SMB1001 in 2026: What the Cyber Certificate Actually Proves, and What It Doesn't
Three of the five SMB1001 tiers rest on a company director's signature, not an audit. Our read on what the certificate proves, and where to be careful.
Jump to section
This is an IT operator’s read of the SMB1001 standard and where it stands in the Australian market in 2026. It isn’t legal or compliance advice. Whether a cyber certification satisfies a regulator’s expectation, an insurer’s renewal questionnaire or a customer’s procurement gate is your compliance officer’s or broker’s call. We implement cyber controls. They sign off on whether the certificate is enough. We are not a CyberCert partner and don’t currently sell SMB1001 certification.
Say you run a 25-person Australian business and a managed service provider (MSP) has pitched you SMB1001 in the last six months. The certificate on offer costs $95 to $5,995 per year, and what it proves depends on the tier. At Bronze, Silver or Gold, the three cheaper tiers, it proves that a company director signed an attestation. That is a document stating the controls listed in the standard are in place. At Platinum or Diamond, it proves that an external auditor verified the same. Three of the five tiers are self-attested, and most certificates issued in the Australian market are in those three. Whether that proves enough to be worth paying for depends entirely on what you want the certificate to do.
SMB1001 is published by Dynamic Standards International (DSI), a private Australian standards body. It traded as Cyber Security Certification Australia (CSCAU) until 2023, and certification is operated through a sister entity called CyberCert. The framework launched in late 2023, updated to a 2025 edition in September 2024, and is now on its 2026 edition, certifiable since January. Annual revision is the framework’s flagship marketing point, and on that one claim it delivers. Three editions in three years is faster than the Australian Signals Directorate’s Essential Eight maturity model. It is considerably faster than the five-to-ten year revision cycle of ISO 27001.
The Steering Committee that governs the standard includes credible academic and policy figures. Professor Ryan Ko, a well-known Australian cyber academic, is one. So is the Hon Meegan Fitzharris, a former ACT health minister. There is genuine expertise behind the framework, and that is worth saying up front. What follows is a critical read, but it’s a read. We have an opinion on where SMB1001 stands in the Australian market, and we’ll make our case. Other practitioners will reach different conclusions, and that’s fair.
What does an SMB1001 certificate prove?
For Bronze, Silver and Gold, it proves that a company director has personally attested that the controls in the standard are in place. No external auditor has verified the controls. The director’s word is what the certificate depends on.
That word does carry legal weight. Knowingly false attestation by a company director is not without consequence under the Corporations Act, and the framework relies on this as its accountability mechanism. Whether that is enough assurance for the parties you want to convince depends entirely on those parties’ policies. An insurer, a customer’s procurement panel and a regulator each set their own. They may accept director attestation. They may not.
For Platinum and Diamond, an external audit has happened. These tiers cost more, at AU $3,595 and $5,995 per year respectively, and take considerably more operational work to clear. They are also rare among the certificates we see in the market.
Without the tier on the certificate, whoever receives it can’t tell which of those two things they are being shown. Treat every SMB1001 certificate as evidence of an audit and you are treating a Bronze attestation as a Diamond one. The framework doesn’t make that distinction visually clear in its marketing.
Is SMB1001 recognised in Australian law?
In primary legislation as of April 2026, no.
CSCAU made a substantive submission to the Department of Home Affairs in February 2024, in response to the Cyber Security Legislative Reforms Consultation Paper. It made four recommendations, and asked Government to:
- add SMB1001 to section 10 of the Security of Critical Infrastructure Rules, which set out the Critical Infrastructure Risk Management Program (CIRMP);
- extend Secure-by-Design standards beyond internet-connected devices (IoT) to multiple supply chains;
- adopt prescriptive standards suited to small and medium business over time;
- encourage Government and large organisations to mandate SMB1001 in procurement contracts, as a “ticket to trade” mechanism.
Two pieces of legislation flowed from that consultation. The Cyber Security Act 2024 received Royal Assent on 29 November 2024. It does not name SMB1001, CSCAU, DSI or CyberCert anywhere in its text. Its “security standards” provisions cover consumer internet-connected devices, not how a small business is run. The Security of Critical Infrastructure Amendment (2025 Measures No. 1) Rules 2025 commenced on 4 April 2025. Those Rules brought data storage systems and telecommunications assets explicitly into CIRMP scope. No public reporting of those amendments mentions SMB1001 being added to LIN 23/006. Major Australian law firms wrote about the changes too: Bird & Bird, Pinsent Masons, LK Lawyers and Corrs. None of that trade-press coverage refers to the framework.
Our reading: the lobbying ask was focused, well-argued and well-staffed. It also did not make it into either piece of legislation. In 2026 SMB1001 remains a private market certification offering, not an Australian Government recognised standard.
Does SMB1001 get you a cyber insurance discount?
Many MSP marketing pages claim it does. We could not find documented evidence for that.
We looked for Australian cyber insurers that publish SMB1001 as a documented input to a premium discount. Then we looked for insurers accepting the certificate in place of specific renewal-questionnaire sections. The MSP claim that “many cyber insurers now recognise SMB1001” is widespread. The insurer-side policy document that would support it is not. If your broker says SMB1001 will move your premium, ask which named insurer’s published underwriting guidance recognises it, and what the discount is worth. If they can’t point at the policy, they’re repeating folklore.
