Benefits of SMB1001 for Security-Conscious Businesses
Five Tiers of Compliance
Trusted by Insurers
Built for SMBs
Ready for Bigger Tenders
Head Start on ISO 27001
Certification Designed for Australian Businesses Looking to Grow
Picture the moment a client, insurer or panel asks you to prove your cyber security, and all you have is your word. Right now, that's enough to lose the deal to a competitor who isn't more secure than you, just better prepared for the question. SMB1001 gives you an answer that closes the conversation.
Find the right tier for your business
Bronze
SMB 1001 Level 1
-
Who it’s For?
Small businesses with no cyber security in place.
-
What’s Involved
Your business is checked against 7 essential controls, gaps are closed, then you sign off yourself.
-
What It Looks Like For You
Working with a named IT partner responsible for your security, firewalls and endpoint protection on every device, automatic backups and updates, and strong sign-in rules on every account.
Silver
SMB 1001 Level 2
-
Who it’s For?
Businesses actively looking to close the most exploited gaps.
-
What’s Involved
Your business is checked against 17 controls across Bronze-level requirements and stronger identity controls, gaps are closed, then you sign off yourself.
-
What It Looks Like For You
Individual logins for everyone, multi-factor authentication on email, a managed password approach, and a documented process to stop fraudulent invoice payments. Obtaining cyber insurance requires you to obtain Silver Certification at minimum.
Gold
SMB 1001 Level 3
-
Who it’s For?
Businesses that need cyber security as a governed programme.
-
What’s Involved
Your business is checked against 27 controls across detection, policy and response, gaps are closed, then you sign off yourself. Cyber insurance is required at this tier.
-
What It Looks Like For You
Threats are actively detected and responded to, a signed policy sets expectations for staff, a tested response plan, and cyber insurance in place.
Platinum
SMB 1001 Level 4
-
Who it’s For?
Businesses that must prove security to enterprise clients directly.
-
What’s Involved
Your business is checked against a hardened set of 32 controls, gaps are closed, then an independent auditor verifies everything.
-
What It Looks Like For You
Continuous scanning of internet-facing systems, phishing-resistant remote access, a guaranteed response time, and a recovery plan tested and verified every year.
Diamond
SMB 1001 Level 5
-
Who it’s For?
Businesses competing for regulated or high-value work.
-
What’s Involved
Every control in the framework is checked, gaps are closed, and then an independent auditor verifies that all 39 controls are genuinely in place.
-
What It Looks Like For You
Data is encrypted, detection and response is monitored around the clock, penetration and social engineering testing happens every year, and your standards extend to your suppliers through a digital trust programme.
-
Bronze
SMB 1001 Level 1
-
Who it’s For?
Small businesses with no cyber security in place.
-
What’s Involved
Your business is checked against 7 essential controls, gaps are closed, then you sign off yourself.
-
What It Looks Like For You
Working with a named IT partner responsible for your security, firewalls and endpoint protection on every device, automatic backups and updates, and strong sign-in rules on every account.
-
-
Silver
SMB 1001 Level 2
-
Who it’s For?
Businesses actively looking to close the most exploited gaps.
-
What’s Involved
Your business is checked against 17 controls across Bronze-level requirements and stronger identity controls, gaps are closed, then you sign off yourself.
-
What It Looks Like For You
Individual logins for everyone, multi-factor authentication on email, a managed password approach, and a documented process to stop fraudulent invoice payments. Obtaining cyber insurance requires you to obtain Silver Certification at minimum.
-
-
Gold
SMB 1001 Level 3
-
Who it’s For?
Businesses that need cyber security as a governed programme.
-
What’s Involved
Your business is checked against 27 controls across detection, policy and response, gaps are closed, then you sign off yourself. Cyber insurance is required at this tier.
-
What It Looks Like For You
Threats are actively detected and responded to, a signed policy sets expectations for staff, a tested response plan, and cyber insurance in place.
-
-
Platinum
SMB 1001 Level 4
-
Who it’s For?
Businesses that must prove security to enterprise clients directly.
-
What’s Involved
Your business is checked against a hardened set of 32 controls, gaps are closed, then an independent auditor verifies everything.
-
What It Looks Like For You
Continuous scanning of internet-facing systems, phishing-resistant remote access, a guaranteed response time, and a recovery plan tested and verified every year.
-
-
Diamond
SMB 1001 Level 5
-
Who it’s For?
Businesses competing for regulated or high-value work.
-
What’s Involved
Every control in the framework is checked, gaps are closed, and then an independent auditor verifies that all 39 controls are genuinely in place.
-
What It Looks Like For You
Data is encrypted, detection and response is monitored around the clock, penetration and social engineering testing happens every year, and your standards extend to your suppliers through a digital trust programme.
-
Stay ahead of evolving threats. Contact Unified IT for help securing your business today.
Get in Touch
The Standard Runs Both Ways
Anyone can sign you up to CyberCert and walk you through a checklist. Unified IT holds SMB1001 certification itself, alongside ISO 27001 and ISO 9001, and runs its own business to the Essential Eight. It's not a service bolted onto an IT contract, it's the standard already in use internally.
If you’re ready to partner with a business who will walk the walk with you and ensure you’re compliant all-year round, our team are ready to help.
From Assessment to Certified
Assessment
A structured review of your business against every control in your chosen tier, run alongside CyberCert.
Evidence Gathering
The proof each control requires is collected and organised, ready for sign off or audit.
Uplift to Meet Controls
Any work needed to close the gaps. Licensing or third-party fees are quoted separately, only if required.
Certification
Bronze, Silver and Gold are signed off directly. Platinum and Diamond are independently verified by CyberCert.
Ongoing Maintenance and Compliance
Every control stays active and evidenced all year, not just at sign-off.
Proudly supported by
Ready to Get Certified?
Talk to Unified IT about SMB1001 certification and stop losing work over cyber security.
Please Complete the Form Below
"*" indicates required fields