• About SCAP™
  • Toolkit
Login
  • About SCAP™
  • Toolkit
  • Login

For SMBs

  • Why Certify?
  • Certification Selector
  • Certifications

For Partners

  • CyberCert Amplify
  • CyberCert Verify
  • Substack

Supply Chain

  • SCAP™
  • Case Studies

More Info

  • About Us
  • Resources
  • Careers

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy

© Copyright 2022-2026, CyberCert. All rights reserved. Unauthorized reproduction or distribution is strictly prohibited.
The CyberCert name, logo, badges, and Know It. Show It., are registered trademarks of CyberCert Pty Ltd. SCAP™ is used under license.
Patents pending: 2023903514, 2023903509, 2023903507, 2023903506. All other trademarks and logos are the property of their respective owners.

Follow us

Your SCAP™
Activation Toolkit.

Everything you need to launch a whole-of-supply-chain cyber assurance program — from contract clauses and supplier comms to real-time verification. Built to run independently or alongside your CyberCert dashboard.

Enterprise-supported

Enterprise-supported

What This Toolkit Gives You.

A complete, ready-to-deploy activation pack for primes managing supplier cyber risk at scale.

Program Setup Guide

Phased rollout plan — from supplier segmentation to ongoing assurance. Run it independently or with a CyberCert implementation partner.

Tier Classification

Clear supplier segmentation — Tier 1 enterprise vs Tier 2 SMB, with risk-mapped certification requirements for High, Medium, and Low risk suppliers.

Contract Clauses

Ready-to-insert procurement clauses with the 2-tier supplier model. Risk-based requirements mapped to Bronze through Diamond certification levels.

Email Templates

Full communication flow — initial announcement, reminders, escalation, and confirmation. Separate flows for Silver and Gold+ requirements.

Tracking Tools

Live links to verify.cybercert.ai and dashboard.cybercert.ai to check and track supplier certification status in real time.

Insurance Integration

Built-in cyber insurance requirements and pathways — including sponsored Gold certification subscription credits for eligible insurer partners.

View →

Disclaimer

General use

This SCAP™ Activation Toolkit is provided by CyberCert Pty Ltd for general informational and operational guidance. It is not a substitute for professional legal, cybersecurity, insurance, procurement, or risk-management advice. Use of this toolkit does not guarantee compliance with any law, standard, contractual obligation, or insurer requirement, nor does it eliminate cyber risk.

No warranty

The materials, templates, clauses, checklists, and tools are provided “as is” and “as available,” without warranties of any kind, express or implied, including accuracy, fitness for a particular purpose, or non-infringement. To the maximum extent permitted by law, CyberCert disclaims liability for any loss or damage arising from use of, or reliance on, this toolkit.

Currency

Cybersecurity standards, threats, and best practice evolve. Content reflects CyberCert’s view as at the publication date and may be superseded without notice.

Contract Clauses

The clauses in Section 4 are illustrative drafting examples only. They have not been prepared for any specific transaction, jurisdiction, supplier relationship, or regulatory regime. They are not legal advice and do not create a solicitor–client relationship. Before incorporating any clause into a contract you must obtain advice from qualified legal counsel admitted in the relevant jurisdiction. CyberCert accepts no responsibility for clauses that are adopted, modified, or rejected.

Sponsored Pathways & Cyber Insurance

References to cyber insurance, the CyberCert Insure pathway, sponsored Gold certifications, and insurer partners are informational only. They do not constitute insurance advice, a binding offer of cover, a recommendation, or a guarantee of eligibility.

Email Templates

The email templates in Section 5 are sample communications. Before sending you must: review for accuracy and tone, replace every merge field, verify supplier eligibility, and confirm compliance with applicable privacy, anti-spam, and electronic communications laws (e.g. Spam Act 2003 (Cth), GDPR, CAN-SPAM, as relevant). Templates that imply contractual consequences (suspension, termination, eligibility review) should be reviewed by legal and procurement before issue.

