers focus on core hygiene such as backups, updates and multi-factor authentication; higher tiers add endpoint detection and response, incident response, and the requirements that support independent audit.

3

Certification Fee

Paid to the certification body. As a guide, industry sources put 2026 SMB1001 annual fees from around AUD 95 at Bronze up to around AUD 5,995 at Diamond, reflecting the move from self-attestation at the lower tiers to independent audit at Platinum and Diamond.

What Does SMB1001 Certification Cost?

SMB1001 is deliberately low-cost at the entry tiers. Industry sources put 2026 annual certification fees from around AUD 95 for Bronze up to around AUD 5,995 for Diamond, reflecting the move from self-attestation at the lower tiers to independent audit at Platinum and Diamond. For most small and medium businesses the larger consideration is the readiness and implementation work, which CyberPulse delivers on a fixed price once we have confirmed your target tier and scoped your environment.

From AUD 95 / year

CyberPulse provides fixed-price SMB1001 readiness and certification support Australia-wide. Contact us for a scoped estimate based on your target tier and current controls.

FAQ – SMB1001 Certification

What is SMB1001?

SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it offers five graded tiers so a business can certify at the level that matches its size, risk, and customer requirements.

What are the SMB1001 tiers?

SMB1001 has five tiers in ascending order: Bronze, Silver, Gold, Platinum, and Diamond. Each builds on the one below, from foundational hygiene at Bronze up to independent audit, vulnerability scanning and penetration testing at the higher tiers.

Which SMB1001 tier do I need?

It depends on your size, the sensitivity of the data you hold, and what your customers, insurers and tenders expect. Many small businesses start at Bronze or Silver, Gold is a common target where customers expect real assurance, and Platinum or Diamond suit higher-risk businesses. CyberPulse helps you choose.

How is SMB1001 certified?

The lower tiers (Bronze, Silver, Gold) use self-attestation, where a business owner or director attests that the controls are in place. The top tiers (Platinum, Diamond) require an independent audit. Certification is administered through CyberCert.

How does SMB1001 compare to the Essential Eight and ISO 27001?

The ASD Essential Eight is a self-assessed maturity model with no certificate, and ISO 27001 is an audited, pass-or-fail international standard. SMB1001 sits between them as a graded, certified standard built for SMBs, offering a realistic path for businesses that find ISO 27001 too heavy.

Is SMB1001 mandatory in Australia?

No. SMB1001 is not named in Australia’s Cyber Security Act 2024 and is not an Australian Standard published by Standards Australia. Its value is as a recognised, achievable credential for demonstrating a security baseline to customers, partners, and insurers.

How long is SMB1001 certification valid?

SMB1001 requires annual recertification. The standard is also revised each year, so recertification is assessed against the current edition, such as SMB1001:2026.

Who publishes SMB1001?

SMB1001 is published by Dynamic Standards International (formerly Cyber Security Certification Australia) and certified through CyberCert. Its development steering group includes a range of Australian organisations.

How long does SMB1001 certification take?

The lower tiers can often be achieved quickly once the required controls are in place. The higher tiers take longer because they involve an independent audit. Businesses with good IT hygiene, or existing Essential Eight practices, typically move faster.

Does CyberPulse issue SMB1001 certificates?

CyberPulse provides end-to-end readiness and implementation support, helps you choose the right tier, and prepares your evidence. Certification is completed through CyberCert, with self-attestation at the lower tiers and independent audit at Platinum and Diamond.

Ready to get SMB1001 certified?

Contact us for a complimentary SMB1001 readiness session.

No obligation. A 30-minute call with a consultant.

What is SMB1001?

SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it is revised annually to stay current, with SMB1001:2026 the edition certifiable from January 2026.
Instead of a single pass or fail, SMB1001 offers five graded tiers: Bronze, Silver, Gold, Platinum, and Diamond. Each tier builds on the one below, moving from foundational hygiene such as backups, updates, and multi-factor authentication at the lower tiers, up to endpoint detection and response, independent audit, vulnerability scanning, and penetration testing at the higher tiers. Businesses certify at the tier that matches their size, risk, and customer requirements, and can step up over time. The lower tiers use self-attestation, while the top tiers require an independent audit.
SMB1001 is not an Australian Standard published by Standards Australia, and it is not named in Australia’s Cyber Security Act 2024. Its value is as a recognised, achievable credential that lets a small or medium business demonstrate a security baseline to customers, partners, and insurers. CyberPulse helps Australian SMBs choose the right tier, implement the controls, and certify through the appropriate route.