Back to Home
Dynamic Standards International (DSI)

SMB1001
Built for Australian SMBs

SMB1001 is a multi-tiered cybersecurity certification standard purpose-built for small and medium-sized businesses. It provides a clear, practical pathway - from foundational cyber hygiene all the way to advanced maturity - with formal certification at every level.

What is SMB1001?

Developed by Dynamic Standards International (DSI), SMB1001 is a dynamic standard that refreshes annually to keep pace with the rapidly evolving cyber threat landscape. It recognises that not all organisations have the same resources or needs - so rather than one-size-fits-all compliance, it offers five progressive tiers.

Each tier builds on the previous one, covering the "People, Process and Technology" dimensions of cybersecurity across five domains. Levels 1-3 may be self-attested in compliance with JAS-ANZ guidelines, while Levels 4 and 5 require independent third-party verification and attestation by a DSI-accredited Dynamic Standard Certifier (DSC).

SMB1001:2026 aligns with global standards including ISO/IEC 27001, SOC 2, and CMMC 2.0 - giving your business a solid foundation for broader compliance, supply chain requirements, and cyber insurance. It is designed to be scalable for organisations from fewer than 20 employees up to 500+.

Five Security Domains

Technology Management

Practices to manage the security of technology over its lifecycle - patching, updates, scanning, and testing.

Access Management

Ensuring only authorised users access organisational systems, including MFA, password management, and privilege control.

Backup and Recovery

Strategies to maintain operations during downtime or incidents, including tested backup schedules and business insurance.

Policies, Processes and Plans

Formal documentation and governance including cybersecurity policy, incident response plans, and supplier trust programs.

Education and Training

Ongoing employee awareness programs, social engineering training, and incident response exercises.

The Five Certification Tiers

Each tier is cumulative - higher levels include all requirements from lower tiers.

Level 1
7 controls · 4 domains

Targeted at organisations with limited cyber hygiene that are beginning to prioritise cybersecurity. Focus is on the initial essential measures with minimal resources required.

Level 2
17 controls · 5 domains

For organisations ready to formalise their cybersecurity practices. Builds on Level 1 by adding policies, access controls, and email authentication that are affordable and achievable for SMBs.

Level 3
27 controls · 5 domains

For organisations developing a mature, proactive risk management approach. Adds EDR, expanded MFA, formal cybersecurity policy, incident response, AI use policy, and ongoing security awareness.

Level 4
32 controls · 5 domains

For organisations with relatively mature cyber hygiene. Requires independent assessment. Adds vulnerability scanning, cloud credential management, advanced MFA, and an SLA with IT providers.

Level 5
39 controls · 5 domains

Maximum maturity. Requires independent assessment. Adds encryption at rest, application control, penetration testing, MDR service, supply chain trust programs, police vetting, and incident response exercises.

Certification Lifecycle

Annual Renewal

Certifications are valid for one year. Organisations can re-certify at the same level or progress to a higher tier.

Self-Attestation (L1–3)

Levels 1, 2, and 3 may be self-assessed and attested in compliance with JAS-ANZ guidelines.

Third-Party Verification (L4–5)

Levels 4 and 5 require independent assessment and attestation by a DSI-accredited Dynamic Standard Certifier (DSC).

Ready to start your SMB1001 journey? We guide you through every level.

Get in Touch

Third-Party Acknowledgments

SMB1001 is a registered standard of Dynamic Standards International (DSI). All rights reserved. © Dynamic Standards International. Referenced here solely for informational purposes.

The Essential Eight is a framework developed by the Australian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC), a division of the Australian Government. © Commonwealth of Australia. All rights reserved.

ISO/IEC 27001 is a standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). © ISO/IEC. All rights reserved.

SOC 2 is a framework developed by the American Institute of Certified Public Accountants (AICPA). © AICPA. All rights reserved.

CMMC 2.0 (Cybersecurity Maturity Model Certification) is a framework of the United States Department of Defense (DoD). All rights reserved.

All trademarks, standards, and frameworks are the property of their respective owners. VMAAS Australia is not affiliated with, endorsed by, or officially associated with any of the above organisations.