Black Shard

SMB1001 certification readiness in Australia.

A gap review against your target SMB1001 tier, remediation sequenced against the certification date, and an evidence pack for the certifying assessor.

SMB1001 is a tiered cybersecurity certification standard for small and medium businesses. A business certifies at the tier its risk and its customers require, and the certificate is listed on a public registry where a buyer, insurer or supply chain can verify it.

Readiness work starts with the current environment. Each control of the target tier is identified as met, partial or missing, the gaps are prioritised against the target tier and the certification date, and evidence is collected as controls land. Delivered Australia-wide from the Brisbane head office.

What is SMB1001?

The standard runs five tiers, Bronze, Silver, Gold, Platinum and Diamond, at Levels 1 through 5. Each tier adds controls over the one below, so the requirement can be sized to the business. Each edition carries a year mark; the current edition is 2026.

Gold sits at Level 3 and rests on twenty-seven controls, formally attested by a company director: multi-factor authentication, patching, restricted administrative privilege, backups and recovery, incident handling, and discipline around vendors and third parties. The certificate is listed on CyberCert's public registry, which is what gives it weight in a commercial negotiation: the counterparty can confirm it directly.

The five tiers, Bronze to Diamond

Bronze, Level 1, is the entry tier: an IT support relationship, a firewall, endpoint protection kept current, patching, backups, and staff who know the basics. Silver, Level 2, adds multi-factor authentication, individual user accounts in place of shared logins, restricted administrative privilege, SPF on email, and written processes. Gold, Level 3, adds endpoint detection and response, stronger email authentication, a documented incident response process, asset governance, and consideration of cyber insurance and how the business uses AI tools, twenty-seven controls in total. Platinum and Diamond, Levels 4 and 5, cover much of the same ground and ask for it to be demonstrably operating and monitored.

Verification changes as the tiers climb. Bronze, Silver and Gold are self-attested: a company director signs off through the CyberCert portal that the tier's controls are in place, and the certificate issues on that attestation. Platinum and Diamond move to external audit: an accredited Independent Verification Organisation examines the evidence and confirms the controls are operating before CyberCert issues the certificate.

Why are Australian supply chains asking for SMB1001?

Security questionnaires travel down the supply chain. Large Australian organisations and government buyers carry obligations they cannot discharge alone, so they push assurance requirements onto every supplier that touches their data or their systems. For a small or medium supplier, ISO 27001 is often more than a single contract justifies, and a written security policy on its own gives a procurement team nothing to verify.

SMB1001 is tiered, so the requirement can be sized to the supplier. It is certifiable, so a procurement team can rely on the listing. And the registry entry answers the questionnaire before it is sent. The 2026 Privacy Act reforms add to the same pressure on businesses holding personal information.

What a readiness engagement involves

A readiness engagement runs as a defined program with milestones set against your certification date. It starts with the environment as it runs today, records each control of the target tier as met, partial or missing, and sequences the remediation so the controls that cut the most risk land first.

We work under least-privilege access for the duration, asking only for the access the review requires. Findings are written with the reasoning shown. Where a gap needs engineering, our engineers can carry it as a shipped change, since the firm designs, builds and operates production software.

  • A gap review against your target SMB1001 tier: each control checked against the environment as it runs day to day and recorded as met, partial or missing
  • Remediation sequenced against the target tier and the certification date, with our engineers doing the hands-on work where you want it
  • An evidence pack assembled for the certifying assessor as controls land: the policies, records and configuration proof the standard expects, organised against the standard's structure

Our own certificate

Black Shard holds SMB1001:2026 Gold, Level 3, issued by CyberCert and active to 17 June 2027. The certificate is listed on CyberCert's public registry against the company's ABN, which is the check we recommend to any buyer: open the listing, confirm the holder, the level and the dates, and do not rely on the PDF.

That matters for readiness work in one specific way. The twenty-seven Gold controls were implemented on the firm's own estate and attested by a director through the same portal a client's director will use, so the evidence pack we assemble is shaped by having stood one up. The SMB1001 reference page sets out the tiers, the issuing process and how to verify a certificate.

