For years, the answer to "which cyber security framework should a small Australian business follow?" was the Essential Eight. With ASD now replacing the Essential Eight with its broader Essentials series, more Perth business owners are asking about SMB1001 instead - usually because an insurer, a customer or a competitor has mentioned it. Here's what it is, how it works, and whether it's the right fit for you.
What Is SMB1001?
SMB1001 is a cyber security standard designed specifically for small and medium businesses. It's published by Dynamic Standards International (DSI), an Australian standards body, and certification is issued through CyberCert. Unlike the Essential Eight, it's a certification: at the end, you have a certificate you can show customers, insurers and tender panels.
It's built around five domains that together cover much more than technology:
- Technology management - patching, endpoint protection, secure configuration.
- Access management - MFA, admin accounts, who can reach what.
- Backup and recovery - backups that exist, are protected, and can actually be restored.
- Policies and processes - written rules for how the business handles security.
- Education and training - making sure staff can recognise and report threats.
DSI revises the standard every year. The current edition at the time of writing is SMB1001:2026, so check which edition you're being assessed against before you start.
The Five Levels, Bronze to Diamond
SMB1001 is cumulative: each level includes everything in the level below it and adds more. That lets a business get certified early and improve in stages, instead of facing one large compliance project.
Bronze
Director self-attestation
Foundational controls. A quick first certificate that proves the basics are in place.
Silver
Director self-attestation
Stronger identity, email and policy controls. A sensible target for most businesses in year one.
Gold
Director self-attestation
27 controls across people, process and technology in the 2026 edition. Where most SMBs should end up.
Platinum
Independent verification
Higher assurance for businesses whose customers or contracts ask for external audit.
Diamond
Independent verification
The top tier. Rarely needed by a typical small business.
The 2026 edition raised the bar at Gold, increasing it from 23 to 27 controls. Published summaries of the changes point to endpoint detection and response (EDR), enforced email authentication (SPF, DKIM and a DMARC policy that actually blocks spoofed mail) and an AI use policy among the additions. Check the current control list with DSI or your assessor before planning your work.
Self-Attestation Isn't a Rubber Stamp
Bronze, Silver and Gold are self-assessed, with a director attesting that the controls are in place. That keeps the cost low, but it means a director is personally signing off on the business's security. If something goes wrong and the controls turn out never to have been in place, that signature becomes a problem - with the insurer, the customer who relied on it, or both.
Treat attestation the way you'd treat signing off on the accounts: have evidence for every control - screenshots of MFA enforcement, a backup restore test, a training record - kept somewhere you can find it next year when you renew.
What Does SMB1001 Cost?
There are two costs, and the certificate is the smaller one.
- Certification fees. The self-attested levels are relatively inexpensive, generally in the range of tens to hundreds of dollars a year. The independently audited levels cost several thousand dollars, because they include an external audit. Check CyberCert's current pricing, as it changes.
- Getting the controls in place. This is where the real cost lies, and it depends entirely on your starting point. A business already on Microsoft 365 Business Premium has most of the tools it needs for Gold - EDR, device management and conditional access - and mainly needs them configured and documented. A business on basic licences with no endpoint protection and no written policies has more work ahead.
SMB1001 vs the Essential Eight
| SMB1001 | Essential Eight | |
|---|---|---|
| Who publishes it | Dynamic Standards International (private) | Australian Signals Directorate (government) |
| Certificate? | Yes, issued through CyberCert | No official certificate - assessed by consultants |
| Designed for | Small and medium businesses | Originally government and large organisations |
| Scope | Technology plus policies, training and backups | Eight technical mitigation strategies |
| Levels | Bronze to Diamond (five levels) | Maturity Levels One to Three |
| Future | Revised annually | Being replaced by ASD's Essentials series over about two years |
The overlap is large. MFA, patching, restricting admin rights and tested backups sit at the heart of both, and DSI publishes mappings between SMB1001 and other frameworks, including the Essential Eight. Work done for one is rarely wasted on the other.
Which Should Your Business Choose?
Choose the Essential Eight (and its successor) if…
A government client, a tender, or your insurer specifically asks for Essential Eight maturity. That requirement won't disappear overnight - see our compliance transition checklist for how to handle the changeover period.
Choose SMB1001 if…
You want a certificate you can put in front of customers, you're being asked about security in supply-chain questionnaires, or you want a staged roadmap sized for a small business rather than a government department. For many Perth SMBs without a specific Essential Eight requirement, it's the more practical choice.
Or do both
Because the controls overlap so heavily, a business working towards SMB1001 Gold will usually be close to Essential Eight Maturity Level One at the same time. Build the controls once and map them to whichever framework each customer asks for.
The Gaps We See Most Often
When we assess small Perth businesses against frameworks like this, the same few items come up again and again:
- Email authentication. SPF is set up but DMARC is missing or stuck on monitoring mode. You can check your own domain in seconds with our free email security checker, and our SPF, DKIM and DMARC guide explains the fix.
- Antivirus instead of EDR. Traditional antivirus doesn't meet the bar. See EDR vs antivirus.
- MFA with exceptions. MFA on most accounts, but not on the shared mailbox, the old admin account, or the finance system. See our MFA setup guide.
- Backups that have never been restored. A backup you haven't tested is an assumption. See how to test your backups.
- No written policies or training records. The controls may exist, but nothing proves it. That's where security awareness training and an AI usage policy come in.
Frequently Asked Questions
Is SMB1001 a government standard?
No. SMB1001 is published by Dynamic Standards International (DSI), an Australian private standards body, and certification is issued through CyberCert. It isn't produced or endorsed by the Australian Signals Directorate. The Essential Eight is ASD's guidance, but it is guidance rather than a certification.
Which SMB1001 level should a small business aim for?
Most small businesses start at Bronze or Silver to get a certificate quickly, then work towards Gold. Gold is where the standard covers the controls that stop most real-world attacks on small businesses, such as endpoint detection and enforced email authentication. Platinum and Diamond are usually only worth it if a customer or contract specifically asks for independently audited assurance.
Does SMB1001 replace the Essential Eight?
No. They're separate frameworks from separate organisations. ASD is replacing the Essential Eight with its own Essentials series over roughly the next two years. SMB1001 is an independent certification that overlaps heavily with Essential Eight controls, so work done for one counts toward the other.
Can we self-certify SMB1001?
At Bronze, Silver and Gold, yes: a director attests that the business meets the required controls. Platinum and Diamond require independent verification. Self-attestation isn't a formality, though. A director is putting their name to the claim, so the controls need to be genuinely in place and evidenced.
How long does SMB1001 certification take?
A business already running Microsoft 365 with MFA and working backups can often reach Bronze within a few weeks. Gold typically takes a few months, depending on how much needs fixing: email authentication, endpoint protection, policies and training are the usual gaps.
Not sure where you'd land today? A gap assessment shows which controls are already in place and what's left to do.
Security Assessment →Want a straight answer on which framework fits your business?
Call 0433 087 091 for a free, no-obligation look at your current security setup.
Book a Free IT Health CheckFor related reading, see the Essential Eight explained, ISO 27001 for small businesses, and how insurers use the Essential Eight.