Skip to Content

Get certified with an expert.

SMB1001 CERTIFICATION

Independent implementation for Bronze through Gold. We hold Gold ourselves, so the process we put you through is one we have been through. Discovery quoted up front, then priced per project.

Got questions? Give us a call. No fee or obligation, speak to the person who has done it before directly.

What is SMB1001?

An Australian standard built for small and medium business. Five levels run from Bronze to Diamond, each adding controls on top of the level below.

What we actually do

We work through the controls at your target level and establish where you stand. That tells you what evidence you already have and what you still need.

Then we do the work. The technical controls are usually straightforward. The bigger job is the writing: policies that describe how you actually operate rather than a template, and an evidence pack that holds up if someone checks it.

We don't earn commission on anything you buy.


What does SMB1001 cost?

Most Gold engagements land between $15,000 and $40,000, discovery through to certification. That excludes CyberCert's certificate fee and any software licences you need. Bronze and Silver certifications are cheaper.

A business with under 10 staff, managed endpoints and existing policies sits near the bottom. A business with 30 staff, mixed devices and nothing written down sits near the top. What moves you along the range is how many staff and devices you have, whether MFA and managed endpoints are already in place, how much of your evidence exists in writing, and whether your IT provider does the technical work or we do.

Discovery and gap analysis is quoted separately and up front. Everything after that is quoted per project once we can see the actual gap.


How long does SMB1001 take?

Most Gold certifications can be completed in less than 6 months. Implementation heavily depends on the starting point and how proactive the business is. Bronze and Silver certifications are quicker.


SMB1001 readiness checklist

Wondering what is involved? Download our readiness checklist. Written as plain-English questions with the evidence you will need for each one. Fill it in and the summary sheet scores you by tier. It is the same structure we use on client engagements, condensed for self-assessment.


Get your free checklist here:

Thanks for registering!

We will email the checklist and add you to The Check, our fortnightly cyber security note for small business. Unsubscribe any time. See our privacy policy.


FAQs

Discovery needs a few hours of yours. Evidence gathering needs someone internally who can find things.

Yes! The standard is public. You can find the standard here. Businesses bring us in when they have no time, are unsure what the evidence needs to look like, or want someone independent checking before they attest.

CyberCert allows self attestation up to Gold. Beyond that external certification is required.

CyberCert audits a percentage of all certifications to ensure compliance.

Certification lasts 12 months. At renewal the business must meet the current SMB1001 standards for their certification level.

Yes, and it is usually cheaper if they do the technical implementation while we scope and verify it.

Some can. Most will quote you for it either way.

Security is a specialisation. The person who resets passwords on Monday and rebuilds a laptop on Tuesday is not usually the person who knows what SMB1001 wants for evidence, or what an insurer will accept when they ask. That is not a criticism of their work. It is a different job.

Where it shows up is time and cost. A generalist learns the standard on your money, and the evidence work tends to land back on you when they run out of road.

The other difference is where the money comes from. Most providers earn margin on the products they recommend, so the fix that gets proposed tends to be the one that pays. We take no commission, no rebate and no margin on software.

Plenty of our engagements run alongside an existing provider. They do the technical work, we scope it and verify the evidence.

No. We deliver you to the standard.

Most of what a certification asks for is not technical. Policies have to exist and match what you actually do. Processes have to be written down and followed. Staff have to know what is expected of them, and you have to be able to show that they were told.

We write the policies with you rather than handing you a template, implement the technical controls, and build the evidence pack that supports your attestation. Technology, process and people, because leaving any one of them out means you do not meet the standard.

Working to a deadline?

Tell us what has been asked of you and by when. A free 20-minute call establishes whether the timeline is realistic, which level you actually need, and what discovery would cost. No pitch, no obligation.