Skip to main content
SMB1001 Evidence

What Evidence Do You Need for SMB1001 Compliance?

You do not submit an evidence pack to get certified at Bronze, Silver or Gold — a director attests, and the certificate is issued. The evidence matters for what comes next: the insurer assessing a claim, the customer running a security review, the regulator asking what steps you took. This is the control-by-control record that answers them.

SMB1001 is published by Dynamic Standards International; certification is issued by accredited bodies such as CyberCert. Cleverer is not a certifier, auditor or accreditation body and is not affiliated with either. This guide is general information, not legal advice.

Three tests any record has to pass

1
Attributable It names a person. “The team was trained” is not a record; “these eleven people completed it” is.
2
Dated It carries a date you did not choose after the fact, and shows the state on that date.
3
Contemporaneous It was created while the control was running, not assembled the week the question arrived.

A record that fails any one of the three is an assertion, not evidence.

Control by control
What is asked for in practice
Requirement vs recommendation, labelled
Australian obligations in context
The honest answer

Does SMB1001 require you to keep evidence?

Not in the way people assume. SMB1001 specifies controls — things that must be in place. At Bronze, Silver and Gold, verification is a director’s attestation that those controls are in place; the standard does not hand you an evidence schedule to file, and no auditor arrives to inspect it. Platinum and Diamond are different: those tiers require an independent audit, and an auditor will ask for substantiation.

So the evidence in this guide is not a certification checklist. It is the record that makes a self-attestation defensible when someone tests it — and that is a genuinely different question, asked by different people, usually at the worst possible moment. Everything below is labelled so you can tell the two apart.

🛡️

The insurer, at claim time

Your policy assumed certain controls. The adjuster’s question is whether they were operating on the date of the incident — not whether you held a certificate.

📋

The customer, during review

Enterprise and government buyers rarely accept a certificate as the end of the conversation. They send a questionnaire and ask for artefacts.

⚖️

The regulator, after a breach

Under APP 11 the test is the reasonable steps you actually took. Contemporaneous records are the only way to show them.

The map

SMB1001 evidence by control area

Control areas are grouped by the tier they typically first appear in. Tiers are cumulative, so a Gold business carries everything below Gold as well. DSI publishes the authoritative control set for SMB1001:2026 and revises it annually — treat the “typically appears from” column as orientation and confirm the current requirements with DSI or your certification body.

The final column is Cleverer’s practical recommendation, not a requirement of the standard. SMB1001 does not prescribe these record formats.

Control area Typically from What you get asked for A defensible record Cleverer recommendation
Backups Bronze “Prove your data was backed up before the incident, and that you could restore it.” Backup job history showing successful runs across the period, plus a dated restore test with who ran it and what was recovered. A configuration screenshot alone shows intent, not outcome.
Updates and patching Bronze “Were the systems involved patched, and how quickly?” A patch or update report per device for the period, or a dated management-console export. Named owner for the process and evidence of exception handling where a device could not be patched.
Anti-malware and firewall Bronze “Was protection installed and active on every device — including the laptop that was compromised?” Coverage report reconciled against your device list, so the answer is a count and not an impression. Note and date every gap you accepted.
Technical support arrangement Bronze “Who is responsible for your security controls, and what did you engage them to do?” The current agreement or scope of work, plus a named internal owner. Where the provider holds the evidence, record who to ask and what they retain — an outsourced control is still your obligation.
Passwords and credential practice Bronze “What is your password standard, and did people follow it?” The written standard with an approval date, evidence it was issued to staff, and a dated configuration export showing the policy enforced in the identity system rather than only written down.
Multi-factor authentication Silver “Was MFA enforced on email and remote access at the time — for everyone?” A dated per-user enforcement report, not a tenant-level setting. Exclusions are where claims are lost: list every exempt account, the reason, who approved it and when it was reviewed.
Access and offboarding Silver “Who had access to this data, and when did the person who left lose it?” A dated access review per system and a leaver record with the date each account was disabled. Departure dates that post-date access removal are the detail people check.
Policies Silver → Gold “Send us your policy — and show it was adopted, not drafted.” Version number, approval date, approver, and a distribution or acknowledgement record per employee. An undated document with no adoption trail carries almost no weight.
Staff training and awareness Gold “Which people completed training, when, and did it cover their role?” Named completion records with dates, mapped to roles, and evidence of the recurring cycle. Attendance at one session two years ago is not a live control.
Incident response plan Gold “Show the plan that was current on the day, and that you followed it.” The approved, versioned plan plus an incident log — dated entries, decisions, who was notified and when. This is also the material your NDB assessment will rest on.
Digital asset register Gold “What devices, systems and data do you hold, and who owns each?” A maintained register with an owner per entry and a last-reviewed date. Its real function is to make every other control countable — you cannot prove full coverage without a denominator.
Email authentication Gold “Were SPF, DKIM and DMARC configured, and at what enforcement level?” Dated DNS records or a report showing the policy in force across the period, with any change to enforcement noted and approved.
Endpoint detection and response Gold “Was EDR deployed on all devices, and was anyone watching the alerts?” Coverage reconciled to the asset register, plus evidence alerts were triaged — who reviewed them and what happened to the ones that mattered.
Responsible AI use Gold “What is your position on staff putting company or customer data into AI tools?” An approved, dated policy naming permitted tools and prohibited data, with a staff acknowledgement record. New in recent editions and increasingly the first thing customers ask about.
Vendors and third parties Gold “Which suppliers touch your data, and what did you check before onboarding them?” A vendor list with the data each handles, dated assessment notes, and their own certifications or questionnaire responses on file. Your customer’s reviewer will follow the chain past you.
Ongoing review All tiers, continuous “The certificate is twelve months old. What has happened since?” Dated review cycles with an owner, outcomes and closed actions. This is the single most persuasive category and the one businesses almost never have — proof the program stayed alive between certificates.
Where it goes wrong

