SMB1001 · Certification

Cyber security your customers can actually verify.

SMB1001 is a tiered Australian standard designed for organisations that will never run a full ISO 27001 program but still have to prove they take security seriously. REDD was the first managed IT provider accredited into the CyberCert program, and we take clients through it tier by tier.

1stMSPaccredited into the CyberCert program
5tiersBronze through to Diamond
ISO27001certified security management

What it is

A standard scaled for smaller organisations

Most security standards were written for enterprises with a compliance team. SMB1001 is graded, so a ten-person firm can certify at a level that matches its risk and step up over time rather than facing a single, unreachable bar.

That matters commercially. A certificate is something a customer, an insurer or a tender panel can check, which is far more useful than a policy document nobody reads.

Graded tiers

Each tier adds controls. You certify where you are, then move up as the business grows or a customer asks for more.

Built for SMEs

The controls are written for organisations without a dedicated security team, which is most Australian businesses.

Independently certified

Certification is issued against a published standard, so it means the same thing to everyone who asks.

It stacks

The work behind a tier is the same work that lifts your Essential Eight maturity. Neither effort is wasted.

Which one

SMB1001 or the Essential Eight

They are complementary rather than competing. Most of our clients end up doing both, in this order.

SMB1001Essential Eight
What it isA tiered, certifiable standardAn eight-control mitigation baseline from the ACSC
Who it suitsSmaller organisations needing proof for customersAny organisation, and mandatory for many government entities
What you getA certificate at a defined tierA maturity level from zero to three, evidenced
Who asks for itCustomers, insurers, smaller tendersGovernment, enterprise procurement, insurers
Where to startIf you need something to show, start hereIf you need to reduce risk fastest, start here

Scroll the table sideways to see every column.

How it runs

What certification looks like with REDD

01

Week 1

Pick the tier

We look at what your customers and insurer are actually asking for, then choose the tier that answers it. Aiming too high is the most common way these programs stall.

02

Weeks 2 to 6

Close the gaps

The controls behind each tier are practical: multi-factor authentication, backups, patching, a tested incident response plan. We implement, you approve.

03

Certification

Evidence and submission

We gather the evidence and support the certification, rather than handing you a checklist and wishing you luck.

04

Ongoing

Keep it true

A certificate is a point in time. Managed services keep the controls in place between renewals so the next tier is a step, not a restart.

Why us

We were first through this door

First accredited MSP

REDD was the first managed IT services provider accredited into the CyberCert program, which is why we have run this process more times than most.

One accountable partner

The same team that certifies you runs your IT, so the controls survive contact with daily operations instead of lapsing after the audit.

See managed technology →

A real SOC behind it

Certification proves the controls exist. Our 24x7 Security Operations Centre is what notices when one of them fails at 3am.

See MDR →

Common questions

Questions we get asked

What is SMB1001?

SMB1001 is an Australian cyber security standard written for small and medium businesses. It is graded into tiers, so an organisation can certify at a level that matches its size and risk and then step up, rather than facing the single high bar of a standard such as ISO 27001.

How is SMB1001 different from the Essential Eight?

The Essential Eight is a set of eight mitigation strategies published by the ACSC and scored by maturity level. SMB1001 is a certifiable standard with tiers. The Essential Eight tells you what to fix, SMB1001 gives you something a customer can verify. The underlying work overlaps heavily.

How long does SMB1001 certification take?

For an organisation with reasonable IT foundations, the lower tiers are usually a matter of weeks. Most of the elapsed time goes into the controls the business has been deferring, typically multi-factor authentication everywhere and a backup that has actually been restore tested.

Do we need to be a REDD managed services client?

No. We take organisations through certification on its own. Clients who also have us running their technology tend to hold the tier more easily, because the controls are maintained rather than revisited once a year.

Get something your customers can check

Thirty minutes to work out which tier your business actually needs, and what stands between you and it.

Get in touch

Tell us what is running your business

Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.

Thanks. Your enquiry is on its way, and a REDD engineer will come back to you within one business day.

Your details go to the REDD team and nowhere else.

1300 697 333 Book a consult