What Do Businesses Ask Most About SMB1001 Certification?

Choosing the Right SMB1001 Tier Depends on Your Risk Profile
We get asked which tier a business should aim for before we’ve even looked at their setup, and honestly, we can’t answer that yet. The framework works in layers: Bronze covers the baseline controls, Silver builds on that, and Gold is the level most insurers and larger clients expect when they want proof of a solid security posture.
Your tier comes down to risk profile more than industry. A 15-person accounting firm handling client financial data can carry more risk than a 40-person manufacturer running simpler systems. Staff count plays a role too, since more people means more devices, more logins, and more ways in. We’ve seen businesses assume they need Gold just because a competitor mentioned it, then discover Bronze or Silver already covers what their insurer or client contracts actually require.
Cyber insurance is the biggest driver we see. If a business wants cover, or wants to renew a policy without the premium jumping, insurers are increasingly asking for SMB1001 evidence. That conversation is usually a Gold-level one, since insurers tend to want the fuller control set rather than just the basics.
- Bronze fits smaller teams with lower data sensitivity and no immediate insurance requirement
- Silver suits businesses building towards a stronger posture without the full Gold workload yet
- Gold suits businesses that need to satisfy cyber insurance requirements or client security questionnaires
- Staff numbers and endpoint count affect scope and workload at every tier
- Gaps found during the risk assessment can shift a business up or down a tier from what they expected
We won’t push a business towards Gold if Bronze genuinely covers their exposure, since that’s real cost and time for no real gain. We’ll also tell you straight if Bronze won’t satisfy what your insurer is asking for, because finding that out after you’ve applied for cover is a much worse position to be in.
If you want to see how the tiers relate to cost, our pricing guide for SMB1001 Certification Support lays out what each level typically involves.
SMB1001 Certification Requires Real Operational Changes, Not Just Documents
Most business owners who call us about SMB1001 think it’s a paperwork exercise: fill in a policy, get a badge, move on. It isn’t. SMB1001 checks whether the controls in your policy are actually running on your network, on staff laptops, and in your email system. A written password policy nobody follows won’t get you certified.
The first thing people notice is the gap between what they thought they had and what an assessor actually finds. A business might have antivirus on every machine but no multi-factor authentication on email. Or a backup routine nobody’s tested in a year. That’s not a failing on the owner’s part, it’s just how security tends to drift once a business passes 20 or 30 staff and nobody owns it full time.
This happens because SMB1001 is built to demonstrate operating security, not filed security. It sits inside the same framework we build our own cybersecurity work around, and it’s designed to be checked, not just claimed.
We start with a 15 minute founder call to check for fit, then a 45 minute discovery call to get properly aligned on where the business stands. From there we run a Cyber Risk Assessment across the environment: endpoints, email, network, backups, staff practices. That assessment shows us where the gaps sit against SMB1001 Bronze, Silver, or Gold, and we build a proposal around closing them, not around selling everything at once.
- Multi-Factor Authentication Setup across email and remote access, not just on the admin account
- Password Management tools replacing shared spreadsheets or sticky notes
- Security Awareness Training so staff recognise phishing attempts before they click
- Firewall Management and Application Whitelisting configured and reviewed, not just installed once
- Data Backups and Disaster Recovery tested, not assumed to work
We don’t take on residential clients or businesses under five staff, because the framework and the ongoing management behind it are built for a workforce, not a single laptop. If that’s where you’re at, SMB1001 through our Cyber Security Consulting isn’t the right starting point yet.
Getting from Bronze to Gold takes real change across the business, not a rubber stamp. If you want the full picture of what our SMB1001 Certification Support involves before you commit, it’s worth a look before the assessment call.
Certification Timelines Depend on Your Starting Point
The 90 day figure people hear for SMB1001 Gold is a target, not a guarantee for every business. Where you land depends on what’s already in place when we start. A business running Multi-Factor Authentication Setup, a password manager, and some form of Security Awareness Training walks in ahead of one that has none of that. We’ve worked with businesses at both ends.
This is the question we get asked most before anyone signs anything: how long will this take us? The honest answer is we don’t know until we’ve looked. That’s the whole point of the Cyber Risk Assessment. We’re not guessing at gaps, we’re finding them.
- How many staff and endpoints need to be brought into scope
- Whether Multi-Factor Authentication is already switched on across the business
- Whether firewalls and antivirus are current and properly configured
- How much documentation already exists around IT policy and data handling
- Whether staff have had any prior Security Awareness Training or Phishing Simulation Testing
We start every engagement the same way, no matter how far along a business is. A 15 minute founder call to check fit, then a 45 minute discovery call to get properly aligned on what the business needs. From there we run the Cyber Risk Assessment, which is where the real gaps show up. Password sprawl with no Password Management system in place is common. So is Firewall Management that hasn’t been touched since setup, or no Dark Web Monitoring at all.
Once we’ve mapped the gaps, we put together a proposal specific to your business, not a generic template. Some businesses close their gaps in weeks because most of the groundwork already existed. Others take longer, usually because there’s more to build from scratch: Application Whitelisting, proper Email Protection, or a documented Business Continuity Plan. We’d rather tell you upfront that your timeline looks longer than promise a date we can’t hit.
Being built around the SMB1001 framework ourselves, and holding ISO 27001 and ISO 42001 certification, means we’re not learning the standard as we go. We know what auditors look for because we’ve been through it. That doesn’t shorten every timeline, but it does mean less back and forth once you’re in the process.
Ready when you are – get in touch today.
Get a free 15-minute IT health check. OxygenIT is ready to help.