Third-party links and resources

This toolkit references third-party websites, frameworks, training programs, and tools (including dsi.org, cyberwardens.com.au, partner technology providers, and insurer partners). CyberCert does not control and is not responsible for the content, accuracy, availability, security, or practices of third parties. Inclusion is for convenience and does not constitute endorsement.

Statistics and external data

Statistics in this toolkit, including figures attributed to the WEF Global Cybersecurity Outlook 2024, are drawn from third-party publications at a point in time. CyberCert has not independently verified the underlying methodology of these statistics. Refer to the original source for current data and full context.

No guarantee of cyber resilience

Implementation of the SCAP program, achievement of any SMB1001 tier, ISO/IEC 27001, SOC 2 attestation, or any combination of the above, reduces but does not eliminate the risk of cyber attack, data breach, supply-chain compromise, or operational disruption. No certification, framework, attestation, or insurance product can guarantee security outcomes.

Up next

Tier Classification

Launch Checklist

Your implementation roadmap.

Step 1: Nominate your SCAP™ program leadAssign an internal owner — procurement, risk, or IT governance typically leads this
Step 2: Map your supplier baseExport your supplier list and categorise by Tier (Enterprise vs SMB) and risk level (High / Medium / Low)
Step 3: Insert procurement clauses into new contractsUse the clauses in Section 4 of this toolkit. Align tier requirements to your supplier risk classification
Step 4: Send initial announcement to existing suppliersUse Flow 1 (Silver) or the Gold Initial template from Section 5 depending on supplier risk level
Step 5: Add suppliers to your CyberCert dashboardGo to dashboard.cybercert.ai to add suppliers and track certification progress in real time
Step 6: Set your compliance deadline and send remindersUse Flow 2 (Reminder) 2–3 weeks before deadline. Flow 3 (Escalation) in the final week
Step 7: Verify and record complianceUse verify.cybercert.ai to confirm certification status. Send Flow 4 (Confirmation) to compliant suppliers

Step Detail

Click any step to see full guidance.

1

Nominate your SCAP™ program lead

Designating a clear owner is the most important first action — without an internal champion, the program stalls at the first point of resistance.

  • Choose someone with cross-functional authority — procurement, risk management, or IT governance are natural fits.
  • Give them a mandate to request supplier data and enforce compliance deadlines.
  • Ensure they have access to this toolkit, your supplier register, and your contract templates.

Phased Program Detail

Your implementation roadmap.

Phase 1 / 5
  • Export your full supplier list from your ERP, procurement system, or accounts payable records.
  • Classify each supplier as Tier 1 (Enterprise) — complex organisations typically 1,000+ staff — or Tier 2 (SMB).
  • Assign a risk rating: High (sensitive data, mission-critical, privileged access), Medium (interacts with systems, not critical), or Low (no sensitive data, easily replaceable).
  • Use the DSI Categorization Matrix at dsi.org/categorization-matrix to support classification decisions.
  • Map each supplier to a required certification level — see Section 3 of this toolkit.

Up next

Contract Clauses

Tier 1 · Enterprise

ISO / SOC 2 Pathway

~5% of your Supplier

Cyber Risk Level

Tier 2 · SMB Suppliers

SMB1001 / CyberCert Pathway

~95% of your Supplier

Required Standard

ISO 270001 IconSOC2 Icon

ISO/IEC 27001 or SOC 2 Type II or equivalent. Plus: Supplier Cybersecurity Questionnaire on request.

Assurance Model

Audit, remote assessment, or onsite verification at any time during contract.

HighHigh Cyber Risk

Required Certification

Platinum IconDiamond Icon

SMB1001 (Platinum/Diamond Tiers)

Definition

Handles sensitive/regulated data, mission-critical, or privileged system access. Cannot be substituted within 7 days.

Assurance Model

Audit, remote assessment, or onsite verification. Remediation within agreed timeframe.

Required Standard

ISO 270001 IconNIST Icon

Supplier Cybersecurity Questionnaire. Controls maintained per ISO 27001 or NIST CSF governance model.

