The United Kingdom’s flagship cyber certification initiative, Cyber Essentials, has achieved a notable milestone, having awarded a record 61,430 certificates in the last year. However, despite this achievement, the program has seen a relatively modest uptake among businesses across the nation.
Recent data reveals a 20% increase in the number of Cyber Essentials (CE) certifications issued between July 2025 and June 2026, comparing favorably to the same period in the previous year. Out of the total certificates awarded, 46,245 were for the basic Cyber Essentials level, which is self-assessed, whereas 15,185 were for the more rigorous CE+ designation, which necessitates a third-party audit. It is important to note that approximately 75% of these certifications represent renewals rather than new registrations from enterprises.
When set against the backdrop of the UK’s vast number of small and medium-sized enterprises (SMEs) – estimated at around 5.7 million or over 99% of the private sector – these figures suggest that the overall participation in the Cyber Essentials program remains significantly limited.
In a related finding, new statistics from ESET have surfaced, indicating a pressing cybersecurity concern among the UK’s SMEs. Approximately 49% of these businesses reported experiencing a cybersecurity incident over the past year. The data, stemming from a survey of 500 responses, is elaborated in ESET’s 2026 SMB Cyber Risk Report, which highlights that on average, it took organizations over four weeks to identify and recover from a breach. The report attributed most security incidents to well-known vulnerabilities such as phishing attacks, unpatched software, weak password practices, and insufficient monitoring. These issues echo the very principles of cybersecurity hygiene promoted by the Cyber Essentials framework.
John Pepper, CEO and founder of Managed 247, has highlighted this significant disconnect between the cyber risks faced by smaller companies and their strategies for tackling those risks. He articulated, “For many SMEs, cybersecurity competes with the immediate pressures of running and growing a business.” This sentiment underscores a critical challenge: smaller organizations are operating within a hazardous digital environment and cannot afford to overlook cybersecurity.
Pepper advocates a focus on fundamental cybersecurity practices, suggesting that SMEs should prioritize secure configurations, robust access controls, timely software updates, and proactive measures against malware. He emphasized that good cybersecurity hygiene should be recognized as an essential component of business operations rather than a remedial step following an incident.
Will Government Initiatives Prompt Change?
The UK government has acknowledged that none of the organizations that sought Cyber Essentials certification in the past year did so at the behest of a customer. This scenario is one the government aims to alter. The introduction of the voluntary Cyber Resilience Pledge mandates that participating organizations require their suppliers to attain Cyber Essentials certification. Additionally, the government’s Cyber Security and Resilience Bill is designed to establish a legal obligation for businesses to manage cyber risks within their supply chains. Such legislative measures could encourage more organizations to seek certification and prioritize cybersecurity.
In December 2025, the National Cyber Security Centre (NCSC) rolled out a Cyber Essentials Supply Chain Playbook, recommending that organizations enforce certification as a basic requirement across their supplier networks. This initiative reflects a growing recognition of cybersecurity’s importance in fostering trust and security within business relationships.
Pepper underscored the implications of these evolving expectations, stating, “For SMEs, cybersecurity can affect whether they can win and retain business.” As supply chain demands escalate, demonstrating adherence to basic cybersecurity protocols could become crucial for companies striving to position themselves as trusted suppliers in the marketplace.
Moreover, the government has asserted that organizations certified under the Cyber Essentials scheme are 92% less likely to file a cyber insurance claim, emphasizing the program’s potential benefits in risk management. By promoting Cyber Essentials as an integral aspect of business operations, the government hopes to bolster the overall cybersecurity posture of SMEs, ultimately safeguarding them against prevalent cyber threats in a rapidly evolving digital landscape.
In summary, while the Cyber Essentials program has made strides in certification awards, the low participation rate among SMEs highlights an urgent need for increased engagement and awareness. Both government initiatives and proactive measures from businesses are essential to closing the cybersecurity gap and ensuring that SMEs can navigate the complexities of today’s threat environment effectively.
