Customer example
70 years
Cuttriss are a Wellington surveying and civil engineering practice with no security team of their own — exactly the organisation SMB1001 was written for.
Read the Cuttriss case studySMB1001 certification
Layer3 implements the controls and prepares the evidence behind your attestation, with the certificate issued by CyberCert.
SMB1001 is a cybersecurity standard designed for organisations that do not have a security team. It defines five levels, with certificates issued by CyberCert. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. Each managed plan includes the applicable controls, certification preparation and CyberCert certification cost.
Certifier
CyberCert
Standard
SMB1001:2026
Layer3 holds
SMB1001 Gold
Your cost
Included in the plan
Who certifies you
CyberCert, the authorised Dynamic Standard Certifier for SMB1001. DSI writes the standard but deliberately does not certify against it. Layer3 is a registered CyberCert partner.
Which level
Manage and Protect certify you at Bronze, Secure Edge at Silver, and Sentinel at Gold. Moving up a plan moves the certification with it. Layer3 does not offer Platinum or Diamond.
What it costs
Included. The CyberCert subscription and certification cost sit inside every managed plan fee, along with the work of meeting the applicable controls.
How long it lasts
Twelve months. Maintaining the controls through to renewal is part of the managed service rather than a separate re-certification project.
Not ISO 27001
ISO/IEC 27001:2022 covers an entire management system and is audited by an accredited body; SMB1001 certifies a defined control set. It is designed as a route towards ISO/IEC 27001:2022, not a replacement. Layer3 holds both.
Insurers and suppliers
Silver is the level built to be cyber-insurable, and it is what most enterprise supplier questionnaires are reaching for. Send us the questionnaire and we will map it against the levels before you commit to one.
01
Why a standard
Insurers, tender panels and enterprise customers increasingly ask for evidence. An independent certificate provides a defined answer.
The question
Supplier questionnaires, insurance renewals and government tenders ask what controls you hold and who verified them. Certification provides that evidence.
The gap
It certifies an entire management system, with the cost and staffing that implies. For most New Zealand small and mid-sized organisations that is the wrong instrument rather than a stretch goal. SMB1001 was built for the gap underneath it.
The pace
The 2026 edition added email authentication, endpoint detection and response, and a policy for responsible AI use as requirements that did not exist before. Certifications that update every few years do not keep up with that.
The shape of it
SMB1001 organises its requirements around people, process and technology. Every control in the standard sits in one of these five areas, at every level.
The hardware, software and networks you run - kept patched, correctly configured and current, with the vulnerable things found before someone else finds them.
Who can reach what, and how that is proven. Individual accounts, multi-factor authentication, a password manager, and administrative rights that are not handed out by default.
Backups that exist, with restores that have been tested. The standard asks for a strategy, not a checkbox, because an untested backup is a belief rather than a control.
The written rules: how you respond to an incident, how you handle invoice fraud, what staff may do with AI, and what contractors are bound to.
The staff-facing half. Cybersecurity awareness training is one of the seven controls in Bronze - a requirement from the very first level rather than an advanced extra.
The levels
Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. Each level is a certification in its own right, and the levels are cumulative – each contains the controls of the level below.
Bronze
Baseline hygiene. Firewall, antivirus, automatic patching, password discipline, a backup strategy and awareness training for staff.
Silver
The insurable tier. Adds MFA on email, individual accounts, a password manager, server patching, email authentication and an invoice-fraud procedure.
Gold
Formal governance. Adds endpoint detection and response, a cybersecurity policy, an incident response plan, an AI usage policy and cyber insurance. Layer3's own level.
SMB1001 also defines two levels above Gold, Platinum and Diamond, which are independently audited. Layer3 does not offer them through its managed plans. If one has been specified to you, confirm the requirement with whoever is asking before you commit to a service.
The requirements
Every control across the three levels Layer3 certifies. The levels are cumulative, so each column contains everything in the columns to its left.
Control
Bronze
Level 1
Silver
Level 2
Gold
Level 3
● Required at this level
- Not required at this level
Source: the SMB1001:2026 certification requirements published by CyberCert, the Dynamic Standard Certifier for SMB1001. Controls 14, 18 and 27 are new in the 2026 edition.
Your plan
Each managed plan maps to SMB1001 Bronze, Silver or Gold. Layer3 implements the applicable controls, prepares the evidence behind your director's attestation, and includes the CyberCert subscription and certification cost in your plan fee. None of these three levels requires an external audit.
Bronze is the target for Manage and Protect. Layer3 helps put the essential controls in place, maintain them and prepare the evidence required for certification.
Silver is the target for Secure Edge. CyberCert describes this as the cyber-insurable level, and it is commonly requested in supplier questionnaires.
