SMB1001:2026 is the most significant update to Australia's only purpose-built SMB cybersecurity certification standard, and it arrives at a moment when security requirements are moving through supply chains faster than most mid-market organisations have adapted. Released in September 2025 by Dynamic Standards International and certified through CyberCert, the 2026 edition strengthens email authentication requirements, increases mandatory controls at Gold, and introduces EDR and MDR as non-negotiable at certification level. Organisations with between 50 and 500 staff that are yet to formalise their security posture now have both a clear framework and an increasingly tangible reason to use it.

What SMB1001 Is and Why It Exists

Most cybersecurity frameworks were not built with mid-market organisations in mind. ISO 27001 demands significant documentation effort and ongoing audit investment. NIST CSF and similar frameworks reflect regulatory environments and risk appetites that do not map cleanly onto Australian mid-market operating conditions. The Essential Eight was designed for government and critical infrastructure contexts before it found wider adoption.

SMB1001 takes a different approach. Dynamic Standards International built the standard from the ground up for organisations that do not have a dedicated security team, cannot absorb the overhead of enterprise-grade compliance programmes, and need practical guidance rather than abstract frameworks. The first edition was released in 2023 and has been updated iteratively since. The 2026 edition reflects three years of real-world deployment across Australian SMBs and feedback from organisations that have used it.

The standard is structured across five control domains. Technology Management covers network security, patching, and endpoint controls. Access Management covers identity, authentication, and privilege. Backup and Recovery covers data protection and restoration capability. Policies and Processes covers governance, incident response, and vendor management. Education and Training covers staff awareness and security culture. Together, these domains give organisations a coherent view of their security programme rather than a fragmented list of technical tasks.

The Five Tiers - Bronze to Diamond

The tiered structure is what makes SMB1001 practical for organisations at different stages of security maturity. Each tier builds on the previous, so certification is achievable in stages rather than requiring a complete security transformation before any credit is earned. A Bronze-certified organisation that improves its posture can certify at Silver without starting over.

  • Bronze

    The entry-level certification, Bronze establishes baseline security hygiene. It requires foundational controls including basic access management, endpoint protection, patch management, and a documented password policy. Suited to organisations starting their security formalisation or needing a credible minimum baseline for procurement purposes.

  • Silver

    Building on Bronze, Silver introduces mandatory email authentication with SPF required at this tier. Silver also requires more formalised backup procedures, documented incident response capability, and structured staff security awareness activities. Appropriate for organisations with some existing security investment seeking formal recognition of their posture.

  • Gold

    Gold represents a substantive shift in security maturity. In the 2026 edition, mandatory controls at Gold increase from 23 to 27. EDR and MDR become mandatory, and DKIM with DMARC policy set to p=reject or p=quarantine is required. The target tier for most mid-market organisations handling sensitive client data, regulated information, or operating in government or enterprise supply chains.

  • Platinum

    Platinum extends Gold with stronger controls across all five domains, including more prescriptive requirements around vulnerability management, vendor security assessment, and security testing. Suited to organisations that have achieved Gold and are progressing toward more comprehensive security programme maturity.

  • Diamond

    The highest tier, Diamond aligns closely with the controls and assurance expectations of ISO 27001 and similar enterprise frameworks. Designed for organisations operating in high-risk environments, handling significant volumes of sensitive data, or needing to demonstrate security maturity equivalent to larger enterprise peers for procurement or regulatory purposes.

What Changed in SMB1001:2026

The 2026 edition is not a cosmetic update. The changes are targeted at the attack patterns causing the most measurable harm to Australian SMBs right now. The primary driver is business email compromise, which the ACSC 2024-2025 Annual Cyber Threat Report identifies as costing Australian small businesses an average of $56,000 AUD per incident. The update also reflects the reality that threat actors increasingly target endpoint weaknesses at organisations that lack the detection capability to identify intrusions before they escalate.

Business email compromise costs

BEC attacks cost Australian small businesses an average of $56,000 AUD per incident according to the ACSC 2024-2025 Annual Cyber Threat Report. The 2026 edition addresses this directly by requiring SPF at Silver and DKIM with DMARC policy set to p=reject or p=quarantine at Gold and above. Without these controls, spoofed sender addresses remain trivially easy to forge.

Endpoint detection gaps at scale

Attackers who gain a foothold on an endpoint in an organisation without detection capability can operate undetected for days or weeks before causing measurable damage. The 2026 edition makes EDR and MDR mandatory at Gold, changing endpoint detection from a recommended control to a certification requirement.

Weak or inconsistent MFA

Credential compromise remains one of the most common initial access vectors for ransomware and data breach incidents across the mid-market. The 2026 edition tightens MFA requirements across tiers, closing gaps that allowed organisations to claim compliance while relying on authentication mechanisms that offer limited real-world protection.

