SMB1001 Gold for NZ SMBs: What It Is & How to Pass

Posted: July 30, 2026Category:

Your insurer just asked for evidence your business is cyber-safe. Now what?

That question is landing in Kiwi inboxes every week. The insurer wants proof — not promises — that you’ve done the sensible things: MFA on everything, backups you’ve actually tested, a plan for when someone clicks the wrong link. And the answer they’re increasingly happy with is one word.

SMB1001.

SMB1001 is the cyber security certification standard purpose-built for small and medium businesses in Australia & New Zealand. It’s the answer to “how do we prove we’re secure without spending ISO 27001 money?” Gold — Level 3 — is the certification most NZ businesses land on, and it’s what IT Live carries ourselves. Here’s what it is, what the 27 Gold controls actually mean in plain English, what it costs, and how an NZ business gets there.

What SMB1001 actually is

SMB1001 is a five-level cyber security certification standard developed by Dynamic Standards International (DSI). Each level layers more controls on top of the last:

  • Bronze — the essentials. The stuff every business should already do.
  • Silver — adds documented processes and evidence.
  • Gold (Level 3) — 27 controls covering technology, processes, people & insurance. This is the sweet spot for most NZ SMBs.
  • Platinum — Gold + enhanced governance for larger or regulated organisations.
  • Diamond — the top tier, close to ISO 27001 territory.

The current edition — SMB1001:2026 — has been certifiable since January 2026. Certification is independently assessed by a licensed assessor (that’s us for the New Zealand market), then verified and issued by DSI.

Why NZ businesses care in 2026

Three things changed this year:

1. Cyber insurers are asking

NZ underwriters now want documented evidence of multi-factor authentication (MFA), an incident response plan, and alignment with a recognised security framework — before they’ll grant cover. Policies over $1M in cover typically require Bronze at minimum. Higher limits push you into Silver or Gold territory. Early NZ market data suggests certified businesses are seeing premium reductions in the 5–25% range.

2. Big customers are asking

Council contracts, government tenders, larger head-contractors — the pattern is the same. “Are you certified?” now sits on the pre-qualification form. Not being able to answer it costs you the work.

3. Your supply chain is asking

If you handle client data, hold IP, or process payments, the businesses upstream and downstream from you have started asking about YOUR security. SMB1001 is the answer that fits on one line.

The 27 Gold controls, in plain English

Here’s how the 27 controls break down. Don’t be intimidated by the count — most well-run businesses already have half of them. The certification is about proving it and closing the gaps on the rest.

Identity & access (5 controls)

  • MFA on every account. Every account.
  • Password manager rolled out to the team.
  • Sensible password policy — no forced monthly changes, no reuse of last passwords.
  • Named accounts only — no shared logins.
  • Admin rights kept away from daily user accounts.

Device & network (7 controls)

  • Automatic patching on every device.
  • Managed endpoint detection & response (EDR) — not just the free antivirus.
  • Full-disk encryption (BitLocker on Windows, FileVault on Mac).
  • Tamper protection on your security tools.
  • Firewall configured at each business location.
  • No risky services exposed to the internet (RDP, unauthenticated file shares).
  • End-of-life operating systems retired or isolated.

Data & email (5 controls)

  • Backups running & tested — including at least one restore in the last 90 days.
  • Email authentication set up properly — SPF, DKIM & DMARC with an enforced policy.
  • Email gateway filtering inbound spam & phishing.
  • Data classification & sharing controls in place.
  • Website using TLS 1.2+ with a valid certificate.

People & process (7 controls)

  • Security awareness training every 12 months, evidenced.
  • Written incident response plan — who does what at 2 a.m. when it happens.
  • Visitor register at each staffed location.
  • Documented policy pack (acceptable use, password, remote work, BYOD).
  • Signed employment terms covering IT & data.
  • Responsible AI policy — new for 2026.
  • Bank-account change verification process for accounts payable.

Insurance (3 controls)

  • Cyber insurance policy in force, with cover appropriate to your revenue.
  • Business interruption / cyber cover reviewed annually.
  • Legal & supply-chain compliance documented.

What it costs & how long it takes

Two costs to think about:

1. The assessment itself

A certified assessor (that’s us) works through the 27 controls with you, gathers evidence from your systems, and files the paperwork with DSI. For a typical NZ SMB — say 15 to 60 users — that’s roughly two to three days of assessor time, done over three or four weeks so we can pull evidence at the right moments in your business cycle.

2. The remediation

This is the “closing the gaps” work. It depends entirely on where you’re starting from. A business already on Microsoft 365 with MFA everywhere, a managed EDR product, and a decent backup solution might have only three or four controls to close — a few weeks of work. A business relying on ad-hoc backups, no EDR, and passwords shared over Post-It notes is looking at three to six months of steady work before the assessment is worth booking.