SMB1001 and Cyber Insurance Requirements Often Overlap
Most business owners come to us for one of two reasons. Either their insurer is asking hard questions before renewal, or they want SMB1001 certification for a tender or client requirement. What they don’t usually expect is how much the two overlap. Insurers ask about multi-factor authentication, backups, endpoint protection, and staff training. SMB1001 asks about the same things, just organised into a formal framework with named controls.
That’s not a coincidence. Insurers built their underwriting questionnaires around the same baseline controls that frameworks like SMB1001 formalise. A business already working through SMB1001 certification is usually most of the way to answering an insurance questionnaire without extra work. We see this often enough that our Cyber Risk Assessment covers both from the start, rather than treating them as separate exercises.
- Multi-factor authentication on email and remote access, checked by both insurers and SMB1001 assessors
- Documented backup and disaster recovery processes, not just backups running in the background
- Staff security awareness training records, since untrained staff are a common gap insurers flag
- Password management practices across the organisation, not just on paper policy
- Evidence of a firewall and endpoint protection setup that’s monitored, not installed and forgotten
Where it gets confusing is when a business already has cyber insurance and assumes that means they’d pass a SMB1001 audit, or the other way round. In our experience that’s rarely true. Insurance renewal forms are self-reported. SMB1001 requires evidence. A business can tick a box on an insurance form believing it’s covered, then find during an audit that the control isn’t documented the way an assessor needs it documented. That gap is common, and it’s just a different bar, not a sign anything was done wrong.
We run a Cyber Risk Assessment early, before quoting any work, specifically to find those gaps against both standards at once. From there we put together a proposal based on what’s missing, not a generic package. If cost is part of your decision, our pricing guide breaks down what different levels of cover typically involve.
If you’re weighing up certification against an insurance renewal deadline, our SMB1001 Certification Support page covers how the 90 day process works from first call to Gold level.
Watch Our Video
OxygenIT
Certification Needs Ongoing Maintenance After It’s Issued
A lot of business owners treat certification like a project with an end date. It isn’t. SMB1001 is built around controls that have to keep working, not just exist on the day an assessor checks them. That catches people off guard, because most of the sales conversation happens before certification and most of the maintenance conversation happens after.
The first thing people notice is that the paperwork side doesn’t stop. Policies need reviewing, access lists need trimming when staff leave, and security awareness training needs repeating rather than run once and filed away. None of this is unusual. It’s how the framework is designed to work, because a control that was true six months ago isn’t automatically true today.
Why this happens is straightforward. Staff turn over, software gets added, new laptops get issued, and old ones don’t always get wiped properly. Every one of those small changes can quietly move a business out of alignment with the standard it was certified against. We’ve seen businesses pass an assessment cleanly, then a year later have three new starters with admin rights nobody meant to give them.
Certification bought and then left alone tends to drift. It’s not a failure of the certificate itself, it’s just what happens when a compliance document sits still while a business keeps moving. A one-off audit isn’t the same thing as ongoing management.
What we do about it is built into how we work day to day. Our Cyber Risk Assessment process happens up front, but the controls it uncovers, things like multi-factor authentication setup, password management, and firewall management, need monitoring, not a single fix. Our New Zealand team in Christchurch answers the phone in an average of 11 seconds during business hours, and after-hours cover is an optional add-on staffed by our United Kingdom team, which matters when something needs actioning quickly rather than queued.
- Policy and access reviews on a regular cycle, not a one-time signoff
- Security awareness training repeated, since a single session doesn’t hold
- Device and user changes tracked so certified controls stay accurate
- Firewall and endpoint settings checked rather than assumed static
This isn’t a sign certification is fragile. It behaves like a live system, similar to how our own ISO 27001 and ISO 42001 certifications require continued conformance, not a single audit. If you want to see how ongoing management fits into the bigger picture, our SMB1001 Certification Support page covers how that work gets structured over time.
SMB1001 Certification Support: Frequently Asked Questions
What’s the most common gap you find when we start the assessment?
The most common gap is multi-factor authentication missing from email, even when antivirus is running on every machine. We also see backup routines nobody has tested in the last year. These gaps show up during the Cyber Risk Assessment, not before, and they don’t mean anything went wrong on your end. Security tends to drift once a business grows past 20 to 30 staff and nobody owns it full time.
Do we need to fix problems ourselves before we call you?
No, you don’t need to fix anything before we start. We set up Multi-Factor Authentication, Password Management, Security Awareness Training, Firewall Management, and tested backups as part of closing the gaps we find. The Cyber Risk Assessment tells us what needs work first, and we build the proposal around that, rather than selling every service at once.
What if the assessment finds more gaps than we expected?
We build the proposal around the gaps we find, not a fixed list decided in advance. That can mean more work than a business expected going in, or less. We won’t push a business toward Gold if Bronze genuinely covers their exposure, since that’s added cost and time for no real gain.
Will finding gaps push our certification timeline out?
It can, depending on your starting point. The 90 day figure for SMB1001 Gold is a target, not a guarantee for every business. A business already running Multi-Factor Authentication, a password manager, and some staff training starts closer to that mark than one with none of that in place. We don’t know your timeline until the Cyber Risk Assessment tells us where you stand.
Is SMB1001 Certification Support right for a small team just starting out?
It depends on staff count. We don’t take on residential clients or businesses under five staff, because the framework and the ongoing management behind it are built for a workforce, not a single laptop. If that’s where your business is at, SMB1001 through our Cyber Security Consulting isn’t the right starting point yet.
Related reading