Winner, TechNews Fast 50 | ARN Innovation
SMB1001 Certification Services Australia
CyberPulse helps Australian small and medium businesses achieve SMB1001 certification, the tiered Australian cyber security standard built specifically for SMBs. We provide end-to-end support across all five tiers, from Bronze through to Diamond, covering readiness assessment, control implementation, and attestation or independent audit through CyberCert. Our fixed-price engagements give you a clear, achievable path to a recognised cyber security certificate that customers, partners, and insurers understand.
Trusted by leading Australian organisations
CyberPulse clients include Minter Ellison, Veolia, Sydney Roosters, Utopia Digital and Meshed.





SMB1001 Certification Support for Australian Businesses
SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses, published by Dynamic Standards International and certified through CyberCert. Rather than a single pass or fail, it offers five graded tiers, so a business can certify at the level that matches its size, risk, and customer requirements, and step up over time. It is a realistic alternative for SMBs that find enterprise frameworks such as ISO 27001 too heavy, or the ASD Essential Eight hard to evidence on their own.
CyberPulse delivers SMB1001 readiness and certification support end to end, applying the same fixed-price, evidence-led model we use across our ISO 27001 and Essential Eight engagements. We help you choose the right tier, implement the controls it requires, and complete either the self-attestation at Bronze, Silver and Gold or the independent audit at Platinum and Diamond, so certification is straightforward rather than another project that stalls.
Free readiness checklist The SMB1001 Tier and Controls Readiness Checklist ✓ All five tiers (Bronze to Diamond) and what each requires, in plain English ✓ Which tier your customers and insurers are likely to expect ✓ How to map your existing IT and security practices across the controls | Get your copy No spam. Unsubscribe anytime. |
Why SMB1001?
For a small or medium business, SMB1001 turns cyber security from an all-or-nothing project into a clear, staged path. It gives you a recognised certificate to show customers and insurers, at a level and cost that fits your business.
Built for small and medium businesses
SMB1001 is designed around the reality of businesses without a dedicated security team, so its requirements are practical and achievable rather than assuming enterprise resources.
Certify at the right level for you
Five tiers from Bronze to Diamond let you certify at a level that matches your size, risk, and customer needs, and move up as your business grows.
Answer supply chain and tender questions
A recognised certificate lets you demonstrate a security baseline to larger customers and partners without completing a lengthy, bespoke questionnaire every time.
A realistic step before ISO 27001
For businesses that find ISO 27001 too heavy, SMB1001 provides a graded, lower-cost path that still builds genuine security maturity.
Build on what you already have
Much of what SMB1001 asks for aligns with good IT practice and the ASD Essential Eight. We map your existing controls across so you certify efficiently.
Independent assurance at the top tiers
Platinum and Diamond require an independent audit, giving higher-risk businesses and their customers stronger, externally verified assurance.
Our track record in numbers
Why SMB1001 Matters Now for Australian SMBs
Cyber risk for small and medium businesses keeps rising, and larger customers, insurers, and government buyers increasingly ask suppliers to demonstrate a security baseline. SMB1001 gives SMBs a way to answer that demand without the cost and complexity of enterprise certification. The standard is revised annually to stay current, and the SMB1001:2026 edition added requirements such as mandatory cyber insurance at the Gold tier, according to the standard’s publisher. Certifying now gives you a credential to put in front of customers and insurers today, and a clear path to raise your tier as expectations grow.
Some of the frameworks we support
Value of SMB1001
SMB1001 gives small and medium businesses something enterprise frameworks rarely offer: a security certificate that is achievable, affordable, and recognised. It lets you prove a baseline to customers and insurers at a tier that fits your business today, backed by a standard whose development steering group includes the Australian Signals Directorate, the Insurance Council of Australia, and major Australian firms. CyberPulse helps you certify at the right level and step up as your needs grow.
CyberPulse’s SMB1001 Approach
Assess | Implement | Certify
We make SMB1001 certification clear and achievable with fixed-cost engagements and award-winning expertise.
Tier Selection | Gap Assessment
Confirm the right tier for your size, risk and customers
Assess current practices against that tier’s controls
Identify gaps and quick wins
Prioritise remediation with a clear plan
Control Implementation
Implement the controls the tier requires, such as backups, updates, MFA and EDR at Gold
Put the required policies and registers in place
Deliver staff awareness where the tier requires it
Assemble the evidence for attestation or audit
Certification | Attestation or Audit
Complete self-attestation for Bronze, Silver or Gold
Coordinate independent audit via CyberCert for Platinum or Diamond
Support you through evidence and any findings
Plan annual recertification and tier progression
The SMB1001 Certification Process
SMB1001 certification follows a clear path from choosing the right tier through to attestation or independent audit. For most small and medium businesses the lower tiers can be achieved quickly once the controls are in place, while the higher tiers involve an independent audit through CyberCert. CyberPulse manages the journey end to end, so you certify at the right level with evidence that stands up.
