SMB1001

SMB1001 · COMPLIANCE · CERTIFICATION READINESS
The Essential Eight is retiring.
Here's where you land.

ASD confirmed in June 2026 that the Essential Eight will be phased out within two years. SMB1001 certification is filling the gap for small and mid-sized businesses. DFNCE gets you readiness-assessed, remediated, and evidence-ready for the tier your customers, tenders and supply-chain contracts actually ask for.

DIAMOND

Independently audited · top assurance tier

PLATINUM

Independently audited

GOLD

Director-attested · DKIM + enforced DMARC required

SILVER

Director-attested · SPF required

BRONZE

Director-attested · entry tier

The five SMB1001 certification tiers, 2026 edition

5 TIERS

Bronze to Diamond — matched to your risk and customer requirements

2026 EDITION

Current standard — email authentication now mandatory, revised annually

≤ 24 MONTHS

Until the Essential Eight is fully retired, on ASD's stated timeline

01 · WHAT IS SMB1001

A cyber security certification built for SMBs.

Tiered, achievable, revised annually. Certification you can hand to a customer.

SMB1001 is a tiered cyber security certification standard developed by Dynamic Standards International (DSI) and certified through CyberCert. Unlike enterprise frameworks such as ISO 27001, it is designed to be achievable for businesses without a dedicated security team — starting with foundational controls at Bronze and stepping up to independently audited certification at Platinum and Diamond.

The standard is revised annually. The current 2026 edition, released September 2025, made email authentication mandatory: SPF is required from Silver, and DKIM plus an enforced DMARC policy (quarantine or reject) is required from Gold.

STRAIGHT TALK: SMB1001 is a private market standard, not government legislation — it isn't named in the Cyber Security Act 2024 or the PSPF. At Bronze, Silver and Gold, certification rests on a director's attestation; independent audit only applies at Platinum and Diamond. DFNCE prepares you for certification — CyberCert issues it. Anyone telling you otherwise is selling something.
02 · What it covers

Five domains. Not just eight controls.

SMB1001 measures your whole security posture, not just your technology. Every tier draws its controls from the same five domains, and the bar rises as you climb.

Technology management

Firewalls, patching, endpoint protection, and email authentication. The technical controls that stop the common attacks. From Gold, that means EDR on every workstation and server.

Access management

Who can reach what, and how they prove it. Password managers, MFA, and admin access locked down to the people who need it.

Backup and recovery

Backups that exist, run, and restore when tested. If you cannot recover, nothing else on this list matters.

Policies and processes

Written rules your business actually follows. Incident response, acceptable use, and from Gold under the 2026 edition, a written AI use policy.

Education and training

Your people can spot a phish before they click it. Human error is the top entry point, so the standard treats training as a control, not an extra.

This is the difference from the Essential Eight. The Essential Eight measured your technology. SMB1001 measures your business.

03 · WHY NOW

The compliance ground is shifting under Australian SMBs.

Two events in twelve months changed what "cyber compliant" means for small business in Australia.

SEP 2025

SMB1001:2026 released

Email authentication becomes mandatory — SPF from Silver, DKIM and enforced DMARC from Gold.
24 JUN 2026

Essential Eight retirement confirmed

ASD announces the Essential Eight will be replaced by a new "Essentials" series covering enterprise IT, OT and cloud.
12 JUL 2026

Essentials consultation closes

Consultation on the Essentials series for enterprise IT closes via the ASD Cyber Security Partnership Program. ASD is now working through submissions.
~MID 2027

Deprecation begins

Essential Eight deprecation expected around 12 months from the announcement.
~MID 2028

Full retirement

Essential Eight fully retired at 24 months. Businesses aligned to it need a landing place.

If your security posture, customer contracts, or insurance renewals reference the Essential Eight, you have a window — not a crisis — to transition deliberately. SMB1001 is the certification the Australian market is consolidating around for SMBs, and moving early means moving on your terms.

04 · THE FIVE TIERS

Which tier do you actually need?

Most businesses don't need the top tier — they need the tier their customers, tenders, and supply-chain contracts ask for. We'll tell you which one that is before you spend a dollar on remediation.

Bronze

DIRECTOR-ATTESTED
Foundational cyber hygiene. The entry point for micro and small businesses starting from zero.

Best for: getting off zero

SILVER

Director-attested
Steps up the control set. SPF email authentication becomes mandatory from this tier under the 2026 edition.

