SMB1001 Compliance for Australian Businesses: What You Attest To, and What You Must Be Able to Prove
At Bronze, Silver and Gold, SMB1001 is self-attested — a company director signs to say the controls are in place. The certificate records that declaration. It does not, on its own, show an insurer, a customer or a regulator that the controls were actually running. SMB1001 tells you what to attest to. Cleverer is how you prove you could.
SMB1001 is published by Dynamic Standards International. Certification is issued by accredited certification bodies such as CyberCert. Cleverer is not a certifier, auditor or accreditation body, and is not affiliated with either organisation. Cleverer is the evidence layer underneath your attestation.
The short version
What is SMB1001?
SMB1001 is a tiered cyber security standard written for small and medium businesses. It sets out a progressive set of controls across five tiers, so a business can certify at a level that matches its size and risk and move up over time. The standard is published by Dynamic Standards International (DSI), which was previously known as Cyber Security Certification Australia. Certification against it is issued by accredited certification bodies, of which CyberCert is the best known in Australia. The current edition is SMB1001:2026, released in September 2025; DSI updates the standard annually.
It exists because the alternatives did not fit. ISO 27001 and SOC 2 assume a compliance function and a budget to match. The ACSC Essential Eight is a technical maturity model, not a certification. SMB1001 gives a 15-person business something it can actually reach, and gives the party asking — an insurer, a head contractor, an enterprise procurement team — a name and a tier to ask for.
Who is SMB1001 for?
Businesses being asked for proof
A customer questionnaire, a tender condition, a supply-chain requirement or an insurer renewal has put cyber security on your desk with a deadline attached.
Businesses too small for ISO 27001
You need a credible, recognised position without a full information security management system and the overhead that comes with it.
Businesses holding personal information
Health, legal, financial, education, care and property services all hold data that makes an APP 11 reasonable steps question a live risk.
What are the SMB1001 tiers, and who checks them?
Certification is available at any one of five levels, from Level 1 — described in CyberCert’s Certification Practice Statement as “minimum requirements of the standard and minimal independent validation” — through to Level 5, “all requirements of the standard and all assertions independently validated”. The tier names map to those levels in order.
| Tier | Level | Indicative focus | How it is verified |
|---|---|---|---|
| Bronze | 1 | Foundational hygiene — technical support arrangements, firewall and anti-malware protection, automatic updates, password practice, backups. | Director self-attestation |
| Silver | 2 | Stronger identity and email controls — multi-factor authentication, password management, and the first written policies. | Director self-attestation |
| Gold | 3 | A managed program across people, process and technology — formal policies, staff training, incident response planning, asset register, email authentication, endpoint detection, responsible AI use. | Director self-attestation |
| Platinum | 4 | Higher-assurance controls, independently checked. | Independent audit |
| Diamond | 5 | The full requirements of the standard, with every assertion independently validated. | Independent audit |
Tiers are cumulative — each builds on the one below. The control descriptions above are indicative and are not the definitive requirement list; DSI publishes the authoritative control set for SMB1001:2026, and requirements change with each annual edition. Confirm the current requirements with DSI or your certification body before you attest.
What does self-attestation actually mean?
At Bronze, Silver and Gold, the business tells the certification body that the controls are in place, and the certificate is issued on the strength of that declaration. CyberCert’s own practice statement makes the distinction plain: for Level 4 and Level 5, “a certificate cannot be issued by a CyberCert CO without a successful audit by a CyberCert AO”, and only those two levels require the auditing and certifying roles to be held by separate people. At Levels 1 to 3 they may be performed by a single Certification Registrar.
This is a feature, not a loophole — it is what makes the standard reachable for a small business. But it moves the burden of proof. The certification body has validated who you are and recorded what you declared. Nobody has inspected your systems. The person carrying that statement is the director who signed it, and a knowingly false declaration is not a small thing.
What an SMB1001 certificate does prove
- That your business exists and was identified by the certification body.
- That a responsible officer formally declared the tier’s controls were in place, on a given date.
- That the certificate is registered and can be verified by a third party.
- At Platinum and Diamond: that an independent auditor tested the assertions.
What it does not prove on its own
- That the controls were operating on the day an incident occurred.
- That they stayed in place across the certification year.
- That named people completed the training the tier requires.
- That the policies were adopted and communicated, not just drafted.
- That you can produce any of the above when someone asks for it.
What evidence should you keep behind an SMB1001 attestation?
