All Articles

SMB1001 Gold for QLD Law Firms: The QLS-Endorsed Cyber Certification Pathway

Michael Jordison Michael Jordison
·

A corporate client sends your firm a panel questionnaire. Page three, question 14: “Please provide evidence of current cybersecurity certification (SMB1001, ISO 27001, or equivalent).” Your practice manager pauses. The firm runs Microsoft 365, has antivirus on the laptops, and an IT guy who “handles it.” None of that is a certification. You’re about to lose a tender over a line item most partners hadn’t heard of twelve months ago.

This is happening across Brisbane, the Gold Coast, and the Sunshine Coast right now. And the Queensland Law Society has already told you what to do about it.

What is SMB1001 and why does QLS care?

SMB1001 is an Australian cybersecurity certification standard built specifically for small and mid-sized businesses. It’s published by Dynamic Standards International (DSI) and certified through CyberCert. There are five tiers: Bronze, Silver, Gold, Platinum, and Diamond, each layering more controls on top of the last.

The Queensland Law Society formally endorsed the standard and points members at it through its resource centre. Their position, paraphrased: SMB1001 is a way for members to take practical steps to protect confidential client information, and Gold is the level QLS recommends as a reasonable target.

QLS also ran a sponsored deal with CyberCert and Cyber Wardens through mid-2025 that gave members a free Silver subscription voucher. That offer has closed, but the endorsement and the recommended target (Gold) remain.

Why QLS? Because law firms have an ethical duty under the Australian Solicitors Conduct Rules to take reasonable steps to protect client confidentiality. When your regulator’s own ethics special counsel publicly recommends a certification, “we thought we were okay” stops being a defence.

Why Gold, not Silver or Bronze?

Bronze and Silver are the floor. They prove you’ve done the basics: MFA on email, a password manager, staff training, working backups, patched servers. Useful, but not differentiating. Every coffee shop and dental practice in Queensland can hit Bronze.

Gold is the level that matters for a professional services firm holding client trust accounts, privileged communications, and sensitive commercial information. It’s also the level insurers, corporate clients, and government panels are starting to reference in security questionnaires.

Under SMB1001:2026 (the current edition), Gold requires 27 controls across five domains: Technology Management, Access Management, Backup and Recovery, Policies and Processes, and Education and Training. A few of the Gold-specific requirements worth naming:

  • Endpoint Detection and Response (EDR) with behavioural detection and automated response. Not plain antivirus. Not “Defender, she’ll be right.”
  • DMARC enforcement on your email domain so attackers can’t spoof partner@yourfirm.com.au to your clients.
  • Immutable or air-gapped backups that a ransomware operator can’t encrypt even with domain admin.
  • Server patching discipline with documented cadence and evidence.
  • Cyber insurance is now mandatory at Gold (which most firms already carry, but the policy documentation has to exist).
  • Director-level attestation. Gold is self-attested by a director, not externally audited. That puts personal accountability on the line, but it also means the integrity of the certification depends on the firm being honest about what’s actually in place.

Gold isn’t hard because the controls are exotic. It’s hard because most firms don’t have the evidence, the policies, or the governance documentation to prove they actually do what they think they do.

How does SMB1001 relate to Essential Eight and ISO 27001?

Three different audiences, three different answers.

Essential Eight is the Australian Signals Directorate’s list of eight mitigation strategies with maturity levels 1 to 3. Technical, narrow, and the baseline most Commonwealth tenders and insurers reference. SMB1001 maps cleanly to Essential Eight controls and covers the same technical ground at the Gold level, plus governance and training Essential Eight leaves out.

ISO 27001 is the international heavyweight. Full information security management system, audited externally, typically 6 to 12 months and $40K+ to certify for a small firm. Overkill for a 20-lawyer practice until a major bank client demands it.

SMB1001 sits between them. It’s formal, certifiable, and recognised, but proportional to the size of a professional services firm. Firms that reach Gold or Platinum arrive at ISO 27001 (if they ever need it) with most of the policies, procedures, and training already in place. It’s a stepping stone, not a dead end.

What does it actually cost?

The certification subscription through CyberCert is intentionally cheap. Current pricing: A$95 per year for Bronze, A$195 for Silver, and A$395 for Gold. Annual renewal, not a one-off.