Assurance Model

Random audits or assurance reviews.

MediumMedium Cyber Risk

Required Certification

Gold Icon

SMB1001 (Gold Tier or above)

Definition

Interacts with systems/information but doesn't store regulated data. Substituted in 7–30 days.

Assurance Model

Random audits or assurance reviews at discretion.

Required Standard

Annual cybersecurity attestation confirming basic safeguards (passwords, patching, antivirus, backups, MFA).

Assurance Model

Spot-check audits at discretion.

LowLow Cyber Risk

Required Certification

Bronze IconSilver Icon

SMB1001 (Bronze/Silver Tiers)

Definition

No access to sensitive data, not critical to continuity. Replaced in 30+ days without material impact.

Assurance Model

Spot-check audits.
Alternatively: completed reduced cyber questionnaire.

Sponsored Pathways

Free & subsidised options for smaller suppliers.

Suppliers with fewer than 20 staff can access Silver at no certification cost via the Cyber Wardens pathway. Gold certification subscription credits may be sponsored by eligible insurer partners — explore and select your options below.

Explore CyberWardens OfferExplore Insurers Offer

SMB Size Guidance.

Employee count ranges to help suppliers find their recommended starting certification level.

Level 01

Bronze Icon

Bronze

Baseline cyber hygiene for any business with an Internet connection.

Level 02

Silver Icon

Silver

Cyber-insurable. Enhanced security for businesses facing moderate risk.

Level 03

Gold Icon

Gold

Compliance Ready. Advanced measures for compliance-heavy industries.

Level 04

Platinum Icon

Platinum

Hardened and Audited. Comprehensive controls for high-risk, critical sectors.

Level 05

Diamond Icon

Diamond

Ecosystem Hardened and Audited. Most comprehensive controls for highest assurance.

Employee Count

Fewer than 20

Recommended Start

Bronze (L1) IconBronze (L1)

Typical Maximum Target

diamond IconUp to Diamond depending on risk

Employee Count

20–99

Recommended Start

Silver (L2) IconSilver (L2)orGold (L3) IconGold (L3)

Typical Maximum Target

diamond IconUp to Diamond depending on risk

Employee Count

100–249

Recommended Start

Gold (L3) IconGold (L3)

Typical Maximum Target

diamond IconDiamond (L5)

Employee Count

250–499

Recommended Start

Gold (L3) IconGold (L3)orPlatinum (L4) IconPlatinum (L4)

Typical Maximum Target

diamond IconDiamond (L5)

Employee Count

500+

Recommended Start

Platinum (L4) IconPlatinum (L4)

Typical Maximum Target

diamond IconDiamond (L5)
Employee CountRecommended StartTypical Maximum Target
Fewer than 20
Bronze (L1) IconBronze (L1)
diamond IconUp to Diamond depending on risk
20–99
Silver (L2) IconSilver (L2)orGold (L3) IconGold (L3)
diamond IconUp to Diamond depending on risk
100–249
Gold (L3) IconGold (L3)
diamond IconDiamond (L5)
250–499
Gold (L3) IconGold (L3)orPlatinum (L4) IconPlatinum (L4)
diamond IconDiamond (L5)
500+
Platinum (L4) IconPlatinum (L4)
diamond IconDiamond (L5)

Certification requirements.

Check out the requirements below to see what certification level your business may immediately qualify for.

Select Standard

Up next

Email Templates

✓ Copied to clipboard

Important:

These clauses are sample language for internal use only and are not legal advice. See full disclaimer at end of document. Review with your legal team before contractual use.

Contract Clauses

1. Purpose & Scope

This clause establishes the cybersecurity and information security obligations applicable to all Suppliers engaged by the Customer. It applies proportionally based on the Supplier's assigned risk category (High Risk, Medium Risk, or Low Risk), as determined by the Customer's risk assessment framework and supported by the DSI Categorization Matrix (dsi.org/categorization-matrix).

