Here's what SMB1001 actually is, what the five tiers mean, and how a practice gets certified without turning it into a second job.
First, what is SMB1001?
SMB1001 is a multi-tiered cyber security certification standard built specifically for small and medium businesses, maintained by Dynamic Standards International (DSI) and certified in Australia through CyberCert. It has five cumulative tiers, Bronze, Silver, Gold, Platinum and Diamond, and certification is renewed annually, so it proves your firm's security is current, not that it was fine once.
That certifiable part is the point. Plenty of frameworks tell you what good looks like. SMB1001 is the one that hands your firm something to show for it.
Why this matters for an accounting firm specifically
A practice holds tax file numbers, financials and a direct line into client money. You already know that makes you a target. What's changed is who's asking for proof:
Clients
Especially larger ones, now run vendor security checks before handing over their books.
Insurers
Price your cyber cover on what you can demonstrate, not what you believe.
Referrers and licensees
Increasingly want evidence that the firms they work with take security seriously.
“We take security seriously” is a sentence anyone can say. A current SMB1001 certificate is a fact. For a profession that sells trust, that difference does real commercial work: it closes the security question in tenders and questionnaires before it gets asked.
The five tiers, in plain English
The tiers are cumulative: each one includes everything below it and adds more. The other thing that changes as you climb is who checks.
1
Bronze
The foundational hygiene every business should have. Your director attests the controls are in place, through the CyberCert portal. The realistic starting point, and quick to reach for a firm with its basics in order.
2
Silver
Adds tighter access control and more formal process. Still director-attested.
3
Gold
The credibility tier for a firm holding client financials: fuller governance, policies and training expectations. The highest of the director-attested tiers, and the one that starts meaning something in tenders.
4
Platinum
The step change: an independent verification organisation audits your controls rather than your director attesting them.
5
Diamond
The top of the standard, externally audited, for businesses that want the strongest claim the framework can make.
For most accounting firms the sensible path is Bronze soon, then a deliberate climb to Silver or Gold. The attestation tiers exist so that getting certified doesn't require an audit budget on day one, and the audited tiers exist so the claim keeps getting stronger as you grow into it.
What the standard actually covers
SMB1001 spreads its controls across five domains: technology management, access management, backup and recovery, policies and processes, and education and training.
Read that list again and notice something: barely half of it is technology. The rest is governance and people, written policies your staff have actually read, training that actually happens, plans for the day something goes wrong. That's deliberate, and it's why the standard fits firms your size. Most breaches don't start with exotic hacking; they start with a person, a password and an inbox.
It's also why a provider who only does tech can't carry you to certification. The controls live in how the firm runs, not just in how the laptops are configured.
How certification actually works
1
Pick the target tier
Bronze first for nearly everyone; the climb is planned from there.
2
Close the gaps
Implement the controls for that tier across the five domains. This is the real work, and it's where we come in: as a CyberCert partner, Worktopia runs the uplift as part of managing your IT, and our
Compliance Portal scores your SMB1001 readiness continuously from the systems we already run for you, so you can see exactly how far from certifiable you are on any given day.
3
Certify
At Bronze, Silver and Gold, your director attests through CyberCert that the controls are in place. At Platinum and Diamond, an independent verification organisation audits them.
4
Keep it current
Certification renews annually. That's a feature, not a nuisance: a renewal cycle is what makes the certificate worth something to the people you show it to.
Where the Essential Eight fits
If your firm has been working on the ACSC Essential Eight, nothing is wasted: the two share most of their controls, and most firms start with the Essential Eight because it's what tenders and insurers name. The short version of the difference is that the Essential Eight is a technical baseline with maturity levels and no certificate, while SMB1001 is broader, covering people, policies and governance, and ends in a certification you can show. They're complementary, not competing. For the detail on the Essential Eight itself, read the Essential Eight, explained for accounting firms.
→SMB1001 is a five-tier cyber security certification standard built for businesses your size, maintained by DSI and certified through CyberCert.
→Bronze, Silver and Gold are director-attested; Platinum and Diamond are independently audited. Certification renews annually.
→It covers five domains, and barely half of them are technology. The rest is policies, training and governance.
→For a firm that sells trust, a current certificate does commercial work a “we take security seriously” sentence can't.
→Sensible path for most firms: Bronze soon, then a planned climb to Silver or Gold. Essential Eight work carries across.
Certification and uplift
SMB1001 certification for accounting firms.
See the path →
Common questions
What is SMB1001?
SMB1001 is a multi-tiered cyber security certification standard designed for small and medium businesses, maintained by Dynamic Standards International (DSI). It has five cumulative tiers, Bronze to Diamond, across five domains covering technology, access, backup, policies and training, and certification is renewed annually.
Who certifies SMB1001 in Australia?
CyberCert is the certification body for SMB1001 in Australia. At the Bronze, Silver and Gold tiers a company director attests through the CyberCert platform that the controls are in place; at Platinum and Diamond an independent verification organisation audits them.
Which SMB1001 tier should an accounting firm aim for?
Bronze is the realistic starting point and quick to reach for a firm with its basics in order. For a practice holding client financials, a planned climb to Silver or Gold is the sensible target: Gold is the highest director-attested tier and the one that carries real weight in tenders and insurance questionnaires.
How much does SMB1001 certification cost?
It depends on the tier and on how far your firm is from the controls. The certification itself is issued through CyberCert; the real cost driver is closing the gaps, which scales with your starting point. A gap assessment first tells you the actual number rather than a guess.
Is SMB1001 the same as the Essential Eight?
No. The Essential Eight is a technical baseline with maturity levels and no certificate. SMB1001 is broader, adding policies, training and governance, and ends in an annually renewed certification you can show clients and insurers. The two share most of their controls, so work on one largely counts toward the other. Read more:
The Essential Eight, explained for accounting firms
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.