Running a small business means balancing customer expectations, daily operations and costs. Cybersecurity adds another responsibility: protecting the systems and information your business depends on.
But where should you start, and how can you demonstrate progress?
SMB1001 cybersecurity certification offers a structured approach for small and medium-sized businesses. Its five levels help organisations establish security foundations and build more advanced capabilities as their needs grow.
In this guide, SS NovaTech explains what SMB1001 is, how its certification levels differ and what to consider before getting started.
What Is SMB1001?
SMB1001 is a cybersecurity standard developed by Dynamic Standards International (DSI) with the needs and resources of small and medium-sized businesses in mind.
It provides five certification levels, allowing organisations to select a target that reflects their risks, resources and customer requirements. DSI reviews the standard annually and currently lists the SMB1001:2026 edition. Official DSI overview
For business owners, the value is a defined starting point. You can assess your existing safeguards, identify gaps and organise improvements around a clear target.
What Are the Five SMB1001 Certification Levels?
SMB1001 progresses from foundational protection to more comprehensive security and governance.
| Level | Certification | Broad focus |
|---|---|---|
| Level 1 | Bronze | Basic preventive security measures |
| Level 2 | Silver | Additional layers of preventive protection |
| Level 3 | Gold | Broader risk management across people, processes and technology |
| Level 4 | Platinum | Advanced security controls and governance |
| Level 5 | Diamond | The most comprehensive tier of security and governance |
These descriptions explain the overall progression. The applicable standard edition sets out the precise requirements for each level. DSI’s explanation of the five levels
The verification model also matters. Bronze, Silver and Gold use director attestation, while Platinum and Diamond involve external validation. A business should consider the level of assurance its customers require when choosing a target. CyberCert’s certification model
Which SMB1001 Level Is Right for Your Business?
Start with the information you handle and the services you provide.
A business holding sensitive client records has different security needs from one that processes only public information. An IT provider with access to customer systems also has responsibilities beyond protecting its own devices.
DSI’s supplier categorisation approach considers:
- Information: What data does the business store or process?
- Access: Which customer systems can it access, and with what permissions?
- Service criticality: What would happen if its services became unavailable?
These factors help connect the certification level to actual business exposure. DSI Supplier Categorization Matrix
Before choosing a level, check whether customers or procurement teams have specified a particular certification or verification requirement.
How to Prepare for SMB1001 Certification
A practical preparation process turns requirements into assigned actions and verifiable results.
1. Define what the certification will cover
Identify the business entity, locations, systems and services involved. Include outsourced technology arrangements so responsibilities are clear.
2. Review your existing safeguards
Gather information about device protection, account access, backups, security procedures and staff practices. Ask your IT provider to explain which responsibilities it manages and which remain with your business.
3. Compare your position with the requirements
Use the applicable SMB1001 edition to assess your chosen level. Create a gap register that records each requirement, its owner, current status and next action.
4. Implement improvements and retain evidence
Complete the required work and verify that it operates as intended. Depending on the requirement, evidence might include configuration records, approved procedures, training records or recovery-test results.
5. Complete the certification process
Follow the certification provider’s requirements for your target level. CyberCert publishes certification options and notes additional external audit fees for Platinum and Diamond. Certification information
Allow for both certification costs and the work needed to address gaps when planning your budget.
Getting Value Beyond the Certificate
The preparation process is an opportunity to answer practical business questions:
- Can we recover important information after an outage?
- Are former employees’ accounts removed promptly?
- Do staff know how to report suspicious activity?
- Who coordinates the response when something goes wrong?
- Can we explain our security arrangements to a customer?
Keep those answers current as your business changes. Assign owners to recurring tasks and review evidence when you introduce new software, suppliers or services.
When presenting your certification to customers, clearly state its level, edition, scope and current status. This helps buyers understand the assurance it provides.
Frequently Asked Questions About SMB1001
Who is SMB1001 designed for?
SMB1001 is designed with small and medium-sized businesses in mind and can support organisations across different sectors. DSI standard overview
Do I need to obtain all five certifications?
No. DSI explains that organisations can target a suitable level without completing five separate certifications. Your selected level still has requirements that must be met. DSI certification pathway
Is SMB1001 Gold independently audited?
CyberCert describes Gold as director-attestable. Platinum and Diamond involve external validation. CyberCert assurance model
How much does SMB1001 certification cost?
Costs depend on the certification level and the improvements your business needs. Check current certification fees and include any external audit costs, technology changes and implementation support in your budget. CyberCert certification options
Discuss Your Cybersecurity Priorities With SS NovaTech
Understanding your current position is the first step towards a realistic security plan. Identify the information and services you need to protect, clarify customer expectations and select a target that fits your business.
Contact SS NovaTech to discuss your cybersecurity priorities and your next steps towards SMB1001 readiness.