How to Get SMB1001 Certification: Process, Cost, and What to Expect

Table of Contents

SMB1001 certification can look simple from the outside; choose a tier, meet the requirements and apply.

Yet the part that often decides how smoothly the process goes happens before the application begins.

Your business may already have many of the right controls. The harder question is whether they are ready to be presented and supported.

That uncertainty can make a manageable certification goal feel much more complicated than it needs to be.

A clear view of the journey changes that. It helps you move forward with fewer surprises and a better sense of what deserves attention first.

If your business is considering certification, the smartest starting point is understanding what the process will actually ask of you.

That is where this article begins.

What to Prepare Before You Start

Before starting SMB1001 certification, you need to assess your current position, choose a realistic tier and secure the budget and internal support needed to move forward.

Run a Readiness Self-Assessment

Checklist tool to do Readiness Self-Assessment
A good way to run this self-assessment is with RedScale’s free SMB1001 checklist tool, which breaks controls down by area so you can see what’s already in place.

A readiness self-assessment should show which target-tier controls are working, missing or difficult to prove.

You can start with the SMB1001 readiness checklist as your practical self-check, not formal certification or an independent assessment.

Then, record four outputs from the review:

  • An initial gap list mapped to the current target-tier controls.
  • An evidence inventory showing what exists and when it was last reviewed.
  • A control ownership map covering business, technical and executive responsibilities.
  • Remediation priorities based on risk, dependencies and certification impact.

Use the current SMB1001:2026 requirements as the baseline. A previous-edition workbook or an older internal checklist can miss changed controls.

Decide Which Tier to Target

Choose the SMB1001 tier that matches your risk exposure, customer obligations and capacity to maintain every cumulative control.

DSI’s supplier categorisation matrix considers three factors: the information a supplier handles, its access to systems and the criticality of its goods or services.

Tier selection should reflect data exposure, access level and operational criticality, not only ambition.

These confidentiality, integrity and availability factors give businesses a grounded way to discuss tier selection.

TierWhen it may be a practical targetReadiness question to answer first
Bronze, Level 1Lower-exposure businesses that need a baseline cyber hygiene positionCan we show that the basic controls are in place and owned?
Silver, Level 2Businesses with more user, email, website and access-management exposureAre identity, email, access and admin controls managed consistently?
Gold, Level 3Businesses facing stronger customer, procurement, governance or insurance evidence expectationsCan we prove governance, incident response, asset records and broader technical controls?
Platinum, Level 4Sensitive or higher-criticality environments where external assurance is expectedIs our evidence strong enough for independent review across important systems?
Diamond, Level 5High-assurance environments with advanced resilience, testing and supplier-trust needsCan we prove mature testing, response readiness and ongoing control operation?

For additional context, you can use the SMB1001 requirements list as a supporting reference when reading the tier table.

For many businesses, tier choice comes down to the level of cybersecurity compliance a customer, procurement process, or insurer expects them to demonstrate.

Because some industries may also have sector-specific guidance. For example, the Queensland Law Society recommends that Australian law practices work towards Gold.

But this should not be treated as a universal tier rule for every Australian SMB.

Set a Budget and Get Buy-In

Build the budget around the whole readiness and certification journey, then secure leadership buy-in before work begins. This means separating the main cost categories before work begins:

  • Certification subscription and any required external audit fee.
  • Readiness review or independent gap assessment.
  • Remediation projects and control implementation.
  • Security tools, licences and managed services.
  • Internal staff time and executive oversight.
  • Evidence collection, review and storage.
  • Annual control maintenance and recertification.

Then, assign an executive sponsor and a named owner for each control. The sponsor resolves priorities and funding, while control owners implement, operate and evidence the requirements.

How to Get SMB1001 Certified: The Certification Process

The SMB1001 certification process is a step-by-step path from the following:

  • Closing security gaps
  • Preparing evidence
  • Engaging an authorised certifier
  • Completing assessment
  • Panning for renewal.

The smoother the early work is, the fewer surprises your business is likely to face later. Here is how the process breaks down.

Step 1 – Close Identified Security Gaps

smb1001 checklist to check security gap
Check your own gaps first: RedScale’s free SMB1001 checklist tool shows exactly which controls you’re missing before you start remediation.

Close every material gap against the target tier before asking a director to attest or an auditor to validate the controls.

Turn the readiness findings into a remediation plan with owners, dependencies and acceptance evidence.

The remediation work may involve technical fixes, policy updates, ownership changes, staff training, tooling improvements or evidence clean-up. For example, some businesses may need the following:

  • A vulnerability assessment to identify exposed systems, missing patches or weaknesses that could affect the target tier.
  • Stronger password management to reduce shared, weak or reused credentials across business accounts.
  • Security awareness training to help staff recognise phishing, invoice fraud and everyday cyber risks.
  • Multi-factor authentication improvements to protect email, business applications, remote access and other important systems.
  • Backup and recovery testing to prove that important data can be restored if a system fails or an incident occurs.

These are examples, not the complete SMB1001 control set. The right remediation work depends on the gaps found during the readiness review, the target tier and the evidence needed for assessment.

