Cybersecurity

SMB1001:2026: what changed, and what it means for your certification

If your business certified against SMB1001, or your customers and insurers are starting to ask whether you will, the standard changed underneath you. The 2026 edition was released in September 2025 and became certifiable in January 2026, and the changes are meaningful, particularly at Gold.

Here is what a director needs to know, without the vendor breathlessness.

The quick version

SMB1001 is Australia’s tiered cyber security standard for small and mid-sized businesses: five levels, Bronze through Diamond, each adding controls. Its genius has always been practicality. Bronze, Silver and Gold are self-attested, meaning a director signs off that the controls are in place, which keeps certification affordable for businesses that could never contemplate ISO 27001.

The 2026 edition tightened the middle of the ladder:

Email authentication is now a certification requirement. SPF from Silver. DKIM and an enforced DMARC policy from Gold. In plain terms: technical proof that email claiming to come from your domain actually does, which is the single most effective control against the invoice-fraud and impersonation attacks flooding Australian SMBs.

Gold grew from 23 controls to 27. The additions matter: endpoint detection and response (EDR) is now mandatory, so antivirus alone no longer cuts it. Cyber insurance is required. And, a sign of the times, a responsible AI use policy is now on the list.

The standard now maps formally to the big frameworks: ISO 27001, the Essential Eight, UK Cyber Essentials, and the US CMMC. That matters if you sell into supply chains that ask about those.

The barrier that is about to drop

Here is the part that matters most if you have been putting this off.

Until now, reading the standard cost money. To see the actual controls, you purchased the framework and it was licensed to you. A director deciding whether to certify was, in effect, asked to commit before being allowed to read what they were committing to.

That ends. Under an initiative DSI calls SMB1001 Unlocked, the standard becomes free to every small business, worldwide, from 1 January 2027.

Be clear about what that does and does not mean. Certification still costs money, and it should: someone has to assess you and issue the certificate. What becomes free is the document setting out what is required. From 2027 a director can read the controls their business will be attested against before spending a cent.

I think this is the right call and a slightly brave one. DSI is an ACNC-registered not-for-profit, and the obvious commercial move would have been to keep charging for the document. Making it free removes the single silliest barrier in SMB security: businesses being unable to find out what good looks like without a purchase order.

It also tells you something about where this standard is heading. A free standard gets read, gets quoted in tenders, and gets asked about by insurers. If your customers are not asking about SMB1001 yet, the odds of that continuing past 2027 are not good.

What this means in practice

If you certified at Gold under the previous edition: your renewal will be against the 2026 controls. The likely gaps for most businesses are DMARC enforcement (most companies have it switched to “monitor” mode, which does not count), EDR if you are still on traditional antivirus, and the AI policy, which most businesses simply do not have yet.

If you were considering certifying: the bar at Gold moved up, and so did the value of the badge, because a Gold certificate now proves more. For many of our clients, customers and insurers are the driving force here; a certificate that maps cleanly to recognised frameworks is becoming a tender-table requirement.

On picking a tier: there is no default answer, and be wary of anyone who gives you one. DSI itself recommends a tier based on your turnover, your staff numbers and the sensitivity of the data you hold. That is the right way round: the tier follows the business, not the seller’s margin.

We hold Diamond ourselves, so we are not talking down a tier we cannot deliver. We are saying the honest answer comes out of those three inputs plus whatever your customers and insurers are actually asking for, and for plenty of businesses that lands well below the top. Higher tiers cost more to run and to maintain, which should be a considered decision rather than an upsell.

The directors’ detail everyone glosses over

Bronze, Silver and Gold are self-attested, and the person doing the attesting is a director. Personally. Through the certification portal.

Think about what that means. When you sign that attestation, you are stating that the controls exist and operate. If an incident later shows they did not, that signature is part of the record. I have watched directors treat the attestation as a formality their IT provider handles. It is not. It is your name.

Our approach: before any client director signs an SMB1001 attestation, we audit the controls as if an assessor were coming, document the evidence, and only then put the paperwork in front of the board. Attestation should be the easiest signature you make all year, because everything behind it is genuinely true.

Where DJC sits on all this

We are certified to SMB1001 Diamond. That is Level 5, the top of the ladder, and unlike the self-attested tiers it requires an independent external audit. We went through it for the same reason we tell clients to certify: you should not advise anyone on a standard you have not been assessed against yourself. Most providers selling SMB1001 hold no tier of it at all.

We also hold ISO 27001 and ISO 9001, which govern how we run the business behind the certificate.

None of that changes what we recommend for you. We align clients to the tier their risk actually justifies, and our security services are built so the controls run continuously rather than being dusted off at renewal time.

The 2026 edition is a good revision of a good standard. It asks a little more, and what it asks for is the right list. If you want the full picture of the tiers and what certification involves, we have a guide to SMB1001 certification.

Book Your Free IT Roadmap Session: 30 minutes with me or Julian. We will map where you stand against SMB1001:2026, alongside your costs and your AI opportunities. You keep the roadmap.

Quick answers

What changed in SMB1001:2026?

Email authentication became a certification requirement (SPF from Silver; DKIM and enforced DMARC from Gold), Gold expanded from 23 to 27 controls including mandatory EDR, cyber insurance and a responsible AI use policy, and the standard now maps formally to ISO 27001, the Essential Eight, Cyber Essentials and CMMC.

When did SMB1001:2026 take effect?

The 2026 edition was released on 1 September 2025 and became certifiable from January 2026.

Is the SMB1001 standard free?

It will be. Under an initiative DSI calls SMB1001 Unlocked, the standard becomes free to read for every small business worldwide from 1 January 2027. Until then it is purchased under licence. Certification remains a paid service either way, because an assessment has to be carried out and a certificate issued.

Do I need to re-certify against the new edition?

Certifications renew annually, so your next renewal will be assessed against the 2026 controls. The common gaps are DMARC enforcement, EDR, and the AI use policy.

Which SMB1001 tier does my business need?

There is no single default tier. Dynamic Standards International recommends a tier based on your turnover, your staff numbers and the sensitivity of the data you hold, alongside whatever your customers and insurers require. DJC works to the tier those inputs justify rather than the highest one available.

Want this working in your business?

Thirty minutes with a DJC owner: your IT cost snapshot, cyber gap check, and AI opportunity map. You keep the roadmap.

Book Your Free IT Roadmap Session