SMB1001 is a cyber security standard built specifically for small and medium businesses. Instead of one all-or-nothing bar, it uses five progressive tiers, so you can reach a recognised, demonstrable level of cyber maturity quickly and affordably, then climb higher as your needs grow. This breakdown explains each tier and the risk of stopping short. For a shorter overview, see our SMB1001 guide.
How to read this breakdown:
In black — what the tier covers, in plain summary.
In blue — what it actually means for your business.
In red — the risk of stopping short.
Bronze
What the tier covers: Fundamental controls — engaging technical support, firewalls and antivirus, automatic updates, routine password changes, and regular data backups. Self-assessed and low-cost.
What it means: The essential basics every business should have in place. You can typically reach this quickly without external help.
Risk of stopping short: Without even these fundamentals you’re exposed to the most common, opportunistic attacks — the ones that hit unprepared businesses every day.
Silver
What the tier covers: Stronger controls and documented processes, building on Bronze. Still self-assessed.
What it means: You start writing down how security is actually done and add measures like MFA and staff awareness, so controls are consistent.
Risk of stopping short: Without documented, repeatable processes, controls quietly slip as staff, tools and suppliers change — and no one notices until something breaks.
Gold
What the tier covers: Formal security policies and monitoring, verified by an external audit.
What it means: An independent assessor confirms your controls — a credible signal you can show customers and partners.
Risk of stopping short: Self-claims that aren’t independently audited carry little weight in tenders and supply-chain checks, and real gaps go unchallenged.
Platinum
What the tier covers: Advanced governance and vulnerability management, assessed by a third party.
What it means: Suited to businesses with significant client-data or supply-chain obligations that need stronger, proactive governance.
Risk of stopping short: Handling sensitive data or critical supply-chain roles without this level of governance leaves systemic weaknesses unmanaged.
Diamond
What the tier covers: The highest tier — cyber governance comparable to a mature large-enterprise security program.
What it means: Reserved for organisations operating at the highest stakes, where security is core to the business.
Risk of stopping short: For high-stakes operators, anything less may simply not meet client, regulatory or contractual expectations.
Choosing a tier
Most small businesses start at Bronze or Silver, which are self-assessed and affordable, then move up to Gold and beyond — which require external audit — as customer and supply-chain expectations grow. The tiered model means you get recognised credit for progress at every stage, rather than waiting until you can meet a single high bar.
See which controls you already have in place — free, in about five minutes.