Cyber security certification

SMB1001 Certification for New Zealand Organisations

SMB1001 is a practical, five tier cyber security standard built for organisations like yours, certified through CyberCert. We hold SMB1001 Gold ourselves, and we take our clients up the same ladder: clear controls, honest evidence, and a certificate you can show your insurer, your customers and your board.

Why it matters

Good security deserves proof

More of the people you deal with are asking how your organisation manages cyber risk. Insurers ask at renewal time. Larger customers ask during procurement. Boards ask because they are accountable for the answer. Most organisations that are doing the right things still have no simple way to show it.

SMB1001 changes that conversation. Written specifically for small and mid-sized organisations and certified through CyberCert, it sets out practical controls across five achievable tiers, and the standard is refreshed every year so the controls keep pace with real threats. It is used by organisations on both sides of the Tasman, and it sits comfortably alongside our cybersecurity services rather than replacing them.

Instead of saying we take security seriously, you answer with a current certificate and the evidence behind it.

The five tiers

A ladder you can actually climb

Start at the tier that fits how you operate today, certify, then step up when it makes sense. Each tier builds on the one below it.

Bronze

The foundations: firewalls, automatic updates, backups and sound password practice. A first structured step that any organisation can reach quickly.

Silver

Adds day to day operational discipline: tighter access control, staff security awareness and stronger recovery practice for growing teams.

Gold

The tier most organisations aim for. Twenty seven controls across technology, people and process, including multi factor authentication, endpoint detection and response, email authentication, offline backups, an incident response plan and a responsible AI policy, signed off by a company director.

Platinum

Independently audited assurance for organisations with higher obligations, building on everything Gold requires.

Diamond

The most comprehensive tier, independently audited, for organisations whose customers and regulators expect the highest standard of care.

Already a managed client?

You are closer than you think. The controls we already run for managed IT clients cover much of what Gold asks for, so certification is mostly evidence, policies and sign off rather than new spending.

The pathway

From where you are now to a certificate you can show

It starts with a gap assessment. We map your current environment against the tier you are aiming for and give you a plain English picture of what is already in place and what is missing. No jargon, no scare tactics, just a clear list.

Then we close the gaps in a planned piece of work: the technical controls, the policies written with you rather than handed to you, and the staff awareness that makes the controls stick. The current edition of the standard asks every certified organisation for a responsible AI use policy, and that control is written with our AI enablement practice, people who work on AI governance every day.

When the controls are in place we assemble the evidence pack, a company director signs the attestation through the CyberCert platform, and your certificate is issued.

Staying certified is the part that matters most. The standard is updated every year and certification renews annually, so for managed clients we fold recertification into the ongoing agreement. Your certificate stays current as the standard moves, rather than becoming a yearly scramble.

Why IT Works

We only ask of you what we prove ourselves

We hold SMB1001 Gold, and you can verify our certificate with CyberCert. Independently of that, our own operations are audited to SOC 2 Type II, one of the more demanding assurance standards available, so we know what living with a standard means, not just what reaching one takes.

That matters when you are choosing who to climb the ladder with. The pathway is delivered by the same Wellington based team that runs managed technology for organisations across New Zealand, and every recommendation we make is one we already follow ourselves.

Common questions

Questions we get asked about SMB1001

Short answers. Ask us for the longer ones.

What is SMB1001?

An international cyber security standard written specifically for small and mid-sized organisations, with five certification tiers from Bronze to Diamond. It is certified through the CyberCert platform and updated every year so the controls track current threats rather than a fixed snapshot.

Is it an audit?

Bronze, Silver and Gold are attested: a company director formally signs that the controls are in place, supported by an evidence pack. Platinum and Diamond add independent audit. We prepare the evidence with you either way, so the signature is one you can stand behind.

Will it help with our insurance?

It changes the conversation. The questions underwriters ask are answered with a current certificate and evidence rather than a best guess. What that does to your terms is between you and your broker, and we are happy to work alongside them.

How long does it take?

It depends where you start. Organisations with well run technology often reach Gold within one to three months, and the gap assessment gives you a clear picture before you commit to anything.

Next step

Ready to prove what you are already doing well?

A short conversation tells you which tier fits your organisation and how far along you already are. No pitch, no pressure.