Skip to main content
Whitesec AU

Proportionate Certification

SMB1001 Readiness

Tiered readiness from Bronze to Diamond for smaller businesses that need recognised proof of their security position — without carrying the cost and overhead of a full ISO 27001 management system.

Who This Is For

  • Australian small and medium businesses being asked to prove their cyber security posture by enterprise clients, prime contractors, or procurement portals
  • Businesses that need recognised proof for a cyber insurance renewal but do not yet need full ISO 27001 certification
  • Firms that want to climb maturity in graded, affordable steps rather than jumping straight to a full-scale management system

Service Overview

Proof That Is Proportionate to Your Size

The demand for security evidence no longer stops at large enterprises. Prime contractors, healthcare networks, and government buyers now push their own security obligations down the chain — to suppliers with twenty people. For many of those businesses, standing up a full ISO 27001 ISMS to answer that request is out of proportion to the risk they actually carry.

SMB1001 exists for precisely that gap. Its tiers let a smaller business demonstrate a graded, recognised, verifiable security position, and raise it as the business grows. Whitesec AU maps where you stand, recommends the tier your requirement genuinely calls for, closes the gaps, and assembles the evidence file an assessor will work through.

Bronze → Diamond

Five graded tiers, so you pay for the maturity level your requirement actually demands.

Regulatory & Standards Alignment

SMB1001 — Tiered Framework

An Australian cyber security standard built specifically for small and medium businesses, with graded tiers running from Bronze through to Diamond.

ASD Essential Eight

ACSC mitigation controls that overlap heavily with SMB1001 requirements, so one uplift effort supports both positions.

Privacy Act & Australian Privacy Principle 11

Personal information protection obligations that still bind small businesses in certain sectors, whichever certification tier is chosen.

Business Value & Executive Outcomes

The Tier That Matches the Requirement

We read your buyer's or underwriter's requirement first, then recommend the lowest tier that genuinely satisfies it.

Cost in Proportion

You don't build an enterprise-scale management system for a twenty-person business, and you don't pay as though you did.

A Clear Path Upward

Each tier builds on the one below it, so the next step is a continuation rather than a project started from scratch.

Tender-Ready Evidence

The evidence file is assembled so it can be attached straight to vendor portals and buyer security questionnaires.

Essential Eight Overlap

Most of the uplift work also raises your Essential Eight position, so one engagement answers two separate demands.

A Foundation Toward ISO 27001

If you do eventually need ISO 27001, the upper-tier SMB1001 work is the starting point rather than wasted effort.

The Problem

Challenges We Solve

The situations that bring organisations to this engagement in the first place.

ISO 27001 is oversized for you

A client wants proof of your security, but building a full ISMS is out of proportion to the size, risk, and budget of the business.

Self-assessment no longer clears

The questionnaire you filled in yourself is increasingly being rejected. Buyers want a graded position somebody else has verified.

It isn't obvious which tier is enough

Bronze, Silver, Gold, Platinum, or Diamond — aim too low and you fail the requirement, aim too high and you have overspent.

Scope of Service

SMB1001 Readiness Scopes

Fixed-scope engagements, from setting the tier through to handing over the evidence file.

01

Tier Selection & Gap Analysis

Starting Point

Establish the tier your requirement demands, then map where you currently stand against it.

02

Bronze & Silver Control Uplift

Foundation Tiers

Close the foundational controls — MFA, patching, backups, access control — and document evidence for each.

03

Gold, Platinum & Diamond Readiness

Upper Tiers

The written policies, risk treatment, and operational discipline the upper tiers call for.

04

Evidence File Assembly

Deliverable

An evidence file ordered the way an assessor works through it, not a folder of screenshots.

Methodology

How the Engagement Runs

Four steps from the requirement that landed on your desk to an evidence file you can hand over.

01

Read the Requirement

We start from the document that triggered all of this — the buyer's questionnaire, the tender condition, or the insurer's form — and establish which tier is actually being asked for.

02

Map the Current Position

A gap analysis against the target tier, with findings scored and prioritised by their effect on whether you pass.

03

Close the Gaps

Hands-on implementation of the missing controls, worked through with your team or your IT provider, each mapped to its evidence.

04

Hand Over the File

The final evidence file is delivered in a form you can attach, along with the maintenance notes that stop the position drifting.

Deliverables

What You Receive

The artifacts that land in your hands at the end of the engagement.

01

Tier Recommendation

A written statement of the tier your requirement demands, and the reasoning behind it.

02

Gap Report

Every missing control, scored and prioritised by its effect on whether you pass.

03

Evidence File

Evidence ordered the way an assessor will work through it.

04

Maintenance Notes

What has to keep running for the position to hold until the next cycle.

FAQ

Frequently Asked Questions

Find Out Which Tier Your Requirement Actually Demands

Send us the questionnaire or tender condition you have been handed, and we will establish the right tier and a fixed price for reaching it.