Skip to content

SMB1001 Certification for Aged Care Providers

Cyber security stopped being an IT matter for aged care providers on 1 November 2025. When the strengthened Quality Standards took effect, managing cyber security risk became part of an outcome the Aged Care Quality and Safety Commission assesses you against — and something your board is accountable for demonstrating.

The difficulty is not usually that providers are doing nothing. It is that what they are doing cannot be evidenced. A quality manager asked "how do you manage cyber security risk" cannot answer with a firewall model number, and a board asked the same question by its insurer cannot answer with reassurance from its IT provider.

Certification against SMB1001 turns that activity into an assessed, dated, externally verified statement. This page is about what that statement lets you evidence, and to whom.

The obligation certification maps to

Strengthened Quality Standard Outcome 2.7 on information management requires providers to put in place an information management system that, among other things, "manages cyber security risks" — cross-referencing Outcome 2.4. Cyber security is therefore not a separate technology topic sitting alongside the Standards. It is a named component of the information management system the Standards require.

Separately, section 168 of the Aged Care Act 2024 obliges a registered provider to ensure personal information "must be protected by security safeguards that it is reasonable in the circumstances to take against the loss or misuse of the information".

The operative phrase is "reasonable in the circumstances". That is a standard you have to argue you met, after something has gone wrong. Certification against a published framework is materially easier to argue than a description of your own good intentions.

Who asks, and what satisfies them

What each audience is actually asking for

What each audience is actually asking for
Who asks What they are really asking What certification gives you
Your board or committee of management Can we say we have discharged our duty of care over resident information? A dated certificate against a named standard, with a defined scope and expiry
Commission Quality Auditors How does your information management system manage cyber security risks? An assessed control set mapped to Outcome 2.4 and Outcome 2.7
Cyber and professional indemnity insurers Is this risk priceable, and are the declarations on the proposal true? Independent verification rather than self-declaration
Government and tender panels Does this provider meet a minimum security bar? A recognised credential that answers the question without a bespoke response
Families and prospective residents Is my information safe with you? Something specific to point to, rather than a general assurance

 

These audiences are the reason certification is worth more than an equivalent amount of unverified security work. The controls reduce your risk. The certificate is what lets somebody else accept that you have.

Why aged care is treated differently by attackers

Aged care providers hold an unusually complete personal record: identity documents, Medicare details, next-of-kin, financial arrangements, and clinical history — often for people who are not in a position to monitor their own credit file or notice misuse. That combination is why the sector is targeted disproportionately relative to its size and margin.

There is a second factor specific to residential care. Systems that support medication administration, nurse call and access control are not back-office systems. An outage is a care event, which shortens the decision window in a way that suits an attacker and creates pressure that a purely commercial business does not face.

Our detailed treatment of the standard's structure and how a provider gets through it sits on SMB1001 cyber security certification for aged care providers, including how the framework compares to the Essential Eight and what the certification journey involves.

What certification does not do

Certification is a point-in-time assessment against a defined scope, and it is worth being clear with a board about the limits so that nobody treats a certificate as a guarantee.

It does not cover systems outside the assessed scope, which in aged care commonly means clinical applications hosted and administered by a vendor. If your clinical system is delivered as a hosted service, your certification says nothing about the vendor's own posture — that has to be established separately, through their attestations and your contract. Coordinating that across a mixed vendor estate is part of what our vCIO vendor coordination work exists to do.

It also does not remove your record-keeping obligations. A certified provider that cannot produce a complete email thread for a complaint investigation has a compliant security program and a records problem. Those are managed together, which is why email archiving for aged care providers and certification tend to be scoped in the same conversation.

Fitting certification into a governance cycle

Where certification adds the most value is when it is timed against decisions your organisation already makes, rather than run as a standalone project.

Insurance renewal is the most common anchor, because the proposal form asks questions certification answers directly. Board reporting cycles are the second, since a quality and risk report benefits from a control statement that does not change wording every quarter. Where a provider is approaching a Commission audit or has recently had findings against Standard 2, sequencing the certification work ahead of reassessment lets you present remediation as a program rather than as a response.

Multi-site providers have an additional consideration: scope. Certifying a corporate office while facilities run inherited infrastructure produces a certificate that does not describe the environment residents' information actually sits in. Deciding scope honestly at the start is the difference between a useful credential and a misleading one, and it is a governance decision rather than a technical one. Our multi-site vCIO services cover standardising a mixed estate to the point where a single meaningful scope is possible.

For the mechanics of the standard itself — the tiers, what each requires, costs and timeframes — see SMB1001 certification and our SecureStart program.

Aged Care Cyber Security Topics

Cyber Security and Aged Care

Meeting the mandated cyber security requirements across a residential care setting does not need to be an Enterprise-scale compliance burden. Microsolve's SecureStart program delivers SMB1001 compliance meeting the Essential Eight Maturity Level 1 controls.

What is the SMB1001 framework?

Learn how SMB1001 gives aged-care providers a practical, tiered path to stronger cyber security.

Which is The Right Certification Tier?

Identify the certification tier that matches your aged-care organisation’s risks, systems and requirements.

Demonstrate Cyber Security to Regulators

See how documented controls and evidence can demonstrate cyber security assurance to regulators and boards.

Certification Without Burden!

Take a staged approach to SMB1001 certification that strengthens security without overwhelming your team.

Frequently asked questions

Do the aged care Quality Standards actually require cyber security certification?

No standard requires certification specifically.

Outcome 2.7 requires an information management system that manages cyber security risks, cross-referencing Outcome 2.4, and section 168 of the Act requires reasonable security safeguards.  Both describe an outcome and leave the method to you.

Certification is one way of evidencing that outcome that a third party can verify, which is why boards and insurers favour it. You can meet the Standards without it — you just carry the burden of demonstrating equivalence yourself.

Our clinical software is hosted by the vendor. Does our certification cover it?

Not unless it is inside the assessed scope, and usually it is not.

A hosted clinical system is the vendor's environment, so their controls apply to it, not yours.

What certification covers is your side: identity and access, the devices staff use to reach it, how administrative rights are granted, and how you respond to an incident.

The vendor's posture has to be established separately through their own attestations and your contract terms. Providers who assume otherwise discover the gap during an incident.

Will certification satisfy our insurer?

It generally improves the conversation substantially because it replaces self-declaration with independent verification, and the control areas map closely to what proposal forms ask about.

It is not a guaranteed premium reduction and no adviser should promise one.

What it reliably does is prevent the situation where a claim is complicated by a declaration your organisation could not substantiate.

We are a small single-site provider. Is this proportionate?

The obligation under section 168 is scaled to what is reasonable in your circumstances, and SMB1001 is tiered for exactly this reason — the lower tiers are designed for small organisations without dedicated security staff.

Size does not reduce the sensitivity of the information you hold, and it does not change what the Commission assesses. It changes what a proportionate response looks like, not whether one is required.

How does this relate to the Essential Eight?

They overlap considerably and are not alternatives in the way they are often presented.

The Essential Eight is a mitigation strategy model with maturity levels and no certification pathway.

SMB1001 is a tiered standard you can be certified against, which is what makes it useful for evidencing to a third party.

Most aged care providers we work with end up implementing Essential Eight mitigations and certifying against SMB1001, because the first improves the posture and the second communicates it.

Start the conversation with evidence in mind

If your board has asked a question you could not answer with a document, or an insurance renewal is approaching, that is the right moment to scope this.