Total timeline

Most NZ SMBs run from “let’s find out where we are” to certificate-in-hand in three to six months. Some go faster; nobody who’s serious takes longer than nine.

How IT Live delivers LiveSecure Gold end-to-end

Our LiveSecure Gold service takes a business through the whole path in four stages:

Stage 1 — Free 2-minute self-check

Take the check here. It covers 13 of the 27 controls — the ones you can answer honestly from your desk. You get an on-screen score, a grade (Below Bronze / Bronze / Silver / Gold track), and your top three gaps. Costs you nothing. Takes two minutes.

Stage 2 — Full gap assessment

We run the other 14 controls that need to be tested, not guessed — MFA registration per user, patch compliance across every device, DMARC policy at DNS, backup restore evidence, EDR tamper protection, and the rest. You get a written gap report scoring all 27 controls red / amber / green, with a prioritised fix list.

Stage 3 — Close the gaps

Nice & simple. We work through the fix list with you — most of the technical items are things we can do from our end without disrupting your team. Policy pack and training we deliver alongside.

Stage 4 — Certification

Once everything is Green, we submit the evidence to DSI on your behalf. They review, verify, and issue the certificate. You get a Gold badge for your website, a certificate for your insurer, and something concrete to point at when the next big customer asks.

Start with the free self-check

The 2-minute self-check is the honest way to find out where you stand — no sales call, no email hoop-jump before you see your score. If you land on Gold track, we’ll tell you. If you’re Below Bronze, we’ll tell you that too — plus what to do about it. Want the deeper version? Find out where you stand with an audit.

→ Take the free 2-minute Cyber Readiness Check

Or if you’d rather talk it through with a human first, give us a call — we’re on 09 280 1780 and we’re happy to walk you through what SMB1001 would look like for a business your size before you commit to anything.

Frequently asked questions

Is SMB1001 recognised in New Zealand?

Yes. SMB1001 was developed by Dynamic Standards International (DSI) for the Australia & New Zealand market. It’s the certification most NZ SMB cyber insurers now specifically ask about, and it’s aligned with the NZ Government’s cyber security recommendations for small business.

How is SMB1001 different from ISO 27001?

ISO 27001 is the enterprise-grade international standard — thorough, expensive, and typically overkill for a 20-person business. SMB1001 was built specifically for SMBs, is a fraction of the cost, and covers the controls that actually stop the attacks SMBs face. Think of Gold as the sensible middle ground.

How is SMB1001 different from the Essential Eight?

The Essential Eight is an Australian government mitigation strategy — a list of eight technical controls, no certification involved. SMB1001 is a certification standard covering the same technical ground plus people, process & insurance. Essential Eight tells you what to do; SMB1001 gets you a certificate proving you’ve done it.

Do I need Gold, or is Bronze / Silver enough?

Depends on what you’re trying to unlock. Bronze usually satisfies cyber insurance up to about $1M in cover. Silver clears most SME insurance and supplier requirements. Gold is what big customers and larger insurance policies typically ask for — and it’s the level most NZ SMBs settle on because the jump from Silver to Gold is smaller than most people expect.

Does the certification expire?

Yes — it’s an annual renewal. You re-attest each year and re-assess every two to three years, depending on your risk profile.

What happens if we fail an assessment?

Nothing bad. You get a written gap report and a clear list of what to fix. Most businesses treat the first assessment as a diagnostic — the certificate itself follows once the gaps are closed. There’s no “fail” on your record.

Can we do it ourselves without an assessor?

You can self-attest at Bronze & Silver in some cases, but Gold requires a licensed assessor to verify the evidence. That’s who signs off the certificate that gets issued.

How much does an assessment cost?

Assessor fees for an NZ SMB typically land in the low thousands — depends on business size and how much evidence-gathering support you need. The bigger cost is usually the remediation work if you’re starting from scratch. We give you a fixed quote after the free self-check so there are no surprises.

Will my cyber insurance premium actually drop?

Early NZ market data suggests certified businesses are seeing 5 to 25% premium reductions on renewal. Bigger wins are on cover availability — many insurers now decline SMB cyber cover altogether without at least Bronze certification.

Is IT Live SMB1001 Gold certified ourselves?

Yes. We put ourselves through the same assessment we deliver to our clients — it wouldn’t be right to sell you a standard we don’t hold ourselves. See our certifications page for the current Gold certificate.


IT Live is a certified SMB1001 assessor serving businesses across New Zealand — with teams in Whangārei, Auckland, Wellington & Wanaka. LiveSecure Gold is our end-to-end SMB1001 Gold certification service — assessment, remediation, evidence-gathering & certification submission in one relationship.

Contact us today