SMB1001 is a tiered Australian standard designed for organisations that will never run a full ISO 27001 program but still have to prove they take security seriously. REDD was the first managed IT provider accredited into the CyberCert program, and we take clients through it tier by tier.
What it is
Most security standards were written for enterprises with a compliance team. SMB1001 is graded, so a ten-person firm can certify at a level that matches its risk and step up over time rather than facing a single, unreachable bar.
That matters commercially. A certificate is something a customer, an insurer or a tender panel can check, which is far more useful than a policy document nobody reads.
Each tier adds controls. You certify where you are, then move up as the business grows or a customer asks for more.
The controls are written for organisations without a dedicated security team, which is most Australian businesses.
Certification is issued against a published standard, so it means the same thing to everyone who asks.
The work behind a tier is the same work that lifts your Essential Eight maturity. Neither effort is wasted.
Which one
They are complementary rather than competing. Most of our clients end up doing both, in this order.
| SMB1001 | Essential Eight | |
|---|---|---|
| What it is | A tiered, certifiable standard | An eight-control mitigation baseline from the ACSC |
| Who it suits | Smaller organisations needing proof for customers | Any organisation, and mandatory for many government entities |
| What you get | A certificate at a defined tier | A maturity level from zero to three, evidenced |
| Who asks for it | Customers, insurers, smaller tenders | Government, enterprise procurement, insurers |
| Where to start | If you need something to show, start here | If you need to reduce risk fastest, start here |
Scroll the table sideways to see every column.
How it runs
Week 1
We look at what your customers and insurer are actually asking for, then choose the tier that answers it. Aiming too high is the most common way these programs stall.
Weeks 2 to 6
The controls behind each tier are practical: multi-factor authentication, backups, patching, a tested incident response plan. We implement, you approve.
Certification
We gather the evidence and support the certification, rather than handing you a checklist and wishing you luck.
Ongoing
A certificate is a point in time. Managed services keep the controls in place between renewals so the next tier is a step, not a restart.
Why us
REDD was the first managed IT services provider accredited into the CyberCert program, which is why we have run this process more times than most.
The same team that certifies you runs your IT, so the controls survive contact with daily operations instead of lapsing after the audit.
See managed technology →Certification proves the controls exist. Our 24x7 Security Operations Centre is what notices when one of them fails at 3am.
See MDR →Common questions
SMB1001 is an Australian cyber security standard written for small and medium businesses. It is graded into tiers, so an organisation can certify at a level that matches its size and risk and then step up, rather than facing the single high bar of a standard such as ISO 27001.
The Essential Eight is a set of eight mitigation strategies published by the ACSC and scored by maturity level. SMB1001 is a certifiable standard with tiers. The Essential Eight tells you what to fix, SMB1001 gives you something a customer can verify. The underlying work overlaps heavily.
For an organisation with reasonable IT foundations, the lower tiers are usually a matter of weeks. Most of the elapsed time goes into the controls the business has been deferring, typically multi-factor authentication everywhere and a backup that has actually been restore tested.
No. We take organisations through certification on its own. Clients who also have us running their technology tend to hold the tier more easily, because the controls are maintained rather than revisited once a year.
Thirty minutes to work out which tier your business actually needs, and what stands between you and it.
Get in touch
Send the basics and a REDD engineer will come back to you within one business day. Prefer to talk? Call 1300 697 333.