SMB1001··4 min read

SMB1001:2027: What Changes for Your Business (and What to Do Now)

SMB1001:2027 is out. Your current certificate still counts. Here is what the new edition means in plain English, who it affects, and the first step for each change.

By Pardeep Sharma

The short version: your current SMB1001 certificate still counts for its full year. Most small businesses at Level 1 or 2 have very little new work. The big changes land at Level 4 and 5, and the headline is AI: if your staff use AI tools, you will soon need a simple policy for it. Write that policy now. It takes an afternoon.

Dynamic Standards International (DSI) publishes a new edition of SMB1001 every year. The 2027 edition keeps the same five levels (Bronze to Diamond) and the same five areas. Here is what actually changed, in plain English.

What changes at your level

If you're at...What changes for you
Level 1 or 2Mostly wording. Check your patching covers every device, and use a password manager.
Level 3Same as above, plus a stronger cybersecurity policy and incident response plan.
Level 4New: an AI governance framework, Mobile Device Management, and separating your office network from smart devices.
Level 5New: security keys or passkeys for admin logins, and controls on AI tools nobody approved.

The new requirements, explained

1. Have a plan for AI

  • What it means: write down which AI tools staff can use, and what company data they must never paste in.
  • Who it affects: anyone targeting Level 4 or 5, but it's worth doing at any level.
  • First step: list the AI tools your team actually uses today (ChatGPT, Copilot and so on), then write a one-page "approved tools and rules" policy.

2. Stop AI tools nobody approved (Level 5)

  • What it means: know when staff sign up to AI apps on their own.
  • First step: if you have Microsoft 365 E5 or Defender for Cloud Apps, turn on app discovery to see which AI apps are in use.

3. Stronger logins for admin accounts (Level 5)

  • What it means: admin accounts need a physical security key or passkey, not a text code or app prompt that can be phished.
  • First step: in Microsoft Entra, require the built-in "Phishing-resistant MFA" authentication strength for admin roles using Conditional Access.

4. Manage phones and laptops centrally (Level 4)

  • What it means: company devices should be enrolled in a system that can lock, wipe and update them.
  • First step: enrol devices in Microsoft Intune if you have it.

5. Keep smart devices off your main network (Level 4)

  • What it means: printers, cameras and other smart gear shouldn't sit on the same network as your laptops and file server.
  • First step: ask your IT provider to put them on a separate network or VLAN.

Things that got stricter

  • Old software and hardware. Anything past end-of-life or end-of-support must be replaced, upgraded, or formally signed off with a documented reason. First step: list anything running old Windows or unsupported software.
  • Patching. Updates must install automatically on all devices, and servers must be patched too.
  • Encryption. Important data must be encrypted when stored. First step: turn on BitLocker for company laptops.
  • Passwords. Strong password hygiene plus a password manager.
  • Remote access. Remote Desktop only over a VPN, and with MFA.
  • Insurance. Hold business or cyber insurance.
  • Application control moved up to Level 4.

Worked example

A 20-person accounting firm certified at Level 2. Their 2027 to-do list is short: confirm updates install automatically on every laptop, roll out a password manager, and write a one-page AI policy (optional at Level 2, but smart). If they later aim for Level 4, they'd add Intune enrolment, a separate network for printers and cameras, and a proper AI governance framework.

Your checklist

  • Note when your current certificate expires. That's your 2027 deadline.
  • List the AI tools your staff use and write a one-page policy.
  • Find any end-of-life software or devices.
  • Check automatic updates are on for every device and server.
  • Turn on BitLocker and use a password manager.
  • If you're aiming for Level 4 or higher, talk to your IT provider about Intune and network separation.

Need a hand?

The standard itself tells businesses to work with a technical support specialist, and for most that's their IT provider or MSP. CYBERWHITE is a DSI Founding Mission Supporter and Licensed Commercial Holder of SMB1001. The platform assesses SMB1001:2026 today, scans Microsoft 365 for gaps, and deploys many fixes in one click with rollback. We hold the 2027 standard and are building its controls in.

Start with the SMB1001 page or our SMB1001 levels guide.


Keep reading: SMB1001 Maturity Levels: Bronze to Diamond for Australian SMBs

Frequently asked questions

Does my SMB1001:2026 certificate still count?
Yes. An SMB1001 certificate is valid for one year. Plan for the 2027 changes at your next recertification.
What is the biggest change in SMB1001:2027?
AI. Higher tiers now expect an AI policy, an AI governance framework, and controls on unapproved AI tools.
Does SMB1001:2027 affect Level 1 and 2 businesses?
Only a little. Most changes at Level 1 and 2 are wording, stronger patching and password manager requirements. The new controls land at Level 4 and 5.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.