Nothing in a self-attested tier requires you to hand over a folder of evidence to get certified. The reason to build one is what happens afterwards. A cyber insurer assessing a claim, a customer running a security review, or the OAIC examining whether you took reasonable steps after a notifiable data breach will not be satisfied by the certificate. They will ask what you actually did, and when.
Policies with dates
Not just a document — a version, an approval date, and a record of who adopted it and who it was issued to.
Training per person
Named completions with dates, covering the people whose roles the control actually applies to.
Control state over time
Evidence that MFA, backups, updates and endpoint protection were in place across the period, not only at sign-up.
Proof of recurrence
Dated review cycles, reassigned obligations and closed-out actions that show the program kept running.
Where Cleverer fits
Cleverer is the operating layer that produces the record. It assigns each obligation to a named person, delivers and dates the training the tier expects, generates and versions the policies with an approval trail, drives the recurring reviews that stop a control quietly lapsing, and keeps the whole history in one place you can export when someone asks. The result is a defensible audit trail rather than a scramble through inboxes and shared drives.
Cleverer does not certify you and does not audit you — that is your certification body’s role. What Cleverer does is make sure that when a director signs the attestation, the evidence behind it already exists. See how Cleverer works, or the cyber compliance platform in full.
How does SMB1001 relate to your other Australian obligations?
SMB1001 is a voluntary standard. It does not replace anything you are already required to do, and certifying does not discharge a legal obligation. It is best understood as a structured way of doing work the law already expects of you.
| Obligation or framework | Status | Relationship to SMB1001 |
|---|---|---|
| Privacy Act — APP 11 | Legal requirement | Requires reasonable steps to protect personal information. Operating an SMB1001 tier, and keeping the records that show it, is strong material for that argument. Certification alone is not the argument. |
| Notifiable Data Breaches scheme | Legal requirement | Governs assessment and notification after an eligible breach. The incident response planning at Gold is directly relevant, and your dated records are what the assessment draws on. |
| ACSC Essential Eight | Guidance | A technical maturity model, not a certification. Overlaps SMB1001 on patching, MFA, backups and application control. Compare the options on our cyber compliance frameworks page. |
| ISO 27001 / SOC 2 | Certification | Heavier, independently audited, and usually driven by enterprise or offshore customers. SMB1001 is the smaller, faster starting point, not a substitute where a customer has specified ISO. |
| Cyber insurance conditions | Contractual | Policies commonly require stated controls such as MFA and backups. At claim time the insurer tests whether those controls were operating — see cyber insurance compliance requirements. |
Could you prove it today?
The readiness check takes a few minutes and no email address. It tells you the position you could honestly defend right now, and exactly which evidence is missing.
SMB1001 questions we are asked
Is SMB1001 mandatory in Australia?
No. SMB1001 is a voluntary standard. Businesses usually pursue it because a customer, head contractor, tender or insurer has asked for a recognised cyber security position, not because legislation requires it. Your Privacy Act obligations apply whether or not you certify.
Which SMB1001 tiers are self-attested?
Bronze, Silver and Gold — Levels 1 to 3 — are self-attested by a company director through the certification body’s portal. Platinum and Diamond, Levels 4 and 5, require a successful independent audit before a certificate can be issued.
Does an SMB1001 certificate prove my controls were in place?
At Bronze, Silver and Gold it proves a director formally declared they were in place on a given date. It is not an inspection of your systems. If an insurer, customer or regulator later tests the claim, they will ask for dated records — which is why the evidence behind the attestation matters more than the certificate itself.
Who issues SMB1001 certification?
Dynamic Standards International publishes the standard. Certification is issued by accredited certification bodies; CyberCert is the best known in Australia. Cleverer is neither — we are not a certifier, auditor or accreditation body, and we have no affiliation with DSI or CyberCert.
What evidence do I need for SMB1001?
Self-attested tiers do not require you to submit evidence to be certified. What you need is a record you can produce afterwards: dated policies with approval trails, named training completions, proof that controls such as MFA and backups were operating across the period, and evidence of recurring review. Our SMB1001 evidence guide maps this control by control.
Will SMB1001 certification lower my cyber insurance premium?
Treat any such claim carefully. No Australian insurer publishes SMB1001 certification as a premium input. What does matter at claim time is whether the controls your policy assumes were genuinely in place — and that is an evidence question.
Does Cleverer replace my IT provider?
No. Your IT provider implements and maintains technical controls. Cleverer governs the people-and-process layer around them: who is accountable, what was trained, which policies were adopted, what was reviewed and when. The two are complementary.