Reached with Sentinel. Formal security governance, documented and defensible at board and audit level.
The plans themselves - what each includes, and what changes between them - are set out on Managed IT and Support.
The process
Four stages. The middle one is the work, and it is the part your plan already covers.
01
We measure your environment against every control at the level your plan targets, and show you exactly which ones you do not yet meet.
02
We close the gaps and keep them closed. This is the substantial part, and it is inside your managed plan rather than quoted as a project.
03
A director of your organisation signs the attestation. We supply the evidence sitting behind every control so the signature is an informed one.
04
CyberCert issues the certificate. It runs for twelve months. Layer3 helps you maintain the applicable controls and prepare for renewal under the responsibilities agreed in your service schedule.
The CyberCert subscription and certification cost are included in every Layer3 managed plan. Layer3 implements the applicable controls, helps you prepare the evidence and supports annual renewal.
The boundary
Certification rests on a director's attestation. We can make that attestation true and evidenced, but we cannot sign it for you - and any provider who offers to should worry you.
Implement
Configure, deploy and operate every technical control the level requires, across endpoints, identity, email, servers and backup.
Document
Draft the policies the standard asks for - cybersecurity, incident response, AI use, invoice fraud - and keep them current rather than filed.
Evidence
Maintain the proof behind each control, so an attestation is a statement of fact rather than a hope.
Maintain
Hold the controls through the twelve months and carry the CyberCert subscription to renewal.
Attest
A director signs to say the controls are in place. This is the legal heart of the certificate and it is yours alone.
Decide the level
Tell us what your insurer, customers or board are asking for, and we will tell you which level answers it.
Release your people
Awareness training is a requirement from Bronze upward, and staff must complete it.
Hold insurance
Business or cyber insurance is a Gold requirement - control 21. Cover must be in place before your organisation can be certified at that level.
The limits
A certificate answers a specific question well. Its limits should be clear so it is not mistaken for something broader.
ISO/IEC 27001:2022 certification covers an entire information security management system and is audited by an accredited body. SMB1001 certifies a defined set of controls. Layer3 holds both, which helps us identify which one your customer is asking for – it is often not the one named in the email.
Penetration testing is outside Layer3's SMB1001 Bronze, Silver and Gold offering. If someone has asked you to demonstrate that a specific application or environment withstands attack, that is a separate engagement – book a discovery call.
A certificate is a point in time. Deciding what should change over the next year, what it costs and what the board needs to approve is a continuing cadence rather than an annual attestation - see IT Strategy and Governance.
Our position
Layer3 maintains its own SMB1001 certification through CyberCert and works to the same published standard it helps customers implement.
Gold
SMB1001
Layer3's own certification level - Level 3, 27 controls.
27001
ISO/IEC
Certified to ISO/IEC 27001 by Compass Assurance Services.
Partner
CyberCert
Layer3 is a registered CyberCert partner and supports customers through the certification process; CyberCert issues the certificate.
Client work
Customer example
70 years
Cuttriss are a Wellington surveying and civil engineering practice with no security team of their own — exactly the organisation SMB1001 was written for.
Read the Cuttriss case studySMB1001 FAQ
The questions we hear most about SMB1001 certification, CyberCert and how it fits your plan. If yours is not here, ask us directly.
Book a discovery callA cybersecurity certification standard for small and medium organisations. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold.
CyberCert, the authorised Dynamic Standard Certifier for SMB1001. DSI writes the standard but deliberately does not certify against it. Layer3 is a registered CyberCert partner.
Manage and Protect certify you at Bronze, Secure Edge at Silver, and Sentinel at Gold. Moving up a plan moves the certification with it.
Included. The CyberCert subscription and certification cost sit inside every managed plan fee, along with the work of meeting the applicable controls.
It depends entirely on how much of the control set you already meet. The assessment tells you that in the first weeks; closing the gaps is the variable part.
Twelve months. Maintaining the controls through to renewal is part of the managed service rather than a separate re-certification project.
No. ISO/IEC 27001:2022 certification covers an entire management system and is audited by an accredited body; SMB1001 certifies a defined control set. It is designed as a route towards ISO/IEC 27001:2022 rather than a replacement for it. Layer3 holds both.
No. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. If another level has been specified, confirm the requirement directly with the requesting party before selecting a service.
Silver is the level built to be cyber-insurable, and it is what most enterprise supplier questionnaires are reaching for. Send us the questionnaire and we will map it against the levels before you commit to one.
Start the conversation
An honest read on where your controls sit against SMB1001 today, which target level fits your managed plan, and what would have to change to prepare for certification. No obligation.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation