Layer3 Logo

SMB1001 certification

SMB1001 certification for New Zealand businesses

Layer3 implements the controls and prepares the evidence behind your attestation, with the certificate issued by CyberCert.

SMB1001 is a cybersecurity standard designed for organisations that do not have a security team. It defines five levels, with certificates issued by CyberCert. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. Each managed plan includes the applicable controls, certification preparation and CyberCert certification cost.

Certifier

CyberCert

Standard

SMB1001:2026

Layer3 holds

SMB1001 Gold

Your cost

Included in the plan

At a glance — how SMB1001 certification works

Who certifies you

CyberCert, the authorised Dynamic Standard Certifier for SMB1001. DSI writes the standard but deliberately does not certify against it. Layer3 is a registered CyberCert partner.

Which level

Manage and Protect certify you at Bronze, Secure Edge at Silver, and Sentinel at Gold. Moving up a plan moves the certification with it. Layer3 does not offer Platinum or Diamond.

What it costs

Included. The CyberCert subscription and certification cost sit inside every managed plan fee, along with the work of meeting the applicable controls.

How long it lasts

Twelve months. Maintaining the controls through to renewal is part of the managed service rather than a separate re-certification project.

Not ISO 27001

ISO/IEC 27001:2022 covers an entire management system and is audited by an accredited body; SMB1001 certifies a defined control set. It is designed as a route towards ISO/IEC 27001:2022, not a replacement. Layer3 holds both.

Insurers and suppliers

Silver is the level built to be cyber-insurable, and it is what most enterprise supplier questionnaires are reaching for. Send us the questionnaire and we will map it against the levels before you commit to one.

01

Why a standard

Sooner or later, someone asks you to prove it

Insurers, tender panels and enterprise customers increasingly ask for evidence. An independent certificate provides a defined answer.

The question

"We take security seriously" is not evidence

Supplier questionnaires, insurance renewals and government tenders ask what controls you hold and who verified them. Certification provides that evidence.

The gap

ISO/IEC 27001:2022 assumes you have a security team

It certifies an entire management system, with the cost and staffing that implies. For most New Zealand small and mid-sized organisations that is the wrong instrument rather than a stretch goal. SMB1001 was built for the gap underneath it.

The pace

The standard is revised every year

The 2026 edition added email authentication, endpoint detection and response, and a policy for responsible AI use as requirements that did not exist before. Certifications that update every few years do not keep up with that.

The shape of it

Five areas, people as well as technology

SMB1001 organises its requirements around people, process and technology. Every control in the standard sits in one of these five areas, at every level.

Technology management

The hardware, software and networks you run - kept patched, correctly configured and current, with the vulnerable things found before someone else finds them.

Access management

Who can reach what, and how that is proven. Individual accounts, multi-factor authentication, a password manager, and administrative rights that are not handed out by default.

Backup and recovery

Backups that exist, with restores that have been tested. The standard asks for a strategy, not a checkbox, because an untested backup is a belief rather than a control.

Policies, plans and procedures

The written rules: how you respond to an incident, how you handle invoice fraud, what staff may do with AI, and what contractors are bound to.

Education and training

The staff-facing half. Cybersecurity awareness training is one of the seven controls in Bronze - a requirement from the very first level rather than an advanced extra.

The levels

The three levels available through Layer3

Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. Each level is a certification in its own right, and the levels are cumulative – each contains the controls of the level below.

Bronze

Level 1 · 7 controls

Baseline hygiene. Firewall, antivirus, automatic patching, password discipline, a backup strategy and awareness training for staff.

Silver

Level 2 · 17 controls

The insurable tier. Adds MFA on email, individual accounts, a password manager, server patching, email authentication and an invoice-fraud procedure.

Gold

Level 3 · 27 controls

Formal governance. Adds endpoint detection and response, a cybersecurity policy, an incident response plan, an AI usage policy and cyber insurance. Layer3's own level.

SMB1001 also defines two levels above Gold, Platinum and Diamond, which are independently audited. Layer3 does not offer them through its managed plans. If one has been specified to you, confirm the requirement with whoever is asking before you commit to a service.

The requirements

All 27 controls, and the level each one belongs to

Every control across the three levels Layer3 certifies. The levels are cumulative, so each column contains everything in the columns to its left.

Control

Bronze

Level 1

Silver

Level 2

Gold

Level 3

Engage a technical support specialist for your organisation
Install and configure a firewall
Install anti-virus software on all organisation devices
Automatically install tested and approved software updates and patches on all organisation devices
Ensure strong password hygiene is maintained
Implement a backup and recovery strategy for important digital assets
Conduct cybersecurity awareness training for all employees
Install TLS certificates on all public internet facing websites
Ensure all servers are updated and patched
Ensure employee accounts do not have administrative privileges
Ensure employees have individual user accounts
Implement a password manager system
Multi-factor authentication (MFA) on all employee email accounts
Email authentication and anti-spoofing
Confidentiality agreement for all employees, contractors and third parties
Implement a policy with procedures to manage invoice fraud
Implement a visitor register
Implement Endpoint Detection and Response (EDR)
MFA on all business applications and social media accounts
Ensure Remote Desktop Protocol (RDP) occurs only over VPN connections
Purchase and maintain business or cyber insurance
Implement a cybersecurity policy
Implement a response plan for cyber related incidents
Utilise secure methods of physical document destruction
Ensure all computer devices that store sensitive, private and/or confidential information are disposed of securely
Implement and maintain a digital asset register
Implement a policy for the responsible and secure use of AI technology

● Required at this level

- Not required at this level

Source: the SMB1001:2026 certification requirements published by CyberCert, the Dynamic Standard Certifier for SMB1001. Controls 14, 18 and 27 are new in the 2026 edition.

