SMB1001 Gold, Tier 3
SMB1001 Gold Certification: Enterprise-Grade Security for Growing Organizations.
Self-attested by a company director. Gold needs no external assessor.
Organizations managing sensitive data, taking part in regulated supply chains or facing higher client expectations, such as finance, healthcare, technology and government suppliers.
Overview
What Gold Is For.
Gold builds on Bronze and Silver with mature governance, detection and response, and strategic oversight: a comprehensive set of defenses comparable to what large enterprises use, sized for a small or mid-sized business and delivered as a managed service.
In the 2026 edition, Gold adds endpoint detection and response, an AI usage policy and holding business or cyber insurance, alongside the cybersecurity policy and incident response plan.
What Gold Adds
10 REQUIREMENTSPlus every requirement of Bronze, Silver, for 27 in total. Requirement titles are CyberCert's own, from its published SMB1001:2026 matrix.
How We Put It in Place
6 PARTS24/7 SOC Monitoring and Detection
A managed SIEM and MDR service watching logs across cloud, network and endpoints.
Virtual CISO and Governance
A vCISO who develops the governance framework and incident response plan.
Endpoint, Network and Cloud Protection
EDR on every device, MFA on admin consoles and business applications, secure remote access.
Asset and Disposal Management
An up-to-date digital asset register and secure device and document disposal.
Security Awareness and Culture
Ongoing training and phishing simulations.
Incident Response and Resilience
A formal response plan, tested backups and validated recovery procedures.
Considering a Different Tier?
Talk Through Gold in 30 Minutes.
Pick a time. We will help you choose the right tier for your risk, growth and budget.
Looking for CMMC? Our Compliance Division, Capital Cyber Compliance, delivers it.
