Get you ready
We assess your environment against every control at your target tier and tell you plainly which ones would stand up and which would not. You get a populated control tracker and a prioritised roadmap, not a spreadsheet of jargon.
SMB1001:2026 · Australia's cyber standard for small business
A customer's supplier questionnaire, an insurer's renewal form, a tender that scores it. SMB1001 is how an Australian small business answers that properly, and we take you through it, from where you stand today to a certificate you can actually defend.
What it is
SMB1001 is an Australian cyber security standard for small and medium businesses, published by Dynamic Standards International and administered by CyberCert. It sets out 39 practical controls across five tiers, so you start at a level that matches your risk and step up as your obligations grow, without the cost and ceremony of ISO 27001.
It is not a legal requirement. Businesses come to it because someone else has made it their problem: a customer wants assurance, an insurer wants evidence, a tender awards points for it. The certificate is the easy part. Being able to stand behind it is the part we handle.
The five tiers
Each tier builds on the one below it. Bronze, Silver and Gold are attested by your own director through the CyberCert portal. Platinum and Diamond are verified by an independent organisation.
Whichever tier you are aiming at, the preparation is our job: working out where you stand, producing the evidence behind each control, and closing whatever gaps are left. The point is that when your director signs, or an independent verifier turns up, nothing comes as a surprise.
| Tier | Controls | What it adds | Verified by |
|---|---|---|---|
| Bronze | 7 | Firewall, anti-virus, patching, password hygiene, backup, staff awareness training, engaged IT support | Your director |
| Silver | 17 | Adds MFA on email, SPF, a password manager, individual accounts, server patching, TLS, a visitor register and core policies | Your director |
| Gold | 27 | Adds EDR, enforced DMARC, cyber insurance, incident response and AI use policies, secure document destruction and device disposal | Your director |
| Platinum | 32 | Adds vulnerability scanning of internet-facing systems, and MFA on VPN, RDP and data stores | Independent verifier |
| Diamond | 39 | Adds encryption at rest, application control, penetration testing, supplier trust, police vetting and tested incident response | Independent verifier |
Not sure which tier applies? Dynamic Standards International recommends a starting point by turnover: under $1M start at Bronze, $1M–$10M at Silver or Gold, $10M–$50M at Gold or Platinum. Most businesses being asked for proof by a customer land on Silver.
Where it sits
A fair question about any smaller standard is whether it really counts. The standard's own documentation answers it in two ways.
SMB1001 states plainly that its five tiers are intended to give smaller businesses a foundation and a pathway for adopting international standards such as ISO/IEC 27001 more easily. That is the design intent rather than a marketing line. ISO 27001 asks for a fully implemented information security management system, with the cost and effort that implies, which is precisely why most small businesses never begin. SMB1001 gives you somewhere to start that still counts on the way through.
The control set was not invented from scratch either. The standard names its source material: ISO/IEC 27001:2022, the AICPA’s SOC 2 criteria, and the United States Department of Defense CMMC 2.0.
SMB1001 is published by Dynamic Standards International and overseen by a steering committee whose member organisations include the Australian Signals Directorate, AusCERT, the Australian Computer Society, the Australian Digital Health Agency, the Council of Small Business Organisations Australia, CyberCX, Deloitte, Telstra, the Government of South Australia, CSA Singapore and the CMMC Industry Standards Council. It is revised every year, which is unusual for a standard and is the reason the 2026 edition differs from the 2025 one.
None of this makes SMB1001 a lesser standard. It makes it the right size to start at, with somewhere to go afterwards.
How we work
We do not certify you; no IT provider can. Your director attests, or an independent verifier audits. What we do is everything that has to be true first.
We assess your environment against every control at your target tier and tell you plainly which ones would stand up and which would not. You get a populated control tracker and a prioritised roadmap, not a spreadsheet of jargon.
Configuration reports, policy sign-offs, restore-test records, training completion. This is the part most businesses cannot do alone, and the part that has to hold up when somebody actually checks.
MFA, EDR, DMARC, patching, backup and restore testing, awareness training and phishing simulation, certified secure erase of retired drives and devices, access control. We build the controls as well as document them, then support your director through the attestation, or hand the roadmap to whoever you would rather use.
