Can we start Free and upgrade later?
Yes. Most customers start Free to test contract clauses and supplier messaging, then upgrade to Starter or Professional once they are ready to scale.
Do our suppliers pay anything?
Yes. Suppliers pay a small, proportionate fee for the certification level you request. This can be as little as $95 for Bronze. CyberCert credit bundles are included from the Starter license, so suppliers can get started at no cost - typically applied at pilot stages only.
How long does it take for a supplier to get certified?
It depends on supplier readiness. There are many cases of certification taking just days for Bronze and Silver, and up to a few weeks if there are many gaps against the requested level. The ecosystem of specialists, vendor bundles, and insurance bundles can reduce the time significantly.
What if a supplier's certification expires?
CyberCert alerts SMBs 90 days before expiry and continues to alert them as expiry approaches. Professional and Enterprise tiers include automated renewal campaigns. Enterprise customers using implementation partners can request custom renewal management.
Can we require different certification tiers for different supplier risk levels?
Yes. That is the intended model. Many customers require Bronze and Silver for lower-risk suppliers, Gold for medium-risk suppliers, and Platinum or Diamond for higher-risk suppliers. Professional and Enterprise tiers support custom tier-by-risk-level mapping.
What happens if a certified supplier has a breach?
Gold includes incident response requirements. You can also require supplier notification through your incident management and contract processes. It is common to mandate Silver plus insurance as a baseline. Enterprise customers working with implementation partners can tailor this to your requirements.

Closing the supply chain cyber gap by removing the burden on SMBs and providing verifiable proof of security for every supplier.
Supply chain assurance in days, not years.
nth Party Scale.
Zero Friction.
Fit-for-purpose
for any industry.
A predictable, scalable, Two-Tiered approach that provides the right level of assurance for every supplier segment:
High-assurance certifications like ISO/IEC 27001 and SOC2, enhanced by automated data and evidence validation.
Standardized, proportionate certification via the DSI SMB1001 standard.
Requires a robust, certifiable baseline like ISO/SOC 2, which can be paired with automation to check what's under the hood (data/evidence validation).
Requires a prescriptive, proportionate certification that validates the controls themselves, not the paperwork around them.
ISO/IEC 27001, SOC 2 mandated
Mandatory evidence validation; automated where possible
SMB1001 (Platinum/Diamond Tiers)
Highest assurance, independently verified
ISO/IEC 27001, SOC 2 preferred
with automated TPCRM Questionnaire alternative. Discretionary validation; automated where possible
SMB1001 (Gold Tier)
Covers the most common cyber compliance criteria for SMB suppliers
Light-touch self-assessment
SMB1001 (Bronze/Silver Tiers)
Base hygiene at Bronze, Cyber Insurable at Silver
