Decoding the world of cybersecurity

· ·

Cyber Essentials awards reach record level

More than 61,000 Cyber Essentials certificates were awarded in the year to June, extending adoption of the UK government-backed baseline security scheme.

Cyber Essentials awards reach record level
Summary
  • A record 61,430 Cyber Essentials certificates were awarded in the year to 30 June 2026.
  • The total included 46,245 standard Cyber Essentials awards and 15,185 Cyber Essentials Plus certificates.
  • Government policy is increasingly linking the scheme with board accountability and supply-chain expectations as well as technical assurance.

The number of Cyber Essentials certificates awarded across the UK has reached a record level, with 61,430 awards issued in the year to 30 June 2026 as the government continues to use the scheme as a baseline for organisational and supply-chain cyber assurance.

The latest government figures show that the annual total comprised 46,245 standard Cyber Essentials certificates and 15,185 Cyber Essentials Plus awards. The combined figure increased from 59,090 reported at the end of March.

The National Cyber Security Centre-backed scheme focuses on a defined set of controls intended to reduce exposure to common attacks. Cyber Essentials Plus adds independent technical verification rather than relying solely on the self-assessment route used for standard certification.

The figures count certificates awarded rather than unique organisations. Certificates are time-limited, organisations renew them, and larger groups may certify different parts of their operations, so the total should be treated as a measure of certification activity rather than a census of protected businesses.

Even with that limitation, continued growth provides an indication of how baseline assurance is becoming embedded in purchasing and supplier relationships. Government contracts already use Cyber Essentials requirements in defined circumstances, while larger organisations increasingly use certification to establish minimum expectations for third parties.

The September figures were published alongside the government’s wider emphasis on its Cyber Resilience Pledge, under which signatories commit to make cyber security a board responsibility, use the NCSC’s Early Warning service, and require Cyber Essentials across supply chains.

The Cyber Resilience Pledge has reached 149 signatories, giving the baseline certification scheme a place in a broader programme covering senior accountability and supplier expectations.

That approach gives Cyber Essentials a wider role than a standalone certificate. It provides a common language around controls including secure configuration, access management, malware protection, firewalls, and software updates, particularly where customers have limited ability to inspect suppliers’ internal security programmes directly.

Certification does not establish that an organisation cannot be breached. The controls are deliberately focused on common attack paths and do not replace architecture, identity governance, incident response, application security, or sector-specific regulatory requirements where those are needed.

The NCSC has also been adapting the scheme for organisations whose environments do not fit its standard model. Cyber Essentials Pathways has been widened for complex organisations, providing a managed route to demonstrate equivalent security outcomes while retaining certification requirements.

That combination of volume and flexibility is relevant as assurance becomes more closely tied to procurement. Supply-chain programmes can create duplication where providers face different customer questionnaires and technical expectations. A recognised baseline can reduce some of that friction, although buyers still have to determine whether certification addresses the risk attached to a particular service.

The latest figures therefore demonstrate continued adoption rather than a complete measure of national cyber maturity. Their significance lies in the increasing use of a common minimum standard across procurement, supplier management, and governance — including organisations that may face little direct cyber regulation of their own.

×