2. General Requirements (All Suppliers)

All Suppliers, regardless of tier, must:

a) Implement and maintain reasonable and proportionate cybersecurity measures to protect against unauthorised access, disclosure, loss, or compromise of Customer data.

b) Promptly notify the Customer of any actual or suspected cyber incident, data breach, or security compromise affecting services or data under this Agreement.

c) Cooperate fully with any Customer investigation, audit, or remediation activity related to cybersecurity.

d) Ensure subcontractors and affiliates engaged in delivery of the contracted services adhere to equivalent standards.

3a. Tier 1 Enterprise Suppliers: Risk-Based Certification

High Risk Enterprise Suppliers must demonstrate compliance with one of the following: ISO/IEC 27001 certification; SOC 2 Type II report; or an equivalent internationally recognised standard approved by the Customer. Must complete the Enterprise Supplier Cybersecurity Questionnaire on request and maintain updated responses throughout the contract term. May be subject to audit, remote assessment, or onsite verification at any time during the contract term and prior to service commencement. Must remediate any deficiencies within a mutually agreed timeframe.

Medium Risk Enterprise Suppliers must provide evidence of cybersecurity maturity by completing the Enterprise Supplier Cybersecurity Questionnaire. May be subject to random audits or assurance reviews. Must maintain controls in accordance with an industry standard governance model (e.g. ISO 27001, NIST CSF).

Low Risk Enterprise Suppliers must complete an annual cybersecurity attestation confirming implementation of basic safeguards (e.g. strong passwords, patching, antivirus, backups, MFA). May be subject to spot-check audits at the Customer's discretion.

3b. Tier 2 SMB Suppliers: Risk-Based Certification

High Risk SMB Suppliers must demonstrate compliance with Platinum or Diamond SMB1001 Certification issued by CyberCert, as defined in the DSI Categorization Matrix. May be subject to audit, remote assessment, or onsite verification at any time.

Medium Risk SMB Suppliers must hold a CyberCert Gold or higher SMB1001 Certification. May be subject to random audits or assurance reviews.

Low Risk SMB Suppliers must hold at minimum a CyberCert Bronze or Silver SMB1001 Certification, or alternatively provide a completed reduced set of cyber questions as provided by the Customer. May be subject to spot-check audits at the Customer's discretion.

4. Evidence & Verification

Suppliers must provide current certificates, attestations, or completed questionnaires within ten (10) business days of request.

Failure to maintain compliance with these obligations, or refusal to provide evidence, may constitute a material breach of contract and grounds for suspension or termination.

The Customer reserves the right to verify certification status at any time via the CyberCert certification registry at verify.cybercert.ai.

5. Continuous Improvement

The Customer and Supplier acknowledge that cybersecurity standards and threats evolve. Suppliers shall review and update their security controls and certifications annually or as required to remain aligned with current best practice and the SMB1001 standard or its successors.

Clauses

Disclaimer

General use

This SCAP™ Activation Toolkit is provided by CyberCert Pty Ltd for general informational and operational guidance. It is not a substitute for professional legal, cybersecurity, insurance, procurement, or risk-management advice. Use of this toolkit does not guarantee compliance with any law, standard, contractual obligation, or insurer requirement, nor does it eliminate cyber risk.

No warranty

The materials, templates, clauses, checklists, and tools are provided “as is” and “as available,” without warranties of any kind, express or implied, including accuracy, fitness for a particular purpose, or non-infringement. To the maximum extent permitted by law, CyberCert disclaims liability for any loss or damage arising from use of, or reliance on, this toolkit.

Currency

Cybersecurity standards, threats, and best practice evolve. Content reflects CyberCert’s view as at the publication date and may be superseded without notice.

Contract Clauses

The clauses in Section 4 are illustrative drafting examples only. They have not been prepared for any specific transaction, jurisdiction, supplier relationship, or regulatory regime. They are not legal advice and do not create a solicitor–client relationship. Before incorporating any clause into a contract you must obtain advice from qualified legal counsel admitted in the relevant jurisdiction. CyberCert accepts no responsibility for clauses that are adopted, modified, or rejected.

