CyberCert SMB1001
CyberCert SMB1001 Certification, From Bronze to Diamond.
SMB1001 is a cybersecurity certification standard built for small and medium businesses. We put each tier's controls in place, run them, and keep the evidence behind the director's attestation.
For businesses that want independent, verifiable proof that their security is real, for clients, partners and insurers.
Why Certify
Proof You Are Serious About Cybersecurity.
Certification gives clients, partners and insurers external assurance that you meet a recognized standard, and a publicly accessible record of your commitment to managing cyber risk. Every tier is attested by a company director, whose name is on the certificate.
The tiers are cumulative, so a business can start where its risk calls for and move up. Bronze, Silver and Gold are self-attested; Platinum and Diamond add an external audit.
The Five Tiers
SMB1001:2026Bronze, Level 1
Cybersecurity Essentials for Emerging Businesses. Businesses starting their security program, with a low risk profile and no in-house IT staff.
Silver, Level 2
Advanced Cyber Defense for Growing Organizations. Businesses that have outgrown the basics, such as professional service firms, healthcare clinics and retailers expanding online.
Gold, Level 3
Enterprise-Grade Security for Growing Organizations. Organizations managing sensitive data, taking part in regulated supply chains or facing higher client expectations, such as finance, healthcare, technology and government suppliers.
Platinum, Level 4
Proactive Security and Assurance. Organizations that handle critical assets, operate in highly regulated sectors or supply enterprise clients with little tolerance for risk.
Diamond, Level 5
Ultimate Cyber Resilience. The most security-mature organizations: those that cannot afford a breach, lead their supply chains or need the strongest trust signal.
How We Work
The Controls Run by Your MSP, Not Just Written Down.
Each tier's requirements map onto our managed IT and managed security: patching, backups, MFA, EDR, monitoring, policies and training. We help you choose the right tier for your risk profile, growth and budget, put the controls in place, and keep them running for the next renewal.
Frequently Asked Questions
5 QUESTIONSWhat is SMB1001?
SMB1001 is a cybersecurity certification standard for small and medium businesses, published by Dynamic Standards International and certified through CyberCert. It has five cumulative tiers, Bronze through Diamond.
Which edition do these pages describe?
The current SMB1001:2026 edition. Requirement titles and counts come from CyberCert's own published requirement matrix: 7 for Bronze, 17 for Silver, 27 for Gold, 32 for Platinum and 39 for Diamond.
Who signs the certification?
Every tier carries an attestation by a company director, whose name is on the certificate. Bronze, Silver and Gold are self-attested; Platinum and Diamond add an external audit.
Is SMB1001 the same as CMMC?
No. SMB1001 is a general standard for small and medium businesses. CMMC is the Department of Defense requirement for contractors that handle FCI or CUI, delivered by our Compliance Division, Capital Cyber Compliance. The two are separate engagements.
Which tier should we start with?
It depends on your risk profile, growth and budget. Many businesses start at Bronze or Silver and move up. We help you choose on a call.
Choose Your Tier in 30 Minutes.
Pick a time. Tell us who is asking for proof of your security.
Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.

