SMB1001 certification can look simple from the outside; choose a tier, meet the requirements and apply.
Yet the part that often decides how smoothly the process goes happens before the application begins.
Your business may already have many of the right controls. The harder question is whether they are ready to be presented and supported.
That uncertainty can make a manageable certification goal feel much more complicated than it needs to be.
A clear view of the journey changes that. It helps you move forward with fewer surprises and a better sense of what deserves attention first.
If your business is considering certification, the smartest starting point is understanding what the process will actually ask of you.
That is where this article begins.
What to Prepare Before You Start
Before starting SMB1001 certification, you need to assess your current position, choose a realistic tier and secure the budget and internal support needed to move forward.
Run a Readiness Self-Assessment

A readiness self-assessment should show which target-tier controls are working, missing or difficult to prove.
You can start with the SMB1001 readiness checklist as your practical self-check, not formal certification or an independent assessment.
Then, record four outputs from the review:
- An initial gap list mapped to the current target-tier controls.
- An evidence inventory showing what exists and when it was last reviewed.
- A control ownership map covering business, technical and executive responsibilities.
- Remediation priorities based on risk, dependencies and certification impact.
Use the current SMB1001:2026 requirements as the baseline. A previous-edition workbook or an older internal checklist can miss changed controls.
Decide Which Tier to Target
Choose the SMB1001 tier that matches your risk exposure, customer obligations and capacity to maintain every cumulative control.
DSI’s supplier categorisation matrix considers three factors: the information a supplier handles, its access to systems and the criticality of its goods or services.
Tier selection should reflect data exposure, access level and operational criticality, not only ambition.
These confidentiality, integrity and availability factors give businesses a grounded way to discuss tier selection.
| Tier | When it may be a practical target | Readiness question to answer first |
|---|---|---|
| Bronze, Level 1 | Lower-exposure businesses that need a baseline cyber hygiene position | Can we show that the basic controls are in place and owned? |
| Silver, Level 2 | Businesses with more user, email, website and access-management exposure | Are identity, email, access and admin controls managed consistently? |
| Gold, Level 3 | Businesses facing stronger customer, procurement, governance or insurance evidence expectations | Can we prove governance, incident response, asset records and broader technical controls? |
| Platinum, Level 4 | Sensitive or higher-criticality environments where external assurance is expected | Is our evidence strong enough for independent review across important systems? |
| Diamond, Level 5 | High-assurance environments with advanced resilience, testing and supplier-trust needs | Can we prove mature testing, response readiness and ongoing control operation? |
For additional context, you can use the SMB1001 requirements list as a supporting reference when reading the tier table.
For many businesses, tier choice comes down to the level of cybersecurity compliance a customer, procurement process, or insurer expects them to demonstrate.
Because some industries may also have sector-specific guidance. For example, the Queensland Law Society recommends that Australian law practices work towards Gold.
But this should not be treated as a universal tier rule for every Australian SMB.
Set a Budget and Get Buy-In
Build the budget around the whole readiness and certification journey, then secure leadership buy-in before work begins. This means separating the main cost categories before work begins:
- Certification subscription and any required external audit fee.
- Readiness review or independent gap assessment.
- Remediation projects and control implementation.
- Security tools, licences and managed services.
- Internal staff time and executive oversight.
- Evidence collection, review and storage.
- Annual control maintenance and recertification.
Then, assign an executive sponsor and a named owner for each control. The sponsor resolves priorities and funding, while control owners implement, operate and evidence the requirements.
How to Get SMB1001 Certified: The Certification Process
The SMB1001 certification process is a step-by-step path from the following:
- Closing security gaps
- Preparing evidence
- Engaging an authorised certifier
- Completing assessment
- Panning for renewal.
The smoother the early work is, the fewer surprises your business is likely to face later. Here is how the process breaks down.
Step 1 – Close Identified Security Gaps

Close every material gap against the target tier before asking a director to attest or an auditor to validate the controls.
Turn the readiness findings into a remediation plan with owners, dependencies and acceptance evidence.
