Black Shard

We hold the certificate we get you ready for.

SMB1001 readiness for Australian businesses, from a national firm that holds SMB1001:2026 Gold and is listed on the public CyberCert registry.

SMB1001 is a cybersecurity certification standard built for small and medium businesses, and it is one of the frameworks Australian businesses are asked for. The standard is tiered, so a business certifies at the level its risk and its customers demand, with the credential listed on a public registry where anyone can verify it.

We prepare Australian businesses to certify at their target tier: a gap review against the standard, step-by-step remediation, and an evidence pack ready for the certifying assessor. Delivered Australia-wide from our Brisbane head office.

What is SMB1001?

The standard runs five tiers, Bronze, Silver, Gold, Platinum, and Diamond, sitting at Levels 1 through 5, each adding controls over the one below, so the requirement can be sized to the business rather than imposed whole. Each edition carries a year mark; the current edition is 2026, the one Black Shard certified against.

Gold, the tier Black Shard holds, sits at Level 3 of the standard. It rests on twenty-seven controls, formally attested by a company director. The territory is practical rather than theoretical: multi-factor authentication, patching, restricting administrative privilege, backups and recovery, incident handling, and discipline around vendors and third parties. The credential is listed on CyberCert's public registry, and that verifiability is what makes the standard useful in a commercial negotiation: it can be confirmed without taking anyone's word for it.

Why are Australian supply chains asking for SMB1001?

Because security questionnaires now travel down the supply chain. Large Australian organisations and government buyers carry obligations they cannot discharge alone, so they push assurance requirements onto every supplier that touches their data or their systems. For a small or medium supplier, the ask used to be awkward: ISO 27001 is a serious undertaking, often more than a single contract justifies, and a self-written security policy convinces nobody.

SMB1001 fills that gap. It is tiered, so the requirement can be sized to the supplier. It is certifiable, so a procurement team can rely on it rather than reading your policies line by line. And a registry listing answers the questionnaire before it is sent. The 2026 Privacy Act reforms sharpen the same pressure: businesses holding personal information are being asked to show their working, not assert good intent.

What a readiness engagement involves

A readiness engagement takes you from wherever you stand today to the point where the certifying assessment is a step you have already rehearsed. It runs as a defined program with milestones set against your certification date, and it follows the discipline set out on our approach page: read the real risk first, fix like an engineer, then prove it.

We work under least-privilege access for the duration, asking only for the access the review requires, because that is the same discipline the standard asks of you. Findings arrive in plain English with the reasoning shown. And where a gap needs engineering rather than paperwork, we can carry it ourselves: we design, build, and run production software, so remediation is a change that ships, not a recommendation that sits in a document.

  • A gap review against your target SMB1001 tier: each control of the standard checked against your environment as it runs day to day, with a plain verdict on every one
  • Step-by-step remediation to close the gaps, sequenced so the controls that cut the most risk land first, with our engineers doing the hands-on work where you want it
  • An evidence pack assembled for the certifying assessor: the policies, records, and configuration proof the standard expects, organised so assessment is confirmation, not archaeology

Why work with a firm that holds the certification?

We put our own operations through the same certification we prepare you for. Black Shard Pty Ltd holds SMB1001:2026 Gold, issued by CyberCert, active through to June 2027, and listed on the public registry where anyone can check it. Our trust page carries the certificate and the frameworks we self-assess against.

That changes the quality of the advice. We know which controls are an afternoon of configuration and which need planning and budget. We know what evidence the attestation actually requires, because we assembled our own. And we know how the standard sits beside the ASD Essential Eight, whose strategies overlap most of the same ground, so uplift you have already done counts instead of being repeated. Readiness advice from a firm that has walked the path reads differently from readiness advice assembled out of the standard's table of contents.

It also keeps us precise about the boundary. The word certified appears on our site only about our own credential, because it is the only certification we hold. We apply the same precision to yours: your credential exists when the issuer says it does, not before.

The outcome to expect

Readiness to certify. Stated plainly: the gaps against your target tier closed, the evidence assembled and organised, and your business in a state we would be willing to attest to if it were ours. The certification decision belongs to the certifying process, not to us, and no honest advisor promises an outcome another party controls. What we promise is that you arrive at the assessment prepared, with every control either demonstrably met or carrying a named, sequenced fix.

You also come out the other side with more than a credential path. The controls are real once they land: multi-factor authentication that is enforced, backups that have been restored rather than assumed, an incident path someone has rehearsed. That posture outlasts any certificate, and it is the point of the exercise.

What does SMB1001 readiness cost?

The price is driven by scope: the tier you are targeting, how far your current posture sits from it, the number of environments and tenancies in the review, and how much of the remediation our engineers carry versus your own team closing gaps against our plan. A business already partway through Essential Eight uplift is a smaller job than one starting cold. The engagement itself runs as a defined program with milestones toward your certification date, scoped and agreed before the work starts.

The spread is too wide for a published range to mean anything. Send the brief instead: someone will contact you as soon as possible with the questions that let us scope it properly.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix.

  • Evidence as you go

    Every closed gap lands with the artefact the assessor expects.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Which SMB1001 tier should we target?
The standard runs five tiers, Bronze through Diamond, and the target is usually set by what your customers and contracts require of you. Where the ask is unstated, we size the tier to the data you hold and the contracts you serve, as part of the gap review, and we will say plainly if a lower tier discharges the obligation.
Is SMB1001 the same as the Essential Eight?
No. The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate that you self-assess against; SMB1001 is a certification standard with an issuing body and a public registry. The controls overlap substantially, so Essential Eight uplift you have already done counts directly toward SMB1001 readiness.
Can you guarantee we will be certified?
No, and be wary of anyone who says otherwise. Certification is issued by the certifying body, not by your advisor. What we deliver is readiness: gaps closed against the target tier and an evidence pack the assessor can work through without friction.
Do you issue the certification yourselves?
No. SMB1001 certification is issued through CyberCert. We prepare you for that process. Our own Gold credential was issued the same way and sits on CyberCert's public registry, which is why we know what it takes.
How long does SMB1001 readiness take?
It depends on the distance between your current posture and the target tier, and on how many environments are in scope. We run readiness as a defined program with milestones set against your certification date, so the timeframe is agreed at the start, not discovered along the way.
Do you only work with Brisbane businesses?
No. We are a national firm and we deliver Australia-wide from our Brisbane head office. Readiness work runs under least-privilege access, asking only for the access the review requires, and the engagement is the same wherever you are.

Ready to certify, with the evidence to prove it.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au