Black Shard

SMB1001, explained properly.

The Australian tiered cyber security standard: what it is, what the five tiers mean, how a certificate is issued, and how to check one you have been sent.

SMB1001 is a cyber security certification standard for small and medium businesses, published by Dynamic Standards International. It is tiered, running from Bronze up to Diamond, so a business certifies at the level it can sustain and steps up as it matures. A certification body issues the certificate against the standard and lists it publicly, which is what makes it useful in a commercial negotiation: the other side can check it without taking your word for anything.

It exists because the standards that came before it were built for organisations with a compliance function. A twelve-person business asked for security assurance by a customer had, until recently, two answers: an ISO 27001 program it could not carry, or a spreadsheet of self-declared answers nobody believed. A tiered certificate with an issuer and a registry entry is the third answer, and it is why the standard has moved quickly into Australian supply-chain questionnaires and insurance proposals.

Black Shard holds SMB1001:2026 Gold, issued by CyberCert and listed on its public registry. This page is the explainer we wanted when we went through it.

Who ends up certifying.

Almost nobody certifies unprompted. Something asks the question first, and the standard exists because the honest answer used to be expensive.

  • The business being asked

    A customer questionnaire, an insurance proposal, a tender or a larger partner tightening its vendor list puts a deadline on a question the business has never had to answer in writing. That request starts most certifications.

  • The business doing the asking

    A buyer who wants something better than a self-declared spreadsheet and has no way to audit a supplier itself. A tier, an issuer and a registry entry can be checked by one person in a minute, which is why the requirement spreads down supply chains.

  • The business that expects to be asked

    Anyone whose contracts are trending toward larger counterparties. Certifying ahead of the request costs the same work and none of the deadline, and the evidence pack answers the questionnaires that arrive later.

The five tiers, and what each one signals.

Each tier adds controls over the one below, so the requirement is sized to the business instead of imposed whole. The control set for every tier is defined in the published standard; the count we can stand behind is the one we hold.

The five SMB1001 tiers and what each signals to a buyer
LevelTierWhat it signals
Level 1BronzeThe entry tier. It says someone has deliberately put the basics in place, and it is the fastest honest answer to a buyer who has asked for something and will accept a starting point.
Level 2SilverBronze plus a further set of controls. The usual reason to stop here is that the business is genuinely small, holds little sensitive data, and has no contract asking for more.
Level 3GoldTwenty-seven controls covering the fundamentals a buyer actually asks about. This is the tier Black Shard holds, and in our experience it is the tier that answers most Australian supply-chain and insurance questions without further argument.
Level 4PlatinumFor businesses whose customers, data or regulator push past the fundamentals. At this tier the requirement usually arrives written into a contract.
Level 5DiamondThe top tier. Relevant to a small number of businesses, usually ones whose buyers would otherwise be asking for ISO 27001.

What Gold actually asks for.

27

controls at Level 3. The territory is practical, which is the point of the standard.

  • Access and identity

    Multi-factor authentication on the accounts that matter, administrative privilege restricted to the people who need it, and a process for removing access when someone leaves.

  • Keeping systems current

    Patching operating systems and applications on a cadence the business actually keeps, and retiring software that no longer receives security updates.

  • Backup and recovery

    Backups that run, are held where an attacker on the network cannot reach them, and have been restored from at least once so the restore is a known quantity.

  • Incident handling

    A written plan for who is called, in what order, when something goes wrong, and a record of incidents when they do.

  • People

    Security awareness training that happens on a schedule, with a record of who completed it and when.

  • Suppliers and governance

    Documented policies, an owner for each of them, and discipline about the vendors and third parties who can reach your data.

How to read a certificate you have been sent.

Most of the value of this standard is that a certificate can be checked in about ninety seconds. Five things decide whether the one in front of you means what the sender implied.

  • The edition year

    The standard is revised annually and certificates carry the year they were issued against. Ours reads SMB1001:2026. A certificate quoting an older edition is not wrong, but it tells you when the assessment happened.

  • The tier and level

    Bronze through Diamond, Levels 1 to 5. A certificate that says only "SMB1001 certified" without a tier is not answering the question you asked.

