Skip to content

SMB1001 certification | CyberCert partner

SMB1001 certification, done with you

SMB1001 certification help is a guided engagement for Australian small businesses preparing for one of the five current certification tiers, from Bronze to Diamond, for tenders, insurers or client requirements. VibeZero is a CyberCert partner and holds SMB1001 Silver certification. We provide readiness, governance, policy and implementation support; CyberCert operates the certification process and issues the certificate.

Best fit
Australian SMBs preparing for a client, tender or insurer requirement
VibeZero role
Readiness, implementation and workbook support
Certifier
CyberCert makes the decision and issues the certificate
Commercial model
Implementation quoted after a readiness discussion
Delivery ownership
  1. Scope
  2. Assess
  3. Implement
  4. Handover

The accountable team stays responsible for the specialist scope from assessment through handover. Boundaries, evidence and external dependencies are agreed before work starts.

The standard

A cyber standard built for small business

SMB1001 is a multi tier cyber security standard designed for small and medium businesses. It provides a staged alternative to starting with an enterprise management system standard.

The current SMB1001:2026 edition is published by Dynamic Standards International. Certification is available through CyberCert. The certificate and badge show the tier achieved; the assurance model differs by tier.

Why us

Certified ourselves, partnered with CyberCert

VibeZero is a CyberCert partner and holds SMB1001 Silver certification. The guidance therefore comes from experience completing the workbook as well as supporting governance and security work.

We help prepare the evidence, policies, staff practices and technical actions that sit behind the target tier. CyberCert remains the certifying authority and final certification outcome is not controlled or guaranteed by VibeZero.

The tiers

Five tiers, start where you are

These summaries are guidance only. The SMB1001:2026 workbook and CyberCert requirements are authoritative.
Level 1 | director attestable

Bronze

Foundational controls and a practical starting point for lower risk supplier profiles.
Level 2 | director attestable

Silver

More protection up front, including stronger identity and staff practices. This is VibeZero's current tier.
Level 3 | director attestable

Gold

Covers people, processes and technology, for businesses that need more.
Level 4 | externally validated

Platinum

A higher assurance tier requiring independent external validation.
Level 5 | externally validated

Diamond

The highest tier, with the most advanced governance and assurance expectations.
Readiness decision

Choosing the tier

The target should follow client requirements, contracts and the DSI categorisation approach rather than a generic recommendation.
If this matches the problem, send us the evidence you have. We will confirm whether the specialist scope fits before preparing a proposal.

Comparison

SMB1001 and the Essential Eight, together

They are complementary, not interchangeable, and neither automatically proves compliance with the other.
Technical mitigation baseline

Essential Eight

Australian Cyber Security Centre mitigation strategies focused on common technical attack paths. It is not itself a tiered certificate.
Tiered certification standard

SMB1001

A certifiable standard adding governance, policy, training and staged assurance around cyber controls.
Implementation approach

Map the overlap

Existing technical work may support relevant SMB1001 controls, but each requirement still needs evidence. Related work includes AI security and data and privacy advisory.

Process

How we get you certification ready

VibeZero prepares and guides the engagement; CyberCert makes the certification decision and issues the certificate.
  1. Assess

    Readiness and gap check

    Compare the current evidence with the target tier and identify what is missing.
  2. Implement

    Close the gaps

    Put controls, policies and training in place with the appropriate internal or IT owners.
  3. Submit

    Through the workbook

    Prepare the CyberCert workbook and tier specific attestation or validation process.
  4. Renew

    Renew and progress

    Support annual renewal and plan a higher tier when business requirements justify it.

Commercial boundary

Preparation and certification are separate

VibeZero engagement

Readiness and implementation

We quote the work required to assess gaps, prepare evidence and implement the agreed controls. The scope depends on the target tier and current state.
CyberCert

Certification process and fees

CyberCert controls its platform, certification fees, validation requirements, decision and certificate. Confirm its current terms directly with CyberCert.

Practical details

Questions about SMB1001 Certification

The scope boundary, evidence, delivery model and responsibility before engagement.

SMB1001 is a tiered cyber security standard built specifically for small and medium businesses, as a practical alternative to starting with an enterprise framework like ISO 27001. Dynamic Standards International publishes and maintains the standard, and CyberCert operates a certification pathway. The current edition is SMB1001:2026.

Find your tier

Prepare for the right SMB1001 tier

VibeZero supports readiness and implementation. CyberCert makes the certification decision.Enquiries get a reply within one business day.