SMB1001 is an Australian, tiered cyber security standard built specifically for small and medium businesses. It's a realistic, affordable way to prove your security to clients and insurers — and a natural stepping stone toward Essential Eight and ISO 27001.
Bigger frameworks can be overkill for a growing business. SMB1001 is designed for where you actually are.
Unlike enterprise standards, SMB1001 is scaled for small and medium businesses — achievable without a huge security budget.
Graduated levels mean you start where you are and step up over time, spreading cost and effort sensibly.
A recognised certification gives clients, partners and insurers confidence that you take cyber security seriously.
Move from 'we think we're secure' to a certificate you can actually show in tenders and renewals.
SMB1001 builds the habits and controls that make Essential Eight and ISO 27001 far easier later.
The controls target real threats — phishing, weak passwords, unpatched systems — so you're safer, not just certified.
SMB1001 is graduated, so you can certify at a level that matches your business today and progress as you grow.
Bronze
Essential foundational controls — the cyber security basics every business should have in place.
Silver
Strengthened controls and processes, suitable as expectations from clients increase.
Gold
A robust, well-documented security posture for businesses handling more sensitive data or larger contracts.
Platinum & Diamond
The highest tiers, for businesses needing to demonstrate advanced, mature cyber security to major partners.
We guide you through certification and keep you there — without pulling your team off their real jobs.
Gap Assessment
We review your current security against your target SMB1001 tier and map exactly what's needed.
Implement Controls
We put the required technical and policy controls in place, configured properly for your environment.
Certify
We prepare the evidence and support you through achieving certification at your chosen tier.
Maintain & Step Up
We keep your controls current and help you move up tiers as your business and contracts grow.
SMB1001 was created by Dynamic Standards International specifically for small and medium businesses (roughly 5–200 staff) that need to prove their cyber security but for whom ISO 27001 is overkill. It's fast becoming a commercial requirement, not a nice-to-have.
5–200
staff — the size of business SMB1001 is purpose-built for
— Dynamic Standards International
Supply chain
larger clients and government vendors increasingly ask suppliers to prove certification
— Industry research
Lower premiums
many cyber insurers now recognise SMB1001, which can improve cover and reduce premiums
— Industry research
SMB1001 frames cyber security across five practical domains: Technology Management, Access Management, Backup & Recovery, Policies & Processes, and Education & Training. It's especially relevant for:
SMB1001 is an Australian, tiered cyber security certification developed by Dynamic Standards International for small and medium businesses, offering a practical alternative to ISO 27001.
Small and medium businesses, roughly 5 to 200 staff, that supply larger businesses or government, hold client data, or want better cyber-insurance terms and proof of their security posture.
Five graduated tiers: Bronze, Silver, Gold, Platinum and Diamond, so you can certify at the level that matches your business today and step up over time.
Ready to get SMB1001 certified?
Book a free assessment and we'll recommend the right tier for your business and map the path to get there.