Beyond the technology
SMB1001 is a cyber standard, but several of its controls are physical or about people. Most of them can be met simply, and where a notebook and a procedure will do, we will tell you that rather than sell you a system.
| Control | The simple way to comply | If you want more than that |
|---|---|---|
| Visitor register Silver |
A bound visitor book at reception, filled in by hand and kept for at least six months. Entirely compliant. | An access control system that logs every entry automatically, so the register maintains itself. Any licensed installer can do this; use whoever you already work with. |
| Secure document destruction Gold |
A cross-cut shredder, a written procedure and a destruction log. For most small offices this is the sensible answer. | A scheduled collection service that issues formal Certificates of Destruction. Several operate in Perth; the certificates go straight into your evidence pack. |
| Secure device disposal Gold |
Cryptographic erase or a full secure wipe before the device leaves, recorded against your asset register. | Certified erasure software that produces an auditable report per device, or physical destruction through a specialist where the data warrants it. |
| Police vetting Diamond |
An accredited online police check. Fast, inexpensive, and what almost every business should use. | Where vetting forms part of a wider investigation, or needs to go further than a standard check, that is licensed investigative work, and we hold an Inquiry Agent Licence if you need it. |
Our job is to tell you which column you actually need, and it is often the left one.
Where our advice and our services overlap, we say so. An assessment tells you what a control requires and whether you meet it, not what to buy, or who from. If you already have an electrician, a security installer or an IT provider, use them; the report is written so they can act on it without us. We quote only if you ask us to, and where we end up both assessing a control and implementing it, that is recorded in writing on a shared risk register so it is visible to you and to anyone reviewing your certification.
Pricing
You can buy the certificate yourself for about $95. What you cannot do is know whether you would survive being asked to prove it. That is what the assessment is for.
| Target tier | What you get | Fixed price |
|---|---|---|
| Bronze | All 7 controls assessed, evidence notes, prioritised remediation roadmap | $1,250 |
| Silver | All 17 controls assessed, including MFA and email authentication posture | $2,500 |
| Gold | All 27 controls, including EDR coverage, DMARC, incident response and AI policy | $4,500 |
Prices exclude GST and cover an environment of up to 15 users, 25 endpoints and one site. Larger environments are quoted after a short scoping call. Remediation and ongoing compliance care are quoted after the assessment, because until we have looked, neither of us knows what is involved, and we would rather price it honestly than pad it.
Proof
Owls Nest Solutions Pty Ltd (ABN 32 699 767 587) is certified to SMB1001:2026 through CyberCert, valid to 8 August 2027. You do not have to take our word for it: check the entry on the public certification registry, where the ABN should match the one in our footer. We are held to the same controls we assess you against, including the ones nobody enjoys, like proving our own backups restore.
The two Dynamic Standards International badges are a supporter membership, not a certification. We support DSI’s mission to make SMB1001 freely available to small businesses. Only the CyberCert badge above represents a certification we hold.
We are not an Independent Verification Organisation, and we will never tell you we can certify or audit you. We assess, evidence, remediate and support you to attestation. That distinction matters, and any provider who blurs it is telling you something about how they work.
Questions
No. SMB1001 is not law. It is how you answer someone who has asked you to prove your posture: a customer, an insurer, a tender panel.
It can help, and insurers increasingly ask about controls at renewal. We are not licensed to give insurance advice and we do not sell insurance. If you need cover, we will point you to a licensed broker and stay out of the way.
There is nothing to fail. The assessment tells you where you stand; the roadmap tells you what to fix and in what order. Nobody sees it but you.
Yes, and it is common. We can assess and evidence while your existing provider does the remediation, or do both. Your choice, and we will not push either way. The report is written to be handed to whoever does the work. If we end up doing both, we say so in writing and record it on a shared risk register, because you should always know when your assessor is also your implementer.
The assessment is typically a week from kick-off to report. Remediation depends on what we find, which is why we quote it afterwards.
Most of the assessment is done remotely, so yes. Controls with a physical component (visitor register, document destruction, device disposal) need a site visit, and those are quoted with travel where you are outside the metro area.
Thirty minutes, no charge, no obligation. We will tell you which tier fits and whether you would pass the Bronze controls today.