The five ways evidence fails when it is finally needed

Weak

  • Undated documents. A policy with no version or approval date cannot be tied to the period in question.
  • Tenant-level settings. “MFA is on” hides the four exempt accounts, and one of them is the one that was used.
  • Point-in-time screenshots. They prove a state on one day, usually the day you went looking.
  • Records only the departed IT manager could produce. Evidence held in one person’s inbox is not held.
  • Reconstruction after the request. Assembled files look assembled, and the metadata says so.

Strong

  • Versioned, approved, distributed. Who wrote it, who approved it, when, and who received it.
  • Per-person and per-device. Named, counted, reconciled against a register.
  • Continuous over the period. A series of dated records, not a single snapshot.
  • Held by the business. Exportable by whoever is asked, without a hunt.
  • Created as the work happened. Which is only possible if the system creates it for you.

How Cleverer produces this record

Every row in that table is a by-product of operating the control properly, which is exactly what Cleverer is built to do. Obligations are assigned to named people. Training is delivered and dated per person and per role. Policies are generated, versioned, approved and acknowledged with the trail intact. Recurring reviews are scheduled and closed out, so the twelve months between certificates leave a record instead of a gap. When someone asks, you export it.

Cleverer does not certify or audit you — your certification body does that. Cleverer makes sure the evidence behind the attestation exists before anyone asks for it. Start with the readiness check, see the compliance platform, or read how SMB1001 attestation works tier by tier.

Find the gaps before someone else does

The readiness check takes a few minutes and no email address. It returns the position you could defend today and names the evidence you are missing.

FAQ

Questions about SMB1001 evidence

Do I have to submit evidence to get SMB1001 certified?

Not at Bronze, Silver or Gold. Those tiers are verified by a director’s attestation that the controls are in place, and no evidence pack is submitted or inspected. Platinum and Diamond require an independent audit, where substantiation is requested.

How long should I keep SMB1001 evidence?

SMB1001 does not set a retention period for these records. As a practical matter, keep at least the current certification period plus the prior one, since insurance claims and customer reviews routinely look back beyond the last twelve months. Where personal information is involved, your Privacy Act retention obligations apply independently.

Are screenshots acceptable as evidence?

They help, and they are far better than nothing, but they prove a state on a single date — usually the date you went looking. Reports and exports covering a period are stronger, because the question is almost always whether the control was operating over time.

My IT provider holds most of this. Is that a problem?

Only if you cannot get it. The obligation stays with your business, so record which controls the provider operates, what evidence they retain, how long for, and who to ask. Test that once, before you need it in a hurry.

Is this the same evidence I would need for APP 11 or a cyber insurance claim?

Largely, yes — which is the useful part. The dated, attributable records that make an SMB1001 attestation defensible are the same material that supports a reasonable steps argument under the Privacy Act and an insurer’s questions at claim time. Build it once.

Which evidence category do businesses most often miss?

Proof of continuity. Most businesses can eventually produce a policy and a training list. Almost none can show that the program kept running between certificates — dated reviews, reassigned obligations, closed actions. That is the gap that turns a certificate into a liability rather than a defence.

© 2026 Cleverer. Human-layer cyber compliance for Australian business.