a black and yellow background with a green stripe

ISO 27001 Certified

Security and compliance assured

SMB1001 - Gold

Blackbird IT is Gold

cert achievements

What is SMB1001

SMB1001 is a nationally recognised cyber security standard developed for Australian small and medium businesses.

Unlike enterprise frameworks that are expensive and overly complex for SMBs, SMB1001 is scaled to be practical, affordable, and achievable while still meeting the expectations of insurers, corporate supply chains, and government procurement.

Certification is issued by CyberCert, Australia's independent SMB1001 certification body, and is built around a tiered structure so businesses can start where they are and grow their maturity over time.

Getting certified isn't just a compliance exercise. It's proof to your customers, partners, and insurers that you take cyber security seriously.

the result?

  • Issued by CyberCert
  • Proof for your Customers
  • Demonstrated experience and trust

Why Smb1001 matters

Our managed IT and security services are designed to identify risks early, act fast when it matters, and keep improving over time.

win more work

Many corporate and government tenders now require proof of cyber security controls before you can even bid

reduce insurance premiums

Insurers increasingly reward certified businesses with better terms

Build client trust

Show customers and partners you protect their data, not just your own

reduce real risk

The controls behind SMB1001 are the same fundamentals that stop the vast majority of real-world cyber incidents

Future proof your business

As supply-chain security requirements tighten across every industry, certification puts you ahead of the curve

Big cybersecurity frameworks can be a lot for smaller businesses to handle. SMB1001 is different, it's built for Australian SMBs, with their real limitations in mind: smaller budgets, fewer resources, less in-house expertise. It gives businesses a practical way to boost security without losing focus on running and growing the business.

the tiers that matter

SMB1001 is structured across four progressive levels, each adding further controls and maturity

  • Bronze - Foundational controls; passwords, backups, patching, and basic security hygiene
  • Silver - Stronger technical controls multi-factor authentication, endpoint protection, access management
  • Gold - Formalised governance — documented policies, incident response, and staff awareness
  • Platinum - Advanced maturity continuous monitoring, third-party risk management and ongoing assurance

Not sure which tier is right for you? We'll assess your current environment and recommend the level that matches your risk profile, industry, and business goals.

Know Exactly Where You Stand

SMB Secure workshop

Blackbird IT is an accredited SMB1001 service provider, offering hands-on advisory support from day one. Rather than a single point-in-time assessment, we work alongside you throughout your entire 12-month certification journey — helping you achieve and maintain Gold-level certification and stay there.

Our SMB Secure Workshop gives SMBs a practical, guided introduction to the SMB1001 standard, with the chance to ask questions in real time. Led by Blackbird IT's cybersecurity specialists, the workshop covers the key areas your business needs to address, and finishes with a tailored report outlining your next steps towards certification.

Getting SMB1001 certified is a structured process not a one-off audit. Here's how Blackbird IT takes you from where you are today to a certified, more secure business.

1. Discovery Call
We start with a short, no-obligation conversation to understand your business, your industry requirements, and why you're pursuing certification, whether that's a tender requirement, an insurer request, or simply strengthening your security.

2. Readiness Assessment
We conduct a structured assessment of your current environment against the SMB1001 controls  covering passwords, MFA, backups, patching, endpoint protection, policies, and more, and map exactly where the gaps sit relative to your target tier.

3. Gap Report & Roadmap
You receive a clear, plain-English report showing what's already in place, what's missing, and a prioritised roadmap to close the gaps — with fixed, transparent costs and timeframes.

4. Remediation
Our team implements the required technical controls and documentation, configuring MFA, hardening backups, deploying endpoint protection, and drafting the policies and procedures SMB1001 requires, with minimal disruption to your day-to-day operations.

5. Evidence & Certification
We compile and prepare the evidence required for certification and manage the submission process with CyberCert, so you're not left navigating the paperwork alone.

6. Certification Achieved
Once certified, you receive your SMB1001 certification, giving you a credential you can put in front of clients, insurers, and tender panels with confidence.

7. Ongoing Assurance
Cyber security isn't static, and neither is certification. We provide ongoing managed IT and security support to keep your controls current, so you stay certified and stay protected year-round.

Book My Assessment
FAQs

The Questions That Shape Better Decisions

1. How long does it take to get to at least silver

This depends on your starting point and target tier, but most Bronze and Silver certifications can be achieved within a few weeks once remediation work begins.

2. Do I need to already have good cyber security in place

Not at all, that's exactly what the readiness assessment and remediation phases are for. Most businesses start with gaps; that's normal.

3. Is smb1001 required for government tenders

Increasingly, yes. Many state and federal procurement panels now list SMB1001 (or equivalent) as a requirement or scoring criterion.

4. How much does it cost

Costs vary depending on your current environment and target tier. Book an assessment and we'll give you a clear, fixed quote.

5. how does smb1001 help reduce my risk of cyber breach?

SMB1001's controls target the security gaps most commonly exploited in real attacks through weak passwords, missing MFA, unpatched systems, and inadequate backups. By addressing these systematically, certified businesses are significantly better positioned to prevent, detect, and recover from a breach, rather than finding out the hard way.

Let's Work Together

Let's Work Together

Let's Work Together

Let's Work Together