SMB1001 Diamond Compliance
The elite SMB1001 certification tier requiring continuous security monitoring, threat intelligence integration, comprehensive incident response, and mandatory third-party external audit.
Overview
SMB1001 Diamond is the highest tier of the CyberCert SMB1001 certification, representing elite cybersecurity maturity for SMBs.
It requires continuous security monitoring, threat intelligence integration, advanced incident response, and comprehensive vulnerability management.
Mandatory third-party external audit verifies that all controls are operational and that continuous monitoring is effective.
Diamond certification demonstrates the highest level of cybersecurity assurance available within the SMB1001 framework.
It is designed for organisations in high-risk environments and serves as a bridge toward or complement for international standards like ISO 27001.
Key Areas
- All Platinum-level controls and audit requirements remain in force
- Continuous security monitoring with real-time alerting and dashboard visibility
- Threat intelligence integration informing defensive priorities and monitoring rules
- Advanced incident response capability with threat-informed procedures
- Comprehensive security documentation maintained at continuous audit-readiness
- Regular security assessments including vulnerability scanning and penetration testing
- Advanced data protection measures including encryption and data loss prevention
- Supply chain security management with vendor risk assessment processes
Who It's For
- SMBs in critical infrastructure supply chains requiring the highest level of security assurance
- Organisations handling highly sensitive personal, financial, or health data
- Businesses in high-risk industries targeted by sophisticated threat actors
- Companies seeking an elite SMB certification as a stepping stone to or complement for ISO 27001
Core Requirements
- Policies and Governance
- All Platinum governance requirements apply with additional emphasis on continuous improvement. Policies must reflect current threat intelligence and be reviewed more frequently. Governance activities should demonstrate proactive security leadership, not just compliance management.
- Risk Management
- Risk management at Diamond must be threat-intelligence-informed and continuously updated. The risk register should reflect current threat landscape data, and risk treatment decisions should be reviewed whenever significant threat intelligence changes occur.
- Security Controls
- All Platinum controls remain required. Diamond adds continuous monitoring, threat intelligence feeds, advanced vulnerability management including regular scanning or penetration testing, data loss prevention measures, and supply chain security controls.
- Incident Response
- Incident response at Diamond must demonstrate sophistication: threat-informed procedures, integration with monitoring and intelligence feeds, defined recovery time objectives, post-incident forensic capability, and regular testing through exercises that reflect current threat scenarios.
- Evidence and Reporting
- Evidence management must support continuous audit readiness. Documentation should be maintained as a living system rather than a periodic compilation. The external auditor will assess the currency and completeness of evidence as part of the Diamond audit.
Implementation Steps
- Platinum baseline verification - Confirm Platinum certification is current and all controls are operational. Diamond builds directly on Platinum, so the entire Platinum control set must be in place before Diamond-specific enhancements begin.
- Continuous monitoring deployment - Implement continuous security monitoring with real-time alerting. This typically requires a SIEM platform or managed security operations centre (SOC) service. Ensure monitoring covers network traffic, endpoint activity, authentication events, and critical system logs.
- Threat intelligence integration - Subscribe to relevant threat intelligence feeds and integrate them into monitoring rules, risk assessments, and incident response procedures. Ensure intelligence is actionable and relevant to the organisation's threat profile, not just generic data.
- Advanced security assessments - Implement regular vulnerability scanning across all systems and conduct periodic penetration testing. Establish processes for triaging findings, prioritising remediation, and tracking resolution.
- Incident response enhancement - Uplift incident response capabilities with threat-informed procedures, integration with monitoring systems, defined recovery objectives, and forensic investigation capability. Conduct regular exercises using scenarios informed by current threat intelligence.
- External audit and certification - Engage an accredited auditor for the Diamond-level audit. The audit will assess continuous monitoring effectiveness, threat intelligence integration, control maturity, and documentation completeness. Address any findings and submit for Diamond certification.
Frequently Asked Questions
- Is Diamond necessary?
- For most SMBs, Gold or Platinum will provide sufficient certification. Diamond is recommended for organisations in high-risk environments, handling highly sensitive data, or competing in markets where elite security credentials are a differentiator.
- How does Diamond compare to ISO 27001?
- Diamond provides elite SMB certification with continuous monitoring requirements. ISO 27001 is a broader international standard covering the full information security management system. Diamond may serve as a pathway to ISO 27001 readiness.
- What continuous monitoring tools are needed?
- A SIEM platform or managed SOC service is typically required. Options include cloud-based SIEM services, managed detection and response providers, or security operations centre as a service. The approach should match the organisation's size and budget.
- What threat intelligence is required?
- The standard expects integration with relevant threat intelligence that informs monitoring and risk decisions. This can range from commercial feeds to industry-specific sharing groups. The intelligence must be actionable, not just informational.
- How much does Diamond certification cost?
- Diamond involves the highest total cost across all tiers: implementation of continuous monitoring, threat intelligence subscriptions, advanced security tools, and external audit fees. Contact CyberCert for indicative pricing.
- Can we go directly to Diamond?
- In theory, an organisation could implement all controls from Bronze through Diamond simultaneously. In practice, the progressive approach is recommended as it builds maturity incrementally and ensures foundational controls are solid before adding advanced capabilities.
Why It Matters
- Continuous monitoring represents the gold standard in operational security. Rather than relying on periodic checks or reactive responses, Diamond-certified organisations maintain persistent visibility over their security posture, enabling real-time detection and response.
- Threat intelligence integration ensures the organisation's defences are informed by the current threat landscape. This proactive approach means controls and monitoring are tuned to the threats most likely to affect the organisation, not just generic best practices.
- Diamond certification is the strongest credential available within the SMB1001 framework. For organisations competing in environments where security is a differentiator or a contractual requirement, Diamond provides the maximum assurance signal.
Common Challenges
- Continuous monitoring requires ongoing operational cost that significantly exceeds lower-tier investments
- Consuming and acting on threat intelligence effectively requires skills that many SMBs do not have in-house
- Maintaining continuous audit readiness demands sustained discipline and dedicated resources
- The gap between Platinum and Diamond in terms of operational maturity and cost can be substantial
- Finding managed security service providers that can deliver Diamond-grade monitoring at SMB-appropriate pricing
- Justifying the investment in Diamond certification when Gold or Platinum may satisfy most business requirements