The remediation work may involve technical fixes, policy updates, ownership changes, staff training, tooling improvements or evidence clean-up. For example, some businesses may need the following:
- A vulnerability assessment to identify exposed systems, missing patches or weaknesses that could affect the target tier.
- Stronger password management to reduce shared, weak or reused credentials across business accounts.
- Security awareness training to help staff recognise phishing, invoice fraud and everyday cyber risks.
- Multi-factor authentication improvements to protect email, business applications, remote access and other important systems.
- Backup and recovery testing to prove that important data can be restored if a system fails or an incident occurs.
These are examples, not the complete SMB1001 control set. The right remediation work depends on the gaps found during the readiness review, the target tier and the evidence needed for assessment.
Step 2 – Document Your Controls
Document each of your controls so the assessor can see what exists, how it works and who maintains it. For each control, record:
- Control Owner: Who is responsible for maintaining it.
- System or Process Covered: Where the control applies.
- Evidence File: The policy, screenshot, export, report or register that proves it.
- Review Date: When the evidence was last checked.
- Status: Whether the control is complete, incomplete or needs remediation.
A control is not ready just because it has been implemented. It needs evidence that shows the control is configured, active and relevant to the certification scope. Keep the evidence current and easy to review. For example:
- MFA evidence should show which systems are covered and whether users are enrolled.
- Backup evidence should show that backups exist and that restore testing has been completed.
- Security awareness evidence should show who completed training and when.
Also, always keep the evidence simple. Because the goal is to make every control traceable, reviewable and ready for assessment.
Step 3 – Engage an Authorised Certifier
Engage an authorised certifier once your target tier, scope and evidence pack are clear. Before submission, confirm the key assessment details:
- Certification Scope: The legal entity, business units, systems and services included.
- Target Tier: The SMB1001 tier and standard version being assessed.
- Assessment Route: Whether the tier uses director attestation or also requires an external audit.
- Evidence Format: How policies, screenshots, reports, registers and test records should be submitted.
- Finding Process: How the certifier handles unclear evidence, gaps or required fixes.
- Certificate Details: The certified entity, tier, issue date, expiry date and public verification method.
The certifier’s role is to assess the business against SMB1001. This role is separate from RedScale or any readiness partner.
RedScale can help prepare the controls and evidence, but the certifier makes the certification decision.
Also, ask for the submission requirements before sending the evidence pack. This helps avoid rework and keeps the assessment focused on the right scope.
Step 4 – Complete the Formal Assessment
Complete the required assessment route for the selected SMB1001 tier and respond to any issues raised by the certifier. The assessment usually checks three things:
- Scope: Whether the right entity, systems and services are included.
- Control Evidence: Whether each required control is supported by clear proof.
- Operational Status: Whether the control is actually in use, not only written down.
At this stage, the certifier reviews whether the business can support its certification claim. For lower tiers, this may centre on director attestation and submitted evidence. For higher-assurance tiers, the process may also include external audit activity.
During the assessment, the certifier may ask for clarification or corrected evidence. Treat this as part of the process. Keep one owner responsible for responses so answers stay consistent.
Step 5 – Receive Certification and Plan for Renewal
After certification is approved, record the key certification details:
- Certified Entity: The legal business name covered by the certificate.
- Certified Tier: The SMB1001 level achieved.
- Certification Scope: The systems, services or business areas included.
- Issue and Expiry Dates: The dates used for renewal planning.
- Evidence Location: Where the final evidence pack is stored.
Then turn the controls into an ongoing maintenance routine.
Certification should not be treated as the end of the work, because the certificate only reflects the business at the time it was assessed. The controls still need to operate after approval.
After certification, set a regular review rhythm so the controls continue to reflect how the business actually operates, like:
- If users join, leave, or change roles, access records should be checked against current permissions.
- Training records and policies should also be refreshed when systems or responsibilities change.
Also, start renewal planning before the expiry date is close. Because standards, systems and evidence can drift over time, recheck the target tier, refresh stale records and fix gaps early.
How Much Does SMB1001 Certification Cost?