Step 2 – Document Your Controls

Document each of your controls so the assessor can see what exists, how it works and who maintains it. For each control, record:

  • Control Owner: Who is responsible for maintaining it.
  • System or Process Covered: Where the control applies.
  • Evidence File: The policy, screenshot, export, report or register that proves it.
  • Review Date: When the evidence was last checked.
  • Status: Whether the control is complete, incomplete or needs remediation.

A control is not ready just because it has been implemented. It needs evidence that shows the control is configured, active and relevant to the certification scope. Keep the evidence current and easy to review. For example:

  • MFA evidence should show which systems are covered and whether users are enrolled.
  • Backup evidence should show that backups exist and that restore testing has been completed.
  • Security awareness evidence should show who completed training and when.

Also, always keep the evidence simple. Because the goal is to make every control traceable, reviewable and ready for assessment.

Step 3 – Engage an Authorised Certifier

Engage an authorised certifier once your target tier, scope and evidence pack are clear. Before submission, confirm the key assessment details:

  • Certification Scope: The legal entity, business units, systems and services included.
  • Target Tier: The SMB1001 tier and standard version being assessed.
  • Assessment Route: Whether the tier uses director attestation or also requires an external audit.
  • Evidence Format: How policies, screenshots, reports, registers and test records should be submitted.
  • Finding Process: How the certifier handles unclear evidence, gaps or required fixes.
  • Certificate Details: The certified entity, tier, issue date, expiry date and public verification method.

The certifier’s role is to assess the business against SMB1001. This role is separate from RedScale or any readiness partner.

RedScale can help prepare the controls and evidence, but the certifier makes the certification decision.

Also, ask for the submission requirements before sending the evidence pack. This helps avoid rework and keeps the assessment focused on the right scope.

Step 4 – Complete the Formal Assessment

Complete the required assessment route for the selected SMB1001 tier and respond to any issues raised by the certifier. The assessment usually checks three things:

  • Scope: Whether the right entity, systems and services are included.
  • Control Evidence: Whether each required control is supported by clear proof.
  • Operational Status: Whether the control is actually in use, not only written down.

At this stage, the certifier reviews whether the business can support its certification claim. For lower tiers, this may centre on director attestation and submitted evidence. For higher-assurance tiers, the process may also include external audit activity.

During the assessment, the certifier may ask for clarification or corrected evidence. Treat this as part of the process. Keep one owner responsible for responses so answers stay consistent.

Step 5 – Receive Certification and Plan for Renewal

After certification is approved, record the key certification details:

  • Certified Entity: The legal business name covered by the certificate.
  • Certified Tier: The SMB1001 level achieved.
  • Certification Scope: The systems, services or business areas included.
  • Issue and Expiry Dates: The dates used for renewal planning.
  • Evidence Location: Where the final evidence pack is stored.

Then turn the controls into an ongoing maintenance routine.

Certification should not be treated as the end of the work, because the certificate only reflects the business at the time it was assessed. The controls still need to operate after approval.

After certification, set a regular review rhythm so the controls continue to reflect how the business actually operates, like:

  • If users join, leave, or change roles, access records should be checked against current permissions.
  • Training records and policies should also be refreshed when systems or responsibilities change.

Also, start renewal planning before the expiry date is close. Because standards, systems and evidence can drift over time, recheck the target tier, refresh stale records and fix gaps early.

How Much Does SMB1001 Certification Cost?

The formal cost of SMB1001 certification fees ranges from A$95 to A$995 per year, but the pricing is broader than the annual certification charge only. These figures only cover the certificate itself.

The real spend often comes from the internal and external work needed to become assessment-ready.

That’s why the better POV is to separate the fixed certification fee from variable implementation and maintenance costs, since those costs can outweigh the certificate fee itself.

Cost Factors by Tier (Bronze Through Diamond)

Each higher tier adds cumulative controls, broader evidence work and, at Platinum and Diamond, an external audit charge.

TierPublished annual charge in CyberCertFormal Estimation Cost Before TaxMain cost factor to plan for
Bronze, Level 1A$95A$95Basic control setup and evidence clean-up
Silver, Level 2A$195A$195Identity, email, access and admin-control uplift
Gold, Level 3A$395A$395Governance, incident response, asset records and broader technical controls
Platinum, Level 4A$595A$3,595Audit readiness, stronger evidence and external review preparation
Diamond, Level 5A$995A$5,995Advanced testing, supplier trust, resilience evidence and audit preparation

For information, the CyberCert is the official certification portal used to manage SMB1001 certifications.

The CyberCert operates under Dynamic Standards International (DSI), which develops and maintains the SMB1001 framework.

Ongoing Costs: Renewal and Recertification

For an Australian SMB, ongoing SMB1001 operating costs can range from A$300 for a small individual cost line to A$30,000+ per year for a broader managed environment.

The table below shows common ongoing cost lines to plan for.