Tier Selection and Scoping
We work out which tier fits: what your customers, insurers and tenders expect, and what is realistic for you now. We define what is in scope so the assessment is accurate and efficient.
Gap Assessment
We assess your current practices against the chosen tier's controls, identify the gaps, and produce a prioritised remediation plan with clear owners and timeframes.
Control Implementation and Evidence
We implement or strengthen the required controls and gather the evidence the certification needs. Depending on the tier, this spans backups, updates, multi-factor authentication, access control, endpoint protection, incident response, and staff awareness.
Attestation or Independent Audit
For Bronze, Silver and Gold, a business owner or director attests that the controls are in place. For Platinum and Diamond, we coordinate an independent audit through CyberCert and support you through it.
Certification and Annual Renewal
On success, the certificate is issued. We hand over an evidence pack and a plan to maintain the controls, support annual recertification, and help you step up a tier when your customers or growth call for it.
Find out more about our SMB1001 services
Book a free 30-minute SMB1001 readiness call
The SMB1001 Tiers Explained
SMB1001 is a graded standard with five tiers. Each builds on the one below, so you can start where you are and step up over time. The right tier depends on your size, risk, and what your customers and insurers expect. Exact control requirements are set by the current SMB1001 edition and confirmed through CyberCert.
Bronze
Foundational controls covering everyday hygiene: engaging IT support, firewalls and antivirus, automatic updates, sound password practices, and regular data backups. A practical entry point for the smallest businesses, achieved by self-attestation.
Silver
Builds on Bronze with additional baseline controls, raising the bar on core security hygiene for businesses that need to show a little more. Achieved by self-attestation.
Gold
A substantial step up: endpoint detection and response across devices, email authentication, a written incident response plan, an asset register, staff training, and, in the 2026 edition, mandatory cyber insurance. A common target where customers or insurers expect real assurance.
Platinum
Introduces independent verification: external audit, vulnerability scanning of internet-facing systems, and formal data-protection requirements, for businesses handling higher-risk data.
Diamond
The highest tier: penetration testing, rehearsed incident-response exercises, and structured supplier due diligence, for SMBs that need to demonstrate strong, externally verified security.
Not sure which tier you need? CyberPulse helps you choose the right SMB1001 tier for your customers, insurers and risk, then implement the controls and certify. We map your existing IT and Essential Eight practices across so you reach your target tier efficiently.
Why CyberPulse?
Expertise
Award-winning consultants with deep ISO 27001, SOC 2 and Essential Eight expertise, applied to help SMBs certify against SMB1001
Fixed-Price
Fixed-price delivery model with predictable costs and timelines
Support
End-to-end support, from tier selection through attestation or audit and annual renewal
Related Services
View all services →What They Say About Us
The managed service model delivers that, while freeing my team from the bulk of compliance coordination effort and lifting the quality of both controls and supporting evidence. The outcome is a programme with the capacity to mature further and to take on new certification frameworks proactively, ahead of client and regulatory triggers.
What stands out is the depth of expertise. CyberPulse brings real command of the standards and the threat landscape, and applies it with judgement rather than box-ticking. Year on year they strengthen our security and compliance maturity and give leadership confidence that risk is genuinely understood, not just documented.
CyberPulse gave us clarity we didn't have before, not just on where we stood but a practical path forward. The roadmap they delivered has become the foundation of how we think about security investment.
Their guidance was practical, clear, and always grounded in what actually mattered for our business. They didn't just help us tick boxes; they helped us build a security posture we're genuinely proud of. If you're serious about enterprise-grade security, I can't recommend Cyber Pulse highly enough.
SMB1001 Certification Cost
SMB1001 is designed to be affordable for small and medium businesses. The total cost has two parts: the certification fee, which depends on the tier, and the readiness and implementation work to meet that tier's controls. CyberPulse delivers the second part on a fixed price.
Tier Selection and Readiness
Choosing the right tier, assessing current controls against it, and planning remediation. This scales with the tier you target and how far current practices sit from it.
