Skip to content

SMB1001 Certification for Australian Businesses

SMB1001 is an Australian cyber security certification standard with five cumulative levels, designed for small and medium businesses.

Let our SecureStart program be your practical guide to a secure future

Dale Jenkins Microsolve

Reviewed by

Dale Jenkins

Founder & CTO

Dale reviews cyber resilience, technology strategy and compliance content for clarity and technical accuracy.

SMB1001:2026 Gold

Small and medium businesses (SMBs) across Australia are increasingly targeted by cybercriminals, with 60% of cyber attacks now focused on SMBs due to their perceived vulnerabilities.

The SMB1001 certification framework provides a structured, cost-effective pathway for Australian businesses to build robust cyber security defences while meeting compliance requirements and gaining competitive advantages in the marketplace.

And yes, we know what it takes as we hold SMB1001:2026 GOLD (Level 3) Certification - verifiable at the CyberCert website!

60%
of Cyber Attacks Target SME's
3.7x
MORE likely to have a Cyber breach than a Break-In
$97,203
Average COST of recovering from a Cyber Incident in 2022/23

How Much Does SMB1001 Certification Cost?

SMB1001 Gold certification through SecureStart starts at $8,820 excluding GST for a five-seat organisation (or $245 per month over 36 months).

The engagement price is set by organisation size, not by timeline.

Compressing delivery into a shorter period does not change the total or reduce the scope - it changes the payment schedule.
The same work, the same three certifications and the same recertification coverage, delivered faster.

SecureStart investment by organisation size and delivery timeframe.
The total engagement price is fixed per size band; only the monthly amount changes.
Organisation size Total engagement Over 36 months
(default)
Over 24 months Over 18 months Over 12 months
Start-up
(5 Seats)
$8,820 $245/mo $368/mo $490/mo $735/mo
Small Bus
(20 Seats)
$12,420 $345/mo $518/mo $690/mo $1,035/mo
Small Ent
(100 Seats)
$20,340 $565/mo $848/mo $1,130/mo $1,695/mo
Mid Ent
(500 Seats)
$30,780 $855/mo $1,283/mo $1,710/mo $2,565/mo


All prices exclude GST.
Every engagement includes the SMB1001 certification fees and annual recertification for the duration of the term, gap assessment, control implementation guidance, evidence preparation and director attestation support.

Platinum and Diamond Extensions

Priced on the same organisation size bands as the Gold engagement, as a 12-month extension once Gold has been held through a full recertification cycle.

12-month Platinum and Diamond extension pricing by organisation size (excluding external audit costs)
Organisation size 12-month extension Monthly
Start-up
(5 Seats)
$4,140 $345/mo
Small Bus
(20 Seats)
$5,820 $485/mo
Small Ent
(100 Seats)
$7,500 $625/mo
Mid Ent
(500 Seats)
$11,700 $975/mo

What the SecureStart Journey Looks Like

SecureStart is a single 36-month engagement to reach SMB1001 Gold (Level 3).
Bronze and Silver are not separate purchases - they are certification milestones you pass through on the way, and each one is a real, issued certificate you can show clients and insurers while the program is still running.

Platinum and Diamond sit beyond Gold. They are available only to organisations that have achieved Gold and maintained it through a full recertification cycle - so they are earned, not bought.

SMB1001 levels, how each is reached through SecureStart, and what qualifies you for it

Level How it is reached Eligibility Earliest available Controls
Bronze
(Level 1)
Milestone within the SecureStart engagement Open to all - no prerequisite Month 6 7
Silver
(Level 2)
Milestone within the SecureStart engagement Open to all - no prerequisite Month 24 17
Gold
(Level 3)
The target outcome of the 36-month engagement Open to all - no prerequisite Month 36 27
Platinum
(Level 4)
12-month extension to the Gold engagement Gold achieved and maintained through a full recertification cycle Month 48 32
Diamond
(Level 5)
Pursued within the Platinum extension Platinum in progress or achieved Month 48 onward, alongside Platinum 39

 

Microsolve holds SMB1001:2026 Gold (Level 3) certification - independently verifiable here. We have been through the process we are asking you to commit to.

If your team is stretched and security feels ad-hoc

Microsolve brings a calm, managed cyber security service that embeds SMB1001 practices across technology management, access control, and employee training so your business can keep running with confidence.

The SMB1001 Standard: Technology, Access, Response, Training

The SMB1001 Certification provides a clear roadmap for improving security posture while maintaining business operations and growth objectives.

