SMB1001 FAQs

What is SMB1001?

SMB1001 is a multi-level cybersecurity certification framework designed specifically for small and medium-sized organizations. The SMB1001 framework provides a structured and affordable way for smaller companies to develop and demonstrate cybersecurity maturity over time, instead of trying to comply with resource-heavy standards in a single step.

What are the tiers of SMB1001?

The tiers of SMB1001 represent progressive levels of cybersecurity maturity for small and medium-sized businesses. The framework uses five tiers – Bronze, Silver, Gold, Platinum, and Diamond. Each tier builds on the one before it, providing a clear path from baseline protections to advanced cybersecurity.

What is the difference between ISO 27001 and SMB1001?

The difference between ISO 27001 and SMB1001 is that ISO 27001 is a comprehensive information security management standard that requires significant documentation, governance processes, and certain resources.

The SMB1001 adapts similar principles into simpler and more practical controls for small and medium organizations. SMB1001 offers a tiered approach with achievable requirements that smaller teams can implement and improve over time.

What is the difference between SMB1001 and the Essential Eight?

The difference between SMB1001 and the Essential Eight is that the Essential Eight outlines eight technical mitigation strategies focused on reducing common cyber risks, while SMB1001 is a full cybersecurity framework.

Essential Eight covers areas such as patching, multi-factor authentication, and backups. SMB1001 takes a broader approach that includes processes and technical controls such as email authentication with SPF, DKIM, and DMARC. SMB1001 also provides a multi-level certification path designed to be practical for small and medium-sized companies.

Resources