Cyber Essentials. ISO. NIS2. CyberCert + SMB1001.
Finally, the global ecosystem fits together.
TL;DR
CyberCert + SMB1001 is the missing layer between Cyber Essentials and ISO —
the second string to the bow for CE partners and MSPs.
International: works across borders, sectors, and supply chains.
Certifiable: independent, non-subjective proof of proportionate security.
Scalable: built for thousands of SMBs through partner-powered delivery.
Tiered Pathway: Bronze → Diamond maturity progression aligned to real SMB capacity.
Insurable: recognised by brokers and carriers, unlocking cyber cover at Silver+.
Gap Filler: the bridge between CE hygiene and enterprise governance frameworks.
Perfectly complements Cyber Essentials.
Finally gives SMBs a practical, certifiable path forward.
Unlocks new growth opportunities for partners and SMBs that cross borders.
The UK and EU already have strong cybersecurity standards:
Cyber Essentials gives SMBs the essential technical foundation.
ISO 27001 provides a full ISMS for organisations that need enterprise-grade governance.
NIS2, GDPR, and the upcoming Cyber Security & Resilience Bill raise expectations on supply chain assurance and verifiable maturity.
Each part plays an important role.
But there has always been a missing link — something between “basic hygiene” and “enterprise grade” that is actually built for SMB realities, not corporate budgets.
That’s where SMB1001 and CyberCert sit:
the complementary layer that connects all these standards into a practical, scalable path for SMBs.
The Gap: Not Every Business Needs ISO, Not Every Business Should Stop at Cyber Essentials
Cyber Essentials is foundational — a non-negotiable hygiene layer. Especially UK SMBs that supply to Government.
ISO is powerful — a full management system for organisations that need it.
But the majority of SMBs live in the middle:
too small for ISO overhead,
too exposed for just Essential controls,
too important to supply chains to be ignored,
too often targeted by ransomware, BEC, social engineering, and vendor impersonation.
What they’ve been missing is a proportional, certifiable, non-subjective way to prove they’re secure – without stepping into enterprise-grade frameworks they’ll never adopt.
SMB1001 is that bridge.
CyberCert is the independent certifier that makes it real.
SMB1001: The “Pathway Layer” the Market Has Needed for Years
SMB1001 doesn’t replace Cyber Essentials or ISO.
It complements them — filling the space between them.
It gives SMBs:
a clear progression from CE hygiene → Policy, process, continuity, identity, training
a tiered path (Bronze → Diamond) that aligns to real business maturity
controls that map to NIS2, GDPR expectations, NIST, and ISO
a practical pathway for long-term continuous improvement
an international, certifiable standard designed for cross-border adoption
This way, SMBs don’t need to choose between “too little” and “too much.”
They can mature predictably, proportionately, and visibly.
Certification: The Missing Ingredient for Supply Chain Confidence
Most frameworks tell you what to do.
Very few independently verify you did it.
That’s the power of SMB1001 with CyberCert:
Non-subjective controls – either implemented or not
Independent verification at higher tiers
Demonstrable proof that proportionate security is in place
Recognised by insurers, supply chain programs, and risk teams
Designed for automation through MSPs and technical platforms
Auditable reporting at Platinum/Diamond without ISO complexity
This is not a replacement for ISO or CE.
It’s the assurance layer that makes the whole system scalable.
The Ecosystem Finally Has Its Glue
(And it’s partner-powered by design)
Every major framework plays a role:
Cyber Essentials → baseline technical hygiene
SMB1001 → scalable, proportionate, certifiable uplift
ISO 27001 → full ISMS maturity for those who need enterprise governance
CyberCert sits in the middle as the independent certifier, while MSPs, insurers, and technology vendors handle implementation and technical uplift.
This creates:
a predictable, repeatable path for SMBs
a trusted assurance signal for enterprises
a scalable model for MSPs
a risk-reduction engine for insurers
a common language for cross-border contracts
No competition. No duplication.
Just alignment.
CyberCert and SMB1001 are the “sand in the jar” — the complementary layer that fills the space between the stones, allowing Cyber Essentials, ISO, NIS2, GDPR, CMMC and supply chain programs to finally connect into a single, scalable, SMB-friendly assurance ecosystem.
👉 Become a CyberCert Partner at no cost at https://partners.cybercert.ai/msp


