SMB1001 Certification

Get SMB1001 certified, at the tier your business actually needs

Your customers, your insurer or your next tender have asked you to prove your cyber security position. SMB1001 is how Australian SMBs do that. DJC takes you from wherever you are today to certified, and we are certified at Diamond ourselves, the highest tier the standard offers.

Book Your Free SMB1001 Readiness Check

SMB1001 is an Australian tiered cyber security standard published by Dynamic Standards International and certified through CyberCert, its official certifier. The standard is revised annually, and the current edition is SMB1001:2026. It exists because the honest answer for most small and medium businesses was never ISO 27001. That standard is demanding, expensive and slow, and for a fifty person business being asked by a customer to demonstrate basic security maturity, it is the wrong tool.

SMB1001 gives you a proportionate path: five tiers, ascending in rigour, each producing a certification you can actually put in front of the person asking. It is increasingly what sits behind cyber insurance questions and supplier security assessments, which is why most businesses meet it for the first time as a requirement rather than a choice.

We help you meet it properly. Not a checklist exercise that produces a certificate and changes nothing, but the underlying work, so that the security position is real and recertification a year later is routine. See how this fits alongside our broader cyber security services and compliance work.

The five SMB1001 tiers

The tiers ascend in rigour, from an entry level baseline through to independently audited certification. Certifying higher than you need costs money and time you will not get back, so the first job is working out which rung actually satisfies whoever is asking.

Bronze

Entry

The baseline. Establishes that fundamental cyber hygiene is in place and documented, which is often all a smaller supplier is asked to demonstrate.

Silver

Building

Builds on the baseline with broader coverage. The common landing point for businesses that have been asked for evidence by a customer or insurer.

Gold

Established

A mature, documented security position. Typically where businesses land when certification is tied to winning or holding larger contracts.

Platinum

Audited

Independently verified rather than self-attested. This is the tier where certification starts to carry real weight in tenders, and where the cost of managed IT rises to match the controls required.

Diamond

Highest

The most rigorous tier in the standard, for businesses whose customers or regulators demand the strongest available assurance short of ISO 27001.

Requirements for each tier are set by Dynamic Standards International, and we confirm them against the current published criteria as part of your gap assessment, so you are working from what the standard asks today rather than what it asked last year.

How DJC gets you certified

1

Gap assessment

We measure your current position against the tier you actually need, not the one that sounds impressive. You get a written gap list with the work ranked by effort and risk.

2

Remediation

We close the gaps. Access control, backup and recovery, patching, logging, staff process and the documentation the assessment asks for. This is delivery work, not a report handed back to you.

3

Certification

We prepare the evidence and take you through assessment for your tier, then keep the controls in place afterwards so recertification is not a scramble.

Why DJC

We hold the top tier ourselves

  • SMB1001 Diamond certified, plus ISO 27001 and ISO 9001. Most providers offering SMB1001 support have never been through the certification themselves. We have, at Diamond, the highest tier the standard offers. Whatever tier you are going for, we have already been further, so we are advising you from experience rather than from the assessment paperwork.
  • We do the remediation, not just the assessment. Plenty of consultants will tell you where your gaps are and leave you to find someone to close them. We are a managed services provider, so the same team that finds the gap fixes it and keeps it fixed.
  • Certification that survives the year after. A certificate is a point in time. Controls decay, staff change, systems drift. Because we manage environments day to day, the controls behind your certification stay maintained rather than quietly lapsing until recertification comes around.
  • Owner-led since 1999. Daniel and Julian Church built DJC on fewer clients and deeper relationships, backed by a national team. Your certification is a commitment made by the people who own the business.
Book Your Free SMB1001 Readiness Check

Quick answers

What is SMB1001?

SMB1001 is an Australian tiered cyber security standard for small and medium businesses. It is published by Dynamic Standards International and certified through CyberCert, its official certifier. It runs across five tiers, Bronze, Silver, Gold, Platinum and Diamond, and is designed to be more achievable for an SMB than ISO 27001 while still giving customers, insurers and tender panels a credible measure of your security position.

Which SMB1001 tier does my business need?

It depends on what is driving the requirement. A supplier being asked for basic assurance and a business bidding for enterprise or government work are not headed to the same tier. Certifying higher than you need costs money and time you will not get back, so the first step in our program is establishing the tier that actually satisfies your customers, insurer or tender requirements.

How is SMB1001 different from the Essential Eight?

The ASD Essential Eight is a set of eight technical mitigation strategies measured by maturity level. SMB1001 is a broader certification covering technical controls alongside process and governance, and it results in a certification you can show someone. They work together, and most of the Essential Eight work we do for clients also counts toward their SMB1001 position.

Is SMB1001 the same as ISO 27001?

No. ISO 27001 is an international information security management standard and is considerably more demanding to achieve and maintain. SMB1001 is designed as a more proportionate path for small and medium businesses. DJC holds both: we are certified at SMB1001 Diamond, the highest tier the standard offers, and we hold ISO 27001 and ISO 9001 as well. So whichever tier you are aiming at, we have already been through the process ourselves.

Do we have to be a DJC managed services client to get certified?

No. SMB1001 certification support is available as a standalone engagement. It does tend to work better where we also manage or co-manage the environment, because most of the controls the standard asks about are things somebody has to maintain after the certificate is issued.

How long does SMB1001 certification take?

The honest answer is that it depends entirely on your starting position and the tier you are targeting. A business with reasonable existing hygiene aiming at a lower tier is a very different job from one starting cold and targeting an audited tier. The gap assessment is what turns this into a real timeline, and it is the first thing we do.