Sponsored Pathways & Cyber Insurance

References to cyber insurance, the CyberCert Insure pathway, sponsored Gold certifications, and insurer partners are informational only. They do not constitute insurance advice, a binding offer of cover, a recommendation, or a guarantee of eligibility.

Email Templates

The email templates in Section 5 are sample communications. Before sending you must: review for accuracy and tone, replace every merge field, verify supplier eligibility, and confirm compliance with applicable privacy, anti-spam, and electronic communications laws (e.g. Spam Act 2003 (Cth), GDPR, CAN-SPAM, as relevant). Templates that imply contractual consequences (suspension, termination, eligibility review) should be reviewed by legal and procurement before issue.

Third-party links and resources

This toolkit references third-party websites, frameworks, training programs, and tools (including dsi.org, cyberwardens.com.au, partner technology providers, and insurer partners). CyberCert does not control and is not responsible for the content, accuracy, availability, security, or practices of third parties. Inclusion is for convenience and does not constitute endorsement.

Statistics and external data

Statistics in this toolkit, including figures attributed to the WEF Global Cybersecurity Outlook 2024, are drawn from third-party publications at a point in time. CyberCert has not independently verified the underlying methodology of these statistics. Refer to the original source for current data and full context.

No guarantee of cyber resilience

Implementation of the SCAP program, achievement of any SMB1001 tier, ISO/IEC 27001, SOC 2 attestation, or any combination of the above, reduces but does not eliminate the risk of cyber attack, data breach, supply-chain compromise, or operational disruption. No certification, framework, attestation, or insurance product can guarantee security outcomes.

Up next

Tracking Tools

✓ Copied to clipboard

Merge fields to customise:

Replace all [fields] with your organisation's details before sending. These include organisation name, contact mailbox, deadline dates, and supplier names.

Flow 1 — Initial Announcement

Part 1 · Silver Suppliers

Subject Line
Action requested: CyberCert Silver for [Organisation Name] suppliers
Hi [First name], As part of strengthening cyber resilience across our supplier community, [Organisation Name] is introducing a simple new requirement for small to medium suppliers. From [date], we will ask relevant suppliers to hold a minimum CyberCert Silver certification plus an active cyber insurance policy. What this means for you CyberCert is a practical cyber security standard for small and medium businesses. Silver level covers the fundamental controls needed to manage common risks such as business email compromise, ransomware, and basic data protection failures. Many insurers recognise CyberCert (cybercert.ai/insure) and may offer more appropriate or discounted premiums for certified organisations. You will need to: • Achieve CyberCert Silver (or above), and • Hold an active cyber insurance policy appropriate for your risk profile. How to get certified Go to cybercert.ai and click "Get certified." Select Silver (or above) as your target level and follow the guided steps. You can work with your existing IT provider or one of over 700 technology providers listed at partners.cybercert.ai. No-cost option for smaller providers If your business has fewer than 20 staff, there is a no-cost pathway to Silver: • Complete the free Cyber Wardens training (~10 minute federal government course) at cyberwardens.com.au/cybercert • Receive a free Bronze certification • CyberCert will upgrade you to Silver once your Cyber Wardens pathway is accepted Timeline • New suppliers: Prior to [contract start / first engagement / first invoice] • Existing suppliers: By [date] or at your next contract renewal, whichever comes first. How we will verify We will verify your CyberCert certification at verify.cybercert.ai and confirm your active cyber insurance by requesting a copy of your Certificate of Currency. If you have questions, please contact [Department/Mailbox]. Kind regards, [Name]