Best for: small teams with client data

GOLD

Most asked for
DIRECTOR-ATTESTED
DIRECTOR-ATTESTED
The tier supply chains most commonly require. The 2026 edition lifts Gold to 27 controls, adding EDR on every workstation and server, full email authentication (DKIM plus enforced DMARC), mandatory cyber insurance, and a written AI use policy. EDR and the AI policy are the two that stall certifications.

Best for: supply-chain requirements

PLATINUM

INDEPENDENTLY AUDITED
External audit enters here. Real third-party assurance for businesses whose customers demand verified controls.

Best for: regulated customers

DIAMOND

INDEPENDENTLY AUDITED
The highest assurance tier. For businesses competing on trust: government supply chains, critical services, high-value data.

Best for: maximum assurance

Tier requirements follow the SMB1001:2026 edition and are revised annually by DSI. We track each revision so you don't have to.

05 · How it compares

SMB1001 against the frameworks you've heard of.

Four names come up in every compliance conversation. Here is where each one fits, straight.

Framework What it is Certificate? Right for you when
SMB1001 Tiered certification standard for SMBs, developed by DSI, revised annually. Yes. Director-attested to Gold, independently audited at Platinum and Diamond. Customers, tenders, or insurers want proof of your security posture.
Essential Eight → Essentials series ASD’s official guidance. The Essential Eight retires by mid 2028 and becomes the Essentials series. No. Guidance and self-assessment only. Nothing to hand to a customer. You align to government advice. Your controls carry into both SMB1001 and the Essentials series.
ISO 27001 International information security management standard. Heavy documentation, external audit, significant cost. Yes. Independent certification. You sell into enterprise or government contracts that name it. Overkill below that.
RFFR Federal government assurance requirement for suppliers delivering employment services and related contracts. No. A pass requirement, not a tiered certification. You hold or are bidding for the specific government contracts that mandate it. Otherwise ignore it.

STRAIGHT TALK: These are not competitors. Most businesses need their Essential Eight controls (soon Essentials series) as the foundation, SMB1001 as the certificate on top, and ISO 27001 only when a contract demands it. If someone is selling you all four, they are selling you three too many.

06 · WHAT DFNCE DELIVERS

Readiness to certification. One partner, no
hand-offs.

Most providers assess you, hand you a PDF, and leave. Because DFNCE runs security, backup, and IT operations under one roof, we don't just find the gaps — we close them.

07 · COMMON QUESTIONS

SMB1001, answered straight.

What is SMB1001 certification?

SMB1001 is a tiered cyber security certification standard for small and mid-sized businesses, developed by Dynamic Standards International and revised annually. It has five tiers — Bronze, Silver, Gold, Platinum and Diamond — with certification issued through CyberCert. Bronze through Gold are certified by director attestation; Platinum and Diamond require independent audit.

No. SMB1001 is a private market standard — it is not named in the Cyber Security Act 2024, the SOCI Amendment Rules 2025 or the PSPF. In practice, though, it's increasingly requested in supply-chain contracts, tenders and cyber insurance renewals, which is where the commercial pressure comes from.

The Essential Eight is an ASD-published set of mitigation strategies with maturity levels — guidance, not a certification. SMB1001 is a certifiable standard with a certificate you can hand to a customer. With ASD confirming the Essential Eight will be retired within two years, SMB1001 has become the practical destination for SMBs that need something to show for their security posture. Your Essential Eight investment isn't wasted — most of those controls map directly onto SMB1001 tiers.

The headline change is mandatory email authentication: SPF is required from Silver, and DKIM plus an enforced DMARC policy at quarantine or reject is required from Gold. The standard is revised annually, so requirements move — part of our service is keeping your certification aligned to the current edition.

No, and be wary of anyone who claims to. Dynamic Standards International develops the standard and CyberCert is the certification body. DFNCE does the readiness work: gap assessment, remediation, evidence and attestation preparation. You certify through CyberCert with everything in place.

It depends on the tier and where you're starting from. Bronze and Silver can be quick for a business with reasonable hygiene. Gold typically involves real remediation work — email authentication enforcement in particular trips people up. The gap assessment tells you exactly how far off you are before you commit to anything.

Find out which tier you need — and how far off you are.

30 minutes. Straight talk. No slide decks. No pressure. We'll tell you honestly if SMB1001 is even the right move for your business.

Log a support case