The UK Government Cyber Resilience Pledge: What It Means for Businesses

The UK Government Cyber Resilience Pledge: What It Means for Businesses

A practical guide to the declaration, Cyber Essentials, Cyber Essentials Plus, costs and the right route for different business sizes.

What is the UK Government Cyber Resilience Pledge?

The UK Government Cyber Resilience Pledge is a voluntary public declaration for organisations that want to demonstrate a stronger commitment to cyber resilience. It was formally launched at 10 Downing Street on 7 July 2026 and asks organisations to commit to three practical actions: making cyber security a board-level responsibility, signing up to the National Cyber Security Centre Early Warning service, and improving Cyber Essentials coverage across their supply chains.

The pledge is not a certification and it does not prove that a business is secure. Instead, it is a governance and accountability commitment. It tells customers, suppliers, regulators and investors that cyber risk is being treated as a business resilience issue, not just an IT problem.  Trust is such an important commodity in business and it is really important that businesses demonstrate that they treat their IT security seriously and demonstrate this to customers and suppliers. 

What does the pledge involve?

Organisations that sign the pledge commit to the following:

  1. Make cyber a board responsibility. This means implementing the Cyber Governance Code of Practice and ensuring all board members complete NCSC Cyber Governance Training within three months of signing and then annually.
  2. Sign up to NCSC Early Warning. Organisations must register for the free Early Warning service within one month. This service alerts organisations to signs of potential compromise or malicious activity linked to their networks, domains or IP addresses.
  3. Require Cyber Essentials across supply chains. Organisations must register for the Cyber Essentials Supplier Check Tool within two months, audit Cyber Essentials coverage across their supply chain, present the results to the board and take a risk-based approach to requiring certification from suppliers.

Signatories are also expected to encourage the same actions within their own supply chains, publish the signed declaration on their website within two months, and provide an annual public update on the steps taken to deliver against the pledge.

What is the significance?

For larger organisations, the pledge creates a visible board-level commitment to cyber governance and supply-chain assurance. For smaller suppliers, the impact may be indirect but significant: if their customers sign the pledge, they may increasingly be asked to obtain Cyber Essentials as a condition of doing business.

In practical terms, the pledge is likely to accelerate Cyber Essentials adoption across UK supply chains. It also raises expectations that boards should understand cyber risk, measure supplier assurance, and demonstrate that cyber resilience is part of business continuity planning.

Which businesses have already signed up?

The government has published a live list of organisations that have signed the Cyber Resilience Pledge. Early signatories include M&S, Microsoft UK, Vodafone Group, Deloitte LLP, Accenture UK Limited, Cloudflare, Aviva, Capgemini UK, Computacenter, ITV plc, London Stock Exchange Group, Mastercard Europe, Nationwide, Tesco PLC, Harrods, Whitbread and many cyber security and technology providers working towards adopting the Cyber Resilience Pledge including The Silver Cloud Business.

The reasons for signing will vary by organisation, but the common business drivers are clear:

  • Reputation and trust: signing demonstrates that cyber resilience is taken seriously at board level.
  • Supply-chain leadership: large organisations can use the pledge to set expectations for suppliers and partners.
  • Customer assurance: public commitment can help reassure customers after a period of heightened cyber threat.
  • Procurement readiness: businesses working with government, regulated sectors or large enterprises can show alignment with the UK’s preferred cyber-security direction of travel.
  • Incident learning: organisations that have experienced or observed major cyber incidents may see the pledge as a way to demonstrate continuous improvement.

Microsoft UK’s published comment around the launch positioned stronger board-level accountability and supply-chain security as ways for the UK to stay ahead as AI changes both cyber threats and defensive responses. That neatly captures the wider purpose of the pledge: it is about governance, resilience and shared responsibility across the economy.

What would a business need to do before declaring?

A sensible route to signing the pledge would look like this:

  1. Board briefing: explain the pledge, confirm why the business wants to sign, and agree the intended scope.
  2. Assign accountability: nominate a board-level owner for cyber risk and define reporting lines into the board.
  3. Complete cyber-governance training: ensure all directors complete NCSC Cyber Governance Training within the pledge timescale.
  4. Map current controls: assess existing policies, incident response, business continuity, supplier management, patching, identity protection, backups and monitoring.
  5. Register for NCSC Early Warning: identify who will receive alerts, how they will be triaged, and how incidents will be escalated.
  6. Register for the Cyber Essentials Supplier Check Tool: use it to understand supplier Cyber Essentials coverage.
  7. Audit the supply chain: categorise suppliers by criticality, data access, network access and operational dependency.
  8. Set supplier requirements: decide where Cyber Essentials, Cyber Essentials Plus or alternative assurance is required.
  9. Prepare the declaration: have the Chair or CEO sign the pledge, publish it on the company website, and schedule an annual update.

