Skip to content

Choosing the Right SMB1001 Certification Tier for Your Aged Care Organisation

In aged care, where resident data and operations can't afford downtime, SMB1001 certification provides a clear path to cyber resilience without overwhelming your team. Microsolve helps providers like yours select the perfect starting tier, building capability progressively over our proven 36-month program. We focus on practical steps that fit around care delivery, turning compliance into quiet confidence.


Understanding the SMB1001 Tiers

SMB1001 offers five progressive levels, each stacking controls for growing maturity, which is ideal for aged care's regulatory demands.

Bronze Level

Bronze provides the essential foundational cybersecurity controls through self-attestation, perfect for aged care homes establishing basic defences without external audits.

Features include:

  • Firewalls deployed and configured on all network edges.

  • Antivirus/anti-malware running on all endpoints with regular scans.

  • Automated backups of critical data, stored offsite or in cloud.

  • Patch management for OS, apps, and third-party software.

  • Basic multi-factor authentication (MFA) on key accounts like email.

  • Self-assessment and director attestation for quick entry.

Silver Level

Silver builds on Bronze with structured governance and access controls via self-attestation, suiting growing aged care providers managing multiple sites consistently.

Features include:

  • Enhanced access management: Role-based controls and privileged access.
  • Formal IT asset register and inventory tracking.
  • Consistent security policies applied across all locations.
  • Vulnerability scanning and basic endpoint detection.
  • Secure remote access (VPN) for staff and vendors.
  • Gap analysis from Bronze baseline

Gold Level

Gold elevates to advanced policies, training, and monitoring through self-attestation, core for multi-site aged care handling sensitive resident data.

Features include:

  • Formal cybersecurity policies documented and approved.

  • Mandatory staff awareness training programs.

  • Endpoint Detection and Response (EDR) tools deployed.

  • Incident response planning and testing.

  • Email security: DMARC, SPF, anti-phishing filters.

  • Advanced backup testing and recovery drills.

Platinum Level

Platinum introduces supply chain security and deeper compliance, ideal for aged care networks with extensive vendor dependencies like medical devices.

Features include:

  • Third-party vendor risk assessments and contracts.
  • Advanced encryption for data in transit and at rest.
  • Continuous monitoring and logging.
  • Compliance audits for regulations like Privacy Act.
  • Application whitelisting and zero-trust elements.
  • Builds all prior tiers with external verification prep.

Diamond Level

Diamond delivers enterprise-grade risk management with mandatory external audits, for leading aged care groups demanding zero-tolerance resilience.

Features include:

  • Rigorous external audits by accredited bodies.
  • Board-level governance and reporting.
  • Adversary simulation (pen testing, red teaming).
  • Full data encryption at rest and advanced DLP.
  • Supply chain maturity assessments.
  • Highest maturity across all 52 controls.

This tiered approach lets you start small and scale, aligning with Essential Eight for aged care mandates.


Where Most Aged Care Providers Start

Most aged care organisations thrive by starting at Bronze and advancing to Gold within Microsolve's 36-month roadmap that avoids disrupting care staff while delivering measurable uplift. Bronze tackles immediate gaps like backups and antivirus, common pain points in facilities with legacy systems. By Gold, you'll have training and monitoring that supports multi-site ops and regulator scrutiny.

Bronze: 0-12 months

Bronze level's self-assessment shows where any gaps are without the cost or complexity of an external audit, while establishing the essentials.

Silver: 12-24 months

Silver's staged rollout suits real-world budgets and rosters because improvements can be paced around operations. This strengthens governance, access management and consistency.

Gold: 24-36

Gold builds formal policies, staff awareness, and stronger control maturity. This delivers better security, easier audits, and genuine staff confidence through practical, phased changes.

Microsolve handles the technical work so your team can stay focused on residents, not cyber administration. 


Factors That Influence Your Target Tier

What SMB1001 tier is right for you?

It's not a one-size-fits-all scenario. Your target tier depends on a variety of factors including scale, data risks, and regulations. Don't worry if you're not sure about what's best for you, that's where we come in. 

Microsolve assesses each of these factors to recommend a practical path starting at Bronze and building to Gold over the 36 month period to ensure care is not disrupted. Here's how key elements influence your decision:

Organisation Size

The size of your aged care organisation directly impacts the tier needed.

Smaller, single-team providers can achieve strong security with Bronze's foundational controls like antivirus and backups, while larger operations with multiple departments require Silver or Gold to implement scalable governance and monitoring across teams.

Number of Sites

If you operate a single facility, Bronze or Silver provides sufficient basics for local security.

Multi-site providers, however, need Gold to enforce consistent access controls, patching, and backups organisation-wide, reducing risks from inconsistent setups.

Data Types Held

Routine administrative data might suit lower tiers, but aged care providers handling sensitive resident health records, financial details, or personal information under the Privacy Act require Gold's advanced data protection, encryption, and incident response to meet compliance and breach prevention standards.

Regulatory Pressure

With moderate oversight, a steady Bronze-to-Silver path builds capability. High scrutiny from the Aged Care Quality and Safety Commission (ACQSC) or the new Aged Care Act demands faster progression to Gold, ensuring perpetual audit evidence, Essential Eight alignment, and defensible cyber maturity.

Supply Chain Requirements

Basic vendor relationships allow flexibility at Silver, but if partners, insurers, or procurement contracts require verifiable certification - common in healthcare chains - Gold or higher unlocks those opportunities by providing a recognised badge of security maturity.

Cyber Security for Aged Care

Cyber Security and Aged Care

Meeting the mandated cyber security requirements across a residential care setting does not need to be an Enterprise-scale compliance burden. Microsolve's SecureStart program delivers SMB1001 compliance meeting the Essential Eight Maturity Level 1 controls.

Frequently asked questions

Does the initial SMB1001 assessment disrupt resident care?

No, Microsolve's guided assessment runs alongside normal operations using remote scans and short interviews with key staff. We schedule around shift changes and care priorities, completing the gap analysis within one week without impacting clinical delivery.

What if we're already doing Essential Eight basics - do we skip Bronze?

Many aged care providers have basic antivirus and backups but lack governance or training. Microsolve maps your existing controls against SMB1001 Bronze requirements during assessment, often fast-tracking certification if you meet 80%+ of controls already.

How much staff training is actually required for SMB1001 Gold?

Your care team completes four 15-minute modules annually plus two 30-minute phishing simulations. Microsolve delivers these via Microsoft 365 with mobile access during breaks. Admin staff get two additional hours on policy updates - total team time under 4 hours per year.

Can we maintain SMB1001 certification after Microsolve sets it up?

Yes, we provide quarterly compliance reports, automated control monitoring, and annual recertification preparation as ongoing service. Most clients choose our managed model since aged care turnover makes independent maintenance challenging.

What happens if ACQSC requests cyber security evidence tomorrow?

Your SMB1001 assessment report becomes immediate proof of due diligence, showing current gaps and remediation plan. Bronze certification (typically 3-6 months) provides the verifiable badge regulators recognise while you progress to Gold.

Help me decide what tier is best for me

Start your SMB1001 journey with a guided assessment. We'll see where the gaps are and kick-start your cyber security certification by mapping a clear path to fit your budget, timeline and care priorities.