A plain-English guide for business owners

Why SMB1001 matters for your business

Your customers, your insurer and the bigger companies you want to work with are starting to ask the same question: can you prove your business is secure? SMB1001 is the Australian standard that lets you answer it with a certificate, not a promise. This page explains what it is and why it is worth doing, without the jargon.

Shared with you by your IT provider. Powered by CYBERWHITE, a DSI Licensed Commercial Holder of SMB1001.

Why this is landing on your desk now

Customers ask for it

Larger customers and government buyers now send a security questionnaire before they sign. No answer can mean no contract.

Insurers ask for it

Cyber insurance renewals increasingly require proof of basic controls like multi-factor sign-in and tested backups before they will quote.

Attacks target small business

Small businesses are now a common target precisely because attackers expect weaker defences. Proof of security is becoming the price of doing business.

What SMB1001 actually is

SMB1001 is an Australian cyber security standard published by Dynamic Standards International (DSI). Unlike frameworks written for large enterprises or government, it is built for small and medium businesses, in steps you can actually work through.

It runs across five tiers, from Bronze to Diamond. You start where you are and climb as far as your business needs. The lower tiers, Bronze, Silver and Gold, are certified by the company director signing off that the controls are in place. The top two tiers are independently assessed. When you certify, you receive a dated certificate you can show a customer, an insurer or a supplier.

The point is simple: it turns the security work you should be doing anyway into something you can prove.

What certification gets you

  • A certificate you can attach to a tender or hand to a customer who asks about security.
  • A stronger position at cyber insurance renewal, with the controls insurers look for already in place.
  • A clear answer to the supplier security questionnaire, in one line instead of a week of back and forth.
  • Genuinely better protection for your business, your staff and your customer data.
  • A path you can build on each year, rather than a one-off scramble.

A standard built for small business, and here to stay

SMB1001 is published and maintained by Dynamic Standards International, and it is updated every year to keep pace with real threats. A new edition for 2027 adds guidance on areas like the safe use of AI tools.

As the bigger Australian frameworks shift their focus toward enterprise and government, a certification designed specifically for small business fills a real and growing need. Getting certified now puts your business ahead of the curve, not behind it.

CYBERWHITE is a DSI Licensed Commercial Holder of SMB1001 and a DSI Founding Mission Supporter. We hold the 2027 edition and are building its controls into the platform; the platform assesses the 2026 edition today.

DSI Founding Mission Supporter, SMB1001DSI Founding Mission Supporter
DSI SMB1001 Licensed
Learn more about the standard at smb1001.com.au

How you get there

The good news: if you run Microsoft 365, use multi-factor sign-in and keep backups, you are closer than you think. The fastest path is to work with your IT provider, who can check your current setup, close the gaps, and prepare the certification for you to sign.

A tip if you have an IT provider

Ask them about SMB1001. Many Australian IT providers use CYBERWHITE to check a client's Microsoft 365 against the standard in about five minutes and show exactly what is needed to certify.

Common questions

What is SMB1001?

SMB1001 is an Australian cyber security standard published by Dynamic Standards International (DSI). It is written for small and medium businesses and runs across five tiers, Bronze to Diamond, so a business can start with the basics and build up. Certification ends in a dated certificate the business can show customers, insurers and suppliers.

Why would a small business get certified?

Because the people a business sells to increasingly ask for proof of security. A certificate answers a supplier questionnaire, supports a cyber insurance application, and helps win work that now expects a security baseline. It also means the business has genuinely tightened its security, not just described it.

Does a business need an auditor for SMB1001?

Not for the lower tiers. Bronze, Silver and Gold are certified by company-director self-attestation. Platinum and Diamond require independent third-party assessment. Most small businesses, often with help from their IT provider, start at Bronze, Silver or Gold.

Is SMB1001 recognised and here to stay?

SMB1001 is published and maintained by Dynamic Standards International, is updated every year, and is designed specifically for the small-business end of the market. As larger frameworks move toward enterprise, a certification built for small business fills a real and growing need.

Ready to turn your security into proof?

Talk to your IT provider about SMB1001, or if you manage IT yourself, see how CYBERWHITE checks your Microsoft 365 against the standard.