The formal cost of SMB1001 certification fees ranges from A$95 to A$995 per year, but the pricing is broader than the annual certification charge only. These figures only cover the certificate itself.
The real spend often comes from the internal and external work needed to become assessment-ready.
That’s why the better POV is to separate the fixed certification fee from variable implementation and maintenance costs, since those costs can outweigh the certificate fee itself.
Cost Factors by Tier (Bronze Through Diamond)
Each higher tier adds cumulative controls, broader evidence work and, at Platinum and Diamond, an external audit charge.
| Tier | Published annual charge in CyberCert | Formal Estimation Cost Before Tax | Main cost factor to plan for |
|---|---|---|---|
| Bronze, Level 1 | A$95 | A$95 | Basic control setup and evidence clean-up |
| Silver, Level 2 | A$195 | A$195 | Identity, email, access and admin-control uplift |
| Gold, Level 3 | A$395 | A$395 | Governance, incident response, asset records and broader technical controls |
| Platinum, Level 4 | A$595 | A$3,595 | Audit readiness, stronger evidence and external review preparation |
| Diamond, Level 5 | A$995 | A$5,995 | Advanced testing, supplier trust, resilience evidence and audit preparation |
For information, the CyberCert is the official certification portal used to manage SMB1001 certifications.
The CyberCert operates under Dynamic Standards International (DSI), which develops and maintains the SMB1001 framework.
Ongoing Costs: Renewal and Recertification
For an Australian SMB, ongoing SMB1001 operating costs can range from A$300 for a small individual cost line to A$30,000+ per year for a broader managed environment.
The table below shows common ongoing cost lines to plan for.
| Ongoing cost line | Indicative annual range | What it covers |
|---|---|---|
| Security licences | A$300-A$1,500 per user/year | Endpoint protection, EDR, MFA, password manager, backup, email security or monitoring tools |
| Managed security services | A$6,000-A$60,000+/year | Monitoring, patching support, vulnerability management, control health checks and evidence support |
| Vulnerability remediation | A$1,000-A$15,000+/year | Fixing exposed systems, missing patches, weak configurations and failed checks |
| Backup and recovery testing | A$1,000-A$6,000/year | Restore testing, backup reporting and remediation when recovery issues are found |
| Awareness training | A$20-A$250 per user/year | Staff refresher training, phishing education and completion tracking |
| Incident response exercises | A$2,000-A$10,000 per exercise | Tabletop exercises, response-plan testing and post-exercise updates |
| Evidence maintenance | A$2,000-A$12,000/year | Updating policies, asset registers, access records, reports and review notes |
| Internal review time | A$1,500-A$10,000/year equivalent | Control-owner reviews, executive attestation and renewal coordination |
The range is broad and higher than the certificate fee itself because the total cost depends on many variables to keep SMB1001 controls working between certification cycles.
That’s why Australian SMBs choose structured managed security services as an affordable way to maintain those controls rather than hiring or coordinating every capability in-house.
Australia’s managed security service providers can combine those ongoing costs and evidence upkeep for SMBS1001 certification into a more predictable operating cost.
What to Expect During the Assessment Process
During the SMB1001 assessment process, expect the certifier to check whether your selected tier, evidence and operating controls match the claim your business is making.
The sections below break down the likely timeline and what certifiers assess at each tier.
Typical Timeline From Readiness to Certification
The table below can be your reference for the stages most businesses move through before SMB1001 certification, because there is no universal timeline.
As you might know, the readiness, remediation and certifier scheduling vary by business.
| Stage | What happens | What can change the duration |
|---|---|---|
| Readiness | Map current controls and evidence to the target tier | Scope, starting maturity and quality of records |
| Remediation | Implement missing controls and fix weak coverage | Procurement, technical dependencies and staff capacity |
| Evidence preparation | Complete the workbook and assemble reviewable proof | Number of systems, control owners and stale records |
| Certifier engagement | Confirm scope, assurance route and submission process | Certifier availability and audit scheduling |
| Assessment | Complete director attestation or external audit | Tier, evidence quality and clarification requests |
| Findings and approval | Correct issues and wait for the certifier’s decision | Finding severity, remediation work and resubmission needs |
CyberCert’s public Certification Practice Statement gives a subscriber 12 months from subscription purchase to complete certification. That is an administrative completion window, not a typical project duration.
