Reviewed by
Founder & CTO
Dale reviews cyber resilience, technology strategy and compliance content for clarity and technical accuracy.
SMB1001 is an Australian cyber security certification standard with five cumulative levels, designed for small and medium businesses.
Reviewed by
Founder & CTO
Dale reviews cyber resilience, technology strategy and compliance content for clarity and technical accuracy.
Small and medium businesses (SMBs) across Australia are increasingly targeted by cybercriminals, with 60% of cyber attacks now focused on SMBs due to their perceived vulnerabilities.
The SMB1001 certification framework provides a structured, cost-effective pathway for Australian businesses to build robust cyber security defences while meeting compliance requirements and gaining competitive advantages in the marketplace.
And yes, we know what it takes as we hold SMB1001:2026 GOLD (Level 3) Certification - verifiable at the CyberCert website!
SMB1001 Gold certification through SecureStart starts at $8,820 excluding GST for a five-seat organisation (or $245 per month over 36 months).
The engagement price is set by organisation size, not by timeline.
Compressing delivery into a shorter period does not change the total or reduce the scope - it changes the payment schedule.
The same work, the same three certifications and the same recertification coverage, delivered faster.
| Organisation size | Total engagement | Over 36 months (default) |
Over 24 months | Over 18 months | Over 12 months |
|---|---|---|---|---|---|
| Start-up (5 Seats) |
$8,820 | $245/mo | $368/mo | $490/mo | $735/mo |
| Small Bus (20 Seats) |
$12,420 | $345/mo | $518/mo | $690/mo | $1,035/mo |
| Small Ent (100 Seats) |
$20,340 | $565/mo | $848/mo | $1,130/mo | $1,695/mo |
| Mid Ent (500 Seats) |
$30,780 | $855/mo | $1,283/mo | $1,710/mo | $2,565/mo |
All prices exclude GST.
Every engagement includes the SMB1001 certification fees and annual recertification for the duration of the term, gap assessment, control implementation guidance, evidence preparation and director attestation support.
Priced on the same organisation size bands as the Gold engagement, as a 12-month extension once Gold has been held through a full recertification cycle.
| Organisation size | 12-month extension | Monthly |
|---|---|---|
| Start-up (5 Seats) |
$4,140 | $345/mo |
| Small Bus (20 Seats) |
$5,820 | $485/mo |
| Small Ent (100 Seats) |
$7,500 | $625/mo |
| Mid Ent (500 Seats) |
$11,700 | $975/mo |
SecureStart is a single 36-month engagement to reach SMB1001 Gold (Level 3).
Bronze and Silver are not separate purchases - they are certification milestones you pass through on the way, and each one is a real, issued certificate you can show clients and insurers while the program is still running.
Platinum and Diamond sit beyond Gold. They are available only to organisations that have achieved Gold and maintained it through a full recertification cycle - so they are earned, not bought.
| Level | How it is reached | Eligibility | Earliest available | Controls |
|---|---|---|---|---|
| Bronze (Level 1) |
Milestone within the SecureStart engagement | Open to all - no prerequisite | Month 6 | 7 |
| Silver (Level 2) |
Milestone within the SecureStart engagement | Open to all - no prerequisite | Month 24 | 17 |
| Gold (Level 3) |
The target outcome of the 36-month engagement | Open to all - no prerequisite | Month 36 | 27 |
| Platinum (Level 4) |
12-month extension to the Gold engagement | Gold achieved and maintained through a full recertification cycle | Month 48 | 32 |
| Diamond (Level 5) |
Pursued within the Platinum extension | Platinum in progress or achieved | Month 48 onward, alongside Platinum | 39 |
Microsolve holds SMB1001:2026 Gold (Level 3) certification - independently verifiable here. We have been through the process we are asking you to commit to.
Microsolve brings a calm, managed cyber security service that embeds SMB1001 practices across technology management, access control, and employee training so your business can keep running with confidence.
The SMB1001 Certification provides a clear roadmap for improving security posture while maintaining business operations and growth objectives.

Start with bronze and proceed in an additive manner to the level that best suits your Organisation
Address the evolving threat landscape with annual updates to tier requirements
Initial certification levels can be self-assessed for businesses with a good understanding of Cyber Technology
Certification controls align with the requirements of the Essential 8 and International standards
Compared with the complexity of the ISO27001 international standard
SMB1001 is Australia's premier cyber security certification framework specifically designed for small and medium-sized businesses with 5 to 200 staff.
Developed by Dynamic Standards International (DSI), this tiered certification program offers a practical alternative to complex international standards like ISO 27001, providing structured guidance through Bronze, Silver, Gold, Platinum, and Diamond certification levels.
Unlike traditional cyber security frameworks that can overwhelm smaller organisations, SMB1001 recognises the unique challenges facing Australian SMBs: limited budgets, resources, and technical expertise. The framework provides a clear roadmap for improving security posture while maintaining business operations and growth objectives.
The framework provides comprehensive guidelines across essential security areas, including technology management, access control, incident response, and employee training.
Implementing SMB1001 controls significantly reduces the risk of data breaches, ransomware attacks, and other cyber threats that could devastate your business operations.
SMB1001 aligns with Australian cyber security requirements, including the Privacy Act 1988, helping businesses meet local regulations without the complexity of international standards.
This alignment ensures SMBs adhere to national standards while avoiding potential legal issues and regulatory penalties.
Achieving SMB1001 certification signals to clients, partners, and insurers that your organisation prioritises data protection.
This commitment to security fosters trust and provides a competitive edge, as customers increasingly prefer to engage with businesses demonstrating robust cyber security practices.
Many cyber insurance providers now recognise SMB1001 certification, potentially leading to reduced premiums and improved coverage terms.
Certified businesses demonstrate lower risk profiles, making them more attractive to insurers and investors.

