Businesses
Cyber Essentials Certifications Hit Record High as UK SMEs Still Lag on Cyber Readiness
17 Sept 2026

More than 61,000 Cyber Essentials certificates were issued in the year to June 2026, but only 12% of small businesses report holding the government-backed certification, raising concerns that cyber resilience is not keeping pace with the growing commercial and operational risks facing SMEs.
17 September 2026 — Cyber Essentials certification has reached a record level across the UK, yet smaller businesses continue to show significant gaps in cyber preparedness. Government figures show that 61,430 Cyber Essentials certificates were awarded between July 2025 and June 2026, including 46,245 at Cyber Essentials level and 15,185 at Cyber Essentials Plus.
The growth indicates that more organisations are taking basic cyber controls seriously, but the picture among SMEs remains uneven. The latest Cyber Security Breaches Survey found that only 12% of small businesses held Cyber Essentials in 2025/26, up from 5% the previous year, while 46% of small businesses identified a cyber breach or attack during the previous 12 months.
For smaller companies, the issue is increasingly commercial as well as technical. Cybersecurity controls can influence insurance, procurement, supply-chain eligibility and whether larger clients are willing to trust a supplier with sensitive systems or data.
SME cyber readiness is struggling to keep pace with risk
The 2025/26 Cyber Security Breaches Survey shows that progress in some areas has stalled or reversed. Only 41% of small businesses carried out cyber-security risk assessments, down from 48% in 2024/25 and returning to the same level recorded in 2023/24.
That decline comes despite continued exposure to attacks. Across UK businesses overall, 43% reported identifying a breach or attack during the previous year, while the figure rose to 46% among small businesses, 65% among medium-sized companies and 69% among large businesses.
John Pepper, CEO and founder of Managed247, said the figures reveal a mismatch between the risk smaller organisations face and the controls many currently have in place.
For many SMEs, cyber security competes with the immediate pressures of running and growing a business. But smaller organisations are not operating outside the threat landscape, and increasingly they are also part of larger organisations’ supply chains, where customers and partners may expect them to demonstrate that they have basic security controls in place.
Cybersecurity is becoming part of doing business
The business case for stronger cybersecurity is becoming harder for SMEs to separate from everyday operations.
Smaller firms often work with limited IT teams, tighter budgets and fewer dedicated security specialists. However, they may still process customer information, financial data, employee records or commercially sensitive information, while also connecting into the systems of larger organisations.
That makes them relevant to attackers and to procurement teams assessing supplier risk.
The government survey found that relatively few organisations formally review the cyber risks associated with their suppliers. Only 15% of businesses said they reviewed risks posed by immediate suppliers, while 3% specifically required suppliers to hold Cyber Essentials accreditation. Among large businesses, however, the latter figure rose to around a quarter, showing how certification can become more important further up the supply chain.
For SMEs trying to win work from larger companies, cyber readiness can therefore increasingly become part of the commercial proposition rather than merely an internal IT issue.
Pepper said:
For SMEs, cyber security can affect whether they can win and retain business. As supply-chain expectations rise, being able to demonstrate that the basics are in place could become an increasingly important part of being a trusted supplier.
Basic controls remain the starting point
Cyber Essentials is designed around a relatively small number of technical controls intended to reduce exposure to common attacks.
The National Cyber Security Centre says the scheme’s requirements are built around five areas of technical control and are reviewed regularly to remain relevant as cyber threats evolve. The current technical requirements, version 3.3, came into effect in April 2026.
For SMEs, that matters because cyber resilience does not necessarily begin with expensive security platforms or large specialist teams. Secure configurations, controlled access, timely software updates, malware protection and appropriate firewall management can address many common weaknesses.
Pepper argues that those fundamentals should be treated as part of normal business operations.
SMEs should start with the fundamentals: secure configurations, strong access controls, software updates and protection against malware. Good cyber hygiene should be treated as part of running a business, rather than something to address after an incident.
Awareness remains a significant barrier
Certification may be growing, but awareness remains relatively limited.
The government survey found that only 17% of businesses overall were aware of Cyber Essentials, while the original research highlighted in the release put awareness among small businesses at around one quarter. At the same time, the proportion of small businesses actually holding the certification rose from 5% to 12% year on year.
The numbers suggest that uptake can grow quickly once businesses become familiar with the scheme, but many organisations may still see cybersecurity as complex, expensive or disconnected from immediate business priorities.
That perception becomes increasingly difficult to maintain as more commercial relationships depend on digital systems.
Whether a company sells professional services, manufacturing components, software or consumer products, its cyber posture can affect customers, partners and suppliers beyond its own organisation.
Supply chains are changing the business case
One of the strongest forces behind wider adoption may come not from regulation, but from customers.
Large organisations increasingly assess the resilience of companies within their supply chains because an insecure supplier can create a route into their own systems. The Cyber Security Breaches Survey found evidence that some organisations are already requiring new suppliers to hold Cyber Essentials or Cyber Essentials Plus as part of procurement processes.
That changes the economics of cyber investment for SMEs.
A security improvement that once looked like an overhead can become a requirement for competing for contracts. Certification can provide a straightforward way of demonstrating that minimum controls are in place without forcing every customer to conduct a full technical assessment independently.
For smaller businesses competing in B2B markets, cyber credentials may therefore increasingly sit alongside price, service quality, insurance and regulatory compliance when buyers choose suppliers.
Record certifications do not mean the problem is solved
The rise to 61,430 certificates is an important indicator of progress, but it should not be interpreted as evidence that UK business cyber resilience is already mature.
The same government research shows continuing weaknesses in risk assessment, supplier oversight and formal cyber planning, particularly among smaller organisations.
The commercial consequences of those weaknesses are also becoming broader. A cyber incident can interrupt operations, damage customer relationships and create direct financial costs, but inadequate security can also affect whether a business is viewed as credible enough to enter a supply chain in the first place.
For SMEs, that makes cybersecurity part of a larger business-readiness question. Protecting systems remains the immediate objective, but demonstrating resilience may increasingly influence access to customers, partnerships and growth opportunities.
About Managed247
Managed247 is a UK managed IT and cybersecurity services provider supporting organisations with technology infrastructure, cybersecurity and ongoing IT management. John Pepper, CEO and founder of Managed247, provided commentary on the latest Cyber Essentials and SME cyber-readiness figures.