Flow 2 — Reminder / Nudge

Send 2–3 weeks before deadline

Subject Line
Follow-up: CyberCert Silver + insurance for [Organisation Name] suppliers
Hi [First name], This is a quick reminder about our updated cyber and insurance requirements for small to medium suppliers. As shared earlier, [Organisation Name] is asking relevant suppliers to hold: • CyberCert Silver certification (or higher) • An active cyber insurance policy appropriate to their risk profile Our records indicate we have not yet confirmed your organisation meets both of these requirements. Next steps If you have started: Please continue working through the steps in the platform. Once you reach Silver, your status will be visible via CyberCert's verification tools. If you have not started: Visit cybercert.ai, select Silver, and follow the guided steps. Timeline Please either achieve compliance by [date] or contact us by [earlier date] if you believe this requirement may not be appropriate for your organisation. If you have any questions, please reach out to [Department/Mailbox]. Kind regards, [Name]

Flow 3 — Escalation

Final week before deadline

Subject Line
Action required: CyberCert Silver + insurance to continue providing services to [Organisation Name]
Hi [First name], We are following up regarding [Organisation Name]'s updated cyber and insurance requirement. By [deadline date], relevant suppliers are expected to hold CyberCert Silver certification and maintain an active cyber insurance policy. Our records show your organisation has not yet met these requirements. Why this matters This requirement ensures our partners have a minimum set of cyber controls (via CyberCert Silver) and financial resilience/incident support (via insurance) to protect sensitive information shared across our supply chain. Next review If we are unable to confirm your compliance by [review date], we may need to: • Reassess your eligibility to provide services, and/or • Apply additional risk conditions to your engagement. If you believe this has been applied in error or have exceptional circumstances, contact us immediately at [Department/Mailbox]. Kind regards, [Name]

Flow 4 — Confirmation of Compliance

Send once verified in dashboard / verify.cybercert.ai

Subject Line
Thank you – CyberCert Silver + insurance confirmed
Hi [First name], Thank you for completing your CyberCert [Silver/Gold] certification and confirming your cyber insurance policy. We have recorded that your organisation now meets [Organisation Name]'s requirement. This status will be taken into account in our ongoing risk and assurance processes. To maintain this status, please follow the ongoing guidance in the CyberCert platform and ensure your insurance remains active. Kind regards, [Name]

Flow 5— Gold+ Initial Announcement

Part 2 · High-risk suppliers requiring Gold or above

Subject Line
Action requested: CyberCert Gold for [Organisation Name] high-risk suppliers
Hi [First name], As part of strengthening cyber resilience for higher-risk services, [Organisation Name] is introducing an enhanced requirement for selected suppliers. For suppliers that handle more sensitive information or higher volumes of data, we require: • CyberCert Gold certification, which includes an appropriate cyber insurance component • Ongoing adherence to Gold-level controls and incident response expectations What CyberCert Gold means Gold level is designed for organisations that handle heightened volumes of sensitive information. It includes strong technical identity controls and robust backup/recovery expectations. At Gold level, appropriate cyber insurance cover is embedded in the requirement. Sponsored Gold pathways To reduce friction, some CyberCert Insurance partners (cybercert.ai/insure) will sponsor your Gold certification when you take up an eligible policy with them. This can mean your certification fees are partially or fully subsidised. How to move to Gold 1. Go to cybercert.ai 2. Select Gold as your target level 3. Work through the assessment with your IT team or a provider from partners.cybercert.ai 4. Speak with your broker or a partner on the CyberCert Insure page to check eligibility for a sponsored pathway. Timeline • New high-risk suppliers: Prior to [contract start / first engagement] • Existing high-risk suppliers: By [date] or at your next renewal. If you have questions about how this applies to your organisation, please contact [Department/Mailbox]. Kind regards, [Name] [Title] [Organisation Name]
Emails

Disclaimer

General use

This SCAP™ Activation Toolkit is provided by CyberCert Pty Ltd for general informational and operational guidance. It is not a substitute for professional legal, cybersecurity, insurance, procurement, or risk-management advice. Use of this toolkit does not guarantee compliance with any law, standard, contractual obligation, or insurer requirement, nor does it eliminate cyber risk.

