"For many SMEs, cyber security competes with the immediate pressures of running and growing a business." — John Pepper, CEO and founder of Managed 247.
Record numbers: 61,430 Cyber Essentials certificates in a year
The UK government's flagship Cyber Essentials (CE) scheme recorded 61,430 certificates awarded in the year from July 2025 to June 2026 — a 20% increase on the previous 12 months. Of that total, 46,245 were at the basic CE level, which the government describes as self-assessed, and 15,185 were at CE+, which requires a third‑party audit. The government also reported that nearly three‑quarters of the CE figure relates to recertifications rather than new organisations signing up.
Uptake still tiny compared with the SME population
That record total remains small compared with the estimated size of the UK’s small and medium‑sized enterprise population. Government estimates put the number of SMEs at around 5.7 million — more than 99% of the private sector — meaning the newly issued certificates apply to only a fraction of potential candidate organisations.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadESET 2026 SMB Cyber Risk Report: incidents are common and recovery is slow
New data published by security vendor ESET this week underscores the exposure of smaller businesses. Based on 500 responses, the vendor’s 2026 SMB Cyber Risk Report found that 49% of UK SMEs suffered a cybersecurity incident over the past year. Respondents reported that the average time taken to identify and recover from a breach was over four weeks.
ESET’s findings point to a small set of recurring causes — phishing, unpatched vulnerabilities, weak passwords and a lack of monitoring — problems that the Cyber Essentials scheme is explicitly designed to mitigate through basic hygiene and controls.
NCSC playbook, Cyber Resilience Pledge and the Cyber Security and Resilience Bill
The government is using several levers to try to lift takeup. In December 2025 the National Cyber Security Centre (NCSC) published a Cyber Essentials Supply Chain Playbook urging organisations to require certification as a baseline across their supplier base. Separately, the voluntary Cyber Resilience Pledge requires signatories to demand Cyber Essentials throughout their supply chains. The Cyber Security and Resilience Bill currently creates a legal duty for organisations to manage cyber risk in their supply chain — a statutory route that the government says could persuade more firms to demand certification.
At present, the government reported that none of the organisations seeking a Cyber Essentials certificate over the past year did so because they were asked to by a customer. The government also claimed that organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance.
What this means for SMEs, procurement teams, and insurers
- SMEs: As John Pepper put it, many smaller businesses balance cybersecurity against immediate commercial pressures. Pepper advises starting with "secure configurations, strong access controls, software updates and protection against malware," and argues that "good cyber hygiene should be treated as part of running a business, rather than something to address after an incident."
- Procurement teams and buyers: The NCSC playbook, the Cyber Resilience Pledge and the Bill could shift expectations in supply chains. If signatories to the pledge demand CE and statutory duties under the Bill are enacted, buyers may increasingly treat certification as a baseline for suppliers.
- Insurers: The government’s claim that Cyber Essentials holders are 92% less likely to make a cyber insurance claim presents a measurable argument for insurers to consider certification when assessing risk or pricing policies, though the government framed this as a claim rather than as independently validated in the materials published.
Record issuance of certificates shows progress on one axis: more organisations are recertifying and some are moving to audited CE+. But the combination of ESET’s finding that roughly half of SMEs experienced an incident in the past year and the government’s own estimate of 5.7 million SMEs makes plain the scale of the gap between coverage and exposure. The next test will be whether supply‑chain pressure — voluntary through the pledge, prescriptive in the NCSC playbook, or mandatory under the Bill — converts government policy and playbook guidance into materially higher takeup among organisations that today do not appear to feel compelled by customer demand.




