LIMITED OFFER: $5,000 Free Cybersecurity Consulting plus SMB1001 Certification for qualifying Australian SMBs.

Cybercert
SMB1001 Gold Certified

SMB1001 Cybersecurity Certification for Australian SMBs

SMB1001 is the Australian cyber security certification standard built specifically for small and medium businesses. Maintained by Dynamic Standards International and delivered through CyberCert as an independent certification platform, it gives SMBs a tiered, certifiable path from Bronze to Diamond without the overhead of an ISO 27001 information security management system.

This guide explains what SMB1001 is, how its five tiers work, where it sits alongside the ASD Essential Eight and ISO 27001, and how Oxana implements the controls and prepares your evidence so certification is a formality rather than a scramble.

Cybercert

CERTIFICATE

This is to certify that

Oxana Pty Ltd

ABN: 22675969294

SMB1001
GOLD
LEVEL 3

Certificate ID: 0125300002267596929AT

Issue Date: 21 Oct 2025

Expiry Date: 22 Oct 2026

What is SMB1001?

SMB1001 (sometimes written SMB 1001) is a tiered cyber security certification standard built specifically for small and medium businesses. The SMB1001 standard is maintained by Dynamic Standards International (DSI), a standards body with an office in Canberra, and certification is delivered through CyberCert as an independent certification platform.

The standard exists because the alternatives do not fit. ISO 27001 assumes you have a security team, a budget measured in tens of thousands, and twelve months to build a full information security management system. The ASD Essential Eight is a strong technical baseline, but there is no certificate at the end of it, so you cannot hand a client anything that proves you did the work.

SMB1001 sits deliberately in that gap. It is prescriptive rather than principles based, which means it tells you what to actually do. It is certifiable, so you finish with evidence you can put in a tender response. And it is tiered, so a fifteen person practice and a hundred and eighty person business can both start somewhere sensible. That is what makes SMB1001 cyber certification a practical choice rather than an academic one.

The standard is versioned and revised regularly to keep pace with the threat landscape, which is one of its genuine advantages over frameworks that update every few years. Always confirm the current SMB1001 requirements with CyberCert before you begin, and we will do that as part of your readiness assessment.

Which Australian businesses need SMB1001 certification

SMB1001 was written for businesses that are too small to justify ISO 27001 but increasingly asked to prove their cyber security posture anyway. In practice the businesses that benefit most fall into a few clear categories.

Law firms and professional services

Law practices carry an ethical duty to protect client confidentiality. The Queensland Law Society explicitly recommends SMB1001 Gold, and the standard is fast becoming the benchmark for conveyancers, accountants and advisors handling sensitive client data.

Government and enterprise supply chain

If you sell into Commonwealth, state or local government, or into enterprise procurement that runs formal vendor assessments, SMB1001 gives you a recognised certificate that satisfies the cyber security questions in tender responses and vendor questionnaires.

Businesses renewing cyber insurance

Australian cyber insurers have tightened underwriting. A recognised certification gives an underwriter evidence of a documented, assessed posture, which can reduce premiums and avoid restrictions or refusal at renewal.

Accountants and bookkeepers

Practices handling client identifiers, financial data and ATO portal access carry real data risk. SMB1001 controls cover access management, backup and the device hardening that protects both your clients and your professional indemnity position.

Healthcare and allied health

Allied health, specialist practices and NDIS providers hold sensitive personal and health information under the Privacy Act. SMB1001 aligns with APP 11 and the Notifiable Data Breaches scheme, supporting your privacy obligations in one coordinated programme.

Software vendors and managed services

Technology vendors whose own customers run security questionnaires increasingly need their own certification. SMB1001 Bronze or Silver is often enough to clear that bar without the cost and complexity of an ISO 27001 audit.

The five SMB1001 certification levels

The SMB1001 cybersecurity framework uses five progressive tiers. Each builds on the one below it. You are not required to climb all five, and most Australian SMBs certify at SMB1001 Bronze or SMB1001 Silver first, then step up to SMB1001 Gold as contracts demand it.

Bronze

Foundational technical controls. Antivirus, firewall configuration, multi factor authentication on key accounts, regular patching and secure email settings. Achievable through self assessment with a director attestation, meaning a company director formally confirms the controls are in place. This is the minimum credible baseline for any business operating online.

Silver

Adds access control discipline, structured backup practices and a basic incident response procedure. You define who has access to what, and you validate that your backups actually restore. Silver is where most businesses stop guessing and start knowing.

Gold

Introduces holistic risk management across people, process and technology. Risks are identified, assessed and treated in a coordinated way rather than ad hoc. The Queensland Law Society recommends Gold as a reasonable standard for its members, which gives you a sense of where professional services expectations are landing.

Platinum & Diamond

Advanced governance procedures with external audit. The SMB1001 audit at these tiers suits businesses with genuine supply chain obligations, sensitive data holdings or enterprise customers running formal vendor assessments.

Five practical control domains

The controls span five practical domains: technology management, access management, backup and recovery, policies and processes, and education and training. Backup and recovery appears from Bronze upward, at every single tier. It is the control no business escapes, and in our experience it is the one most SMBs quietly fail.