Ongoing cost lineIndicative annual rangeWhat it covers
Security licencesA$300-A$1,500 per user/yearEndpoint protection, EDR, MFA, password manager, backup, email security or monitoring tools
Managed security servicesA$6,000-A$60,000+/yearMonitoring, patching support, vulnerability management, control health checks and evidence support
Vulnerability remediationA$1,000-A$15,000+/yearFixing exposed systems, missing patches, weak configurations and failed checks
Backup and recovery testingA$1,000-A$6,000/yearRestore testing, backup reporting and remediation when recovery issues are found
Awareness trainingA$20-A$250 per user/yearStaff refresher training, phishing education and completion tracking
Incident response exercisesA$2,000-A$10,000 per exerciseTabletop exercises, response-plan testing and post-exercise updates
Evidence maintenanceA$2,000-A$12,000/yearUpdating policies, asset registers, access records, reports and review notes
Internal review timeA$1,500-A$10,000/year equivalentControl-owner reviews, executive attestation and renewal coordination

The range is broad and higher than the certificate fee itself because the total cost depends on many variables to keep SMB1001 controls working between certification cycles.

That’s why Australian SMBs choose structured managed security services as an affordable way to maintain those controls rather than hiring or coordinating every capability in-house.

Australia’s managed security service providers can combine those ongoing costs and evidence upkeep for SMBS1001 certification into a more predictable operating cost.

What to Expect During the Assessment Process

During the SMB1001 assessment process, expect the certifier to check whether your selected tier, evidence and operating controls match the claim your business is making.

The sections below break down the likely timeline and what certifiers assess at each tier.

Typical Timeline From Readiness to Certification

The table below can be your reference for the stages most businesses move through before SMB1001 certification, because there is no universal timeline.

As you might know, the readiness, remediation and certifier scheduling vary by business.

StageWhat happensWhat can change the duration
ReadinessMap current controls and evidence to the target tierScope, starting maturity and quality of records
RemediationImplement missing controls and fix weak coverageProcurement, technical dependencies and staff capacity
Evidence preparationComplete the workbook and assemble reviewable proofNumber of systems, control owners and stale records
Certifier engagementConfirm scope, assurance route and submission processCertifier availability and audit scheduling
AssessmentComplete director attestation or external auditTier, evidence quality and clarification requests
Findings and approvalCorrect issues and wait for the certifier’s decisionFinding severity, remediation work and resubmission needs

CyberCert’s public Certification Practice Statement gives a subscriber 12 months from subscription purchase to complete certification. That is an administrative completion window, not a typical project duration.

The same statement says a certificate is expected within one business day after approval. This covers issuance after the assessment decision rather than the preparation journey.

What Certifiers Assess at Each Tier

Certifiers assess whether your business meets the cumulative controls required for the selected SMB1001 tier.

The table below shows how the assessment focus expands from baseline cyber hygiene at Bronze to stronger testing, resilience and supplier-trust evidence at Diamond.

TierControls assessedWhat the certifier looks for
BronzeBaseline cyber hygiene controlsProof that basic protections are implemented and owned
SilverIdentity, access, email and fraud controlsEvidence that user access and email risk are managed consistently
GoldGovernance, incident response, asset and broader technical controlsRecords showing the business can operate and maintain formal controls
PlatinumVulnerability, cloud credential and MFA coverage controlsStronger evidence that important systems are protected and reviewed
DiamondEncryption, application control, testing, supplier trust and response-readiness controlsEvidence that advanced controls are tested, maintained and ready for review

As the tier increases, the evidence burden increases too. Bronze to Gold can be supported through director attestation and reviewable records.

Platinum and Diamond require stronger assurance, so the evidence needs to be easier to trace and ready for independent review. That’s why, at Diamond, testing becomes part of the assurance story.

For this reason, the penetration testing should be scoped to the systems that matter to the certification claim. Your business should also be ready to show findings, remediation and any follow-up action.

Some supporting controls may strengthen the evidence pack without being mandatory for every business.

For example, data loss prevention can support sensitive-data governance in the right environment. Treat these as supporting measures, not universal SMB1001 requirements.

Get Certification-Ready with RedScale

SMB1001 certification feels easier when your business knows its target tier, current gaps and likely preparation cost before assessment begins.

Structured readiness work helps your team focus budget, time and effort on the controls that matter most. Without that visibility, certification can become slower, more expensive and harder to manage.

That’s why RedScale helps Australian SMBs turn SMB1001 preparation into a practical action plan.

Your team can understand what is already in place, what needs remediation and what evidence will support the certification claim.

RedScale’s SMB1001 support can assist with readiness review, gap assessment, remediation planning, control implementation support and evidence preparation.

Contact RedScale for a free discussion to map your target tier, readiness gaps and next steps towards assessment.

FAQ


Writer

Danoe Santoso

Danu Santuso is a writer for Redscale, focused on creating clear and practical cybersecurity content for Australian businesses.

Expert Reviewer

Handy

As Managing Director of Redscale, Handy brings extensive expertise in IT strategy, cybersecurity, and digital transformation, supporting organizations in building resilient, secure, and scalable technology environments.

Redscale ©2026. All Rights Reserved.