Get Cyber Essentials before someone makes you
A security questionnaire arrives from your largest customer. Or the insurance renewal asks a question nobody in the building can answer. Or a tender you wanted looks straightforward until you reach the section listing certifications, and you do not hold the one it names.
At that point you have a deadline you did not set. The work is the same work it would have been six months earlier, but now it is urgent, and urgent costs more. That is the real argument for Cyber Essentials, and it has almost nothing to do with how many certificates were issued last year.
Cyber Essentials is the UK Government-backed baseline certification: five technical controls and a verified self-assessment. We wrote a plain-English walkthrough of what it actually involves, and what changed in the 2026 update. This filing is about a different question: not what it is, but when you do it.
The window where it is still your decision
Right now, for most UK businesses, holding Cyber Essentials is a choice. Nobody is compelling you. That is a good position to be in, and it is narrowing from two directions at once.
The first is commercial. The Cyber Resilience Pledge asks large signatories to require Cyber Essentials across their supply chains, and the National Cyber Security Centre's Cyber Essentials Supply Chain Playbook gives them a step-by-step method for doing it: profile your suppliers, set certification as a minimum requirement, then write it into contracts and renewals. This is not a campaign aimed at you. It is a set of instructions handed to your customers. It only takes one of them to follow it.
The second is legal. The Cyber Security and Resilience Bill is working its way through Parliament, and it places a statutory duty on organisations in regulated sectors to manage the security risks in their supply chains. We covered what the Bill actually means when it was in Commons committee; it has moved on since, though the substantive obligations are expected to arrive later through secondary legislation rather than the day it passes. Most SMEs will not be regulated directly. But a duty on a regulated organisation to manage supplier risk becomes, in practice, a question that regulated organisation asks its suppliers. Regulation flows downhill the same way procurement does.
Neither is a reason to panic. Both are reasons to notice that the decision is currently yours and will not stay that way.
Why the timing changes the cost
Certifying voluntarily and certifying under a deadline produce the same certificate and two entirely different experiences.
When you choose the timing, you find out what is wrong on a Tuesday with no consequences attached. The assessment surfaces the same things in most small businesses: the laptop nobody has updated, the shared admin login three people use, the cloud service a department signed up for and never mentioned. Fixing those calmly takes a few weeks. Fixing them in nine days because a renewal is blocked means overtime, rushed purchases, and decisions made to clear the questionnaire rather than to improve the business.
The second cost is easier to miss. A certificate obtained under pressure gets treated as a document rather than a change. The controls go in to pass and drift back out afterwards, so you pay for the certification and keep none of the benefit.
Be honest about the limits, too. Cyber Essentials is a floor: five technical controls, checked once a year, self-assessed at the basic level. It says nothing about phishing awareness, incident response, or backups. If you already run a full management system such as ISO 27001, you may not need it at all, though you may still be asked for it because it is the name on the form.
What the numbers say, and what they do not
The Government's published figures for July 2025 to June 2026 show 61,430 Cyber Essentials certificates awarded, a record, and a 20% rise on the year before. Of those, 46,245 were basic and 15,185 were the audited Plus level. Set against roughly 5.7 million UK SMEs, that is a small fraction, and nearly three-quarters of the total were recertifications rather than businesses joining for the first time.
Read that carefully, because it cuts both ways. Adoption is low, so holding a certificate still distinguishes you from most of your competitors. And adoption is rising fast, so that advantage has a shelf life: the certificate is on its way from differentiator to entry ticket.
A survey of 500 UK businesses by ESET, reported alongside the certificate figures, found 49% had suffered a security incident in the past year, with phishing, unpatched software, weak passwords, and a lack of monitoring named as the common causes. That is a vendor survey rather than official statistics, so treat the precise figure with care. The causes are the unsurprising part, and they are largely the ground Cyber Essentials covers.
What to do
- Find out whether the question is already coming. Look at your three or four largest customers. Are any of them large enough to have signed the Cyber Resilience Pledge, or in a regulated sector? Ask your account contact directly whether certification is heading into their supplier requirements. Most will tell you.
- Check your contracts and your insurance renewal date. Security requirements often already sit in contracts nobody has reread since signature, and insurers increasingly ask about the same controls.
- Preview the assessment before you commit. IASME publishes the self-assessment questions, which is the cheapest way to see where you stand. Read them, answer honestly, and the gap list writes itself.
- Fix the gaps whether or not you certify. Multi-factor authentication everywhere, security updates applied promptly, and admin accounts used only for admin work are worth doing on their own.
- If you already hold it, diary the renewal. An expired certificate answers a questionnaire badly.
How Steelwise can help
Getting a smaller business through Cyber Essentials without turning it into a compliance project is a short, well-defined piece of security advisory work. Get in touch and we will tell you honestly whether you need the certificate, something more, or nothing yet.
Further reading
- NCSC: Cyber Essentials overview
- NCSC: Cyber Essentials Supply Chain Playbook
- NCSC: Small organisations guide to security