SMB1001 Certification NZ: What It Is and Why It Matters
SMB1001 is the cyber security certification built for small businesses. What each tier covers, how certification works, and why customers now ask for it.
Somewhere in the last twelve months, the question changed.
It used to be “do you guys have antivirus?” Now it’s a procurement form with thirty questions on it, sent by your biggest customer, asking how you store their data, who has access to it, what happens if you get breached, and whether you can prove any of it.
Most New Zealand businesses can’t. Not because they’re careless; because nobody has ever asked them to produce evidence before, so nothing was ever written down.
SMB1001 fixes that specific problem.
What SMB1001 actually is
SMB1001 is a tiered cyber security certification standard built for small and medium businesses. It was developed by Dynamic Standards International and is certified through the CyberCert platform, with five levels: Bronze, Silver, Gold, Platinum and Diamond. Each tier is cumulative, so Silver includes everything in Bronze, Gold includes everything in Silver, and so on.
It exists because ISO 27001 doesn’t fit. ISO assumes you have a compliance function, an internal auditor and a budget to match. A twenty person engineering firm has none of those, and it still has customer data worth protecting. SMB1001 asks for concrete controls instead of a management system, and it’s revised every year, so the requirements track current threats rather than a snapshot from three years ago.
| Tier | Level | Requirements | Assurance |
|---|---|---|---|
| Bronze | 1 | 7 | Director attested |
| Silver | 2 | 17 | Director attested |
| Gold | 3 | 27 | Director attested |
| Platinum | 4 | 32 | Independently audited |
| Diamond | 5 | 39 | Independently audited |
Bronze covers the foundations: a firewall, antivirus on every device, patching, password hygiene, backups, and security awareness training for staff. Silver adds identity and access controls; individual user accounts, a password manager, MFA (multifactor authentication) on email, email authentication to stop people spoofing your domain, and confidentiality agreements. Gold is where it gets serious: endpoint detection and response, MFA across your business applications, an incident response plan, cyber insurance, a digital asset register, and a policy for responsible AI use.
At Bronze, Silver and Gold, a company director signs off through the CyberCert portal that the controls are in place. That’s not a loophole; it’s a director putting their name to a statement of fact. Platinum and Diamond require an external audit by an independent verification organisation, on top of the annual licence.
Why this is landing now in New Zealand
Three things have converged.
The threat is no longer theoretical for small businesses. NCSC research found that 53% of New Zealand small to medium businesses experienced a cyber threat in the past six months, up sharply from 36% the year before. The same research found 94% of small businesses recognise cyber security is important, but many believe they’re already doing enough. That gap between confidence and evidence is where the damage happens. The NCSC’s own 2025 Cyber Threat Report puts it plainly, saying too many organisations assume they are “not big enough, not wealthy enough or not critical enough to be a target”.
Your customers are being told to check on you. One of the NCSC’s five key judgements for 2025 is that threat actors are exploiting supply chains and hidden dependencies. Large organisations have read that. Their response is to push the question down the chain, which means your customer’s risk team is now asking about you. If you supply into government, healthcare, financial services, construction or anyone with a real procurement function, this is already happening.
The Privacy Act has teeth and it just grew a new one. Under the Privacy Act 2020, if a breach causes or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected people; failing to do so without reasonable excuse is an offence carrying a fine of up to $10,000. And from 1 May 2026, the new information privacy principle IPP 3A requires you to notify people when you collect their personal information indirectly, from any source. The fine is not the real cost. The real cost is the phone call to your largest client explaining that their data was in the system that got hit.
Then there’s insurance. Underwriters have stopped taking your word for it; MFA, endpoint detection and response, tested backups and a documented incident response plan are now the baseline questions on a proposal form. Every one of those is an SMB1001 control.
The part most businesses miss: this is a sales asset
Here’s where certification stops being a cost and starts paying for itself.
Most businesses treat cyber security as something they do quietly, in the background, and never mention to a customer. That’s a waste. Your customers have their own customers, their own boards, their own privacy obligations. When they hand you their data, they’re extending their trust to you and hoping it holds.
