Managed IT and Managed Security · Leesburg, VA

CyberCert SMB1001

CyberCert SMB1001 Certification, From Bronze to Diamond.

SMB1001 is a cybersecurity certification standard built for small and medium businesses. We put each tier's controls in place, run them, and keep the evidence behind the director's attestation.

For businesses that want independent, verifiable proof that their security is real, for clients, partners and insurers.

CyberCert SMB1001 Gold certified, Level 3

Our Own Certificate

We Hold Gold Ourselves.

Capital Cyber holds CyberCert SMB1001:2026 Gold, Level 3, issued by CyberCert under Dynamic Standards International. The certificate holder is Telco D1 LLC, trading as Capital Cyber.

Certificate ID 0126300000874132022Z. Issued March 11, 2026. Expires March 12, 2027.

The five SMB1001:2026 tiers and how many requirements each holdsFive steps rising left to right. Bronze, level 1, 7 requirements. Silver, level 2, 17. Gold, level 3, 27. Platinum, level 4, 32. Diamond, level 5, 39. Tiers are cumulative. Bronze to Gold are attested by a company director; Platinum and Diamond add an external audit.SMB1001:2026, FIVE TIERS, CUMULATIVEBronze7 REQSL1Silver17 REQSL2Gold27 REQSL3Platinum32 REQSL4Diamond39 REQSL5Levels 1 to 3: director attestedLevels 4 and 5: plus an external audit

Why Certify

Proof You Are Serious About Cybersecurity.

Certification gives clients, partners and insurers external assurance that you meet a recognized standard, and a publicly accessible record of your commitment to managing cyber risk. Every tier is attested by a company director, whose name is on the certificate.

The tiers are cumulative, so a business can start where its risk calls for and move up. Bronze, Silver and Gold are self-attested; Platinum and Diamond add an external audit.

The Five Tiers

SMB1001:2026

Bronze, Level 1

Cybersecurity Essentials for Emerging Businesses. Businesses starting their security program, with a low risk profile and no in-house IT staff.

7 REQUIREMENTS · SELF-ATTESTED

Silver, Level 2

Advanced Cyber Defense for Growing Organizations. Businesses that have outgrown the basics, such as professional service firms, healthcare clinics and retailers expanding online.

17 REQUIREMENTS · SELF-ATTESTED

Gold, Level 3

Enterprise-Grade Security for Growing Organizations. Organizations managing sensitive data, taking part in regulated supply chains or facing higher client expectations, such as finance, healthcare, technology and government suppliers.

27 REQUIREMENTS · SELF-ATTESTED

Platinum, Level 4

Proactive Security and Assurance. Organizations that handle critical assets, operate in highly regulated sectors or supply enterprise clients with little tolerance for risk.

32 REQUIREMENTS · EXTERNALLY AUDITED

Diamond, Level 5

Ultimate Cyber Resilience. The most security-mature organizations: those that cannot afford a breach, lead their supply chains or need the strongest trust signal.

39 REQUIREMENTS · EXTERNALLY AUDITED

How We Work

The Controls Run by Your MSP, Not Just Written Down.

Each tier's requirements map onto our managed IT and managed security: patching, backups, MFA, EDR, monitoring, policies and training. We help you choose the right tier for your risk profile, growth and budget, put the controls in place, and keep them running for the next renewal.

Frequently Asked Questions

5 QUESTIONS
What is SMB1001?

SMB1001 is a cybersecurity certification standard for small and medium businesses, published by Dynamic Standards International and certified through CyberCert. It has five cumulative tiers, Bronze through Diamond.

Which edition do these pages describe?

The current SMB1001:2026 edition. Requirement titles and counts come from CyberCert's own published requirement matrix: 7 for Bronze, 17 for Silver, 27 for Gold, 32 for Platinum and 39 for Diamond.

Who signs the certification?

Every tier carries an attestation by a company director, whose name is on the certificate. Bronze, Silver and Gold are self-attested; Platinum and Diamond add an external audit.

Is SMB1001 the same as CMMC?

No. SMB1001 is a general standard for small and medium businesses. CMMC is the Department of Defense requirement for contractors that handle FCI or CUI, delivered by our Compliance Division, Capital Cyber Compliance. The two are separate engagements.

Which tier should we start with?

It depends on your risk profile, growth and budget. Many businesses start at Bronze or Silver and move up. We help you choose on a call.

Choose Your Tier in 30 Minutes.

Pick a time. Tell us who is asking for proof of your security.

Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

Book a 30-Minute Call