Control Implementation
Implementing the controls the tier requires. Lower tiers focus on core hygiene such as backups, updates and multi-factor authentication; higher tiers add endpoint detection and response, incident response, and the requirements that support independent audit.
Certification Fee
Paid to the certification body. As a guide, industry sources put 2026 SMB1001 annual fees from around AUD 95 at Bronze up to around AUD 5,995 at Diamond, reflecting the move from self-attestation at the lower tiers to independent audit at Platinum and Diamond.
What Does SMB1001 Certification Cost?
SMB1001 is deliberately low-cost at the entry tiers. Industry sources put 2026 annual certification fees from around AUD 95 for Bronze up to around AUD 5,995 for Diamond, reflecting the move from self-attestation at the lower tiers to independent audit at Platinum and Diamond. For most small and medium businesses the larger consideration is the readiness and implementation work, which CyberPulse delivers on a fixed price once we have confirmed your target tier and scoped your environment.
CyberPulse provides fixed-price SMB1001 readiness and certification support Australia-wide. Contact us for a scoped estimate based on your target tier and current controls.
FAQ – SMB1001 Certification
What is SMB1001?
SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it offers five graded tiers so a business can certify at the level that matches its size, risk, and customer requirements.
What are the SMB1001 tiers?
SMB1001 has five tiers in ascending order: Bronze, Silver, Gold, Platinum, and Diamond. Each builds on the one below, from foundational hygiene at Bronze up to independent audit, vulnerability scanning and penetration testing at the higher tiers.
Which SMB1001 tier do I need?
It depends on your size, the sensitivity of the data you hold, and what your customers, insurers and tenders expect. Many small businesses start at Bronze or Silver, Gold is a common target where customers expect real assurance, and Platinum or Diamond suit higher-risk businesses. CyberPulse helps you choose.
How is SMB1001 certified?
The lower tiers (Bronze, Silver, Gold) use self-attestation, where a business owner or director attests that the controls are in place. The top tiers (Platinum, Diamond) require an independent audit. Certification is administered through CyberCert.
How does SMB1001 compare to the Essential Eight and ISO 27001?
The ASD Essential Eight is a self-assessed maturity model with no certificate, and ISO 27001 is an audited, pass-or-fail international standard. SMB1001 sits between them as a graded, certified standard built for SMBs, offering a realistic path for businesses that find ISO 27001 too heavy.
Is SMB1001 mandatory in Australia?
No. SMB1001 is not named in Australia’s Cyber Security Act 2024 and is not an Australian Standard published by Standards Australia. Its value is as a recognised, achievable credential for demonstrating a security baseline to customers, partners, and insurers.
How long is SMB1001 certification valid?
SMB1001 requires annual recertification. The standard is also revised each year, so recertification is assessed against the current edition, such as SMB1001:2026.
Who publishes SMB1001?
SMB1001 is published by Dynamic Standards International (formerly Cyber Security Certification Australia) and certified through CyberCert. Its development steering group includes a range of Australian organisations.
How long does SMB1001 certification take?
The lower tiers can often be achieved quickly once the required controls are in place. The higher tiers take longer because they involve an independent audit. Businesses with good IT hygiene, or existing Essential Eight practices, typically move faster.
Does CyberPulse issue SMB1001 certificates?
CyberPulse provides end-to-end readiness and implementation support, helps you choose the right tier, and prepares your evidence. Certification is completed through CyberCert, with self-attestation at the lower tiers and independent audit at Platinum and Diamond.
Ready to get SMB1001 certified?
Contact us for a complimentary SMB1001 readiness session.
No obligation. A 30-minute call with a consultant.
What is SMB1001?
SMB1001 is a tiered cyber security standard designed specifically for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, and it is revised annually to stay current, with SMB1001:2026 the edition certifiable from January 2026.
Instead of a single pass or fail, SMB1001 offers five graded tiers: Bronze, Silver, Gold, Platinum, and Diamond. Each tier builds on the one below, moving from foundational hygiene such as backups, updates, and multi-factor authentication at the lower tiers, up to endpoint detection and response, independent audit, vulnerability scanning, and penetration testing at the higher tiers. Businesses certify at the tier that matches their size, risk, and customer requirements, and can step up over time. The lower tiers use self-attestation, while the top tiers require an independent audit.
SMB1001 is not an Australian Standard published by Standards Australia, and it is not named in Australia’s Cyber Security Act 2024. Its value is as a recognised, achievable credential that lets a small or medium business demonstrate a security baseline to customers, partners, and insurers. CyberPulse helps Australian SMBs choose the right tier, implement the controls, and certify through the appropriate route.