Mandatory control coverage gaps

Gold-level mandatory controls increase from 23 to 27 in the 2026 edition. The additional controls close previously optional areas that field deployment experience identified as consistently contributing to successful compromises at organisations operating at this tier.

Multi-framework procurement demands

Government and enterprise procurement increasingly requires organisations to demonstrate alignment with multiple frameworks simultaneously. The 2026 edition strengthens alignment with ISO 27001, UK Cyber Essentials, and US CMMC, meaning a single SMB1001 certification can now serve as evidence of alignment across multiple procurement requirements.

SMB1001 and the Essential Eight — Complementary, Not Competing

The question of whether to pursue SMB1001 or the Essential Eight comes up regularly, and it frames the choice as a false one. These frameworks address different aspects of an organisation's security programme. The evidence from organisations that have engaged with both is that they reinforce each other rather than duplicate effort.

The Essential Eight is a set of eight mitigation strategies developed by the Australian Signals Directorate. It focuses almost entirely on technical controls: application control, patching, restricting macros, user application hardening, restricting admin privileges, patching operating systems, multi-factor authentication, and regular backups. The maturity model runs from ML1 to ML3. It does not address governance, policy documentation, staff training, or vendor management in any substantive way. It was built to reduce the technical attack surface.

SMB1001 wraps those technical controls in the governance and process layer that turns individual controls into a programme. An organisation that achieves Essential Eight ML2 but has no documented incident response plan, no security awareness training, and no vendor security requirements has a partial security programme. SMB1001 addresses those gaps. Conversely, an organisation working toward SMB1001 Gold will find that many Essential Eight controls already satisfy or partially satisfy SMB1001 requirements, because the frameworks reference similar technical baselines.

For mid-market organisations, the practical approach is to treat the Essential Eight assessment as input to the SMB1001 certification pathway rather than a separate objective. Fortura's Essential Eight Maturity Assessment establishes where an organisation sits against each mitigation strategy and maps that position to the SMB1001 control domains, giving security leaders a unified view rather than two separate gap analyses.

Who Needs to Pay Attention Right Now

The compliance driver for SMB1001 has shifted in the past 12 months. Early adoption was largely voluntary, driven by organisations that recognised the framework's practical value. That picture is changing. Security requirements are flowing down supply chains at pace, and organisations that have not formalised their posture are finding that their lack of certification creates commercial friction.

Government supply chain requirements

Federal and state government agencies are increasingly requiring evidence of security maturity from suppliers and service providers. SMB1001 certification provides a recognised, locally relevant credential that satisfies these requirements without the cost and complexity of an ISO 27001 or SOC 2 programme.

Enterprise procurement gates

Large enterprise customers are passing security requirements to their supplier base through procurement questionnaires, contract conditions, and vendor risk assessments. Organisations that cannot demonstrate structured security maturity are losing commercial opportunities to competitors who can.

Cyber insurance requirements

Insurers are tightening underwriting requirements across the SMB market. Structured evidence of security maturity, including certification against a recognised standard, is increasingly required for coverage at commercially viable premiums. Unstructured responses to insurance questionnaires are no longer sufficient.

Privacy Act accountability obligations

The Privacy Act review reforms increase accountability obligations for organisations handling personal information. Demonstrating documented controls across technology, access, backup, policy, and training directly addresses the kind of evidence regulators and courts expect in the event of a notifiable data breach.

How Fortura Can Help

The starting point for most organisations is understanding where they actually sit before deciding which tier to target. Many organisations overestimate their current posture and underestimate the gaps. Others have strong technical controls in place but lack the governance documentation that certification requires. A structured gap assessment against the SMB1001 control framework identifies both conditions. Fortura's Cyber Risk Assessments map an organisation's current security posture against the SMB1001 control domains, identifies which tier is realistically achievable in the near term, and produces a prioritised remediation roadmap that teams can act on without waiting for a certification programme to be formally scoped.

For organisations targeting Platinum or Diamond, or those with existing ISO 27001 aspirations, the path to SMB1001 and ISO 27001 can be planned as a single programme rather than two separate projects. The alignment between the two standards at the upper tiers means that documentation, control evidence, and governance structures built for one satisfy significant portions of the other. Fortura's ISO 27001 Readiness and Assessment service supports organisations that want to use SMB1001 as a structured stepping stone toward full ISO 27001 certification, avoiding the duplication of effort that comes from running parallel workstreams.

Fortura has worked across sectors including healthcare, professional services, SaaS, and NFP organisations of the size that SMB1001 was built for. The advisory practice is grounded in technical and governance experience across regulated environments, which means the guidance organisations receive reflects how these controls operate in practice rather than how they appear on a compliance checklist.

SMB1001:2026 is a mature, practical standard that reflects the threat environment Australian mid-market organisations are navigating today. The certification pathway is achievable without the overhead that enterprise frameworks demand, and the 2026 update strengthens it at precisely the points where the risk is highest. The question for most organisations is no longer whether to engage with it, but how to sequence the work effectively.