SMB1001 Bronze, Silver, Gold: How to Check Which Tier You Meet

Table of Contents

It’s not always easy to identify which SMB1001 tier your business actually meets. You might satisfy some higher-level controls but still lack a few basic ones, so it’s easy to assume you’re further along than you really are.

This guide breaks down the SMB1001 Bronze, Silver and Gold controls in order so you can confirm which ones your business meets before you apply for certification.

SMB1001 Bronze, Silver and Gold at a Glance

SMB1001 Bronze, Silver and Gold give you three levels of cybersecurity maturity to work towards:

  • Bronze is the essential controls your business should establish first.
  • Silver strengthens access and email security.
  • Gold adds managed protection, formal governance and stronger evidence.

The SMB1001 requirements by tier step up in rigour as your business moves through that path. Each level expects more depth, stronger ownership and stronger proof.

The table below shows how Bronze, Silver and Gold stack up in focus, control depth, evidence burden and practical fit.

TierFocus & ControlsEvidence & Fit
BronzeBasic hygiene: protection, updates, backups, awarenessLight evidence. Confirms security foundation
SilverAdds account controls, access reviews, MFA, SPFDocumented records. For structured access control
GoldAdds EDR, email authentication, policies, response planningBroader evidence with named owners. For stronger assurance

The table is a decision aid. Your target should reflect the controls the business can operate and maintain, together with the assurance its customers and stakeholders require.

How to Check Which SMB1001 Tier Your Business Already Meets

Checking which SMB1001 tier you meet doesn’t take long. RedScale’s SMB1001 readiness checklist walks you through it: you just select the controls that already work in your business and that you can back up with evidence.

As you select controls, the result panel updates to show your progress. Because the tiers are cumulative within the tool, lower-tier controls remain a mandatory part of higher-tier readiness.

The completed-control figures below describe this live RedScale tool. However, they are not definitive official certification-control counts.

SMB1001 Bronze: The Baseline Controls to Confirm First

Bronze readiness appears when all nine controls currently assigned to Bronze in the RedScale tool are selected.

For SMB1001 Bronze Tier, you can go to the Identity & Access section and the Endpoint & Device Security section. Then you can check if your business already meets these several qualifiers or not:

  • Strong Passwords: Confirm that your business enforces explicit password requirements across relevant accounts.
  • Firewall Protection: Check that a firewall is deployed, configured and actively maintained.
  • Endpoint Protection: Verify that antivirus or endpoint protection covers every active business device.
  • Regular Updates: Review patch records to confirm that operating systems and software stay current.
  • Automatic Updates: Confirm that automatic updates are enabled wherever your environment supports them.

Then continue to Governance & Response section. You need to make sure do you have this quality:

  • Qualified IT Support: Record who provides technical support and how urgent security issues are escalated.

Lastly check the Email & User Security section and Data Protection & Recovery section, to see if your business already have:

  • Basic Awareness Training: Check that relevant employees have completed recent cybersecurity awareness training.
  • Critical-data Backups: Verify that business-critical data is covered by successful backup jobs.
  • Isolated Backup Copy: Confirm that at least one backup cannot be easily reached through a compromised account.

After you are done checking those, you can scroll down to the bottom of the list, and you’ll find the result panel confirming your SMB1001 Bronze completeness, along with a list of unticked controls the tool recommends you address next.

Keep the evidence, note any weak or informal controls, and continue to Silver only if its additional practices are already operating.

SMB1001 Silver: What to Check on Top of Bronze

SMB1001 Silve readiness builds on the full Bronze baseline. Keep the nine Bronze controls selected before checking the seven current Silver controls below:

Scroll to Identity & Access and Endpoint & Device Security first. For SMB1001 Silver, check that access controls and admin separation are ticked, MFA on critical apps and EDR only come in at Gold.

