What Does SMB1001 Certification Cost in New Zealand?

SMB1001 certification planning with a New Zealand business owner
SMB1001 certification support from OxygenIT starts at $525 per month for a 10 user business at Bronze and runs to $1,425 per month at Gold. Most businesses that need the certification recognised by a cyber insurer land on Gold. You can start at Bronze and move up later.
ISO 27001 and ISO 42001 certifiedNZ based engineers onlyOperating since 2005100+ NZ businesses supported

All OxygenIT prices in one place. This page covers one service. Every price we publish, and what is never included in any of them, is on our pricing page.

The Real Range for SMB1001 Certification Support

Quick Summary: SMB1001 support at Bronze level starts from $525 per month for a 10 user business. Most businesses that want the certification recognised by cyber insurers land on Gold, which runs to $1,425 per month. The gap between those two figures comes down to how much security your business actually needs, not how many pages we write for the audit.

We price SMB1001 work around the tier you’re aiming for, not a flat consulting fee. Bronze starts from $525 per month for a 10 user business and covers the baseline controls the framework requires. Gold sits at $1,425 per month and is the level most of our clients target when a cyber insurance policy or a larger customer is asking for proof of security posture. The certificate itself doesn’t cost more to print. What costs more is the work that sits underneath it.

User count is the first thing that moves the number. A 10 person business and a 60 person business aren’t doing the same amount of work to get certified, even at the same tier. More staff means more devices, more logins, more places a gap can hide. The second driver is how secure the environment already is. A business running modern multi-factor authentication and patched systems has less ground to cover than one still sitting on defaults.

Each tier up the ladder adds controls, not paperwork. Moving from Bronze to Gold means tightening things like access management and monitoring, not just filling in more of the same form twice. That trade off is worth understanding before you pick a tier, because going in at Bronze because it’s cheaper won’t help much if your insurer or your biggest client is expecting Gold.

There’s no call out fee structure on this work and no financing option, because SMB1001 support isn’t a break fix job. It’s a project with a scope we agree upfront based on your Cyber Risk Assessment. We won’t hand you a number before we’ve looked at what’s actually in your environment. A business with 15 laptops and one server is a different job to one running multiple sites and a mixed device fleet, even at the same headcount.

What’s not included is the ongoing managed security work that keeps you certified year on year. The SMB1001 project gets you across the line. Staying there is a separate conversation, usually folded into whatever managed IT and security arrangement you already have with us, or with someone else.

Call 0800 242 206

What Pushes Your Price Toward the Bronze or Gold End

Two things move your number more than anything else: how many staff you have, and how much security depth your business needs. A 10-user business on Bronze sits around $525 per month. A business chasing cyber insurance cover on Gold sits closer to $1,425 per month. Everything in between depends on where you land.

Staff count is the simple part. More users means more devices, more logins, more endpoints for us to protect and monitor. That scales the price in a fairly linear way, so a 30-person business will naturally cost more than a 10-person one on the same tier.

The bigger driver is how secure your environment needs to be. Bronze covers the base level of protection most small teams need to meet basic SMB1001 requirements. Gold adds the layers insurers and larger clients tend to ask for: tighter access controls, deeper monitoring, and the documentation an insurer wants to see before writing a policy. If your industry or your customers demand a higher standard, you’ll sit higher up the tiers regardless of headcount.

Each tier builds on the one below it. You’re not paying for different vendors or a different quality of work, you’re paying for more security layered onto the same foundation. That’s a deliberate design, not a way to upsell. A business with sensitive client data or contractual security obligations usually needs Gold. A smaller operation with straightforward needs is often well served by Bronze.

We don’t quote a number until we’ve done the Cyber Risk Assessment and worked out where the gaps are. That assessment is part of our SMB1001 Certification Support process, and it’s the reason two businesses of similar size can land on different tiers. Have a look at our SMB1001 Certification Support page for how the assessment itself works before you get a proposal.

Call now

What’s Included in Our SMB1001 Certification Support Pricing

Bronze level SMB1001 support covers a business with 10 users from $525 per month. That price covers the certification work at the base tier: the controls, documentation, and evidence gathering needed to meet the Bronze standard. There’s no call-out fee involved, because call-outs simply aren’t part of how we price this work.

Most businesses that want Cyber Insurance readiness end up at Gold level, which runs $1,425 per month. Gold adds a deeper set of controls on top of Bronze and Silver, built around what insurers and larger customers ask to see before they’ll sign off on cover or a supply contract. The jump in price from Bronze to Gold reflects the jump in what’s being tested and documented, not a markup for the same work.

Two things move the number more than anything else: how many staff and endpoints you’re certifying, and how secure your environment already is when we start. A 10-person office with modern laptops and a basic Microsoft 365 setup is a different job to a 60-person business running legacy servers and a mix of personal devices. We don’t quote off headcount alone.

We don’t hand out a number before we’ve looked at your business. Our process starts with a 15 minute founder call, then a 45 minute discovery call to check we’re the right fit for each other. From there we run the Cyber Risk Assessment and build the proposal around what we find, not a guess.