Your plan

How each managed plan maps to an SMB1001 target

Each managed plan maps to SMB1001 Bronze, Silver or Gold. Layer3 implements the applicable controls, prepares the evidence behind your director's attestation, and includes the CyberCert subscription and certification cost in your plan fee. None of these three levels requires an external audit.

Bronze

Bronze is the target for Manage and Protect. Layer3 helps put the essential controls in place, maintain them and prepare the evidence required for certification.

Silver

Silver is the target for Secure Edge. CyberCert describes this as the cyber-insurable level, and it is commonly requested in supplier questionnaires.

Gold

Reached with Sentinel. Formal security governance, documented and defensible at board and audit level.

The plans themselves - what each includes, and what changes between them - are set out on Managed IT and Support.

The process

How certification works

Four stages. The middle one is the work, and it is the part your plan already covers.

01

Assess

We measure your environment against every control at the level your plan targets, and show you exactly which ones you do not yet meet.

02

Implement

We close the gaps and keep them closed. This is the substantial part, and it is inside your managed plan rather than quoted as a project.

03

Attest

A director of your organisation signs the attestation. We supply the evidence sitting behind every control so the signature is an informed one.

04

Certify and renew

CyberCert issues the certificate. It runs for twelve months. Layer3 helps you maintain the applicable controls and prepare for renewal under the responsibilities agreed in your service schedule.

The CyberCert subscription and certification cost are included in every Layer3 managed plan. Layer3 implements the applicable controls, helps you prepare the evidence and supports annual renewal.

The boundary

What we do, and the one thing only you can do

Certification rests on a director's attestation. We can make that attestation true and evidenced, but we cannot sign it for you - and any provider who offers to should worry you.

Layer3 does

Implement

Configure, deploy and operate every technical control the level requires, across endpoints, identity, email, servers and backup.

Document

Draft the policies the standard asks for - cybersecurity, incident response, AI use, invoice fraud - and keep them current rather than filed.

Evidence

Maintain the proof behind each control, so an attestation is a statement of fact rather than a hope.

Maintain

Hold the controls through the twelve months and carry the CyberCert subscription to renewal.

You do

Attest

A director signs to say the controls are in place. This is the legal heart of the certificate and it is yours alone.

Decide the level

Tell us what your insurer, customers or board are asking for, and we will tell you which level answers it.

Release your people

Awareness training is a requirement from Bronze upward, and staff must complete it.

Hold insurance

Business or cyber insurance is a Gold requirement - control 21. Cover must be in place before your organisation can be certified at that level.

The limits

What SMB1001 is not

A certificate answers a specific question well. Its limits should be clear so it is not mistaken for something broader.

It is not ISO/IEC 27001

ISO/IEC 27001:2022 certification covers an entire information security management system and is audited by an accredited body. SMB1001 certifies a defined set of controls. Layer3 holds both, which helps us identify which one your customer is asking for – it is often not the one named in the email.

It is not a penetration test

Penetration testing is outside Layer3's SMB1001 Bronze, Silver and Gold offering. If someone has asked you to demonstrate that a specific application or environment withstands attack, that is a separate engagement – book a discovery call.

It is not a strategy

A certificate is a point in time. Deciding what should change over the next year, what it costs and what the board needs to approve is a continuing cadence rather than an annual attestation - see IT Strategy and Governance.

Our position

We hold what we ask you to hold

Layer3 maintains its own SMB1001 certification through CyberCert and works to the same published standard it helps customers implement.

Gold

SMB1001

Layer3's own certification level - Level 3, 27 controls.

27001

ISO/IEC

Certified to ISO/IEC 27001 by Compass Assurance Services.

Partner

CyberCert

Layer3 is a registered CyberCert partner and supports customers through the certification process; CyberCert issues the certificate.

Client work

Who we already look after

Customer example

70 years

Cuttriss are a Wellington surveying and civil engineering practice with no security team of their own — exactly the organisation SMB1001 was written for.

Read the Cuttriss case study

SMB1001 FAQ

Before you ask

The questions we hear most about SMB1001 certification, CyberCert and how it fits your plan. If yours is not here, ask us directly.

Book a discovery call

A cybersecurity certification standard for small and medium organisations. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold.

CyberCert, the authorised Dynamic Standard Certifier for SMB1001. DSI writes the standard but deliberately does not certify against it. Layer3 is a registered CyberCert partner.

Manage and Protect certify you at Bronze, Secure Edge at Silver, and Sentinel at Gold. Moving up a plan moves the certification with it.

Included. The CyberCert subscription and certification cost sit inside every managed plan fee, along with the work of meeting the applicable controls.

It depends entirely on how much of the control set you already meet. The assessment tells you that in the first weeks; closing the gaps is the variable part.

Twelve months. Maintaining the controls through to renewal is part of the managed service rather than a separate re-certification project.

No. ISO/IEC 27001:2022 certification covers an entire management system and is audited by an accredited body; SMB1001 certifies a defined control set. It is designed as a route towards ISO/IEC 27001:2022 rather than a replacement for it. Layer3 holds both.

No. Layer3 managed plans cover SMB1001 Bronze, Silver and Gold. If another level has been specified, confirm the requirement directly with the requesting party before selecting a service.

Silver is the level built to be cyber-insurable, and it is what most enterprise supplier questionnaires are reaching for. Send us the questionnaire and we will map it against the levels before you commit to one.

Start the conversation

Find out which level you already meet

An honest read on where your controls sit against SMB1001 today, which target level fits your managed plan, and what would have to change to prepare for certification. No obligation.

Layer3

Book a discovery call - 30 minutes, no obligation