This may change. The framework is being pushed hard through MSP partner channels, and a high-profile Acronis-CyberCert partnership was announced in October 2025. Insurer recognition tends to follow market penetration eventually. As of April 2026, the recognition isn’t there yet at a level we can verify.
Are the SMB1001 controls any good?
Mostly yes. With three specific concerns we’d want resolved before recommending the certificate as substantive evidence of how secure a business is.
The 2026 control set covers the right ground for a small business. Multi-factor authentication (MFA) is there, which is the second step you complete after your password. So are patching, backups and staff awareness training. The list also includes endpoint detection and response (EDR), software that watches each device for attack behaviour, plus the managed version of it (MDR). It covers the email records that stop someone forging mail from your domain: SPF, DKIM and DMARC. And it asks for an acceptable-use policy covering artificial intelligence. The selection is broadly sound, and it addresses the risks a 10-to-30 staff Australian business actually faces.
Our first concern is the published Bronze tier, which still mandates routine password changes. NIST SP 800-63B Revision 4 comes from the United States National Institute of Standards and Technology (NIST). It has been the global baseline for identity and authentication since August 2025, and its predecessor was formally withdrawn that month. Revision 4 explicitly tells organisations to stop forcing scheduled password rotation. ISO 27001, SOC 2, PCI-DSS and HIPAA all align to NIST 800-63B. For a framework that markets itself on annual revision, shipping the 2026 edition with this control unrevised is hard to defend. The framework also contradicts itself. Bronze requires routine rotation, Silver adds a password manager, and a password manager makes scheduled rotation operationally pointless.
Our second concern is where MFA appears. Remote desktop (RDP), remote access over a virtual private network (VPN) and stored data only require MFA at Level 4, which is Platinum. Remote desktop without MFA has been one of the most common ways ransomware crews get in for years. A SMB1001 Gold-certified business may be running remote desktop with a password and no second step, and still hold the certificate. Gold has 22 controls and costs $395 per year, and it is the realistic mass-market tier. The controls that most reduce ransomware risk are a tier above it.
Our third concern is the claim of alignment with the Essential Eight, which is partial at best. Application control and disabling untrusted Microsoft Office macros are both Maturity Level One strategies in the Essential Eight. In SMB1001 they only appear at Level 5. Cybersecurity awareness training only appears at Level 3. A SMB1001 Gold certificate covers a meaningful chunk of Essential Eight Maturity Level One, but it is not equivalent to it. That matters, because the parties most likely to ask you for cyber evidence in Australia are insurers, sector regulators and larger corporate customers. They ask in Essential Eight or ISO 27001 terms, not SMB1001’s.
Who is SMB1001 useful for?
Two distinct cases, and they’re often confused.
As an internal control checklist, the framework is genuinely useful for a 10-to-30 staff business that hasn’t organised its security yet. Working through Bronze, Silver and Gold gives an owner-operator a reasonable list of the things to actually have in place. The director attestation then gives them a reason to take that list seriously. The same applies to bringing a new MSP relationship up to a documented baseline.
As an external credential to wave at insurers, customers or regulators, the case is much weaker. The framework isn’t named in legislation. Insurer recognition appears to be MSP folklore rather than published underwriting policy. The bottom three tiers are self-attested, so a recipient who hasn’t read carefully cannot tell whether your certificate means director attestation or external audit. The parties you most want to convince usually speak Essential Eight and ISO 27001 instead.
A reasonable summary, in our view: SMB1001 is fine as a self-improvement tool, weak as a badge in 2026.
What CCP does about SMB1001
We don’t sell SMB1001 certification, and we aren’t a CyberCert partner. That position may change as the market does, and if the framework picks up the kind of independent recognition we’ve described as missing here. If it does, this article and the disclosure at the top will be updated.
For the same kind of client, what we do is implement the underlying controls. Every Managed IT Complete plan contractually includes MFA, patching, backups, awareness training, EDR, email authentication, password management and admin separation. Those are the same controls SMB1001 lists in its first three tiers. A client on our standard stack who works through the SMB1001 self-attestation checklist will find most of the work already done. What is left is documentation and policy text, not technical implementation.
If you’re weighing SMB1001 against doing Essential Eight Maturity Level One properly, we’d suggest the Essential Eight self-assessment first. It’s free and it takes ten minutes. It gives you a maturity estimate in the language Australian institutions actually speak. The answers also tell you whether the work to clear an SMB1001 tier is already largely done. If you still want a certificate afterwards to hand to a specific party, that conversation is much easier with the picture in front of you. The options are SMB1001, ISO 27001, or an evidence-based claim to Essential Eight Maturity Level One.
Our framework selection guide compares all three in more detail.
Primary sources
- CSCAU 2024 submission to the Department of Home Affairs, including Annex A controls table. Department of Home Affairs. Accessed April 2026.
- Cyber Security Act 2024 (Cth). Federal Register of Legislation. Accessed April 2026.
- NIST SP 800-63B Revision 4 (Digital Identity Guidelines). National Institute of Standards and Technology. Published August 2025.
- ACSC Essential Eight Maturity Model. Australian Cyber Security Centre.
- ISO/IEC 27001:2022. Published jointly by ISO and the International Electrotechnical Commission (IEC).