Proportionate Certification
SMB1001 Readiness
Tiered readiness from Bronze to Diamond for smaller businesses that need recognised proof of their security position — without carrying the cost and overhead of a full ISO 27001 management system.
Who This Is For
- Australian small and medium businesses being asked to prove their cyber security posture by enterprise clients, prime contractors, or procurement portals
- Businesses that need recognised proof for a cyber insurance renewal but do not yet need full ISO 27001 certification
- Firms that want to climb maturity in graded, affordable steps rather than jumping straight to a full-scale management system
Service Overview
Proof That Is Proportionate to Your Size
The demand for security evidence no longer stops at large enterprises. Prime contractors, healthcare networks, and government buyers now push their own security obligations down the chain — to suppliers with twenty people. For many of those businesses, standing up a full ISO 27001 ISMS to answer that request is out of proportion to the risk they actually carry.
SMB1001 exists for precisely that gap. Its tiers let a smaller business demonstrate a graded, recognised, verifiable security position, and raise it as the business grows. Whitesec AU maps where you stand, recommends the tier your requirement genuinely calls for, closes the gaps, and assembles the evidence file an assessor will work through.
Bronze → Diamond
Five graded tiers, so you pay for the maturity level your requirement actually demands.
Regulatory & Standards Alignment
SMB1001 — Tiered Framework
An Australian cyber security standard built specifically for small and medium businesses, with graded tiers running from Bronze through to Diamond.
ASD Essential Eight
ACSC mitigation controls that overlap heavily with SMB1001 requirements, so one uplift effort supports both positions.
Privacy Act & Australian Privacy Principle 11
Personal information protection obligations that still bind small businesses in certain sectors, whichever certification tier is chosen.
Business Value & Executive Outcomes
The Tier That Matches the Requirement
We read your buyer's or underwriter's requirement first, then recommend the lowest tier that genuinely satisfies it.
Cost in Proportion
You don't build an enterprise-scale management system for a twenty-person business, and you don't pay as though you did.
A Clear Path Upward
Each tier builds on the one below it, so the next step is a continuation rather than a project started from scratch.
Tender-Ready Evidence
The evidence file is assembled so it can be attached straight to vendor portals and buyer security questionnaires.
Essential Eight Overlap
Most of the uplift work also raises your Essential Eight position, so one engagement answers two separate demands.
A Foundation Toward ISO 27001
If you do eventually need ISO 27001, the upper-tier SMB1001 work is the starting point rather than wasted effort.
The Problem
Challenges We Solve
The situations that bring organisations to this engagement in the first place.
ISO 27001 is oversized for you
A client wants proof of your security, but building a full ISMS is out of proportion to the size, risk, and budget of the business.
Self-assessment no longer clears
The questionnaire you filled in yourself is increasingly being rejected. Buyers want a graded position somebody else has verified.
It isn't obvious which tier is enough
Bronze, Silver, Gold, Platinum, or Diamond — aim too low and you fail the requirement, aim too high and you have overspent.
Scope of Service
SMB1001 Readiness Scopes
Fixed-scope engagements, from setting the tier through to handing over the evidence file.
Tier Selection & Gap Analysis
Starting Point
Establish the tier your requirement demands, then map where you currently stand against it.
Bronze & Silver Control Uplift
Foundation Tiers
Close the foundational controls — MFA, patching, backups, access control — and document evidence for each.
Gold, Platinum & Diamond Readiness
Upper Tiers
The written policies, risk treatment, and operational discipline the upper tiers call for.
Evidence File Assembly
Deliverable
An evidence file ordered the way an assessor works through it, not a folder of screenshots.
Methodology
How the Engagement Runs
Four steps from the requirement that landed on your desk to an evidence file you can hand over.
Read the Requirement
We start from the document that triggered all of this — the buyer's questionnaire, the tender condition, or the insurer's form — and establish which tier is actually being asked for.
Map the Current Position
A gap analysis against the target tier, with findings scored and prioritised by their effect on whether you pass.
Close the Gaps
Hands-on implementation of the missing controls, worked through with your team or your IT provider, each mapped to its evidence.
Hand Over the File
The final evidence file is delivered in a form you can attach, along with the maintenance notes that stop the position drifting.
Deliverables
What You Receive
The artifacts that land in your hands at the end of the engagement.
Tier Recommendation
A written statement of the tier your requirement demands, and the reasoning behind it.
Gap Report
Every missing control, scored and prioritised by its effect on whether you pass.
Evidence File
Evidence ordered the way an assessor will work through it.
Maintenance Notes
What has to keep running for the position to hold until the next cycle.
FAQ
Frequently Asked Questions
Find Out Which Tier Your Requirement Actually Demands
Send us the questionnaire or tender condition you have been handed, and we will establish the right tier and a fixed price for reaching it.