  • Email MFA: Confirm that multi-factor authentication is enforced across business email accounts.
  • Individual Accounts: Verify that every employee uses an account assigned to them.
  • Restricted Admin Access: Limit administrative privileges to people who genuinely need them.
  • Separate Admin Accounts: Confirm that privileged work uses accounts separated from everyday user accounts.

Move to Email & User Security and Data Protection & Recovery next. SPF and basic backups should be ticked for SMB1001 Silver.

  • Access Reviews: Check that user permissions are reviewed on a defined schedule.
  • Phishing and BEC Awareness: Verify that staff can recognise and report suspicious emails or payment requests, the tactics most commonly used in social engineering attempts against small businesses.
  • SPF Configuration: Confirm that your SPF record covers every authorised email-sending service.

Scroll down to the readiness summary at the bottom. Check that SMB1001 Silver shows Completed with a tick, and confirm the 16/47 counter matches your own progress.

Remember this result only counts once all SMB1001 Bronze controls plus the SMB1001 Silver controls are ticked, since Silver builds on top of Bronze. If you want to continue towards SMB1001 Gold, the tool lists exactly which controls to address next right below the counter.

SMB1001 Gold: What to Check on Top of Silver

SMB1001 Gold readiness requires the complete Bronze and Silver sets, so keep those 16 controls selected before reviewing the 12 current Gold controls. Let’s see what you need to check and tick.

Scroll to Identity & Access and Endpoint & Device Security first. Check that password practices, MFA across email and critical apps, admin controls, access reviews, password manager use and EDR are all ticked here.

  • Critical-application MFA: Confirm that MFA protects the applications your business depends on most.
  • Password Management: Verify that an approved password manager is used across your organisation.
  • Endpoint Detection and Response: Check that EDR covers active endpoints and has an assigned alert owner, typically provided through a managed security services arrangement that keeps monitoring continuous.
  • Central Device management: Confirm that business devices receive consistent policies, updates and security settings.

Move to Email & User Security and Data Protection & Recovery next. This is where SMB1001 Gold adds weight, check that DKIM, DMARC, ongoing awareness training, business-critical backups and an isolated backup copy are all ticked.

  • DKIM Configuration: Verify that legitimate outbound email is signed through DKIM.
  • DMARC Policy: Confirm that DMARC is published and reviewed across your business email domains.
  • Ongoing Awareness: Check that staff receive recurring security training beyond initial onboarding, since a single early session rarely sustains lasting cybersecurity awareness across a growing team.

Check the last two cards, Governance & Response and Security Operations & Supply Chain. Look for documented policies, an incident response plan, a digital asset register, a responsible AI usage policy and reviewed cyber insurance ticked off here.

  • Cybersecurity Policy: Confirm that your policy is approved, current and assigned to an owner.
  • Incident Response Plan: Verify that your business has documented steps for managing a security incident.
  • Digital Asset Register: Maintain a current record of important devices, systems, applications and data.
  • Responsible AI Use: Confirm that staff have firm rules for using approved AI tools and business data.
  • Cyber Insurance Review: Record whether your business has reviewed or obtained suitable cyber insurance.

Scroll down to the readiness summary at the bottom. Check that SMB1001 Gold shows Completed with a tick, and confirm the 28/47 counter matches your own progress.

Remember this result only counts once all Bronze and Silver controls plus the Gold controls are ticked, since Gold builds on the two tiers below it. If you want to continue towards Platinum, the tool lists exactly which controls to address next right below the counter.

What Determines the SMB1001 Tier Your Business Targets

The right SMB1001 target tier is the one that matches the assurance your business needs and the controls it can sustain.

