CyberGrape – cyber security certification and GRC platform for small business

Compliance Frameworks

Compliance that wins business, not just ticks boxes.

Maps every SMB1001 control to your current posture, collects evidence automatically from your connected tools, and tells you exactly what is missing.

See SMB1001 certification
app.cybergrape.io/compliance/smb1001
SMB1001 Certification Progress
Control coverage across all five tiers
BronzeCertified
7 / 7 controls100%
SilverCertified
17 / 17 controls100%
GoldCertified
27 / 27 controls100%
Platinum
26 / 32 controls81%
Diamond
24 / 39 controls62%
6 controls outstanding for Platinum
Estimated 3–4 weeks to close: view remediation plan
Evidence collected automatically
Patch status pulled from NinjaOne
5 min ago
Training completion logged via usecure
1 hr ago
MFA policy acknowledged, 14 staff
3 hrs ago
Vulnerability scan, Qualys
4 hrs ago
77%
Overall compliance score

SMB1001

Five tiers. One platform. Start wherever you are.

The platform tracks your progress across every tier simultaneously. Implement controls in any order; the platform maps them to the tier they satisfy as you go.

SMB1001 Bronze
Bronze
7 controls total

Foundation controls: MFA, patch management, and basic access control. Self-attested. No external auditor required.

Multi-factor authenticationPatch and update managementAccess control policy
1–2 weeks
typical timeline
Self-attested
SMB1001 Silver
Silver
17 controls total

Expands into email security, backup, and endpoint protection. Still self-attested, but evidence is verified against tool outputs.

Email authentication (DMARC/SPF)Encrypted backupsEndpoint detection
2–4 weeks
typical timeline
Self-attested
SMB1001 Gold
Gold
27 controls total

The most commonly requested certification tier. Requires a CyberCert-accredited assessor review. Evidence pack compiled automatically by the platform.

Vulnerability managementSecurity awareness trainingIncident response plan
4–8 weeks
typical timeline
Assessor review
SMB1001 Platinum
Platinum
32 controls total

Advanced controls for organisations with elevated risk profiles: supply chain risk, penetration testing, and board-level governance.

Supply chain risk managementPenetration testingBoard security governance
8–14 weeks
typical timeline
Assessor review
SMB1001 Diamond
Diamond
39 controls total

The highest SMB1001 tier. SOC-equivalent rigour for organisations in regulated sectors or critical supply chains.

Red team exercisesFormal ISMS documentationContinuous audit evidence
12–20 weeks
typical timeline
Assessor review

Control counts are cumulative. Diamond includes all 39 controls from Bronze through Diamond.

Framework support

Standards and frameworks. One evidence library.

NZ Standard

SMB1001

39 controls across 5 tiers

The primary cybersecurity standard for NZ small and medium businesses. All five tiers from Bronze through Diamond are managed from a single view. Progress across every tier is tracked simultaneously so you always know your next milestone.

International Standard

ISO 27001:2022

93 Annex A controls

Statement of Applicability management built into the platform. Assign implementation status, attach evidence, and track progress against all 93 Annex A controls. Evidence collected for SMB1001 is automatically mapped to its ISO 27001 equivalent where controls overlap.

NZ Gov Framework

NZISM v3.9

Classified and unclassified profiles

For organisations operating in or supplying to New Zealand government. NZISM controls are managed alongside SMB1001 and ISO 27001 from the same interface, with separate reporting where required by the agency or procurement process.

Coming soonAICPA Framework

SOC 2

Trust Services Criteria

Type I and Type II assurance reporting against the AICPA Trust Services Criteria. Manage your security, availability, confidentiality, processing integrity, and privacy controls from the same evidence library used for your other frameworks.

Available soon
Coming soonUS Framework

NIST CSF 2.0

6 functions, 22 categories

The updated NIST Cybersecurity Framework, increasingly referenced in NZ and AU enterprise procurement. Map your existing controls to the Govern, Identify, Protect, Detect, Respond, and Recover functions.

Available soon
Coming soonInternational Standard

ISO 42001:2023

AI management system controls

The international standard for AI management systems. As AI becomes embedded in business operations, ISO 42001 provides the governance framework for responsible development, deployment, and monitoring of AI tools.

Available soon

How it works

From posture baseline to issued certificate.

Most organisations approach certification backwards. They pick a target tier, read the control list, and then try to work out what evidence they have. That process takes months and wastes time on controls that are already covered.

CyberGrape starts from what you have. Connect your tools, and the platform maps your current posture to the control framework automatically. You see your gaps on day one, and evidence arrives continuously as your tools report in, not assembled manually before every assessment.

Certification programme
01
Baseline your posture

Connect your existing tools. The platform maps every control to your current posture automatically. No manual survey or spreadsheet required.

02
See exactly what's missing

Every gap is ranked by effort and impact. A prioritised remediation roadmap tells you what to fix first to reach your target tier in the shortest time.

03
Evidence collected for you

As you implement controls, evidence arrives automatically from your connected tools. Patch compliance from NinjaOne. Training records from uSecure. No manual uploads for what your tools already capture.

04
Evidence pack compiled

When you are ready to certify, the platform generates your evidence pack in the format your certifier needs. What used to take weeks of preparation takes minutes.

05
Assessor review and certification

For Gold and above, a CyberCert-accredited assessor reviews your evidence pack. CyberGrape works with CyberCert to take your readiness through to an issued certificate and verifiable digital badge.

06
Continuous monitoring

Certification is not a point-in-time achievement. The platform monitors your controls continuously so you know the moment something drifts, not at your annual renewal conversation.

Automated evidence

Your tools are already collecting evidence. The platform maps it.

Every piece of evidence pulled from a connected integration is automatically mapped to the controls it satisfies across SMB1001, ISO 27001, and NZISM simultaneously. When a control is covered, it is marked. When it lapses, you are alerted.

NinjaOne
1.4: Patch management
Patch compliance %, device count, last scan
CrowdStrike
1.12: Endpoint detection
Active protection, detection count, coverage
PowerDMARC
2.12: Email authentication
DMARC policy status, domain health
uSecure
5.1: Awareness training
Completion rates, phish simulation scores
Qualys
8.8: Vulnerability management
Open CVEs, remediation status, scan frequency
CheckRed
5.23: Cloud security posture
Misconfiguration findings, policy violations
Evidence coverage by source
Pulled from connected tools68%
Manually uploaded documents21%
Platform-generated evidence11%

Average across CyberGrape clients at Gold certification

Manual evidence still required

Policies, procedures, meeting minutes, and vendor agreements must be uploaded directly. The platform shows exactly which controls need manual evidence and what format the assessor expects.

Common questions.

Ready to see your compliance gaps?

Connect your tools and the platform maps your controls automatically. Know exactly where you stand against your target tier in minutes.

See SMB1001 certification