No warranty

The materials, templates, clauses, checklists, and tools are provided “as is” and “as available,” without warranties of any kind, express or implied, including accuracy, fitness for a particular purpose, or non-infringement. To the maximum extent permitted by law, CyberCert disclaims liability for any loss or damage arising from use of, or reliance on, this toolkit.

Currency

Cybersecurity standards, threats, and best practice evolve. Content reflects CyberCert’s view as at the publication date and may be superseded without notice.

Contract Clauses

The clauses in Section 4 are illustrative drafting examples only. They have not been prepared for any specific transaction, jurisdiction, supplier relationship, or regulatory regime. They are not legal advice and do not create a solicitor–client relationship. Before incorporating any clause into a contract you must obtain advice from qualified legal counsel admitted in the relevant jurisdiction. CyberCert accepts no responsibility for clauses that are adopted, modified, or rejected.

Sponsored Pathways & Cyber Insurance

References to cyber insurance, the CyberCert Insure pathway, sponsored Gold certifications, and insurer partners are informational only. They do not constitute insurance advice, a binding offer of cover, a recommendation, or a guarantee of eligibility.

Email Templates

The email templates in Section 5 are sample communications. Before sending you must: review for accuracy and tone, replace every merge field, verify supplier eligibility, and confirm compliance with applicable privacy, anti-spam, and electronic communications laws (e.g. Spam Act 2003 (Cth), GDPR, CAN-SPAM, as relevant). Templates that imply contractual consequences (suspension, termination, eligibility review) should be reviewed by legal and procurement before issue.

Third-party links and resources

This toolkit references third-party websites, frameworks, training programs, and tools (including dsi.org, cyberwardens.com.au, partner technology providers, and insurer partners). CyberCert does not control and is not responsible for the content, accuracy, availability, security, or practices of third parties. Inclusion is for convenience and does not constitute endorsement.

Statistics and external data

Statistics in this toolkit, including figures attributed to the WEF Global Cybersecurity Outlook 2024, are drawn from third-party publications at a point in time. CyberCert has not independently verified the underlying methodology of these statistics. Refer to the original source for current data and full context.

No guarantee of cyber resilience

Implementation of the SCAP program, achievement of any SMB1001 tier, ISO/IEC 27001, SOC 2 attestation, or any combination of the above, reduces but does not eliminate the risk of cyber attack, data breach, supply-chain compromise, or operational disruption. No certification, framework, attestation, or insurance product can guarantee security outcomes.

How to Track Supplier Status Today.

List of current tools and resources available to you. SCAP™ Dashboard is currently in development. Toolkit remains fully functional today alongside the existing verify and dashboard tools.

dashboard.cybercert.ai

Add your SMB suppliers directly to gain visibility into their certification status, progress, and engagement — with minimal management effort.

SCAP Visible
Coming Soon →

verify.cybercert.ai

Instantly verify any individual supplier’s current certification level by name or ABN. Best for point-in-time checks before onboarding or at contract renewal.

verify.cybercert.ai
Verify Now →

cybercert.ai/partners

We’ll connect you with certified Technical Support Specialists (TSS) to offer expert guidance, assisting you through each step to ensure you meet all requirements for your SMB1001 certification.

cybercert.ai/partners
Browse Partners →

cybercert.ai/insure

While cybersecurity measures reduce risk, cyber insurance covers what you and technology can’t, providing peace of mind and financial support if a cyber attack ever occurs.

cybercert.ai/insure
Browse Insurers →

certification.cybercert.ai

The dedicated portal where your suppliers complete their SMB1001 certification — from initial setup through to verified status.

certification.cybercert.ai
Manage Certifications →

cybercert.ai

Certified Cybersecurity. Simplified for SMBs. Achieve recognized cybersecurity certification. Know It. Show It.

cybercert.ai
Explore CyberCert →

Coming Soon!

SCAP Visible

SCAP™ Dashboard.

Gain visibility over the cyber maturity of your entire vendor list, not just the top 5%.

SCAP Visible

Download the SCAP™ Playbook.Risk-Based 2-Tier Model.

Download