SMB1001 Gold Certification in New Zealand: The Complete 2026 Guide

SMB1001 Gold certification is fast becoming the cyber security benchmark New Zealand SMBs are asked to meet in insurance applications, supply chain questionnaires and tender responses. This guide explains what SMB1001 Gold certification in NZ involves, what it costs, which controls you need, who signs it off and how long it takes.

It is written for owners and directors of businesses with 20 to 200 staff who want a straight answer rather than a sales pitch. OxygenIT has operated from Christchurch since 2005, holds ISO 27001 and ISO 42001 certification ourselves, and takes NZ businesses to SMB1001 Gold in 90 days.

What is SMB1001 Gold certification?

SMB1001 Gold is the middle tier of SMB1001, a five tier cyber security certification standard developed by Dynamic Standards International (DSI) and certified through the CyberCert platform. Gold requires 27 controls covering technology, processes, people and insurance, and a company director signs it off. The current edition, SMB1001:2026, has been certifiable since January 2026.

The five tiers are Bronze, Silver, Gold, Platinum and Diamond, and each tier builds on the one below it. The design goal is simple: give small and medium businesses a realistic ladder instead of an enterprise framework that assumes a dedicated security team. Certification runs on an annual cycle, and DSI updates the standard every year so the controls track current threats rather than a fixed snapshot.

SMB1001 started in Australia and is used on both sides of the Tasman. New Zealand businesses certify through CyberCert in exactly the same way as Australian ones, and nothing in the standard depends on Australian legislation. It is the closest thing NZ small businesses currently have to an accessible, recognised cyber certification.

Gold is the tier we recommend most often at OxygenIT because it is the first level that includes the controls insurers and larger customers actually check for: endpoint detection and response, enforced email authentication, cyber insurance and a tested incident response plan. It also lines up naturally with the work we already do on IT compliance for NZ businesses.

How much does SMB1001 Gold cost in New Zealand?

The CyberCert certificate fee for SMB1001 Gold is AUD $395 per year. That sits between Silver at AUD $195 and Platinum at AUD $3,595. The certificate fee is only part of the total: implementing the 27 controls is a separate cost that depends entirely on your current security maturity.

For a typical NZ business of 20 to 200 staff, the implementation side breaks into four buckets:

  1. Technical controls. EDR licensing per device, email authentication setup, MFA rollout and backup hardening. If you already run a managed Microsoft 365 environment, much of this is configuration rather than new spend.
  2. Cyber insurance. Gold makes a current cyber insurance policy mandatory, so the premium becomes part of your certification budget if you are not already covered.
  3. Policies and plans. Time to produce an incident response plan, a responsible AI policy and the supporting documents, either internally or with your IT partner.
  4. Training. An ongoing security awareness programme for all staff, not a single induction module.

We publish our SMB1001 packages openly on our SMB1001 pricing page, so you can see the full per tier cost before you talk to anyone. A gap assessment then turns that into a firm number for your environment.

What controls does SMB1001 Gold require?

SMB1001 Gold requires 27 controls spanning technology, access, backup, policy and training. The headline requirements are endpoint detection and response, SPF, DKIM and DMARC email authentication with an enforced policy, multi-factor authentication, offline backups, a mandatory cyber insurance policy, a responsible AI policy, an incident response plan and ongoing staff awareness training.

The checklist below covers the controls most NZ SMBs need to plan for. Control numbers refer to SMB1001:2026, and CyberCert supplies the full workbook when you enrol.

