SMB1001 is a simple, affordable way for New Zealand small businesses to get certified in cybersecurity and show clients, insurers, and government that you're protected.
Not sure what SMB1001 Certification is or where to start? Join our free online webinar where we walk you through everything in plain English.
Date & Time | Thursday, 7 May @ 1:30pm NZDT
Duration | 45 mins + Q&A
Location | Microsoft Teams
SMB1001 is a simple, affordable way for New Zealand small businesses to get certified in cybersecurity and show clients, insurers, and government that you're protected.
Not sure what SMB1001 Certification is or where to start? Join our free online webinar where we walk you through everything in plain English.
Date & Time | Thursday, 7 May @ 1:30pm NZDT
Duration | 45 mins + Q&A
Location | Microsoft Teams
Most cyber security certifications - like ISO 27001 - were designed for large companies with dedicated IT teams and big budgets. They're complex, expensive, and could take months or even years to complete, and take a significant ongoing commitment to maintain..
It has five levels, starting at just $95 NZD. You start at the level that suits your business today, and work your way up over time - like belt levels in martial arts.
The standard is reviewed and updated every year by a panel of experts - including the Australian Signals Directorate (ASD), Telstra, Deloitte, and BDO - so it always reflects the latest threats.
Once certified, you get a digital badge you can share with clients,
display on your website, and use when applying for government contracts or cyber insurance.
Enterprise frameworks like ISO 27001 require dedicated security staff, large budgets, and months of work. Most small businesses simply can't do it - and until now, there was no real alternative.
Start at your current level, at a price that makes sense. Get certified in weeks, not years. Then grow your certification as your business grows.
SMB1001 aligns with Australia's Essential Eight, UK Cyber Essentials, Singapore's Cyber Essentials, and more - one certification covers multiple requirements at once.

Level 1
$95
Self-attested
Great starting point for micro and small businesses. Covers the basics that every business should have.

Level 2
$195
Self-attested
A step up from Bronze. Shows clients and partners that you take cyber security seriously.

Level 3
$395
Self-attested
Ideal for small-to-medium businesses with supply chain requirements or clients who ask about cyber security.

Level 4
$595
Self-attested + external audit
For businesses working with enterprise clients or government. Independently verified for extra credibility.
+ $3,000 audit fee

Level 5
$995
Self-attested + external audit
The highest level - enterprise-grade assurance for medium and large businesses with the most demanding requirements.
+ $5,000 audit fee

Here's what that looks like from start to finish.
Book a call with our team to find out which SMB1001 certification level is right for your business. Once we've had that conversation, we'll onboard you into the official CyberCert portal and support you through every step of the process - from where you are today to the level you're working toward.
Using the CyberCert Dashboard, you complete a self-assessment that compares your current setup against the requirements for your chosen level. It flags exactly what's already covered and what needs attention - no guesswork, no external consultant required. You can also bring in your MSP or a third party to help if needed.
We help you implement the security controls you're missing. We keep it practical and cost-effective - only what's needed to reach your certification level.
Before submitting for certification, we verify that all the required controls are properly in place. This avoids nasty surprises and keeps the process moving smoothly.
Once everything checks out, your certification is issued. You'll get a digital badge and certificate you can share with clients, display on your website, and use for insurance or procurement.
Certification needs to be renewed each year (the standard is updated annually). We manage your renewal, keep you on track, and help you move to a higher level when you're ready.

Complete IT support & Solutions tailored for your Business
As an official CyberCert partner, we guide businesses through the entire SMB1001 process - from the first conversation to certified and beyond. No tech jargon, no unnecessary complexity, just a clear path to getting it done.
No vague recommendations. We assess your current setup and give you a specific, prioritised action list - so you only do what's actually required.
From choosing the right tools to getting them set up properly, we do the technical work. You stay focused on running your business.
Certification needs renewing every year. We manage that for you, alert you before things expire, and help you level up when the time is right.
Through the CyberCert partner dashboard, you get full visibility into your certification status and compliance at any time.
Talk to one of our team. We'll look at your current setup, recommend the right certification level, and walk you through exactly what's involved - no cost, no obligation.
Join the CloudTorque team for a straightforward, no-jargon walkthrough of SMB1001. We'll cover what the certification means in practice, which level might suit your business, what it costs, and how it can help you win more work, qualify for insurance, and meet client expectations.
Date & Time | Thursday, 7 May @ 1:30pm NZDT
Duration | 45 mins + Q&A
Location | Microsoft Teams
Can't make it live? Register and we'll send you the recording.

SMB1001 is a cyber security certification standard created for small and medium businesses. It was developed by Dynamic Standards International (DSI), and CyberCert is the official platform for getting certified. It has five levels, is updated every year, and gives your business a recognised, verifiable way to show that you take cyber security seriously.
It depends on your starting point and which level you're going for. Bronze and Silver can often be wrapped up in a matter of days if your basics are already in order. Gold typically takes two to four weeks. Platinum and Diamond involve an external audit, so allow around four to eight weeks from start to finish.
Yes, SMB1001 is renewed annually. This is actually one of the things that makes it valuable. The standard gets updated each year to reflect current threats, so your certification always means something current. CloudTorque can help manage your renewal so you don't have to think about it.
Bronze, Silver, and Gold are self-attested - you confirm that you've implemented the required controls through the CyberCert platform. Platinum and Diamond go a step further and require an independent external audit. This gives the highest level of confidence and credibility, which is why larger or more regulated businesses tend to go for these tiers.
You can absolutely self-certify at Bronze through Gold. But most businesses find the process quicker and less stressful with support. We remove the guesswork, make sure nothing gets missed, handle the technical side, and manage your ongoing compliance - so you can focus on running your business rather than worrying about cyber security paperwork.
Generally speaking: Bronze or Silver is a great starting point for micro and small businesses. Gold suits businesses that are asked about cyber security by clients or have supply chain requirements. Platinum and Diamond are for businesses dealing with enterprise clients, government contracts, or specific regulatory obligations. Not sure? Book a free consultation and we'll figure it out with you.
SMB1001 is aligned with internationally recognised frameworks, including ISO/IEC 27001, and provides a practical pathway toward ISO 27001–level maturity. This makes it valuable for businesses serving international clients or operating in global supply chains.
All industries benefit, but it’s particularly valuable for professional services, healthcare, finance, education, manufacturing, and any business handling sensitive customer data or working with larger organisations.
Yes. Many SMB1001 controls align with Privacy Act requirements, PCI DSS (for businesses handling payment cards), and industry-specific standards. We’ll identify how certification supports your broader compliance obligations.
© 2026 CloudTorque Global - All Rights Reserved.