How much does the pledge cost?

The pledge itself is voluntary and does not carry a government certification fee. However, businesses should budget for the practical work needed to meet the declaration commitments.

The pledge areas can be broken down into the following fees and notes:

  • Pledge declaration - £0 government fee - Internal time to review, approve, sign and publish.
  • NCSC Early Warning - Free - Requires internal or managed-service time to monitor and respond to alerts.
  • Cyber-governance training - Free NCSC training - Board time should be planned and recorded.
  • Supplier audit - Internal time or consultancy - Cost depends on supplier volume and complexity.
  • Cyber Essentials - Typically around £320–£600 + VAT by organisation size - Assessment fee only; remediation or consultancy is extra.
  • Cyber Essentials Plus - Commonly from about £1,500 to £4,250+ VAT, sometimes more for complex environments - Includes independent technical testing after Cyber Essentials.

Cyber Resilience Pledge vs Cyber Essentials vs Cyber Essentials Plus

Cyber Resilience Pledge

  • Type - Voluntary public declaration
  • Main purpose - Board accountability and supply-chain resilience

  • Assurance level - Commitment-based

  • Typical audience - Medium, large and enterprise organisations, especially those with supply chains

  • Validity - Ongoing public commitment with annual update expected

  • Cost - No direct government fee, but implementation effort required
  • Best use - Showing leadership, governance maturity and supply-chain influence

Cyber Essentials

  • Type - Government-backed certification
  • Main purpose - Baseline technical controls

  • Assurance level - Self-assessment reviewed by an assessor

  • Typical audience - All organisations, especially SMEs and suppliers

  • Validity - 12 months

  • Cost - Usually around £320–£600 + VAT depending on size
  • Best use -  Proving basic cyber hygiene

Cyber Essentials Plus

  • Type - Government-backed certification with technical audit
  • Main purpose - Independent validation that controls work in practice

  • Assurance level - External testing and verification

  • Typical audience - Higher-risk suppliers, regulated sectors, government supply chains and larger organisations

  • Validity - 12 months 

  • Cost - Usually several thousand pounds depending on size and complexity
  • Best use - Proving basic controls have been independently tested

 

The key difference is that the pledge is a promise to govern and influence cyber resilience, while Cyber Essentials and Cyber Essentials Plus are certifications. In most cases, they should not be seen as alternatives. The pledge depends heavily on Cyber Essentials because one of its three core commitments is to drive Cyber Essentials through the supply chain.

Which route is best by business size?

Small business

Cyber Essentials first. Consider the pledge only if customers ask for it or if the business wants to make a public governance commitment. Cyber Essentials gives the strongest value for money and is increasingly useful in tenders and supply-chain assurance.

SME

Cyber Essentials as a minimum; Cyber Essentials Plus if handling sensitive data, providing IT services, bidding for public-sector work or supporting larger customers. SMEs are often supply-chain targets. Certification gives clear evidence of baseline controls and can unlock commercial opportunities.

Medium organisation

Cyber Essentials Plus, plus consider signing the Cyber Resilience Pledge if the organisation has a board structure and meaningful supplier network. Medium organisations normally have enough operational complexity to justify independent technical validation and formal supplier assurance.

Enterprise organisation

All three: Cyber Resilience Pledge, Cyber Essentials, and Cyber Essentials Plus where appropriate across key business units or subsidiaries. Enterprises influence large supply chains, face higher regulatory and reputational exposure, and need both governance commitment and technical assurance.

What does this mean for my business?

For most businesses, the right starting point is Cyber Essentials. It is affordable, recognised and directly aligned with the government’s supply-chain direction. Cyber Essentials Plus is the stronger option where customers, contracts, risk profile or data sensitivity justify independent testing. The Cyber Resilience Pledge is most powerful for organisations with board-level governance and supplier influence, because it shows public leadership and commits the business to raising cyber standards beyond its own perimeter.

The best outcome is not to treat these as competing options. A mature business should use Cyber Essentials to establish the baseline, Cyber Essentials Plus to validate it, and the Cyber Resilience Pledge to show leadership, accountability and supply-chain responsibility.

Publish Date: Aug 12, 2026