  • The legal entity

    Certificates are issued to a company, not to a trading name or a group. Check the ABN on the certificate against the entity you are contracting with. This is the single most common mismatch we see in supply-chain paperwork.

  • The active period

    Certification is renewed annually. A certificate has a start and an end date, and an expired one tells you what was true a year ago.

  • The registry listing

    Certificates issued through CyberCert are listed on its public registry. Do not take the PDF as the source of truth: open the listing and check the holder, the level and the dates against what you were sent.

Where it sits beside everything else.

Against ISO 27001, the difference is one of kind rather than degree. SMB1001 certifies that a defined set of controls is in place at a stated tier. ISO 27001 certifies that a management system for information security exists, operates, and is independently audited on a cycle. If your buyers are offshore or enterprise, they will name ISO 27001. If they are Australian and mid-market, SMB1001 usually settles the question faster. The full side by side is on our SMB1001 vs ISO 27001 comparison.

Against the ASD Essential Eight, the difference is that one produces an artefact and the other produces a rating. The Essential Eight is a set of mitigation strategies published by the Australian Signals Directorate; there is no certificate, no issuing body and nobody to verify a maturity level with. The controls overlap heavily with SMB1001, so evidence gathered once usually serves both, which is the practical reason to sequence the two together instead of running them as separate projects.

Against a security questionnaire, a tiered certificate is simply legible. A procurement officer who cannot interpret a maturity report can read a current, dated, tier-labelled certificate and move on.

Where the effort goes.

The gap-closing work

This is the whole timeline. Whatever distance sits between your current state and the target tier is the project; everything after it is paperwork.

The evidence

Each control needs something you can point at. Assembling that once, properly, is what makes the next questionnaire and the next renewal cheap.

The renewal

Annual, against the current edition. The controls have to hold between renewals rather than be assembled for the date.

Where Black Shard stands.

We hold SMB1001:2026 Gold, as Black Shard Pty Ltd, ABN 66 696 910 773, issued by CyberCert and active to 17 June 2027. The listing is public and you can check it on the registry. Everything else we hold or self-assess against is set out on our trust page.

We do readiness work, not certification: a gap review against your target tier, the remediation that closes it, and an evidence pack the certifying assessor can work from. The certification decision belongs to the certification body.

This page is free to cite, quote and link to. If something on it is wrong or the standard moves, tell us and we will correct it.

Questions, answered

Who publishes SMB1001?
The standard is published by Dynamic Standards International. Certificates are issued by a certification body against it; ours was issued by CyberCert, which lists issued certificates on a public registry.
Is SMB1001 an Australian standard?
It was built for Australian small and medium businesses and it is what Australian buyers, insurers and supply-chain questionnaires have started to ask for. It carries little weight with offshore buyers, who will usually name ISO 27001 instead.
Which tier should we certify at?
The tier the people asking you for proof will accept. Where nothing has been specified, size the tier to the data you hold and the contracts you serve. A gap review against the target tier settles it quickly, and a lower tier that discharges the obligation is a better answer than a higher one you cannot sustain.
How long does certification take?
The timeline is the gap-closing work, not a queue. Once the controls at your target tier are in place and evidenced, the certificate issues and the registry listing goes up. How long the gap-closing takes depends entirely on how far the current state sits from the tier.
Do we still need the Essential Eight?
They answer different questions and they overlap heavily in practice. The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate that an organisation assesses itself against; there is no certificate and no issuing body. SMB1001 is a certification with a tier, an issuer and a public registry entry. Evidence gathered for one usually serves the other.
What happens at renewal?
Certification is renewed annually, against the current edition of the standard. That is the part businesses underestimate: the controls have to still be true a year later, and the edition you renew against may have moved.
Does Black Shard issue certificates?
No. We do the readiness work: a gap review against your target tier, remediation, and an evidence pack ready for the certifying assessor. Certification bodies certify. We hold SMB1001:2026 Gold ourselves, which is why we know what the evidence has to look like.

Certify at the tier your buyers will accept.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au