The same statement says a certificate is expected within one business day after approval. This covers issuance after the assessment decision rather than the preparation journey.
What Certifiers Assess at Each Tier
Certifiers assess whether your business meets the cumulative controls required for the selected SMB1001 tier.
The table below shows how the assessment focus expands from baseline cyber hygiene at Bronze to stronger testing, resilience and supplier-trust evidence at Diamond.
| Tier | Controls assessed | What the certifier looks for |
|---|---|---|
| Bronze | Baseline cyber hygiene controls | Proof that basic protections are implemented and owned |
| Silver | Identity, access, email and fraud controls | Evidence that user access and email risk are managed consistently |
| Gold | Governance, incident response, asset and broader technical controls | Records showing the business can operate and maintain formal controls |
| Platinum | Vulnerability, cloud credential and MFA coverage controls | Stronger evidence that important systems are protected and reviewed |
| Diamond | Encryption, application control, testing, supplier trust and response-readiness controls | Evidence that advanced controls are tested, maintained and ready for review |
As the tier increases, the evidence burden increases too. Bronze to Gold can be supported through director attestation and reviewable records.
Platinum and Diamond require stronger assurance, so the evidence needs to be easier to trace and ready for independent review. That’s why, at Diamond, testing becomes part of the assurance story.
For this reason, the penetration testing should be scoped to the systems that matter to the certification claim. Your business should also be ready to show findings, remediation and any follow-up action.
Some supporting controls may strengthen the evidence pack without being mandatory for every business.
For example, data loss prevention can support sensitive-data governance in the right environment. Treat these as supporting measures, not universal SMB1001 requirements.
Get Certification-Ready with RedScale
SMB1001 certification feels easier when your business knows its target tier, current gaps and likely preparation cost before assessment begins.
Structured readiness work helps your team focus budget, time and effort on the controls that matter most. Without that visibility, certification can become slower, more expensive and harder to manage.
That’s why RedScale helps Australian SMBs turn SMB1001 preparation into a practical action plan.
Your team can understand what is already in place, what needs remediation and what evidence will support the certification claim.
RedScale’s SMB1001 support can assist with readiness review, gap assessment, remediation planning, control implementation support and evidence preparation.
Contact RedScale for a free discussion to map your target tier, readiness gaps and next steps towards assessment.
FAQ
How Long Does SMB1001 Certification Take?
CyberCert gives subscribers 12 months from purchase to complete certification, but this is a completion window rather than a typical duration. So, there is no fixed SMB1001 certification timeline because readiness, remediation, evidence quality, target tier and certifier availability vary.
Is SMB1001 Certification Mandatory in Australia?
No, SMB1001 is a voluntary certification standard rather than a general statutory requirement in Australia. A customer, procurement programme, insurer or contract may still request a specific tier. Confirm any sector, tender or contractual obligation separately before choosing the scope.
Can a Business Start at Gold or Platinum Without Going Through Bronze and Silver First?
Yes, a business can target Gold or Platinum directly without first holding the lower-tier certificates. It must meet all cumulative controls up to the selected level and complete that tier’s assurance method. Platinum also requires an external audit under the current SMB1001:2026 pathway.
Does SMB1001 Certification Affect Cyber Insurance Premiums?
SMB1001 certification does not guarantee lower premiums, policy acceptance, coverage or any other underwriting outcome. SMB1001 may help a business organise evidence because insurers scrutinise cybersecurity controls during underwriting. The insurer still decides the terms based on its criteria, the applicant’s risk and the evidence supplied.
How Does RedScale Help Businesses Prepare for SMB1001 Certification?
RedScale checks how ready your business is, finds the gaps, plans the fixes, prepares your evidence and issues your SMB1001 certification. We also help close those gaps directly with services like penetration testing, vulnerability assessments, password management and security awareness training.






