Black Shard

Certify for the buyer you actually have.

ISO 27001 is the audited international standard that big procurement asks for, priced and paced accordingly; SMB1001 is the Australian tiered standard sized for SMBs, built so a business can certify now at the tier it can sustain.

Two standards, two different questions. ISO 27001 answers: can you prove to anyone, anywhere, that a managed security system operates here. SMB1001 answers: can you prove to an Australian buyer that the fundamentals are in place. Most businesses only need one of those answers at a time, and the contract in front of you usually decides which.

The comparison below is deliberately plain: who asks for each standard, how each is assessed, what the work actually involves, and what keeping the certificate costs you in attention every year afterward.

Our stake, declared up front: Black Shard holds SMB1001:2026 Gold, verifiable on the public CyberCert registry. We prepare clients for both standards and certify them against neither. Assessors and auditors certify; we do the work that gets you past them.

Side by side.

SMB1001 compared with ISO 27001
CriteriaSMB1001ISO 27001
Who asks for itAustralian buyers, insurers and supply chains that want proof of baseline cyber hygiene from an SMB. It gives a small business a registry-verifiable answer where before there was nothing to point at.Enterprise and government procurement, multinationals and international buyers. When a tender or contract clause names a certification, it almost always names ISO 27001. If your buyers are offshore, this is the standard they recognise.
Assessment modelAt Gold, a company director signs off against the standard's twenty-seven controls, and CyberCert issues the certificate onto a public registry. Buyers can check the listing and ask for the evidence behind each control.Independent audit by a certification body: a stage one review of your documentation, a stage two audit of the system in operation, then surveillance audits to keep the certificate.
Scope and effortA fixed control set per tier, applied to the business as a whole. The effort is closing controls: multi-factor authentication, patching, backups, access management, policies, training. Most of it is work an SMB should be doing anyway.You define the scope of an Information Security Management System, assess risk, justify every included and excluded control in a Statement of Applicability against Annex A, and then operate the machinery: policies, risk register, internal audit, management review. The standard certifies a management system, not a checklist.
Timeframe shapeThe timeline is the gap-closing work itself. Once the controls are in place and evidenced, the certificate issues and the registry listing goes up.A program, not a sprint. The ISMS must operate long enough to generate the evidence an auditor assesses, and the stage one and stage two audits are scheduled around a certification body's calendar. The runway is set by evidence and audit scheduling, not by how fast the gaps close.
Cost shapeThe lighter of the two. The spend is mostly the remediation itself, and the certification step is small against it. What drives the effort: the people and systems in scope, the number of environments and tenancies, and how much documented process already exists.The heavier of the two, structurally: certification-body fees at the initial audit, surveillance fees every year after, and the internal cost of operating an ISMS on top of the gap-closing work.
RecognitionAustralian. It is asked for in Australian supply chains, and the certificate itself can be checked in due diligence. It carries little weight offshore.The international default. Recognised across markets and industries, and the certification large procurement teams are trained to look for. If recognition is the whole game, ISO 27001 wins it.
MaintenanceRenewed annually, always against the current edition, because the standard itself is revised every year. That is why a certificate carries its year, and why the controls have to hold between renewals rather than being assembled for the date.Surveillance audits each year and recertification on a three-year cycle, with internal audits and management reviews running in between. The ISMS is a standing operational commitment, and it needs an owner.

When SMB1001 is the right call

  • You are an Australian SMB and no contract in front of you names ISO 27001.
  • Buyers or insurers are asking whether you hold any certification, not a specific one, and you need a verifiable answer.
  • You want a credential now and a structured uplift path, rather than a long ISMS build before anything is certifiable.
  • Your security budget should go into controls first: the standard puts the spend into multi-factor authentication, patching and backups rather than documentation.
  • You expect to pursue ISO 27001 later. The control work transfers; nothing is thrown away.

When ISO 27001 is the right call

  • A tender, panel or enterprise contract names it. That settles the question.
  • Your buyers are offshore or multinational and will not recognise an Australian SMB standard.
  • Counterparties specifically require an independent third-party audit.
  • You are large enough that a managed ISMS earns its keep: risk formally owned, internal audit, board-level reporting.
  • You handle data at a scale or sensitivity where an independently audited management system is the honest posture, not just the marketable one.

What are SMB1001 and ISO 27001, exactly?

SMB1001 is an Australian cybersecurity certification standard built for small and medium businesses. It is tiered, running from Bronze upward, so a business certifies at the level it can sustain and steps up as it matures. Certification is issued through CyberCert and listed on a public registry, and the standard is revised annually, which is why certificates carry a year: ours reads SMB1001:2026. At Gold, the tier we hold, a director formally attests to twenty-seven concrete controls, the fundamentals of patching, multi-factor authentication, backups, access control and staff training.

