SMB1001 Bronze, Silver and Gold are not audited. They are certified on the strength of a signature: a director, owner or senior executive attests that every control at that level is in place. That makes the attestation the most important thing in the whole process, and it raises a fair question we get asked more and more. If it turns out to be wrong, who carries the consequences?
The short answer is that the director carries most of it, the IT provider carries some of it, and a certificate is only ever as good as the evidence behind it. The longer answer is below.
What does the director actually sign?
Certificates in New Zealand are issued by CyberCert. Under its terms, the person attesting “represents and warrants” that all controls required for the certification level have been implemented, and that the information provided is “true, accurate and complete”. Only an executive officer, owner or senior executive can make that attestation, according to CyberCert’s Certification Practice Statement.
That is the key difference between the levels. Platinum and Diamond cannot be issued without a successful independent audit. Bronze, Silver and Gold rest on the attestation alone, so nobody outside your organisation checks the controls before the certificate is issued.
What happens if the attestation turns out to be false?
The first consequence comes from CyberCert itself. Its terms say a false or misleading attestation “may result in revocation” of the certificate “and may constitute misrepresentation”. CyberCert can place a certificate under review following a random audit or a reported security incident, revoke it if the requirements are not being met, and stop the organisation reapplying for a period.
CyberCert also states plainly that it “gives no warranty as to the correctness” of attestations, and expects anyone relying on a certificate to do their own due diligence. In practice that means the insurer, customer or tender panel who accepted your certificate is relying on your word, not CyberCert’s.
Can a director be personally exposed?
Potentially, yes. This is general information rather than legal advice, but three things are worth knowing about.
- The Fair Trading Act 1986. A certificate is typically used in trade: in tenders, supplier questionnaires and on websites. Misleading conduct in trade (section 9) can lead to court orders, including against people “knowingly concerned” in it (section 43). False or misleading representations about the standard or quality of services (section 13) are an offence carrying fines of up to $200,000 for an individual and $600,000 for a company (section 40). Making a claim without reasonable grounds can also be a breach in its own right (section 12A).
- The Companies Act 1993. Directors must exercise “the care, diligence, and skill that a reasonable director would exercise in the same circumstances” (section 137). A director can rely on advice from an IT provider, but only in good faith, after making proper inquiry where the need for it is indicated, and without knowing the reliance is unwarranted (section 138). Signing an attestation without looking at the evidence is hard to square with that.
- The attestation itself. CyberCert’s terms are governed by the laws of Queensland, so a dispute about the attestation as a contract with CyberCert would sit outside New Zealand courts. The New Zealand exposure comes mainly from how the certificate is then used here.
What about cyber insurance?
This is where a false statement is most likely to cost real money. Under the Insurance Law Reform Act 1977, an insurer can avoid a policy because of a statement in the proposal if the statement was “substantially incorrect” and “material” – meaning it would have influenced a prudent insurer’s decision to take on the risk or the premium it charged (sections 5 and 6). “MFA is enforced on all accounts” is exactly the kind of answer an underwriter treats as material.
The rules are changing. The Contracts of Insurance Act 2024 is due to take effect on 15 November 2027, according to MBIE. Business policyholders will owe the insurer “a fair presentation of the risk”. Where a misrepresentation is deliberate or reckless, the insurer may avoid the contract, refuse all claims and keep the premiums. Honest mistakes will be treated more proportionately. Either way, a certificate you cannot back up does not help at claim time.
Does a certificate protect you under the Privacy Act?
Not on its own. Information Privacy Principle 5 of the Privacy Act 2020 requires security safeguards that are “reasonable in the circumstances”. A current, honest SMB1001 certificate is a useful record of the steps you took. A certificate that overstated your controls is a record of the opposite.
The Act also requires you to notify the Privacy Commissioner and affected people of a breach that has caused, or is likely to cause, serious harm. Failing to notify the Commissioner without reasonable excuse is an offence with a fine of up to $10,000 (section 118). No certificate changes that obligation.
Where does the IT provider’s responsibility sit?
More squarely than most people expect. CyberCert requires every organisation to engage a Technical Service Specialist (TSS) before it can be certified at any level. The TSS must confirm that the technical controls within its engagement have been implemented, and that confirmation has to be submitted before the director can attest. CyberCert describes the two together as a “dual sign-off”. The TSS must also hold its own certification at least equivalent to the level it supports.
So an IT provider acting as TSS puts its own confirmation on the record, and its contract with the customer sits behind that. A provider that confirms controls it has not actually deployed is exposed in the ordinary ways, such as breach of contract and negligence.
The TSS does not take the director’s place, though. CyberCert’s terms are explicit that engaging a TSS “does not reduce your responsibility” for meeting the requirements, and that the organisation is “solely responsible” for the non-technical and human behaviour controls – policies, training, insurance and the like. Those are never the IT provider’s to sign for.
What if you decide not to fix a control?
Then the honest answer is that you are not at that level yet. You can target the level you genuinely meet, or fix the gap first. What you should not do is attest anyway. If a provider has told you in writing that a control is missing and you attest regardless, that decision is yours, and the written record says so.
How Layer3 approaches it
We treat the attestation as a statement of fact, not a formality. Before any director signs, we put the evidence for every technical control in front of them, and we flag which controls are theirs to own. We only confirm controls we can evidence, and we maintain them through the year so the certificate stays true after the day it was issued. Layer3 holds SMB1001 Gold and ISO/IEC 27001 certification itself.
We will help you make an attestation true and evidenced. We will not sign it for you, and any provider who offers to should worry you. See how SMB1001 certification works with Layer3.
This article is general information, not legal advice. It reflects New Zealand legislation and CyberCert’s published terms and Certification Practice Statement (version 1.1, 10 July 2026) as checked on 7 October 2026. For advice on your own position, talk to your lawyer or insurance broker.