Why Australian businesses are certifying now

Supply chain pressure

Larger organisations are scrutinising their suppliers. If you sell into government, healthcare, financial services or any listed company, you are being assessed whether you know it or not.

Insurance

Australian insurers have tightened underwriting. Businesses without documented controls face higher premiums, restricted cover or refusal. SMB1001 gives an underwriter evidence of measurable maturity across defined control domains rather than a completed questionnaire and a hope.

Professional obligations

Law firms have an ethical duty to take reasonable steps to protect client confidentiality. Accountants, brokers and allied health practices carry similar duties. What counts as reasonable has always been vague. A certificate makes it concrete.

Privacy law

SMB1001 aligns with the Privacy Act 1988, Australian Privacy Principle 11 and the Notifiable Data Breaches scheme. Implementing the controls supports those obligations without running a separate compliance programme alongside, which is why SMB1001 compliance appeals to lean teams.

SMB1001 vs Essential Eight vs ISO 27001

These get treated as competing choices. They are not.

Essential Eight

Published by the Australian Cyber Security Centre. Eight technical mitigation strategies with a maturity model (often written Essential 8). Regulators and insurers understand the language. There is no certification.

ISO 27001

The international standard for information security management. Comprehensive, credible, and genuinely heavy. It assumes resources most SMBs do not have.

SMB1001

Designed for businesses under roughly 200 staff. It maps to Essential Eight controls and shares structural elements with ISO 27001, which makes it an effective stepping stone in both directions.

The practical answer for most Australian SMBs: use Essential Eight to define what good looks like at the technical layer, use the SMB1001 framework to wrap those controls in governance, policy, training and incident response, and to produce something you can actually show someone. If ISO 27001 becomes a requirement later, the higher SMB1001 tiers have already built most of the foundation.

We advise on all three, and we will tell you honestly if SMB1001 is not the right starting point for your situation.

How Oxana delivers SMB1001 certification support

We are a Microsoft Cloud Solutions Partner. Most of the SMB1001 controls map directly onto the Microsoft stack your business is already paying for, which means certification is usually less about buying new tools and more about configuring properly what you already own.

1

Gap assessment

We assess your current posture against your target tier and give you a written gap report. No sales theatre. You will see exactly which controls you already meet, which are close and which need real work, with an effort estimate against each.

2

Tier selection

We recommend the tier that matches your contracts, your risk and your budget. Certifying at Gold when your clients ask for Bronze wastes money. Certifying at Bronze when your tenders demand Gold wastes time.

3

Control implementation

This is where the work happens. Multi factor authentication and conditional access through Microsoft Entra ID. Device compliance and application control through Intune. Managed detection and response through Huntress. Data classification and retention through Microsoft Purview. Email authentication including SPF, DKIM and DMARC enforcement, covering the SMB1001 DMARC requirements. Backup and recovery for Microsoft 365 data, which native retention does not cover the way most people assume it does. Security awareness training your staff will actually complete.

4

Evidence preparation

Certification requires evidence, not assertions. We assemble the documentation, screenshots, policies and attestations your tier requires so the workbook is a formality rather than a scramble.

5

Certification

You register on the CyberCert platform, complete the workbook for your tier and receive your certificate and badge. We sit alongside you for it.

6

Ongoing maintenance

Certification is a subscription, not a trophy. Controls drift, staff change, threats move. We keep your posture current and support you upward through the tiers as your contracts require.

Why work with Oxana

We are the IT team behind your IT team. If you have internal IT, we support them rather than replace them. If you do not, we are your IT function.

We support Australian SMBs across Sydney, Melbourne and Brisbane. We are a Microsoft Cloud Solutions Partner, so the security stack we implement is the one Microsoft built, integrated properly rather than bolted together from six vendors.

And we do not sell certification as a product. We sell the security work that makes certification a by product. That is SMB1001 consulting the way it should be done. The certificate matters because it opens doors. The controls matter because they keep you trading.

SMB1001 frequently asked questions

How much does SMB1001 certification cost?

Certification fees are set by CyberCert and vary by tier. The larger cost is usually the remediation work needed to meet the controls, which depends entirely on where you are starting. Our gap assessment gives you both numbers before you commit to anything.

How long does SMB1001 certification take?

Bronze can be achieved in weeks if your fundamentals are sound. Silver and Gold typically take one to three months depending on how much remediation is required. Platinum and Diamond involve external audit and take longer.

Is SMB1001 mandatory in Australia?

No. It is not legislated. It is increasingly a commercial requirement, which in practice is often the same thing.

Does SMB1001 satisfy Essential Eight?

SMB1001 maps to Essential Eight controls and is an effective entry point if you are working toward Essential Eight maturity, but they are separate frameworks with separate assessments.

Can we start at Silver or Gold instead of Bronze?

Yes. Enter at the tier that reflects your current maturity. You are not required to work through all five.

Do we need SMB1001 if we already hold ISO 27001?

Generally no. ISO 27001 is the more comprehensive standard. SMB1001 is the sensible path for businesses that are not there yet.