SMB1001 - Pyramid

Five Tier Progression

Start with bronze and proceed in an additive manner to the level that best suits your Organisation

Annual Updates

Address the evolving threat landscape with annual updates to tier requirements

Self-Assessment Options

Initial certification levels can be self-assessed for businesses with a good understanding of Cyber Technology

Essential Eight Alignment

Certification controls align with the requirements of the Essential 8 and International standards

Cost Effective

Compared with the complexity of the ISO27001 international standard

Why SMB1001 Certification Matters for Your Business

SMB1001 is Australia's premier cyber security certification framework specifically designed for small and medium-sized businesses with 5 to 200 staff.

Developed by Dynamic Standards International (DSI), this tiered certification program offers a practical alternative to complex international standards like ISO 27001, providing structured guidance through Bronze, Silver, Gold, Platinum, and Diamond certification levels.

Unlike traditional cyber security frameworks that can overwhelm smaller organisations, SMB1001 recognises the unique challenges facing Australian SMBs: limited budgets, resources, and technical expertise. The framework provides a clear roadmap for improving security posture while maintaining business operations and growth objectives.

Enhanced Security Posture

The framework provides comprehensive guidelines across essential security areas, including technology management, access control, incident response, and employee training.

Implementing SMB1001 controls significantly reduces the risk of data breaches, ransomware attacks, and other cyber threats that could devastate your business operations.

Regulatory Compliance Made Simple

SMB1001 aligns with Australian cyber security requirements, including the Privacy Act 1988, helping businesses meet local regulations without the complexity of international standards.

This alignment ensures SMBs adhere to national standards while avoiding potential legal issues and regulatory penalties.

Competitive Advantage

Achieving SMB1001 certification signals to clients, partners, and insurers that your organisation prioritises data protection.

This commitment to security fosters trust and provides a competitive edge, as customers increasingly prefer to engage with businesses demonstrating robust cyber security practices.

Insurance Benefits

Many cyber insurance providers now recognise SMB1001 certification, potentially leading to reduced premiums and improved coverage terms.

Certified businesses demonstrate lower risk profiles, making them more attractive to insurers and investors.

Microsolve Client Feedback

Logo - North_Construction

"Dale has an excellent way of cutting through the noise in IT and translating complex concepts into clear, practical insights. His “keep it simple” approach really stood out when he spoke to over 22 subcontractor partners at our Trusted Partner session on Cyber Security and AI for SMEs. Dale added strong value to the discussion and left attendees with knowledge they could genuinely apply to their businesses."

John Melvin
CEO @ North Building & Construction

PCW Commercial Windows

“The cyber security session with Microsolve was informative and important for our staff, and a valuable reminder to stay vigilant. It prompted useful internal discussions and gave us practical next steps to work through with our IT provider.”

Leigh Spinks
Director @ PCW Commercial Windows

Sierra Marketing

"Microsolve has been a game-changer for us and our clients in making cyber security and certification achievable ... Getting cyber security certification felt quite overwhelming at first but Dale and his team made it accessible, clear and manageable. They broke down the actions we needed to take into practical steps and explaining things in plain language. I have no reservations in recommending Microsolve."

Marion Di Benedetto
CEO @ Sierra Marketing

SMB1001 Certification Levels

What's Included in a SecureStart Engagement

Your 36-Month Journey to Cyber Security Excellence

As an accredited SMB1001 service provider, Microsolve offers comprehensive advisory-led support through our SecureStart program.

Unlike assessment-only services, we provide hands-on guidance throughout your entire 36-month certification journey, ensuring you not only achieve, but maintain Gold-level certification.

SecureStart Workshop

We have created an SMB1001 compliant workshop available to SMBs for further information and as a space to ask questions in real time. Microsolve's SecureStart Workshops are run by our experts and focus on guiding you and your business through crucial cyber security elements to provide a tailored report so you can begin your next steps in securing your business' data in line with the SMB1001 standard.

  • secure start cybersecurity workshop presentation
  • Mindset over product to secure your digital assets
  • Antivirus Protection

Guidance - Not Just Assessment

Our experienced vCISOs and cyber security advisors work alongside your team, providing practical, business-aligned advice tailored to your industry, size, and risk profile. We translate complex security requirements into actionable steps your team can implement.

Certification Confidence Guarantee

When you follow our structured roadmap, we guarantee your Gold certification achievement. Our proven methodology has helped numerous Australian SMBs successfully navigate the certification process without overwhelming their operations.

