SMB1001
SMB1001 · COMPLIANCE · CERTIFICATION READINESS
ASD confirmed in June 2026 that the Essential Eight will be phased out within two years. SMB1001 certification is filling the gap for small and mid-sized businesses. DFNCE gets you readiness-assessed, remediated, and evidence-ready for the tier your customers, tenders and supply-chain contracts actually ask for.
DIAMOND
Independently audited · top assurance tier
PLATINUM
Independently audited
GOLD
Director-attested · DKIM + enforced DMARC required
SILVER
Director-attested · SPF required
BRONZE
Director-attested · entry tier
The five SMB1001 certification tiers, 2026 edition
5 TIERS
Bronze to Diamond — matched to your risk and customer requirements
2026 EDITION
Current standard — email authentication now mandatory, revised annually
≤ 24 MONTHS
Until the Essential Eight is fully retired, on ASD's stated timeline
01 · WHAT IS SMB1001
A cyber security certification built for SMBs.
Tiered, achievable, revised annually. Certification you can hand to a customer.
SMB1001 is a tiered cyber security certification standard developed by Dynamic Standards International (DSI) and certified through CyberCert. Unlike enterprise frameworks such as ISO 27001, it is designed to be achievable for businesses without a dedicated security team — starting with foundational controls at Bronze and stepping up to independently audited certification at Platinum and Diamond.
The standard is revised annually. The current 2026 edition, released September 2025, made email authentication mandatory: SPF is required from Silver, and DKIM plus an enforced DMARC policy (quarantine or reject) is required from Gold.
02 · What it covers
SMB1001 measures your whole security posture, not just your technology. Every tier draws its controls from the same five domains, and the bar rises as you climb.
Technology management
Access management
Backup and recovery
Policies and processes
Education and training
This is the difference from the Essential Eight. The Essential Eight measured your technology. SMB1001 measures your business.
03 · WHY NOW
Two events in twelve months changed what "cyber compliant" means for small business in Australia.
SEP 2025
SMB1001:2026 released
Email authentication becomes mandatory — SPF from Silver, DKIM and enforced DMARC from Gold.24 JUN 2026
Essential Eight retirement confirmed
ASD announces the Essential Eight will be replaced by a new "Essentials" series covering enterprise IT, OT and cloud.12 JUL 2026
Essentials consultation closes
Consultation on the Essentials series for enterprise IT closes via the ASD Cyber Security Partnership Program. ASD is now working through submissions.~MID 2027
Deprecation begins
Essential Eight deprecation expected around 12 months from the announcement.~MID 2028
Full retirement
Essential Eight fully retired at 24 months. Businesses aligned to it need a landing place.If your security posture, customer contracts, or insurance renewals reference the Essential Eight, you have a window — not a crisis — to transition deliberately. SMB1001 is the certification the Australian market is consolidating around for SMBs, and moving early means moving on your terms.
04 · THE FIVE TIERS
Most businesses don't need the top tier — they need the tier their customers, tenders, and supply-chain contracts ask for. We'll tell you which one that is before you spend a dollar on remediation.
Bronze
DIRECTOR-ATTESTED
Best for: getting off zero
SILVER
Director-attested
Best for: small teams with client data
GOLD
Most asked for
DIRECTOR-ATTESTED
DIRECTOR-ATTESTED
The tier supply chains most commonly require. The 2026 edition lifts Gold to 27 controls, adding EDR on every workstation and server, full email authentication (DKIM plus enforced DMARC), mandatory cyber insurance, and a written AI use policy. EDR and the AI policy are the two that stall certifications.Best for: supply-chain requirements
PLATINUM
INDEPENDENTLY AUDITED
Best for: regulated customers
DIAMOND
INDEPENDENTLY AUDITED
Best for: maximum assurance
Tier requirements follow the SMB1001:2026 edition and are revised annually by DSI. We track each revision so you don't have to.
05 · How it compares
Four names come up in every compliance conversation. Here is where each one fits, straight.
STRAIGHT TALK: These are not competitors. Most businesses need their Essential Eight controls (soon Essentials series) as the foundation, SMB1001 as the certificate on top, and ISO 27001 only when a contract demands it. If someone is selling you all four, they are selling you three too many.
06 · WHAT DFNCE DELIVERS
Most providers assess you, hand you a PDF, and leave. Because DFNCE runs security, backup, and IT operations under one roof, we don't just find the gaps — we close them.
07 · COMMON QUESTIONS
SMB1001, answered straight.
Related frameworks we advise on
Essential Eight → Essentials Series
What ASD's retirement announcement means, and how to transition without losing your maturity investment.ISO 27001
When SMB1001 isn't enough — full information security management for businesses selling into enterprise.Advisory & Governance
Independent risk, compliance and IT strategy advice — board-ready, vendor-neutral, no product agenda.Find out which tier you need — and how far off you are.
30 minutes. Straight talk. No slide decks. No pressure. We'll tell you honestly if SMB1001 is even the right move for your business.