THE UK government’s Cyber Essentials scheme issued a record 61,430 certificates between July 2025 and June 2026, a 20% increase on the previous year. This comprised 46,245 basic Cyber Essentials certificates, which are self-assessed, and 15,185 Cyber Essentials Plus certificates, which require an independent audit. However, almost three-quarters were recertifications rather than new organisations joining the scheme.
Take-up remains limited compared with the estimated 5.7 million UK small and medium-sized enterprises (SMEs), which account for more than 99% of the private sector.
The figures were published alongside research from ESET, based on 500 responses for its 2026 SMB Cyber Risk Report. It found that 49% of UK SMEs had experienced a cybersecurity incident in the previous year, with respondents taking more than four weeks on average to identify and recover from a breach. The report attributed most incidents to phishing, unpatched vulnerabilities, weak passwords and insufficient monitoring—areas addressed by Cyber Essentials’ baseline controls. Managed 247 CEO John Pepper said smaller businesses should prioritise secure configurations, access controls, software updates and malware protection.
The government said none of the organisations obtaining certification in the past year did so because a customer required it, but initiatives could increase supply-chain pressure. Its voluntary Cyber Resilience Pledge requires participating organisations to demand Cyber Essentials across their supply chains, while the proposed Cyber Security and Resilience Bill would create a legal duty to manage supply-chain cyber risk.
The NCSC’s December 2025 Cyber Essentials Supply Chain Playbook also recommends certification as a baseline. The government claims certified organisations are 92% less likely to make a cyber-insurance claim.