The subscription fee is not the real cost. The real cost is the uplift work: configuring EDR properly, deploying a centrally managed password manager with MFA, fixing your backup architecture so it’s genuinely immutable, writing the policies, and running the training. For a 10 to 20-lawyer firm that’s already on Microsoft 365 Business Premium, this is typically a 6 to 10-week project, not a 6-month overhaul.

If your IT provider is an Acronis MSP partner, there’s also the Acronis-sponsored CyberCert Gold credits program launched in late 2025, where Acronis covers the cost of the Gold certification credit for eligible clients. That doesn’t eliminate the uplift work, but it can take the recurring subscription fee off the table. Worth asking your provider whether they’re enrolled before you assume access.

The tender and insurance angle

This is the lever that will actually move partners.

Corporate clients, insurers, and government panels are increasingly writing cyber certification into their security questionnaires. We’ve fielded panel questionnaires that ask specifically for SMB1001, Essential Eight maturity level, or ISO 27001 evidence. A year ago, the question was “do you have antivirus?” Increasingly it’s “attach your certificate.”

Cyber insurance renewals are running the same playbook. Insurers now want to see MFA coverage, EDR deployed, immutable backups tested, and evidence of staff training. A firm holding SMB1001 Gold walks into renewal with all of that documented. A firm without it is filling out a 40-page questionnaire and negotiating premium increases based on gaps.

We’ve written about this before in how to survive a cyber insurance compliance audit. The short version: insurers are auditing applications now, not just claims. If what you said on the form doesn’t match what’s actually deployed, you’re uninsured when it counts.

Which QLD law firms are already certified?

Honestly, I haven’t seen a public list yet. The certification register on CyberCert shows many Australian SMBs, but firms don’t always publicise legal sector certifications on their websites unless they’re using it as a marketing differentiator. That’s the opportunity.

Being one of the first 10 to 20 firms in Brisbane and the Gold Coast to visibly hold SMB1001 Gold is a competitive advantage you can put on your tender submissions, your website footer, and your client onboarding material while the rest of the market is still debating whether to start. First movers on professional credentials always eat best.

How long does certification actually take?

For a firm that already runs Microsoft 365 Business Premium and has a working MSP relationship, a realistic Gold timeline is:

  • Week 1 to 2: Bronze and Silver self-assessment. Identify gaps in MFA coverage, password management, backup, training, documentation. Most firms discover half the controls they “thought” they had are missing or misconfigured.
  • Week 3 to 5: Technical uplift. Deploy EDR, configure DMARC, fix backup immutability, roll out a centrally managed password manager with MFA, lock down admin accounts.
  • Week 6 to 8: Policy, process, and training. Written incident response plan, access control policy, acceptable use policy, annual staff security training, documented vendor management.
  • Week 9 to 10: Evidence collation, director attestation, Gold certification issued.

Faster if your foundation is already solid. Slower if your backups aren’t tested, your 365 tenancy was configured by the cheapest available provider in 2019, or nobody has touched Conditional Access since it was deployed.

What you should do this week

  1. Start a Bronze self-assessment today. Register at cybercert.ai and work through the Bronze questionnaire. It’s free to begin and will tell you in two hours whether your firm meets the basics.
  2. Audit your MFA coverage. Every staff member, every service, every admin account. Not “most of us have it.” All of you, everywhere, with phishing-resistant methods where possible. See our note on token protection in Microsoft 365 for why SMS MFA isn’t enough anymore.
  3. Check your backup architecture. If your backups live in the same tenant as your live data and a compromised admin can delete them, you don’t have backups. You have a single point of failure with extra steps.
  4. Get a written cyber policy. Even a two-page document covering acceptable use, incident reporting, and password handling. Gold demands documentation, and “we have policies in our heads” doesn’t count.
  5. Book the uplift before your next insurance renewal. Walk into the renewal with Gold in hand and watch the questionnaire shrink and the premium conversation shift.

If you’d rather not untangle the Gold control list yourself, our SMB1001 certification service runs the full SMB1001 gap assessment, delivers the uplift plan, implements the technical controls, and takes you to certification. We work with accounting and legal firms across SE QLD specifically, so we know what your clients, your regulator, and your insurer actually look at.

Not sure where your firm sits? Book a conversation. We’ll give you a straight read on the gap between where you are and Gold, what it will cost to close it, and whether it’s worth doing before your next tender.

Straight answer, no surprises.

Michael Jordison

Need to prove where you stand?

Compare Essential Eight, SMB1001 and DISP side by side, and see the evidence each one expects you to produce.

More on this: Compliance articles · Cyber Compliance