This pricing model is built for businesses with 5 or more employees. We don’t take on residential clients or businesses under that size, because SMB1001 certification is designed around organisational controls that a smaller setup doesn’t need and shouldn’t have to pay for. If you’re weighing this against ongoing security work more broadly, our Cyber Security Consulting page covers how that fits alongside certification.

Ready when you are – get in touch today.

0800 242 206

Get a free 15-minute IT health check. OxygenIT is ready to help.

The Most Common Starting Point and What It Runs

Most businesses that come to us for SMB1001 work start at Bronze level, and for a business with 10 users that runs from $525 per month. That’s the entry point for the framework, not the finished product; it covers the baseline controls SMB1001 asks for at that tier. If your business wants Cyber Insurance readiness built in, that’s usually a Gold level engagement, and the common price point there is $1,425 per month. Two different jobs, two different numbers, and neither one is a guess.

What moves you from one number to the other isn’t complexity for its own sake. It’s staff count and how much security the environment already needs. More people using systems means more endpoints, more accounts, more places a gap can sit. Insurers asking for Gold level assurance want more evidence behind the certificate, not just the certificate itself, and that’s reflected in the price, not hidden in it.

Each tier up adds real security, not just paperwork. That’s by design. You’re not paying more for the same protection with a different badge, you’re paying for a genuinely more secure environment as you climb, which is also what an insurer or a client audit is checking for.

We don’t quote a number before we’ve looked at your environment. Our process starts with a 15 minute founder call, then a 45 minute discovery call to check we’re the right fit both ways. From there we run a Cyber Risk Assessment to find the actual gaps, and the proposal is built around what we find, not a flat rate applied to every business the same way. If you want the full breakdown of what sits inside each tier, our SMB1001 Certification Support page walks through it in more detail.

What this doesn’t include: The Bronze starting price covers the baseline framework work for a 10 user business. It doesn’t include Cyber Insurance readiness, that’s the Gold level scope, and it doesn’t include work outside the SMB1001 scope like broader network security projects.

Call 0800 242 206

When We’d Quote You Differently

The $525 per month Bronze figure is built around 10 users in a fairly standard setup. Add staff and the number moves, because SMB1001 pricing is driven by headcount and endpoints, not a flat monthly fee. A 10-person office and a 60-person office aren’t the same job, even if both just want the certification badge on their website.

The other big driver is how secure the environment needs to be. Each tier from Bronze up adds more controls, and Gold is built for businesses that need to satisfy a cyber insurance underwriter, not just tick a compliance box. That’s where the $1,425 per month Gold figure comes from. If your broker or insurer is asking for evidence of specific controls, we quote to that requirement, not to a generic certification level.

We don’t hand out a number over the phone before we’ve looked at your setup. Our process starts with a 15 minute founder call to check the basics line up, then a 45 minute discovery call to get into the detail of your business. From there we run a Cyber Risk Assessment to find the actual gaps, and the proposal is built around what that assessment turns up. Two businesses with the same staff count can still land on different tiers once we see what’s already in place and what’s missing.

This is also where we’ll tell you if SMB1001 Certification Support through our service, which you can read about on our SMB1001 Certification Support page, is even the right move yet. If your environment has gaps that would fail an assessment outright, we’d rather fix those first and quote the certification work once you’re ready to pass it.

Call now

SMB1001 Certification Support: Frequently Asked Questions

Will you give me a price over the phone before looking at my setup?

No, we don’t hand out a number until we’ve done the Cyber Risk Assessment. SMB1001 work is priced as a project with a scope we agree upfront, not a flat fee we can quote blind. A 15-laptop office with one server is a different job to a business running multiple sites, even with the same headcount. The assessment is what tells us where your gaps are before we put a tier and a price in front of you.

Is there a call-out fee anywhere in the SMB1001 process?

No. There’s no call-out fee structure on this work, because SMB1001 support isn’t a break-fix job. It’s priced as a project with an agreed scope, based on the tier you’re aiming for and what your Cyber Risk Assessment finds. You won’t see call-out charges added on top of your Bronze or Gold price.

Can I start at Bronze now and move up to Gold later?

Yes. Each tier builds on the one below it, so moving from Bronze toward Gold adds controls like tighter access management and deeper monitoring rather than starting over. That’s a deliberate part of how SMB1001 is structured. If your insurer or a bigger client later asks for Gold-level proof, the work you did at Bronze carries forward instead of being repeated.

Why would two businesses with the same number of staff get different quotes?

The gap usually comes down to how secure their environment already is, not headcount. A business running modern multi-factor authentication and patched systems has less ground to cover than one still sitting on default settings. Staff count moves the price in a fairly straight line, but existing security depth is what pushes two similar-sized businesses toward different numbers within the same tier.

Does it cost more if I have physical servers instead of just cloud email?

It can, because how much of your environment needs coverage is one of the things we price around. Email, servers, and cloud systems each add ground for us to check and document against the SMB1001 controls. A business running a mixed setup of on-site servers and cloud tools typically has more to cover than one running a simple cloud-only setup, even at the same tier.