ISO 27001 is the international standard for information security management systems. It does not certify a list of controls so much as a system of management: you define the scope of the ISMS, assess risk, justify every included and excluded control in a Statement of Applicability against Annex A, and then run the machinery of policies, risk register, internal audit and management review. An accredited certification body audits the documentation, then the system in operation, and returns every year to check it is still alive.

That difference in kind explains everything else on this page. One standard certifies that the fundamentals are implemented in a business of your size, and does it quickly and verifiably. The other certifies that a management system exists, operates and is independently audited, and is recognised in nearly every market on earth. Neither is a lesser version of the other. They answer different buyers.

Why do so many businesses do SMB1001 first?

Because the demand usually arrives before the budget does. The first time most Australian SMBs are asked to prove their security posture, it is a supplier questionnaire, an insurer's renewal form or a mid-sized client's procurement checklist, not a multinational tender. SMB1001 answers that demand with a certificate the counterparty can verify, and the work behind it is control implementation your business needed regardless.

The step up later is not wasted motion. The controls SMB1001 forces into place are the same controls an ISO 27001 auditor expects to find operating. Run in this order, the sequence arrives at the ISO program with the technical half largely done and an evidence habit already formed; the genuine new work is the management system itself, not the fundamentals.

The one trap in the sequence: if a live contract names ISO 27001, SMB1001 does not substitute, and no amount of registry-verifiable goodwill changes a procurement checkbox. Read the clause before choosing the path. Where the clause is explicit and the timeline is long, start the ISO program and certify SMB1001 in parallel as the interim proof point. The work overlaps rather than competes.

Where Black Shard stands

We hold SMB1001:2026 Gold ourselves, as Black Shard Pty Ltd, and anyone can verify it on the public CyberCert registry; the certificate and the frameworks we self-assess against are laid out on our trust page. We are not recommending a standard we have not been through: we closed the same twenty-seven controls we help clients close.

We offer readiness for both standards and certification for neither. For SMB1001: a gap review against your target tier, step-by-step remediation, and an evidence pack ready for the certifying assessor. For ISO 27001: scoping of your ISMS, a gap analysis against Annex A controls, and the core policies and documentation an auditor expects. Either way the engagement runs as a defined program with milestones toward your certification or audit date.

The working method is the same one we bring to security testing, documented on our approach page: read the real risk first, then close the gaps with evidence an assessor can hold, in plain English. Certification is won on evidence, not intent.

Questions, answered

Can we do SMB1001 first and step up to ISO 27001 later?
Yes, and it is a sensible sequence. The technical controls SMB1001 forces you to implement, multi-factor authentication, patching, backups, access management, are the same controls an ISO 27001 auditor expects to see operating under Annex A. The policies and evidence you build for one become inputs to the other. You certify sooner, and the later ISO program starts from a working baseline instead of a blank page.
Does Black Shard certify us against either standard?
No. Preparation and certification should not come from the same hands; the conflict is obvious. Assessors and auditors certify, and our job ends at the audit door: the gap review, the remediation plan, and the evidence pack are ours, the certificate is theirs. Our own SMB1001:2026 Gold was issued the same way.
Is SMB1001 recognised outside Australia?
Not meaningfully. It is an Australian standard with an Australian registry, and its weight is in Australian supply chains, where it is actually asked for. Offshore buyers and multinational procurement teams look for ISO 27001. If your revenue depends on international counterparties, treat SMB1001 as a domestic proof point and plan for ISO 27001 as the standard those buyers will actually read.
What does each certification cost?
We will not invent figures on a comparison page. The shape of it: SMB1001 spend is mostly the remediation work, with a small certification step on top. ISO 27001 adds certification-body audit fees, annual surveillance fees and the internal cost of operating an ISMS. Readiness work with us runs to your audit date, and the effort is driven by the people and systems in scope, the number of environments and tenancies, and how much documented process you already have.
Which SMB1001 tier should we target?
The tier the people asking you for proof will accept. The standard runs from Bronze upward with each tier adding controls, and Gold (Level 3) is the tier Black Shard holds as a cybersecurity firm. A gap review settles it quickly: we map your current state against the target tier's controls, and you see the distance before committing to it.
Is ISO 27001 overkill for a small business?
Often, yes, if nobody is asking you for it. An ISMS is a standing management commitment: risk register, internal audits, management reviews, surveillance fees. For a small business with no contractual driver, that overhead buys recognition nobody is requesting, while the same budget spent on SMB1001 buys implemented controls and a verifiable certificate. The moment a contract names ISO 27001, the calculus flips. Certify for demand, not for decoration.

Send the tender clause. Get a straight answer.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au