SMB1001 has been coming up a lot lately within our internal discussions following the recent announcement of Essential Eight's retirement. If you have heard the name and wondered what it actually is, this one is for you.
What is SMB1001?
SMB1001 is a cyber security standard developed by Dynamic Standards International (DSI), built specifically for small and medium businesses rather than large enterprises or government departments.
Instead of one all-or-nothing audit, SMB1001 works in five tiers:
- Level 1 Bronze – entry level, for businesses just starting to formalise their cyber security with basic protections in place.
- Level 2 Silver – for businesses with a bit more maturity where routine security practices are documented and consistently followed.
- Level 3 Gold – for businesses handling sensitive or regulated data as a normal part of operations, with more comprehensive controls in place.
- Level 4 Platinum – for businesses where a security failure would cause serious operational or reputational harm.
- Level 5 Diamond – the highest tier, for businesses whose systems or data are mission-critical either to themselves or to the organisations they serve.
A business certifies at the level that matches where it is at today, then climbs the ladder over time as its security matures.
It is worth noting that Bronze, Silver and Gold levels are self-attested, meaning a director signs off that the controls are in place. Platinum and Diamond require an independent external audit.
This tiered structure is what makes SMB1001 different from most cyber security frameworks: a smaller business without a dedicated IT security team can start somewhere realistic, rather than being measured against the same bar as a listed company.
SMB1001 vs Essential Eight: what is the difference?
Essential Eight is published by the Australian Signals Directorate. It is a list of eight technical controls (e.g. multi-factor authentication, patching, restricting admin privileges etc.) measured against a maturity model.
It is thorough and well understood but there is no formal certification attached to it. You assess your maturity level but there is nothing you walk away holding that says "certified."
SMB1001 is the opposite in that respect. It is an independent, industry-built standard (i.e. not a government one) but it comes with an actual certificate you can put in front of an insurer, a client or a tender panel.
That is the practical difference: Essential Eight tells you what "good" looks like technically but SMB1001 gives you something to show for it.
The two aren't really competitors. SMB1001 maps closely to the Essential Eight controls and plenty of businesses end up using both with SMB1001 as the certifiable framework and documentation trail and the Essential Eight as the technical control list that insurers and regulators already recognise.
Should you look at SMB1001 instead of Essential Eight?
Our honest answer: it is less an either/or decision and more about which problem you are actually trying to solve.
Essential Eight is still the active, ASD-supported standard right now and will remain so throughout the transition to the Essentials series. If you have been working towards a maturity level, that work still counts and is still worth finishing.
Where SMB1001 earns its place is in what it adds. If you are being asked by an insurer, a client or a tender to prove your security posture rather than just describe it, SMB1001 certification is a genuinely useful thing to have in hand. And because it is tiered, SMB1001 is a realistic starting point even if you haven't touched Essential Eight at all yet.
How much does SMB1001 certification cost?
The certification fee itself is modest, generally somewhere between a low hundred dollars a year at the entry tier up to a few thousand a year at the top tier, depending on the level you are certifying at.
However, that is not the real cost, though. The actual investment is in closing whatever control gaps exist to get there (e.g. MFA, backups, endpoint protection, documented policies, staff training etc.) and that varies a lot depending on where your business is starting from.
Where we sit on SMB1001?
If SMB1001 is something you have come across and you are weighing it up, let us know and we can certainly provide more information to help you work through it.
Our overall advice: whichever framework's name ends up on your page, the fundamentals underneath it, i.e. MFA, patching, backups and knowing who can install what, are worth having in place regardless.
Get in touch with our team if you want to talk through where your business actually sits today.