SMB1001 Gold control checklist

  • Firewalls on every office network and managed device.
  • Automatic updates for operating systems and applications, with unsupported software removed.
  • Endpoint detection and response (EDR) on all endpoints, not just traditional antivirus (control 1.12.0.0). Our EDR service shows what this looks like in practice.
  • SPF, DKIM and DMARC on every sending domain, with the DMARC policy enforced at p=reject or p=quarantine (control 2.12.1.0).
  • Multi-factor authentication on email, remote access and all administrator accounts.
  • Password manager deployed to staff, with unique passwords enforced.
  • Restricted admin rights so day to day accounts cannot install software or change security settings.
  • Digital asset register listing hardware, software and data locations.
  • Backups with an offline or immutable copy, plus documented and tested restores.
  • Cyber insurance in force, with cover matched to your risk (control 3.2.0.0).
  • Incident response plan that names who does what in the first 24 hours.
  • Responsible AI policy governing how staff use AI tools with company data (control 4.11.0.0).
  • Ongoing security awareness training for every staff member, refreshed through the year.
  • Starter and leaver process so access is granted and revoked on time.

None of these are exotic. The gap for most 20 to 200 staff businesses is usually DMARC enforcement, the offline backup copy and the written plans.

Who signs off SMB1001 Gold?

A company director signs off SMB1001 Gold. Bronze, Silver and Gold are certified by director attestation: once the 27 controls are implemented, a director formally attests compliance through the CyberCert platform and the certificate is issued. Platinum and Diamond work differently and require an independent external audit before certification.

The attestation model is what keeps Gold fast and affordable, but it is not a rubber stamp. The director is personally putting their name to the state of the controls, which sits squarely within existing directors’ duties around risk oversight. Treat the attestation like a financial declaration: only sign once there is evidence behind every line.

OxygenIT builds an evidence pack alongside the implementation, covering screenshots, policy documents, training records and configuration exports, so the attestation is defensible if a customer, insurer or future buyer of your business asks to see the workings. That last point matters more than most owners expect: certification with evidence survives due diligence, and it is one of the cheapest ways to make a business more saleable.

How long does SMB1001 Gold take?

Most businesses reach SMB1001 Gold in one to six months. The spread depends on your starting point: a company already on a managed security stack can certify quickly, while one starting cold needs time for DMARC enforcement, training rollout and insurance. OxygenIT runs a structured 90 day programme for NZ businesses.

If you are wondering how to get SMB1001 certified, the path has three phases:

  1. Weeks 1 to 2: gap assessment. We map your environment against all 27 controls and price the remediation.
  2. Weeks 3 to 8: remediation. Technical controls first, then policies, insurance and the incident response plan.
  3. Weeks 9 to 12: evidence and attestation. Training underway, evidence pack compiled, director attests through CyberCert.

Two items consume calendar time no matter how organised you are. DMARC has to be monitored before you enforce p=reject, or you risk blocking your own legitimate email. And awareness training is an ongoing control, so the programme needs to be running, not just scheduled. Start both in week one and the rest fits comfortably inside 90 days.

SMB1001 vs Essential Eight vs ISO 27001: which one fits?

SMB1001 is a certifiable standard built for small and medium businesses. The Essential Eight is a set of technical mitigation strategies from the Australian Signals Directorate (ASD) with no certificate attached. ISO 27001 is a full information security management system with external audits. For most NZ businesses under 200 staff, SMB1001 Gold is the practical first certification.

SMB1001 Gold Essential Eight ISO 27001
What it is Tiered cyber security certification for SMBs Eight technical mitigation strategies published by the ASD International standard for an information security management system
Certificate issued Yes, annually via CyberCert No certificate, self assessed maturity levels Yes, three year cycle with annual surveillance audits
Assurance Director attestation Self assessment Independent external audit
Typical cost AUD $395 fee plus implementation Free framework, implementation cost only NZD $20,000 plus in the first year
Time to achieve 1 to 6 months Ongoing programme 6 to 18 months
Best for Insurance, tenders and a first certification Hardening your technical baseline Enterprise and government contracts

These are complements, not competitors. The Essential Eight, published by the Australian Cyber Security Centre, is excellent guidance for your technical baseline and maps closely onto the SMB1001 technology controls. ISO 27001 is the right call when enterprise or government contracts demand it, and we hold it ourselves alongside ISO 42001 for AI management, so we know exactly what that journey asks of a smaller business. SMB1001 Gold sits in the middle: real certification at an achievable budget. We compare the standards in more depth in our SMB1001 vs ISO 27001 guide, and our IT security services cover the technical controls behind all three.