A certificate lets you say something specific instead of something vague:
- In a tender or supplier questionnaire, answer with a certificate number rather than a paragraph of reassurance
- In a proposal, put the badge next to your pricing; you’re now the supplier that made the risk question easy
- In your onboarding pack, tell new clients exactly how their data is handled and what standard you’re certified against
- At renewal time with your insurer, hand over evidence instead of an opinion
- In a client newsletter or on LinkedIn, announce the certification; it’s one of the few security messages a non technical audience actually understands
We’ve watched clients win work off the back of this. Not because the competitor was insecure, but because the competitor couldn’t prove it quickly and the deadline didn’t wait.
Which tier is right for you?
Start with what your customers and your insurer are asking for, not with ambition.
- Bronze suits a small team getting the fundamentals in place and wanting a starting point they can build on
- Silver is the sensible floor for any business holding customer data; identity controls are where most real attacks are stopped
- Gold is where most New Zealand businesses with serious supplier obligations land, because it’s the first tier covering EDR, formal policies, incident response and insurance; it’s also the tier that satisfies most underwriters and procurement teams
- Platinum and Diamond suit businesses in regulated supply chains or those working toward ISO 27001, where independent audit is the point
You don’t have to climb one rung at a time. If Gold is what your market expects, scope to Gold.
What getting certified actually involves
The licence is the cheap part. The work is closing the gaps between what you’re doing and what you can evidence, and for most businesses that gap is smaller than they fear. If you already have managed IT with MFA, patching, backups and endpoint protection in place, you may be most of the way to Silver or Gold without knowing it.
Our process is deliberately unglamorous:
- Assessment. We work through the SMB1001 controls with you and mark each one in place, partly in place, or not yet. Most of the value shows up here; “we do it but can’t prove it” is the fastest thing in the world to fix.
- Gap plan. You get a clear picture of what each tier would take, so you can choose the level on commercial grounds rather than guesswork.
- Remediation. We close the technical gaps and write the policies; the ones SMB1001 requires, plus the ones your insurer and the Privacy Act expect.
- Certification. Your director attests through CyberCert and the certificate is issued.
- Maintenance. Certificates run for twelve months and the standard updates annually, so we keep the evidence current rather than rebuilding it in a panic each year.
One honest warning. A director signs this personally. If the controls aren’t really there, the certificate isn’t protection; it’s a written record of a claim you couldn’t back up. Do it properly or don’t do it.
If you sit on a board and want the wider picture of what directors are accountable for, our cyber security guide for directors covers it.
Frequently asked questions
What is SMB1001 certification? SMB1001 is a tiered cyber security certification standard designed for small and medium businesses, developed by Dynamic Standards International and certified through CyberCert. It has five levels, Bronze to Diamond, each building on the one before.
How much does SMB1001 cost in New Zealand? Certification is an annual licence through CyberCert, priced by tier. Platinum and Diamond also require an independent audit. Get in touch for current pricing. The larger investment is usually the work to close control gaps, which depends on your current setup.
Is SMB1001 recognised in New Zealand? Yes. New Zealand businesses certify through the same CyberCert platform used across the Tasman, and nothing in the standard depends on Australian law. It’s increasingly recognised by insurers and procurement teams on both sides.
How is SMB1001 different from ISO 27001? ISO 27001 requires a full information security management system and an external audit, which suits larger organisations with dedicated compliance staff. SMB1001 asks for specific, practical controls at a level that a business of five to two hundred people can genuinely reach, and the higher tiers make a good stepping stone if ISO is your long term goal.
How long does certification take? If your fundamentals are already in place, Bronze or Silver can be done in a matter of weeks. Gold typically takes longer where EDR, full MFA coverage, email authentication and formal policies still need deploying. The assessment tells you which one you’re dealing with.
Ready to find out where you stand?
You don’t need to commit to a tier to get value from this. Start with the assessment; we’ll show you exactly which SMB1001 controls you already meet, which ones you’re doing but can’t evidence, and what each level would take from here.
iT360 is an authorised CyberCert partner, and we take New Zealand businesses through SMB1001 certification end to end; assessment, remediation, policies, certification and annual maintenance. It sits inside our cyber security services alongside the monitoring, protection and training that keep the controls real once the certificate is on the wall.
Book a free consultation and we’ll map your environment against the standard, then give you a straight answer on the right tier for your business.