Black Shard's role, and where it stops

We build the controls: configuring MFA, standing up EDR, tightening administrative access, testing backups, writing the incident response process your team will run. We assemble the evidence: the policies, records and configuration proof organised against the standard's structure, so whoever signs off, or whoever audits, works from a finished pack. We do not attest, audit or certify. At Bronze, Silver and Gold the attestation is made personally by a company director through the CyberCert portal; Black Shard does not sign it.

At Platinum and Diamond, where the standard calls in an external Independent Verification Organisation, our role is support through that process: the evidence organised and indexed before fieldwork starts, our engineers available during the audit to answer technical questions about how a control operates, and any gap the auditor raises closed as it is raised. The audit itself, the decision on each control, and the certificate belong to the auditor and to CyberCert.

The outcome to expect

Readiness to certify: the gaps against your target tier closed, the evidence assembled and organised, and every control either demonstrably met or carrying a named, sequenced fix. The certification decision belongs to the certifying process.

The controls remain after the certificate issues: multi-factor authentication that is enforced, backups that have been restored, an incident path that has been rehearsed.

What does SMB1001 readiness cost?

The price follows scope: the tier you are targeting, how far the current posture sits from it, the number of environments and tenancies in the review, and how much of the remediation our engineers carry versus your own team closing gaps against our plan. A business already partway through Essential Eight uplift is a smaller job than one starting from nothing. The engagement runs as a defined program with milestones toward your certification date, scoped and agreed before the work starts.

No range is published. Send the brief; the reply carries the questions needed to scope it.

Questions, answered

Does Black Shard hold SMB1001 itself?
Yes. SMB1001:2026 Gold, Level 3, issued by CyberCert and active to 17 June 2027, listed on CyberCert's public registry against the company's ABN.
Which SMB1001 tier should we target?
The standard runs five tiers, Bronze through Diamond, and the target is usually set by what your customers and contracts require. Where the ask is unstated, the gap review sizes the tier to the data you hold and the contracts you serve, and states where a lower tier discharges the obligation.
What tier should we start at?
The tier the current posture can sustain. Bronze and Silver are self-attested and achievable quickly for a business with the fundamentals roughly in place, and Gold is achievable for most SMBs running a defined program. Platinum or Diamond means an external audit before the lower-tier controls have been proven to hold day to day. Unless a contract names a higher tier, start at Gold or below and step up once the controls are bedded in.
Is SMB1001 the same as the Essential Eight?
No. The Essential Eight is a set of mitigation strategies from the Australian Signals Directorate that you self-assess against; SMB1001 is a certification standard with an issuing body and a public registry. The controls overlap substantially, so Essential Eight uplift you have already done counts directly toward SMB1001 readiness.
Can you guarantee we will be certified?
No. Certification is issued by the certifying body. What we deliver is readiness: gaps closed against the target tier and an evidence pack the assessor can work through.
Do you issue the certification yourselves?
No. SMB1001 certification is issued through CyberCert. We prepare you for that process.
Who audits SMB1001?
It depends on the tier. Bronze, Silver and Gold carry no external auditor: a company director attests through the CyberCert portal that the tier's controls are in place, and CyberCert issues the certificate on that attestation. Platinum and Diamond bring in an accredited Independent Verification Organisation, which examines the evidence and confirms the controls are operating before CyberCert issues the certificate. We are not the attestor and we are not the auditor at any tier: the director attests, the Independent Verification Organisation audits at Platinum and Diamond, and CyberCert issues the certificate. Our work is the readiness before each of those steps.
How long does SMB1001 readiness take?
It depends on the distance between your current posture and the target tier, and on how many environments are in scope. Readiness runs as a defined program with milestones set against your certification date, so the timeframe is agreed at the start.
How long does SMB1001 certification take?
The certification step itself is short at the self-attested tiers: once the evidence is in order, a director's attestation through the CyberCert portal can turn a certificate around in days. Platinum and Diamond run to a longer clock, because an Independent Verification Organisation has to schedule and complete an external audit before CyberCert issues the certificate, and that lead time sits on top of the readiness work. In either case the readiness engagement, closing the gaps and assembling the evidence, is usually the longer half of the timeline.
Do you only work with Brisbane businesses?
No. We are an Australian firm and deliver Australia-wide from the Brisbane head office. Readiness work runs under least-privilege access, asking only for the access the review requires, and the engagement is the same wherever you are.

Tell us the target tier and the certification date.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au