The cybersecurity industry failed SMBs. SMB1001 is the apology.
Let's be uncomfortable for a minute. For two decades, cybersecurity failed small- and medium-sized businesses (SMBs). Not maliciously. We built genuinely good technology, wrapped it in a vocabulary nobody outside the industry speaks, priced it for organisations with an internal IT team and a procurement team and then told the local accounting firm with 14 staff members to get serious about their security posture.
So the 14-person firm goes looking. What it finds is "EDR," "XDR," "MDR," "ITDR," "ISPM," "SIEM," "SOAR," "ZTNA" and a vendor at a trade show explaining their platform is "AI-native, agentic and consolidates 17 point solutions." Meanwhile, all the owner is doing is quietly wondering if anyone's backing up the file server. None of those categories is fake. Plenty are ours. The failure was deciding that the buyer had to learn our vocabulary before they were allowed to be safe.
Then someone hands them a framework built for an organisation 200 times their size. Telling them, "Just do ISO 27001," is a bit like telling someone who wants to get fitter to run a marathon on Saturday. Technically correct. But in reality, they read the phrase "information security management system," close the laptop and go back to running their business.
Every day across APAC, it's not resistance but paralysis. SMBs aren't refusing to do security. They simply don't know where to start. They've been burned by shiny things before, and every framework they open assumes they have resourcing they'll never have. We made security expensive and secretive, then acted surprised when SMBs became the softest target in the supply chain.
What if a security standard actually has a finish line?
This is where SMB1001 comes in. I've spent the last few months in the trenches with Sales Engineer Luca Gennai mapping it against Huntress.
SMB1001 is a tiered cybersecurity certification standard built specifically for SMBs. It's published by Dynamic Standards International (formerly Cyber Security Certification Australia), a not-for-profit standards body with an office in Canberra. It launched in 2023 and went international in January 2025. The current edition, SMB1001:2026, became certifiable on 1 January 2026.
It's broken into five tiers: Bronze, Silver, Gold, Platinum, and Diamond. Bronze covers around seven fundamental controls, mainly the things everyone already knows they should do.
Each tier layers controls across five areas: technology management, access management, backup and recovery, policies and procedures and education and training. Bronze through Gold rest on a director's attestation. Platinum and Diamond bring in independent verification.
Here's why SMB1001 beats a binder:
It's non-subjective. Controls are implemented or they're not. No scoring rubric, no partial credit and no creative interpretation, which makes one business' certificate comparable to another's.
You can start and finish it. A small business can achieve Bronze and have something real to show for it. No 18-month programme that stalls out halfway.
It scales to capacity, not ambition. Most businesses don't need Diamond, and the standard doesn't pretend otherwise.
It updates annually. It's "dynamic." Less a certificate on the wall and more a yearly service.
The certificate is publicly verifiable. A trust conversation becomes a 10-second check.
"Community-led" is usually marketing. Here it's structural.
The standard is written by the people who have to deliver it. DSI runs SMB1001 through a steering committee stacked with MSP industry bodies and practitioner organisations, all of whom revisit it every year rather than every five. When the people working at the coalface get a vote on what the controls say, you get requirements that survive contact with a real 20-person business.
The standard setter isn't the certifier. DSI writes SMB1001, but CyberCert certifies against it, with independent verification organisations involved at the audited tiers. Keeping those roles apart is deliberate, and it's the same separation the big schemes use.
The funding model is the clever part. MSPs and technology partners deliver it, and the SMB pays for its own certification. An enterprise worried about its supply chain can write "all suppliers must hold Silver or above" into a contract, verify it in seconds and pay nothing per supplier. Then a Tier 1 supplier can require the same of its own Tier 2s.
That's the piece questionnaires never solved. Most supply chain assurance today is a spreadsheet emailed to hundreds of suppliers who self-report once, after which everyone files it and moves on. That's paperwork, not assurance, and it doesn't scale. Regulatory pressure keeps landing on the big end of town (SOCI here, NIS2 in Europe, prime flow-down in the US) while the actual weak point sits three tiers down, in a business that was never in scope. Affordable, verifiable, cascading certification is the only version of this that works.
So, where does Huntress actually sit on the tier map?
Luca Gennai and I worked through SMB1001:2026 tier by tier, control by control, asking: where does Huntress directly meet a control, where do we materially support one and does the right answer live somewhere else in the stack?
Bronze and Silver mostly ask whether controls exist. This means firewalls, patching, backups, device password policy, individual accounts and MFA on email. Prevention is the floor, and much of that floor sits with the MSP and with Microsoft-native tooling, which is exactly where it should sit. What changes the outcome is whether anyone is watching those controls hold up in production, which is where we come in.
Managed SAT is a direct hit here, because SMB1001 wants training with proof it happened, and completion reporting that becomes your evidence. Managed EDR does the evidentiary half of the antivirus control, reporting the AV status on every managed endpoint with richer detail and managed policy for Microsoft Defender and anything else surfaced as "Other AV." When an assessor asks you to prove AV is running everywhere, that should be a dashboard, not a stocktake. The same agent reports Windows firewall status for the firewall control.
