SMB1001 is the Small Business Cyber Security Standard, developed by the Cyber Security Cooperative Research Centre (CSCRC) in partnership with Australian small business organisations. Released in 2023, it’s designed specifically for businesses with fewer than 200 employees — providing a practical, tiered approach to cybersecurity that doesn’t require a dedicated security team to implement.
Unlike the Australian Signals Directorate’s Essential Eight (which is aimed at mid-to-large organisations), SMB1001 was built from the ground up for small business realities: limited budgets, no in-house security staff, and day-to-day operational priorities.
Why SMB1001 Exists
Australian small businesses are increasingly targeted by cybercriminals — not because they’re valuable individually, but because they’re easier to breach and often connected to larger supply chains. The Australian Cyber Security Centre reports that small businesses account for 43% of all cybercrime victims, with the average incident costing $46,000.
In industries like construction and engineering, the risk is amplified. Subcontractors and project firms handle sensitive project data, client specifications, tender documents, and financial information that head contractors and clients increasingly expect to be protected. A breach at the subcontractor level can cascade across an entire project.
SMB1001 exists because most existing frameworks are too complex, too expensive, or too enterprise-focused for a business with 5–100 staff. It gives small businesses a credible, achievable roadmap.
The Three Tiers: Bronze, Silver, and Gold
SMB1001 uses a tiered certification model. Each tier builds on the previous one, so businesses can progress at their own pace.
Bronze — Foundation Security
Bronze covers the absolute essentials that every small business should have in place. Key controls include:
- Multi-factor authentication (MFA) on all internet-facing accounts
- Regular, tested backups stored separately from primary systems
- Up-to-date antivirus/endpoint protection
- Basic staff awareness training on phishing and social engineering
- Password management and unique credentials per account
- Software and operating system updates applied within 30 days
Bronze is achievable in weeks for most businesses and significantly reduces the most common cyber threats.
Silver — Intermediate Controls
Silver builds on Bronze by adding more structured controls around access, monitoring, and incident response:
- Privileged access management — limiting admin rights to only those who need them
- Network segmentation to limit the spread of a breach
- Vulnerability scanning on internet-facing systems
- A documented incident response plan
- Logging and monitoring for suspicious activity
- Supplier/third-party security assessment
Gold — Advanced Maturity
Gold aligns with more comprehensive security frameworks and is suited for businesses handling sensitive data, working with government, or operating in regulated industries:
- Security information and event management (SIEM)
- Regular penetration testing
- Alignment with ISO 27001 or NIST CSF principles
- Formal risk management processes
- Board-level cyber security governance
- Continuous monitoring and threat intelligence
SMB1001 vs the Essential Eight
Both frameworks aim to improve cybersecurity, but they’re designed for different audiences:
| Feature | SMB1001 | Essential Eight |
|---|---|---|
| Target audience | Businesses <200 staff | Medium-large organisations |
| Complexity | Low to medium | Medium to high |
| Certification available | Yes (Bronze/Silver/Gold) | Maturity Level assessment only |
| Developed by | CSCRC | Australian Signals Directorate |
| Best for | SMBs, sole traders, supply chain compliance | Government contractors, regulated industries |
Many small businesses find SMB1001 more actionable — especially at the Bronze tier — because the controls map directly to tools and practices they may already partially have in place.
Who Should Pursue SMB1001 Certification?
SMB1001 is particularly relevant for Brisbane businesses in industries where data security, supply chain compliance, or client trust are on the line:
- Building and construction firms — subcontractors and project businesses handling tender documents, client specifications, and financial data are increasingly expected by head contractors to demonstrate cyber security practice. SMB1001 Bronze gives you the evidence.
- Engineering and technical services businesses — firms managing project IP, CAD files, site data, and third-party integrations need clear controls around access and data protection. Silver controls (access management, network segmentation) map directly to these risks.
- Businesses in supply chains — enterprise clients and government bodies are pushing cyber requirements down the supply chain. Certification gives you a formal answer when a client asks “what’s your security posture?”
- Professional services firms — accountants, lawyers, and consultants handling client data have clear obligations and benefit from a structured roadmap.
- Any business applying for cyber insurance — demonstrating SMB1001 compliance can improve insurability and reduce premiums.
How to Get Started with SMB1001
The CSCRC provides a self-assessment tool that helps businesses identify where they sit against the Bronze controls. From there, the path to certification involves:
- Completing the self-assessment against your target tier
- Identifying gaps and building a remediation plan
- Implementing the required controls (often with the help of a managed IT provider)
- Engaging a registered SMB1001 assessor for formal certification
Most businesses aiming for Bronze certification find the process takes 4–12 weeks, depending on their current security maturity and the complexity of their environment.
Frequently Asked Questions
Is SMB1001 certification mandatory?
No — SMB1001 is voluntary. However, certification is increasingly being requested by head contractors, enterprise clients, government bodies, and insurers as evidence of cyber security practice. Construction and engineering businesses working in larger project supply chains are seeing this requirement appear in tender conditions and subcontractor agreements.
How much does SMB1001 certification cost?
The cost varies depending on your target tier and the assessor you use. Bronze self-assessments can be completed for minimal cost. Silver and Gold involve a formal third-party assessment, which typically costs $2,000–$8,000 depending on business size and complexity.
How does SMB1001 relate to cyber insurance?
Many cyber insurers are beginning to reference SMB1001 as a baseline. Achieving Bronze certification demonstrates that you have fundamental controls in place — MFA, backups, endpoint protection — which are the controls insurers care most about. Certification can support lower premiums and better coverage terms.
Can a small business implement SMB1001 without an IT provider?
Bronze is achievable without specialist help for businesses with a technically capable person on staff. Silver and Gold controls typically require more expertise, particularly around network segmentation, vulnerability management, and monitoring. Many businesses — including construction and engineering firms managing complex site and project environments — work with a managed IT provider to close the gap between their current state and their target certification tier.
Where can I find an accredited SMB1001 assessor?
The CSCRC maintains a register of accredited assessors. You can find the current list on the CSCRC website along with the official SMB1001 documentation and self-assessment tools.
For Brisbane building, construction, and engineering businesses looking to meet head contractor requirements or simply get their security fundamentals in place, managed IT services provide the technical foundation that supports SMB1001 compliance — from MFA and endpoint protection to backup management and patch maintenance. Talk to a local IT provider about where your business currently sits and what Bronze certification would take.