Predictable Investment

Our fixed monthly pricing model eliminates surprises, allowing you to budget confidently for your cyber security improvement journey. Technical implementation work is quoted separately, giving you complete transparency and control over additional investments.

What's Included in Your Monthly Advisory Fee:

  • Dedicated vCISO/Advisor assigned to your account
  • CyberCert partner portal access for assessment and progress tracking
  • Comprehensive GAP assessments and certification roadmaps
  • Regular progress meetings and milestone check-ins
  • Annual certification review and renewal assistance
  • Policy template library and documentation guidance
  • Strategic cyber security roadmap tailored to your organisation

Latest Cyber Security Insights

Frequently asked questions

These FAQs help Australian organisations understand how SMB1001 cyber security certification can improve security, reduce ransomware risk, and support compliance obligations while Microsolve manages the detail for you.

Does SMB1001 Gold require an independent audit, or can it be self-assessed?

Levels 1 to 3 - Bronze, Silver and Gold - are self-assessed with director attestation, so there is no external auditor fee to reach Gold. Platinum and Diamond require independent verification, and those audit costs sit outside the extension price.

This is one of the main reasons SMB1001 Gold is achievable for a small business where ISO-style certification often is not.

How long does SMB1001 certification take, and can we do it faster?

SecureStart runs over 36 months by default, reaching Bronze at around month 6, Silver at month 24 and Gold at month 36. Shorter timeframes are available down to 12 months.

Compressing the schedule does not increase the total cost or reduce the scope - the same engagement is delivered over fewer months, so the monthly figure is higher and the total is unchanged.

 

What is included in the price, and are certification fees extra?

The engagement price covers gap assessment, control implementation guidance, evidence preparation, director attestation support, the SMB1001 certification fees themselves and annual recertification for the full term.

There are no separate certification charges to reach Gold. Prices exclude GST.

For the Platinum and Diamond extensions, independent audit fees are additional and quoted separately.

 

What happens at recertification, and what if it lapses?

SMB1001 certification is renewed annually, and every renewal during your engagement term is included in the price - so your certification does not lapse part-way through the program.

If certification is allowed to expire after the engagement ends, you would need to recertify before you could evidence compliance to a client, insurer or tender panel again.

Is Bronze or Silver enough to satisfy a client security questionnaire, tender or insurer?

Often yes, and that is deliberate. Bronze and Silver are real, issued certifications rather than progress markers, so you have something verifiable to put in front of a client or broker from around month 6 instead of waiting three years.

Whether a given level is sufficient depends on what the specific contract or policy asks for, which is worth checking before you commit to a level.

 

Does SMB1001 replace ISO 27001?

No.

ISO 27001 certifies a full information security management system against an international standard and involves external audit, ongoing management system overhead and significantly greater cost.

SMB1001 is an Australian standard built specifically for small and medium businesses, with cumulative levels so you can certify your controls proportionately.

If a contract explicitly requires ISO 27001, SMB1001 will not satisfy it - but for most Australian SMBs, Gold demonstrates credible security maturity at a fraction of the cost and in some cases, Gold controls can be used as evidence for ISO27001 requirements.

How does SMB1001 relate to the ACSC Essential Eight?

They overlap substantially.

Many SMB1001 controls map to Essential Eight mitigation strategies, so work done for one contributes to the other.

The difference is that SMB1001 results in a certification you can show a third party, while the Essential Eight is a maturity model rather than a certifiable standard.

We assess both together where a client has obligations under each.

 

Do we need Platinum or Diamond?

Most businesses do not!

Gold is the appropriate target for the large majority of Australian SMBs, and it is the level Microsolve holds.

Platinum and Diamond suit organisations in regulated sectors or supply chains with elevated contractual requirements.

They are also not immediately available - you must hold Gold and maintain it through a full recertification cycle first, so the earliest realistic start is month 24 (assuming a 12 month Gold engagement).

Which organisation size band applies to us?

Pricing is banded by seat count, and the band is set at the start of the engagement.

If you sit between published bands or are unsure how to count contractors and shared logins, our SMB1001 assessment will confirm the band and give you a fixed figure before you commit.

Is Microsolve itself SMB1001 certified?

Yes we are!

 Microsolve holds SMB1001:2026 Gold (Level 3), issued by CyberCert and independently verifiable.  We're also on the journey to be certified to Diamond.

We have been through the same assessment, evidence gathering and attestation process we guide clients through, which is not true of every provider offering SMB1001 advisory services.