Why SMB1001 Gold matters for cyber insurance and tenders in NZ

SMB1001 Gold matters because it packages the exact controls insurers and procurement teams ask about into one certificate. Gold makes cyber insurance mandatory, and the underwriting questions about MFA, EDR, backups and incident response are all Gold controls. A current certificate answers most of a proposal form or supplier questionnaire in one line.

On the insurance side, underwriters now decline cover or load premiums when MFA, EDR or tested backups are missing. Reaching Gold means you answer yes to those questions with evidence behind you. Our breakdown of the questions NZ cyber insurance underwriters ask shows how directly the two overlap.

On the tender side, the pressure is flowing downhill. Large Australian organisations have started requiring SMB1001 tiers from their suppliers, and because so many NZ firms sit inside Australian supply chains, the requirement lands here quickly. Larger NZ corporates and government adjacent buyers are moving the same way, replacing forty question security spreadsheets with a single ask for certification.

The threat data backs the effort. CERT NZ, now part of the National Cyber Security Centre, consistently reports phishing and business email compromise among the top incident types hitting NZ small businesses, and the ASD Annual Cyber Threat Report puts the average self reported cost of cybercrime for a small business at roughly AUD $50,000 per incident. The Gold controls target exactly those attack paths.

SMB1001 Gold certification NZ: frequently asked questions

Is SMB1001 recognised in New Zealand?

Yes. SMB1001 was developed in Australia by Dynamic Standards International and is used on both sides of the Tasman. New Zealand businesses certify through the same CyberCert platform, and NZ insurers, brokers and larger customers increasingly accept the certificate as evidence of baseline cyber security. There is no equivalent locally owned certification aimed at small and medium businesses.

Do we need Bronze or Silver before going for Gold?

No. The tiers build on each other, but you can certify directly at any level. Most businesses we work with go straight to Gold because it is the first tier that satisfies insurers and enterprise procurement teams. Bronze and Silver suit very small teams that need a starting point.

Does SMB1001 Gold require an external audit?

No. Gold is certified by director attestation. A director confirms through CyberCert that all 27 controls are in place, and the certificate is issued. External audits only apply at Platinum and Diamond. Keep evidence for each control anyway, because customers and insurers can ask to see it.

How long does the certification last?

Twelve months. SMB1001 certificates are issued annually and the standard is updated each year, so recertification is always against the current edition. Treat it as an annual health check rather than a one off project. OxygenIT manages recertification for clients as part of our IT compliance service.

Will SMB1001 Gold reduce our cyber insurance premium?

It can improve both insurability and terms. Gold requires the controls underwriters ask about on every proposal form, including MFA, EDR, tested backups and an incident response plan. Certification does not guarantee a lower premium, but it removes the most common reasons for loaded premiums or declined cover. Our guide to cyber insurance underwriters in NZ explains what insurers look for.

Does OxygenIT only work with Christchurch businesses?

No. We are Christchurch based with coverage in Wellington and clients across New Zealand. SMB1001 Gold work is largely remote friendly, since gap assessment, remediation and evidence collection all run through Microsoft 365 and our management tooling. Contact us to talk through your situation.

Get SMB1001 Gold certified in 90 days with OxygenIT

OxygenIT has run IT and security for New Zealand businesses since 2005. We are ISO 27001 and ISO 42001 certified, based in Christchurch with coverage in Wellington, and we take businesses of 20 to 200 staff from gap assessment to a director signed SMB1001 Gold certificate in 90 days.

Book a discovery call and we will map your current environment against the 27 Gold controls, then give you a fixed price and a start date. Or call us on 0800 101 095.