← Getting Started Getting Started

Someone asked if you're SMB1001 certified. Before you can get certified, you need to know where you stand.

SMB1001 is the ASD's cybersecurity framework for small businesses β€” 12 Bronze controls that cover the most critical security practices. This readiness assessment tells you exactly which controls you already meet, which you don't, and what it would take to close the gaps. No system access required. Delivered in under two weeks.

Find out where I stand Binary pass/fail against all 12 controls. Fixed fee.

Four situations that lead to this assessment

"A client's vendor onboarding asked whether we hold SMB1001 Bronze certification. No one in the business knew what it was."

The question has been asked. Now you need to know if you can answer it.

"A tender we're bidding on listed SMB1001 certification as a preferred attribute. A competitor already has the badge."

Certification is becoming a differentiator. Starting now gives you an advantage.

"I saw the CyberCert accreditation badge on a competitor's website. How did they get it β€” and can we get it too?"

Most businesses are closer to certification than they think.

"Our insurance broker mentioned SMB1001 as a way to reduce our cyber premium at next renewal."

Certification signals verified security hygiene β€” insurers notice.

Your MSP handles the technology. But technology is only part of the picture. SMB1001 certification covers controls that span people, processes, and systems β€” including areas your MSP isn't responsible for. The readiness assessment tells you the complete picture.


12 ASD Bronze controls β€” assessed against each one

Every control is assessed as pass or fail. No partial scores, no estimates. You know exactly what you meet and what you need to fix.

1

Multi-factor authentication

2

Unique credentials per service

3

Automatic application updates

4

Automatic operating system updates

5

Automated backup and recovery

6

Security software on endpoints

7

Phishing-resistant email configuration

8

Admin account management

9

Secure configuration of accounts

10

Device and data encryption

11

Staff security awareness

12

Incident response capability


Plain language. Binary answers. Clear path forward.

βœ“

SMB1001 Readiness Report

Binary pass or fail against each of the 12 Bronze controls, with the evidence used and the basis for each result. No ambiguity about where you stand.

πŸ“Š

Gap summary with effort estimates

A plain-language statement of which controls need work, what each gap means in practice, and what it would realistically take to close it β€” policy, configuration, vendor change, or something more involved.

β†’

Certification recommendation

A direct statement: proceed to certification now, or address these specific gaps first. With the reasoning. So you know whether you are weeks away from the badge or whether there is more work to do.

πŸ“ž

30-minute debrief call

Walk through the findings, ask questions about specific gaps, and understand exactly what the certification process looks like from where you are now.


Questionnaire and evidence review β€” no system access

Book and pay β€” no call required

Use the pricing configurator below to get your fixed price and book directly.

30-minute kickoff call

We confirm scope and explain exactly what evidence is needed for each control β€” so there are no surprises when the questionnaire lands.

Questionnaire and evidence submission

Within 24 hours of kickoff, we send a structured questionnaire covering all 12 controls. You gather evidence at your own pace β€” typically three to five business days. We tell you exactly what to look for.

Report and debrief delivered

CyberCraft reviews your evidence against the ASD Bronze criteria and delivers the full report within five business days of evidence received. Debrief call included.


Fixed fee, tiered by organisation size

SMB1001 Readiness β€” Pricing Configurator

Three questions. Fixed price displayed immediately.

$990 β€” under two weeks
↳ Pricing configurator coming soon. Contact us to get your fixed price now.

Readiness leads directly to certification

In a Box

SMB1001 Certification

Your readiness report becomes the working input. No duplication of effort. We close the gaps and take you through to the CyberCert accreditation process.

SMB1001 Certification β†’
Getting Started

Essential Eight Scorecard

Enterprise clients asking about Essential Eight? This assessment runs in parallel and the gap work overlaps significantly.

Essential Eight Scorecard β†’

Most businesses are closer to SMB1001 Bronze than they think. Find out where you stand.

Start my SMB1001 readiness assessment

Binary pass/fail against all 12 controls. No system access. Under two weeks.

Kaurna Acknowledgement

We acknowledge and pay our respects to the Kaurna people, the traditional custodians of the ancestral lands on which we work. We acknowledge the deep feelings of attachment and relationship of the Kaurna people to country and we respect and value their past, present and ongoing connection to the land and cultural beliefs.