More New Zealand small businesses are being asked to prove their cybersecurity with documented evidence instead of a verbal assurance. A client’s procurement team wants documented proof, an insurer wants confirmation of controls before renewing your policy, or a larger customer wants it settled before they’ll put you on their supplier list. SMB1001 certification exists to answer that ask with a single, recognised certificate.
In this guide you will find:
- What SMB1001 certification covers
- The five certification levels, from Bronze to Diamond
- Who needs it, and who can skip it for now
- How to get your business ready
What is SMB1001 certification?
SMB1001 is a cyber security certification standard built specifically for small and medium businesses. It was developed by Dynamic Standards International and is delivered through the CyberCert platform, and it exists because standards like ISO 27001 were designed with large enterprises and dedicated security teams in mind, not a business with twenty staff and no in-house IT department.
SMB1001 uses a tiered structure instead of one fixed checklist. That means a business just getting its security basics in order and a business with a mature, tested security programme can both certify, at the level that matches where they currently sit.
The five SMB1001 certification levels
Each tier builds on the one below it, covering technology, access management, backups, policy, and staff training:
- Bronze: foundational cyber hygiene, including firewalls, antivirus, patching and backups
- Silver: stronger controls such as multi-factor authentication, email security and staff awareness training
- Gold: advanced monitoring, tighter access controls and a documented incident response plan
- Platinum: external assurance alongside deeper governance
- Diamond: the highest level of maturity, with continuous oversight
Bronze, Silver, and Gold are certified by director attestation, meaning a company director confirms the controls are in place. Platinum and Diamond require an independent external audit before the certificate is issued, and certificates renew annually.
Why NZ businesses are getting SMB1001 certified
Certification is becoming less of a nice-to-have and more of a practical requirement in a few specific situations:
- Supply chain and tender requirements: larger organisations and government-adjacent buyers increasingly ask suppliers to prove their security posture before signing a contract
- Cyber insurance: insurers are asking more detailed questions before policy renewal, and a current certificate can answer several of them in one line
- Client and stakeholder trust: certification gives customers and partners documented evidence that security is being taken seriously, backed by director attestation at Bronze, Silver and Gold, and independent external audit at Platinum and Diamond
- A realistic first step: compared with enterprise frameworks, SMB1001 is achievable without the cost or overhead of a full ISO 27001 programme
Does your business need SMB1001 certification?
SMB1001 is worth considering if any of the following sound familiar:
- A client, insurer or supply chain partner has already asked about your cyber security controls or certification
- You’re bidding for contracts with larger organisations or government-adjacent bodies
- You want a clear, recognised benchmark rather than an informal sense that “we’re probably fine”
- You’re renewing cyber insurance and want stronger evidence to support the application
If none of that applies yet, it doesn’t mean security can wait. It just means certification itself may not be the most urgent next step, and getting the underlying controls right matters more than the certificate.
How to get your business ready for SMB1001
Getting ready is mostly a matter of checking your current setup against the controls for the level you are aiming for, then closing any gaps before you apply.
- Confirm which level fits your situation.
- Review your current security setup against that level’s controls, from MFA and patching through to backup testing and incident response planning.
- Close any gaps you find, and document what is in place as evidence.
- For Bronze, Silver, and Gold, a company director attests that the controls are in place. Platinum and Diamond require an independent external audit first.
- Apply through the CyberCert platform once your controls and evidence are ready.
How Revolution IT can help you get SMB1001-ready
Revolution IT displays CyberCert-SMB1001 accreditation, and much of what SMB1001 asks for at the Bronze, Silver, and Gold levels overlaps directly with the managed cyber security services we already provide: multi-factor authentication, patching, backup testing, access controls, and incident response planning are all part of our Total Care Cyber offering, aligned to NCSC’s 10 Critical Controls.
For small businesses without an internal IT or security lead, working through this as part of our IT services for small businesses is generally more cost-effective than building the expertise in-house and gives you a clear picture of where your current setup already meets the bar and where the gaps sit.
Get in touch with Revolution IT to talk through what SMB1001 readiness looks like for your business.
SMB1001 Certification FAQs
It’s a tiered cyber security certification standard for small and medium businesses, covering technology, access management, backups, policy, and training, with five levels from Bronze through to Diamond.
It depends on what’s driving the need. Bronze and Silver suit businesses building their security foundations, while Gold is often the level a lot of insurers and larger customers ask for, though requirements vary by insurer and by contract. Platinum and Diamond generally suit businesses with more advanced compliance requirements.
Only for Platinum and Diamond. Bronze, Silver, and Gold are certified through director attestation once the required controls are in place.
It can support your application by giving insurers evidence that key controls, such as MFA, backups, and incident response planning, are already in place, though it’s worth checking with your insurer or broker directly on how it factors into your specific policy.
Yes. Our managed cyber security services already cover much of the ground SMB1001 requires, and we can help you identify what’s in place and what still needs work. Contact us to discuss preparing your business for SMB1001 certification.