"Dale has an excellent way of cutting through the noise in IT and translating complex concepts into clear, practical insights. His “keep it simple” approach really stood out when he spoke to over 22 subcontractor partners at our Trusted Partner session on Cyber Security and AI for SMEs. Dale added strong value to the discussion and left attendees with knowledge they could genuinely apply to their businesses."
John Melvin
CEO @ North Building & Construction

“The cyber security session with Microsolve was informative and important for our staff, and a valuable reminder to stay vigilant. It prompted useful internal discussions and gave us practical next steps to work through with our IT provider.”
Leigh Spinks
Director @ PCW Commercial Windows

"Microsolve has been a game-changer for us and our clients in making cyber security and certification achievable ... Getting cyber security certification felt quite overwhelming at first but Dale and his team made it accessible, clear and manageable. They broke down the actions we needed to take into practical steps and explaining things in plain language. I have no reservations in recommending Microsolve."
Marion Di Benedetto
CEO @ Sierra Marketing

As an accredited SMB1001 service provider, Microsolve offers comprehensive advisory-led support through our SecureStart program.
Unlike assessment-only services, we provide hands-on guidance throughout your entire 36-month certification journey, ensuring you not only achieve, but maintain Gold-level certification.
We have created an SMB1001 compliant workshop available to SMBs for further information and as a space to ask questions in real time. Microsolve's SecureStart Workshops are run by our experts and focus on guiding you and your business through crucial cyber security elements to provide a tailored report so you can begin your next steps in securing your business' data in line with the SMB1001 standard.
Our experienced vCISOs and cyber security advisors work alongside your team, providing practical, business-aligned advice tailored to your industry, size, and risk profile. We translate complex security requirements into actionable steps your team can implement.
When you follow our structured roadmap, we guarantee your Gold certification achievement. Our proven methodology has helped numerous Australian SMBs successfully navigate the certification process without overwhelming their operations.
Our fixed monthly pricing model eliminates surprises, allowing you to budget confidently for your cyber security improvement journey. Technical implementation work is quoted separately, giving you complete transparency and control over additional investments.
What's Included in Your Monthly Advisory Fee:
These FAQs help Australian organisations understand how SMB1001 cyber security certification can improve security, reduce ransomware risk, and support compliance obligations while Microsolve manages the detail for you.
Levels 1 to 3 - Bronze, Silver and Gold - are self-assessed with director attestation, so there is no external auditor fee to reach Gold. Platinum and Diamond require independent verification, and those audit costs sit outside the extension price.
This is one of the main reasons SMB1001 Gold is achievable for a small business where ISO-style certification often is not.
SecureStart runs over 36 months by default, reaching Bronze at around month 6, Silver at month 24 and Gold at month 36. Shorter timeframes are available down to 12 months.
Compressing the schedule does not increase the total cost or reduce the scope - the same engagement is delivered over fewer months, so the monthly figure is higher and the total is unchanged.
The engagement price covers gap assessment, control implementation guidance, evidence preparation, director attestation support, the SMB1001 certification fees themselves and annual recertification for the full term.
There are no separate certification charges to reach Gold. Prices exclude GST.
For the Platinum and Diamond extensions, independent audit fees are additional and quoted separately.
SMB1001 certification is renewed annually, and every renewal during your engagement term is included in the price - so your certification does not lapse part-way through the program.
If certification is allowed to expire after the engagement ends, you would need to recertify before you could evidence compliance to a client, insurer or tender panel again.
Often yes, and that is deliberate. Bronze and Silver are real, issued certifications rather than progress markers, so you have something verifiable to put in front of a client or broker from around month 6 instead of waiting three years.
Whether a given level is sufficient depends on what the specific contract or policy asks for, which is worth checking before you commit to a level.
No.
ISO 27001 certifies a full information security management system against an international standard and involves external audit, ongoing management system overhead and significantly greater cost.
SMB1001 is an Australian standard built specifically for small and medium businesses, with cumulative levels so you can certify your controls proportionately.
If a contract explicitly requires ISO 27001, SMB1001 will not satisfy it - but for most Australian SMBs, Gold demonstrates credible security maturity at a fraction of the cost and in some cases, Gold controls can be used as evidence for ISO27001 requirements.
They overlap substantially.
Many SMB1001 controls map to Essential Eight mitigation strategies, so work done for one contributes to the other.
The difference is that SMB1001 results in a certification you can show a third party, while the Essential Eight is a maturity model rather than a certifiable standard.
We assess both together where a client has obligations under each.
Most businesses do not!
Gold is the appropriate target for the large majority of Australian SMBs, and it is the level Microsolve holds.
Platinum and Diamond suit organisations in regulated sectors or supply chains with elevated contractual requirements.
They are also not immediately available - you must hold Gold and maintain it through a full recertification cycle first, so the earliest realistic start is month 24 (assuming a 12 month Gold engagement).
Pricing is banded by seat count, and the band is set at the start of the engagement.
If you sit between published bands or are unsure how to count contractors and shared logins, our SMB1001 assessment will confirm the band and give you a fixed figure before you commit.
Yes we are!
Microsolve holds SMB1001:2026 Gold (Level 3), issued by CyberCert and independently verifiable. We're also on the journey to be certified to Diamond.
We have been through the same assessment, evidence gathering and attestation process we guide clients through, which is not true of every provider offering SMB1001 advisory services.