Home
Case Studies
About Us
Contact Us

SMB1001:The Multi-Tiered Standard for Australian Cyber Hygiene

SMB1001:2023 is a multi-tiered standard designed specifically to help Small and Medium Businesses (SMBs) develop robust cyber security hygiene appropriate to their resources and needs. We offer two distinct services to help you achieve certification: Independent External Audit or Expert Readiness Consulting. 
GET Free Consulting READY TODAY

Our SMB1001 Services (No Conflict of Interest) 

We provide two distinct services. You may choose whichever service best fits your current needs. 

SMB1001 Independent Audit (External Auditor) 

Formal Certification: As an Authorised external SMB1001 Auditor, we conduct the final, formal certification assessment of your chosen tier (Level 4 & 5). Our successful audit attests to your organisation's certified level of cyber hygiene. 

SMB1001 Readiness Service 

Gap Analysis & Implementation: We act as your internal consulting partner, helping you identify gaps, implement the measures, and develop all necessary documentation and procedures required for your target tier.  

SMB1001 Readiness Service 

For Level 1, 2, 3 Certification:

After the gap analysis and implementation is complete, We will produce and collate all documentation required for the CAB to issue SMB1001 Certificate for the required level. Formal external audit is usually not required. 
Note: We provide either SMB1001 Readiness Service or SMB1001 Independent Audit for the same system of Platinum (Level 4) & Diamond (Level 5) due to the conflict of interest & maintain compliance with independence requirements for certification bodies. 

SMB1001 FAQs 

What is SMB1001?

SMB1001: 2023 is a multi-tiered cyber security certification standard developed by Cyber Security Certification Australia (CSCAU) specifically for Small and Medium-sized Businesses (SMB). It is an Australian standard that guides SMBs in developing their cyber security capability and hygiene. 

Who need this? 

Small and Medium-sized Businesses (SMBs) in any sector that need to improve their cyber security hygiene and provide assurance to their customers or supply chain partners against cyber threats. It is essential for SMBs seeking to demonstrate credible cyber hygiene. 

Why need this? 

Certification supports the development of mature cyber security hygiene. It provides a credible certification demonstrating a strong suite of security measures, offers a pathway toward adopting international standards like ISO 27001, and is often a competitive advantage in supply chains. 

What are the key components of SMB1001? 

The standard has five tiers (Levels 1-5), each building upon the previous one. Measures are organised into five key categories: 
1. Technology Management 
2. Access Management 
3. Backup and Recovery  
4. Policies, Processes and Plans, and  
5. Education and Training. 

How to Achieve the Certificate? 

1. Choose Your Target Level: Select the appropriate level (1-5) based on your business needs.  
2. Readiness/Consulting (Optional): Implement all required measures and documentation for your target level (our Readiness Service).  
3. Internal Audit: Conduct internal conformance check (our Readiness Service).   
4. External Audit only for Platinum (Level 4) & Diamond (Level 5): Engage an Authorised External Auditor (us) for verification and attestation. 
5. Certification: Receive your official SMB1001 certificate. 

Can you perform both the Readiness Service and the Final Audit? 

No. As an authorised Certifier for the SMB1001 standard, we must act in an impartial way at all times. Providing both consulting (Readiness) and final verification (Audit) would constitute a conflict of interest, invalidating the certification. 
Which service should we choose first? 
If you are starting out or targeting a higher level (Level 3-5), the Readiness Service is essential. It ensures that the necessary controls and documentation are in place before you pay for the final, high-stakes audit. 

How long does an SMB1001 Audit take?

The certification is valid for one (1) year. The audit time varies by the tier and complexity, but independent verification for Levels 4 and 5 requires a formal third-party assessment lasting a 3-5 days, plus reporting time. 

How long does an SMB1001 Readiness take?  

This depends on your organistion's starting maturity and the target tier (Level 1 is much faster than Level 5). Implementing the measures and documentation usually takes between 3 to 9 months. 

Which service should we choose first? 

If you are starting out or targeting a higher level (Level 3-5), the Readiness Service is essential. It ensures that the necessary controls and documentation are in place before you pay for the final, high-stakes audit. 

Schedule Your SMB1001 Certification Assessment

Schedule Your SMB1001 Certification Assessment

Services

RFFR Overview
Managed RFFR Solution
Managed security awareness training
Cyber Threat & Risk Assessment

Additional Info

Phone: +61 2 9123 4567
Email: info@cyberassured.com.au

Learn

Case Studies

Privacy Policy

crossmenu linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram