Cyber Security
SMB1001:2027: Gold is a paperwork year, Platinum is a capability year
Dynamic Standards International released SMB1001:2027 to members ahead of its general availability, and DJC has been working from it since we joined the programme as a Founding Mission Supporter. We have now read it against the 2026 edition line by line.
The headline most people will give you is “AI has arrived in the standard”. That is half right, and the half that is wrong matters if you are budgeting.
Here is what actually changed at the two tiers most Australian businesses certify to, and, more usefully, what each change costs you.
Gold: one new control, and a lot of tightened wording
Gold goes from 27 controls to 28. The single addition:
You must now test your incident response plan, not just write one. Gold has required a documented response plan for some time. The 2027 edition adds a control requiring training that exercises it.
That is the entire list of new controls at Gold.
Fourteen existing Gold controls were revised. The ones worth knowing about:
- The asset register now covers IT and physical assets. It used to be a digital asset register. If yours is a list of laptops and cloud services, it needs widening.
- Patching language tightened, both for devices and for servers.
- Anti-malware replaces antivirus in the wording, which is a nudge away from signature-only products.
- Password hygiene, individual accounts, the password manager, RDP over VPN, email authentication, the cyber policy and the AI use policy all got revised guidance.
None of that requires new technology. If you are certified at Gold today and your provider is doing their job, your 2027 renewal is a tabletop exercise, a wider asset register, and a careful re-read of the guidance on controls you already hold.
It is not free, though. Recertification is an annual cost in its own right: CyberCert’s published fee at Gold is $395 a year ex GST, plus whatever your provider charges to prepare the evidence and run the assessment with you. What the 2027 edition does not add at Gold is a new product to buy.
Gold is a paperwork year.
Platinum: three of the five additions need technology
Platinum goes from 32 controls to 37. The five additions:
| New at Platinum | What it actually takes |
|---|---|
| Application control | Whitelisting, moved down from Diamond. Weeks of tuning in a live environment |
| Mobile device management | Devices enrolled and centrally managed, Intune or equivalent |
| Network segmentation between IT, IoT and OT | VLANs and firewall rules, sometimes new switching |
| AI governance framework | Documentation, beyond the AI policy you already hold at Gold |
| Testing the incident response plan | The same exercise Gold now requires |
Two of those are documentation and discipline. Three are engineering.
Application control is the one to plan for. Whitelisting means the business runs only approved software, and getting there in a working environment is not a configuration change you make on a Friday afternoon. You inventory what people actually run, build the rules, run in audit mode, find the shadow IT nobody declared, and tune until the false positives stop. In most businesses that is weeks, not days. It was a Diamond requirement; now it sits at Platinum.
Network segmentation between IT, IoT and OT is the one we have been arguing for anyway. We wrote about it a fortnight ago: printers, cameras, door controllers and production equipment have no business sharing a flat network with the laptops that open email. The standard now agrees, at Platinum and above.
Platinum is a capability year, and it moves your ongoing costs as well as your project costs. Application control and mobile device management are not one-off builds: somebody has to maintain the rules, approve new software, and enrol new devices, month after month. If your current licensing does not cover the tooling, that is a per-user cost on top.
The step up is real in both directions. Our own tier pricing moves $5 per person between Gold and Platinum, while CyberCert’s annual fees go from $395 to $595 plus a $3,000 audit, and the uplift project is the biggest number of the three. Anyone quoting you Platinum as “a bit more than Gold” has not priced application control.
So where did AI actually land?
Worth being precise, because the competing summaries have been loose about this.
- A policy for the responsible and secure use of AI technology has applied at Gold since the 2026 edition. If you certified at Gold this year, you should already have one.
- An AI governance framework is new at Platinum in 2027. A framework is not a policy: it is who decides, how tools get approved, what gets reviewed and how often.
- Control of unauthorised AI use is new at Diamond. In practice that means knowing when staff sign up to AI tools on their own, which needs discovery tooling rather than a document.
So yes, AI is in the standard from Gold up. It has been for a year at the policy level. What 2027 adds is governance and enforcement as you climb.
What we would do about it
If you are certified at Gold: diarise an incident response exercise before your renewal, widen the asset register, and read the revised guidance on the controls you already hold. Budget for recertification as you would any year; the 2027 edition does not add a product to buy.
If you are at Platinum, or aiming for it: scope application control now. It is the longest-running item on the list and the one most likely to surprise a budget. Mobile device management and segmentation are well-trodden projects by comparison.
If you are certifying for the first time: the tier your customer asks for is the tier you need, and the gap between Gold and Platinum is now wider in effort than the price difference suggests. That is worth knowing before you commit to a date in a tender response.
If your certificate is current: it runs its full term. Your renewal date is your 2027 deadline.
The honest caveat
Every control reference here is read from the standard itself, SMB1001:2027 v1.0 and SMB1001:2026 v1.0, published by Dynamic Standards International, who are its custodian. Certification is issued by CyberCert, independently of us. We are certified to Diamond ourselves and a DSI Founding Mission Supporter, which is how we have the 2027 edition early. Being a supporter funds the work to make the standard free for small businesses; it does not make us a certifier, and nothing here is an endorsement by DSI.
Book Your Free SMB1001 Readiness Check: 20 minutes with me or Julian. We will tell you which tier your customers are actually asking for, what your gap looks like under the 2027 controls, and what it costs to close. If the answer is that you are closer than you think, we will say so.