More New Zealand small businesses are being asked to prove their cybersecurity with documented evidence instead of a verbal assurance. A client’s procurement team wants documented proof, an insurer wants confirmation of controls before renewing your policy, or a larger customer wants it settled before they’ll put you on their supplier list. SMB1001 certification exists to answer that ask with a single, recognised certificate.
In this guide you will find:
- What SMB1001 certification covers
- The five certification levels, from Bronze to Diamond
- Who needs it, and who can skip it for now
- How to get your business ready
What is SMB1001 certification?
SMB1001 is a cyber security certification standard built specifically for small and medium businesses. It was developed by Dynamic Standards International and is delivered through the CyberCert platform, and it exists because standards like ISO 27001 were designed with large enterprises and dedicated security teams in mind, not a business with twenty staff and no in-house IT department.
SMB1001 uses a tiered structure instead of one fixed checklist. That means a business just getting its security basics in order and a business with a mature, tested security programme can both certify, at the level that matches where they currently sit.
The five SMB1001 certification levels
Each tier builds on the one below it, covering technology, access management, backups, policy, and staff training:
- Bronze: foundational cyber hygiene, including firewalls, antivirus, patching and backups
- Silver: stronger controls such as multi-factor authentication, email security and staff awareness training
- Gold: advanced monitoring, tighter access controls and a documented incident response plan
- Platinum: external assurance alongside deeper governance
- Diamond: the highest level of maturity, with continuous oversight
Bronze, Silver, and Gold are certified by director attestation, meaning a company director confirms the controls are in place. Platinum and Diamond require an independent external audit before the certificate is issued, and certificates renew annually.
Why NZ businesses are getting SMB1001 certified
Certification is becoming less of a nice-to-have and more of a practical requirement in a few specific situations:
- Supply chain and tender requirements: larger organisations and government-adjacent buyers increasingly ask suppliers to prove their security posture before signing a contract
- Cyber insurance: insurers are asking more detailed questions before policy renewal, and a current certificate can answer several of them in one line
- Client and stakeholder trust: certification gives customers and partners documented evidence that security is being taken seriously, backed by director attestation at Bronze, Silver and Gold, and independent external audit at Platinum and Diamond
- A realistic first step: compared with enterprise frameworks, SMB1001 is achievable without the cost or overhead of a full ISO 27001 programme
Does your business need SMB1001 certification?
SMB1001 is worth considering if any of the following sound familiar:
- A client, insurer or supply chain partner has already asked about your cyber security controls or certification
- You’re bidding for contracts with larger organisations or government-adjacent bodies
- You want a clear, recognised benchmark rather than an informal sense that “we’re probably fine”
- You’re renewing cyber insurance and want stronger evidence to support the application
If none of that applies yet, it doesn’t mean security can wait. It just means certification itself may not be the most urgent next step, and getting the underlying controls right matters more than the certificate.
How to get your business ready for SMB1001
Getting ready is mostly a matter of checking your current setup against the controls for the level you are aiming for, then closing any gaps before you apply.
- Confirm which level fits your situation.
- Review your current security setup against that level’s controls, from MFA and patching through to backup testing and incident response planning.
- Close any gaps you find, and document what is in place as evidence.
- For Bronze, Silver, and Gold, a company director attests that the controls are in place. Platinum and Diamond require an independent external audit first.
- Apply through the CyberCert platform once your controls and evidence are ready.
How Revolution IT can help you get SMB1001-ready
Revolution IT displays CyberCert-SMB1001 accreditation, and much of what SMB1001 asks for at the Bronze, Silver, and Gold levels overlaps directly with the managed cyber security services we already provide: multi-factor authentication, patching, backup testing, access controls, and incident response planning are all part of our Total Care Cyber offering, aligned to NCSC’s 10 Critical Controls.
For small businesses without an internal IT or security lead, working through this as part of our IT services for small businesses is generally more cost-effective than building the expertise in-house and gives you a clear picture of where your current setup already meets the bar and where the gaps sit.
Get in touch with Revolution IT to talk through what SMB1001 readiness looks like for your business.
Microsoft 365 Price Increase FAQs
It applies from your subscription’s next renewal date on or after 1 July 2026. Existing terms keep their current pricing until then. Check your renewal date in the admin centre before budgeting for the change.
No. Business Premium and Office 365 E1 remain the same, while Business Basic, Business Standard, and most Enterprise and Frontline plans have increased.
Probably not by moving plans alone, since the update covers almost the whole line-up. The bigger opportunity is removing licences you don’t need and matching each user to the right plan.
In the Microsoft 365 admin centre, go to Billing, then Your Products. Your renewal date is listed against each subscription.
Yes. Our Microsoft 365 consulting team can review your licensing and security settings ahead of your renewal date and recommend changes before you commit to another term. Contact us to arrange a review.


