| Who runs it | Australian Signals Directorate (ACSC). Sovereign cyber authority. | Dynamic Standards International (DSI), formerly CSCAU. Private Australian standards body. Sister entity CyberCert operates certification. | ISO and IEC, the international standards bodies. Independently accredited certification bodies run the audits (JAS-ANZ accredits them in Australia). |
| How you prove it | Self-assessment against ACSC criteria. No certificate. Often used as evidence inside cyber-insurance renewals and supplier-security questionnaires. | Bronze, Silver and Gold: self-attested by a company director. Platinum and Diamond: third-party audit. Annual recertification for all tiers. | Third-party audit by an accredited certification body. Three-year certificate cycle, annual surveillance audits. No self-attest pathway. |
| Tier or maturity model | Four maturity levels: ML0 (partial or missing), ML1, ML2, ML3. Your overall maturity equals your weakest of the eight control scores, not the average. | Five tiers from Bronze to Diamond. Each tier adds controls on top of the previous. 6 controls at Bronze, 35 at Diamond. | Single binary state (certified or not), but the certificate covers a defined Statement of Applicability that scopes which controls are in play for your organisation. |
| Direct cost in 2026 | Free. ACSC publishes the model. Audit and assessment cost is your time and your IT spend on the controls themselves. | Annual certification fee per organisation, AU ex GST: $95 (Bronze), $195 (Silver), $395 (Gold), $3,595 (Platinum), $5,995 (Diamond). The standard text itself is paywalled at USD $99 to $1,000 with usage-based pricing. | First-audit cost typically AU $15,000 to $50,000 depending on scope and certifier. Standard text sold by ISO at roughly AU $150 fixed. |
| Update cadence | Maturity model revised every few years. Last major revision November 2023; minor updates more often. | Annual editions (2023, 2025, 2026). Genuinely faster cadence than the alternatives. | 5 to 10 year revision cycles. Current edition 2022, predecessor 2013. |
| Recognised by Australian Government | Yes. ACSC publishes it. Cited in federal cyber strategy, sector regulator guidance, and many procurement panels. | Not in primary legislation. As of April 2026, it is not named in the Cyber Security Act 2024, and not in the Security of Critical Infrastructure (SOCI) Act risk-management rules. Cyber Security Certification Australia asked Government to add it in a 2024 submission. The 2025 SOCI amendments did not add it. | Yes. Specifically named in CIRMP Rules for some critical-infrastructure sectors. Required by Right Fit For Risk and several other government accreditation regimes. |
| Recognised by cyber insurers | De facto baseline language used in most Australian renewal questionnaires. ML1 typically clears a renewal without raised flags. | Managed service provider (MSP) marketing claims insurer recognition. We could not find one named Australian insurer that publishes SMB1001 as a documented premium-discount input. | Universally recognised. Often clears whole questionnaire sections instead of itemised answers. |