This means we suggest you should base your target tier on these factors:

  • Operational Need: Identify the systems, services and business processes that would cause material disruption if compromised. Mapping this out is usually the starting point of a wider cybersecurity strategy, not just a certification exercise.
  • Customer Assurance: Review security questionnaires, contract terms and onboarding requests for the level of proof buyers expect. This kind of proof is increasingly part of standard cybersecurity compliance expectations built into Australian small business contracts.
  • Data Sensitivity: Consider the customer, employee, financial and intellectual property data the business handles.
  • Internal Capacity: Confirm who can operate controls, review evidence and coordinate remediation throughout the year.
  • Current Maturity: Separate controls that work consistently from partial configurations and informal habits.
  • Evidence Quality: Check whether records are current, attributable and easy for another reviewer to understand.
  • Maintenance Capability: Allow for staff changes, new devices and SaaS growth. Include policy reviews and control drift in your planning.

Do not target a higher tier simply because it sounds better. Consider your current control maturity, the quality of your evidence, and your capability to maintain those controls.

Because, a well-maintained Silver posture is often better than a Gold posture you cannot support with consistent evidence.

Has the SMB1001:2026 Update Changed Which Tier You Meet?

The 2026-aligned checklist may change your readiness result if your previous review followed the earlier tier mapping.

Controls that now appear at a different tier could affect whether your business still meets Bronze, Silver or Gold.

For example, the current SMB1001:2026 changes place basic awareness training at Bronze and SPF at Silver.

While at Gold, you also need to consider EDR, DKIM, DMARC, ongoing awareness training and a responsible AI usage policy.

The table below shows what you should recheck in RedScale’s current readiness tool.

TierYour earlier review may have focused onWhat you should recheck for 2026How it may affect your result
BronzePasswords, firewalls, endpoint protection, updates and backupsBasic awareness training for your staffMissing training or evidence may prevent you from completing Bronze
SilverEmail MFA, individual accounts, administrator access and access reviewsSPF coverage for every authorised email senderMissing or incomplete SPF may prevent you from completing Silver
GoldManaged protection, stronger authentication and documented governanceEDR, DKIM, DMARC, ongoing awareness training and a responsible AI usage policyAny incomplete Gold control may keep your result below Gold

How to Prepare for Your SMB1001 Certification

Turn the readiness result into a controlled evidence and remediation plan before beginning the formal SMB1001 certification process.

Practically, use these steps to help you tidy up the gaps and back up your certification with solid evidence:

  • Validate checked items. Ask the control owner to confirm the control’s scope, operation and latest review.
  • Collect evidence. Gather configuration reports, access records and backup results. Add training records, approved policies and review history.
  • Assign owners. Give every control and gap a named business or technical owner with a review date.
  • Remediate gaps. Prioritise missing controls and weak evidence according to the target tier and operational risk.
  • Retest the checklist. Select only the controls that now operate and confirm that the cumulative result is consistent with the evidence pack.
  • Confirm the current certification pathway. Check the applicable attestation, review, assessor and renewal requirements with the current certification authority.

Keep the checklist result, evidence pack and gap register separate in your records. The result summarises selections in RedScale’s live SMB1001 readiness checklist.

The evidence supports what the business can demonstrate, while the certification authority determines whether the formal requirements are met.

Get SMB1001 Certification Support from RedScale

As you’ve seen, preparing for certification involves reviewing controls, gathering evidence, coordinating people and completing technical work.

Gaps in your technology, policies or documentation can make that preparation difficult.

Without strong ownership and a practical plan, those gaps can linger or return. This makes it harder to show that your controls work consistently.

For better guidance, RedScale can help turn your readiness result into a manageable path forward.

Our structured SMB1001 support service brings gap assessment, remediation planning, control uplift and evidence preparation into one practical process.

The main goal is for your team to gain focused priorities, defined responsibilities and ongoing support as your business and risks change.

Contact RedScale to arrange a free consultation and plan the steps towards your target SMB1001 tier.

FAQ


Writer

Danoe Santoso

Danu Santuso is a writer for Redscale, focused on creating clear and practical cybersecurity content for Australian businesses.

Expert Reviewer

Handy

As Managing Director of Redscale, Handy brings extensive expertise in IT strategy, cybersecurity, and digital transformation, supporting organizations in building resilient, secure, and scalable technology environments.

Redscale ©2026. All Rights Reserved.