SMB1001 · a 60-second explainer
A practical cybersecurity roadmap built for small business
SMB1001 is a cybersecurity standard designed specifically for small and medium businesses. It provides a clear pathway from getting the basics right to building a mature, independently verified cybersecurity program.
What is SMB1001?
SMB1001 is a cybersecurity standard published by Dynamic Standards International (DSI). It was built around how smaller businesses actually operate — limited time, no security specialist on staff, and a budget with other jobs to do — rather than being an enterprise framework trimmed down to fit.
What it does well is turn cybersecurity from an open-ended worry into a sequence. There are five levels, Bronze through Diamond, each building on the one before. You start from where you actually are, not from where a checklist assumes you should be.
It is reviewed and updated as threats and technology change, so the guidance doesn't quietly go stale.
The five levels
Each level assumes the one below it is already in place, so the order does a lot of the thinking for you.
Bronze
Get the essential protections in place.
Silver
Strengthen accounts, access and business processes.
Gold
Establish a structured, documented cybersecurity program.
Platinum
Introduce more advanced protection and independent assurance.
Diamond
Demonstrate highly mature, continuously managed security.
What does this mean for your business?
You do not need to become a cybersecurity expert or aim for the highest level immediately. The value of SMB1001 is knowing where you are, deciding where you need to be, and having a sensible order in which to improve.
Understand which protections matter most
The short list of things that actually reduce your risk, separated from the noise.
Prioritise improvements without trying to fix everything at once
A defensible order of work, so progress fits around running the business.
Demonstrate progress to customers, insurers and business partners
Something concrete to point at when somebody asks what you have in place.
How SteadyPoint uses SMB1001
SteadyPoint uses SMB1001 as a practical roadmap to help small businesses understand their current position, identify priority gaps and decide what level of protection is appropriate for their risk.
The SteadyPoint Cyber Checkup is a simple starting point. It shows where your business may be exposed and which actions deserve attention first.
Common questions
Do I have to become certified?
No. A business can use SMB1001 as an improvement roadmap without immediately pursuing formal certification.
Which level should I aim for?
That depends on the information you hold, your customers, contractual and insurance requirements, and your appetite for risk — not simply your employee count.
Can SteadyPoint help me get started?
Yes. The Cyber Checkup helps you understand your present position and identify the actions that deserve attention first.
SMB1001 is published by Dynamic Standards International (DSI). SteadyPoint uses the standard as an educational and cybersecurity improvement framework. Formal certification is issued separately through authorised certification organisations.