If your organization cannot pass a CMMC assessment today, that does not mean you are stuck with nothing. Tiered certification frameworks, including SMB1001, exist because the security world finally admitted that a ten person nonprofit and a ten thousand person prime contractor should not be handed the same checklist and told good luck.
This piece explains what SMB1001 actually is, what a tier system does and does not prove, and how a small team can build defensible maturity in the meantime. It is educational. Nothing here is a promise that any single certificate satisfies a federal contract requirement.
What is SMB1001, in plain language?
SMB1001 is a graduated cyber security certification standard written specifically for small and medium organizations. It is published by Dynamic Standards International and is best known in Australia, where it emerged in response to a simple observation: most small organizations were being pointed at frameworks built for enterprises with security departments.
The structure is what matters. Instead of one pass or fail bar, SMB1001 uses ascending tiers, commonly described as Bronze, Silver, Gold, Platinum and Diamond. Lower tiers cover foundational hygiene that a small team can genuinely accomplish. Higher tiers add documentation, testing and independent verification. An organization certifies where it actually is, then climbs.
To be direct about scope: SMB1001 is not a United States federal requirement, and it does not replace CMMC for anyone handling Federal Contract Information or Controlled Unclassified Information. What it offers is a credible, externally defined ladder, which is very different from a spreadsheet you wrote yourself.
Why does a tiered model work better for small teams?
Because binary frameworks produce paralysis. When the only two states are certified and not certified, an organization with limited staff looks at the gap, decides it is unreachable this year, and does nothing. Nothing is the outcome we see most often.
Tiers change the psychology and the practice. A first tier that asks for multifactor authentication, managed backups, patched systems, a password policy people actually follow and basic awareness training is achievable in weeks, not years. That work is not decorative. Those controls address the attack patterns that actually hit small organizations: credential theft, phishing, unpatched internet facing systems and ransomware.
This is not a fringe idea. The CIS Critical Security Controls use Implementation Groups for the same reason. NIST Cybersecurity Framework 2.0 describes tiers of rigor. The United Kingdom runs Cyber Essentials and Cyber Essentials Plus as a two step ladder. Australia's Essential Eight uses maturity levels zero through three. The pattern repeats because it works.
What is the first control you could realistically finish this month, not this year?
How does this compare to CMMC, honestly?
CMMC is a verification program, not a new control set. Its requirements come from FAR 52.204-21 at Level 1 and NIST SP 800-171 at Level 2, with selected NIST SP 800-172 requirements at Level 3. The CMMC Program rule sits at 32 CFR Part 170 and became effective in December 2024. The companion acquisition rule that places CMMC clauses into solicitations follows a phased approach, and because the schedule has shifted more than once, you should confirm current status in the Federal Register rather than trusting any blog, including this one.
The honest comparison looks like this. CMMC is mandatory for defense contractors in scope and is enforced through contract terms and the False Claims Act. SMB1001 is voluntary, commercially administered and carries no federal weight. They are not substitutes.
They are, however, compatible. Nearly everything in a lower SMB1001 tier maps to something in the seventeen FAR safeguarding requirements or the 110 requirements in NIST SP 800-171. Access control, identification and authentication, media protection, incident response, awareness training. Different vocabulary, same underlying hygiene. Work done at a foundational tier is rarely wasted work.
Who should look at a tiered certification instead of CMMC?
Three groups, in our experience.
Organizations with no defense work at all. Nonprofits, clinics, local suppliers and community organizations that will never touch CUI still need something to show a board, an insurer or a partner. A tiered certificate gives structure to a conversation that otherwise becomes we think we are fine.
Suppliers being pushed by customers rather than by regulation. If a larger partner is sending you a security questionnaire, a recognized tier answers most of it faster than freelance narrative.
Defense suppliers who are early in the journey. If a Level 2 assessment is two or three years away, you still have to start somewhere. A tier gives you a sequence, a deadline and an outside opinion. What you should not do is present a commercial certificate as CMMC compliance. That misrepresentation creates legal exposure far worse than being behind.
Not Sure Which Ladder You Are On?
If you are trying to figure out whether your path runs through CMMC, a tiered framework, or both, our in-kind readiness support is described at Cyber Grants Alliance.
See CMMC Guide →What should you do first, regardless of which framework you choose?
Start with scope. Write down what data you actually hold, where it lives and who touches it. Most small organizations discover their real problem is sprawl: three cloud storage tools, personal devices, a former contractor who still has access.
Then do the four things every framework asks for in some form. Turn on multifactor authentication everywhere it exists. Get backups that are tested and isolated. Patch on a schedule someone owns by name. Remove access when people leave.
Then decide on the ladder. If your driver is federal contracting, your ladder is FAR 52.204-21 and NIST SP 800-171, full stop. If your driver is partners, insurers or general resilience, a tiered scheme such as SMB1001, Cyber Essentials or the CIS Implementation Groups gives you a recognized path.
Which of those is actually driving you right now: a contract, a customer or a fear? The answer changes what you should do next. Our grant programs and resources cover both paths in more depth.
Frequently Asked Questions
Is SMB1001 accepted for CMMC compliance?
No. CMMC compliance is determined under 32 CFR Part 170 through self assessment at Level 1, and self assessment or a C3PAO assessment at Level 2, against FAR 52.204-21 and NIST SP 800-171. SMB1001 is a separate, voluntary commercial standard. Holding it may make CMMC preparation easier, but it does not satisfy the requirement or shorten the assessment path.
What are the SMB1001 tiers?
SMB1001 uses an ascending series of tiers commonly named Bronze, Silver, Gold, Platinum and Diamond. Lower tiers focus on foundational hygiene that a small team can implement directly, while upper tiers add formal documentation, testing and independent verification. Confirm current tier definitions with the publisher, since the standard has been revised.
Is SMB1001 recognized in the United States?
It originated in Australia and has its strongest recognition there. In the United States it carries no regulatory standing, and awareness among American buyers varies. If your goal is credibility with a specific customer or insurer, ask them which frameworks they recognize before you certify to anything.
What is the minimum a small organization should do if it cannot certify to anything yet?
Enable multifactor authentication on email and remote access, maintain tested and isolated backups, patch systems on a documented schedule, remove accounts promptly when people leave, and train staff on phishing. These five actions address the most common intrusion paths for small organizations and appear in essentially every framework.
Does CMMC apply to nonprofits?
Only if the nonprofit holds a Department of Defense contract or subcontract containing the applicable DFARS clauses and handles Federal Contract Information or Controlled Unclassified Information. Most nonprofits are outside that scope. They may still face requirements from grantmakers, state privacy laws or sector rules such as HIPAA.
Can foundational tier work count toward CMMC later?
Yes, functionally. Controls implemented at a foundational tier generally map to requirements in FAR 52.204-21 and NIST SP 800-171, so the underlying work carries forward. What does not carry forward is the certificate itself, and CMMC still requires its own evidence, System Security Plan and affirmation.
Sources: CMMC Program final rule, 32 CFR Part 170, Federal Register; FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems; NIST SP 800-171, Protecting Controlled Unclassified Information; NIST SP 800-172, Enhanced Security Requirements; NIST Cybersecurity Framework 2.0; CIS Critical Security Controls, Implementation Groups; Essential Eight Maturity Model, Australian Cyber Security Centre; Cyber Essentials scheme, UK National Cyber Security Centre; SMB1001 standard, Dynamic Standards International. Verify current version and tier definitions directly with the publisher.