From Silver up, identity is the real story. Managed ISPM defines the target configuration across Entra ID, Exchange, SharePoint and Teams and manages Conditional Access with pre-deployment impact analysis. From there, it keeps watching, catching drift within minutes and rolling settings back if a change causes trouble. Managed ITDR sits on top of the attacks that beat the correct configuration.
Something worth knowing before you assume this is handled: Huntress data shows more than 60% of tenants are missing over half of our recommended identity controls, even when other tooling is already in place.
Here's the honest version of that pitch: turning on MFA is Microsoft's job. Knowing it got bypassed is ours.
Gold is where the framework gets loud, and so do we. Control 1.12.0.0 names EDR, explicitly. Managed EDR plus our 24/7 SOC meets it directly. This is the strongest single mapping in the framework. The ongoing awareness campaign requirement is another direct hit for SAT.
Gold also asks for an incident response plan. The plan is the customer's document, in the customer's language, with the customer's sign-off. Then a real intrusion hits at 2:40am on a Sunday morning, and the gap between a certificate and an outcome is whether anyone is awake to run it. Our 24/7 SOC is. A plan nobody is staffed to execute is a PDF.
Platinum shifts the question from "do you have it" to "can you prove it runs." Independent verification enters the model, and always-on detection is the rare control that generates evidence simply by operating. Managed SIEM retains the log trail an assessor actually wants to examine.
Diamond names the service, not just the tool. Read control 1.12.1.0 slowly and it describes an operating model: endpoint detection, humans who respond to it, defined response timeframes. Managed EDR is the endpoint half, and our human-led 24/7 SOC is the MDR half. The response timeframes are contractual rather than aspirational. CyberCert still awards the certificate, but this is the tier where what we do stops being a nice-to-have.
No single vendor owns this list, and pretending otherwise is how trust breaks again
SMB1001 isn't product-shaped. It's business-shaped. It asks about firewalls and backups and DMARC records and visitor registers. That means no single vendor owns the whole thing, and pretending otherwise may help make the sale, but it costs trust later.
So here's the division of responsibility, out loud, before somebody's assessor asks for it.
Microsoft enforces. Huntress makes sure it holds. Entra is the enforcement plane for identity. Managed ISPM decides what good looks like, deploys it and then keeps it that way with continuous enforcement across Entra ID, Exchange, SharePoint and Teams. It also manages Conditional Access and catches drift in minutes, rather than at the next quarterly review.
Managed ITDR handles the attacks that beat correct configuration: token theft, session hijack, the login that's technically valid and completely wrong. "Configured" is a Tuesday. "Still configured" in March, and monitored when someone works around it, is the control.
Your RMM deploys. Huntress tells you where it mattered. Patch delivery belongs with Intune, Windows Update for Business or your RMM. What we bring is the other half of the vulnerability conversation: exposure that's actually present on actual-live endpoints, prioritised by what attackers are using this week rather than by CVSS in descending order.
The customer owns the policy. Our SOC owns the 3am. IR plans, invoice fraud procedures, cyber security and AI use policies are customer documents and customer decisions. Our job starts the moment one of them is needed, which is the entire reason the Gold and Diamond name a service and not a tool.
And a lot of SMB1001 is just the rest of the business. Backups, TLS certificates, SPF and DKIM and DMARC, encryption at rest, macro hardening, penetration testing, credential storage, visitor registers and cyber insurance. That work lives across the managed stack, the customer's documentation and their broker. An MSP that can walk a client up these tiers is selling something considerably more durable than a licence.
One guardrail to remember is that deploying a tool, ours included, doesn't confer a certificate. CyberCert assesses and awards it independently. Telling an SMB that installing an agent makes them Gold sets that business up for an awkward conversation with an assessor, and sets the whole standard back.
Three questions to ask on your next client call
You don't need a certification programme by Friday. You need better questions.
Are their customers already asking? Supplier security clauses are showing up in contracts well below the regulatory threshold. If a client lost a tender over a security questionnaire, they're ready for this conversation.
What are they already paying for? Most SMBs running a decent managed stack are closer to Bronze or Silver than they think. Count what's deployed before you quote what's missing.
Which rung do they actually need? Silver is the tier insurers tend to care about. Gold is where detection and response get named. Diamond is for a small minority, and selling Diamond to a bakery is exactly the behaviour that broke SMB trust in the first place.
Keep it simple…then keep it simple
SMBs were never the problem. Packaging was. SMB1001 works because it does the unglamorous thing of breaking security into rungs a small business can climb, in an order that makes sense, with something real to hand a customer at the end. Prevention is the floor and the framework stages the climb above it. Gold names EDR. Diamond names EDR plus a managed service. And identity is where everything from Silver up is won or lost.
Want the full tier-by-tier mapping, boundaries included? Book a Huntress demo and watch the SOC do the part that used to require a binder.
Running an MSP and want to turn this into a service line? Start with the Huntress partner page on CyberCert.
Questions on the mapping itself? Find me on LinkedIn. I'd be happy to walk through it with you.
SMB1001 is published by Dynamic Standards International. Certification is assessed and awarded independently by CyberCert. Huntress, DSI and CyberCert are independent companies.
The coverage described here reflects how individual Huntress capabilities meet or support specific SMB1001:2026 requirements. It is not a claim of complete framework coverage, and it does not confer certification, insurance eligibility or regulatory compliance. It isn't legal advice either.