Cyber Essentials Just Became Non-Negotiable: Here’s What That Means for Your Business

Government departments rarely move quickly on cyber security. This year, they have. Ministers have put real weight behind a message that used to live mostly at the technical end of the business. 

Cyber security no longer sits solely with whoever manages your IT. It’s now something the Department for Science, Innovation and Technology (DSIT), the National Cyber Security Centre (NCSC), and Downing Street itself are treating as a board-level responsibility that runs the length of a supply chain. 

For Basildon and South Essex businesses which rely of a supply chain in order to run their businesses, that shift is worth understanding properly and what action needs to be taken. 

Cyber Essentials, the certification many businesses have held for years as a background box-tick, has just been reaffirmed the baseline the whole country’s supply chains are expected to meet. 

Why This Is Happening Now 

Cyber-attacks on UK business have grown year on year and are becoming harder to stop, as attackers adapt new methods and technology resulting in defences not being able to keep pace and stop the new wave of attacks. A run of high-profile incidents affecting house-hold name retailers and public services has demonstrated, cyber security is definitely not someone else’s problem. 

The growing use of artificial intelligence by attackers is accelerating that shift further, making some attacks quicker to launch and harder to spot early. 

The government’s response has been to make Cyber Essentials a named, active expectation, backed by dedicated funding and a public pledge that businesses are expected to act on now. 

What the Cyber Resilience Pledge Actually Asks of Businesses 

The Cyber Resilience Pledge was first announced by the Security Minister at CYBERUK 2026 in Glasgow this April, alongside a £90 million investment aimed largely at helping small and medium-sized businesses raise their defences. It was formally launched at 10 Downing Street on 7 July 2026, when more than 60 founding signatories, including Microsoft UK, Vodafone and the Nationwide Building Society, put their names to it. 

The Pledge sits inside a wider National Cyber Action Plan, due later this summer, setting out how government and industry plan to close the gap on AI-driven threats together. 

Organisations that sign commit to three practical actions, each backed by the National Cyber Security Centre (NCSC): 

  • Making cyber a board-level responsibility by implementing the government’s Cyber Governance Code of Practice and ensuring every board member completes NCSC training 
  • Registering for the NCSC’s free Early Warning service, so suspicious activity on the network gets flagged and investigated early 
  • Taking a risk-based approach to requiring Cyber Essentials certification across the supply chain 

The government’s own figures show organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance than those without it. 

Where a business requires certification of its suppliers, the effect compounds further still: one of the UK’s largest pensions and life companies saw an 80% reduction in cyber incidents across its supplier network of 2,800 businesses after making it mandatory. 

Cyber Essentials Is Already Mandatory in Parts of the Economy 

This isn’t the first time the government has leaned on Cyber Essentials to raise the bar. It builds on requirements already in force elsewhere in the economy, several of which will be directly relevant if your business supplies to the public sector or a regulated industry. 

Since February 2025, Procurement Policy Note 014 has required central government departments, their agencies, and NHS bodies to demand Cyber Essentials or Cyber Essentials Plus certification from suppliers bidding on contracts that involve citizen data, government employee data, or ICT systems handling government information. 

That requirement doesn’t stop at the prime contractor. Where a subcontractor or supplier further down the chain handles the same kind of data or systems, the same expectation applies to them too. 

A Seat at the Table 

Outbound signed the Cyber Resilience Pledge as an early adopter, putting us among the first organisations in the UK to do so. On 7 July, our Chief Information Technology Officer, Keith Bucknall, attended the launch reception at 10 Downing Street alongside the government’s other founding signatories. 

We mention it here for context rather than as the headline. When the government asked British business to raise its standards on supply chain security, we had already committed to the same three actions set out above. 

It’s the standard we hold ourselves to and the one we help our clients reach every day. 

What This Means If You’re an Essex SME With Clients or Suppliers 

If your business supplies to an organisation, bids for public sector work, or sits anywhere in a regulated supply chain, this is moving faster than many SMEs have had time to notice. 

  • Larger clients and public sector buyers are increasingly asking suppliers to hold Cyber Essentials before a contract gets signed 
  • Insurers are factoring certification into premiums and claims decisions, given how sharply it reduces claim rates 
  • Certification is also becoming a due diligence shortcut, since buyers use it to skip lengthy security questionnaires when assessing new suppliers 
  • Businesses in sectors common across Basildon and south Essex are especially likely to see this requirement appear in a tender or contract renewal soon 
  • It’s increasingly built into new client onboarding as standard too, sitting alongside references and financial checks rather than arriving as a one-off request 

A risk-based approach doesn’t mean the decision stays theoretical for long. In practice, it means a growing number of medium and large buyers reviewing their supplier base and asking a straightforward question: does this supplier already hold Cyber Essentials, and if not, why not? 

For many Essex SMEs that have never been asked for a security certification before, that question is more likely to land within the next contract cycle than the next decade. 

None of this means every business needs Cyber Essentials by next month. But it does mean the baseline that government, insurers and larger buyers are converging on isn’t something to leave for later. 

If you’re not sure whether your current setup would hold up to that scrutiny, that’s worth finding out before a client or tender asks the question for you. 

Where Does Your Business Stand? 

Find out what this means for your business and where you stand. Talk to Outbound. 

FAQs 

  1. What is Cyber Essentials, and is it now mandatory? 
    Cyber Essentials is the UK government’s baseline cyber security standard, covering five controls: firewalls, secure configuration, access control, malware protection and patch management. It isn’t mandatory for every business, but it’s now the standard the government has named for supply chains under the Cyber Resilience Pledge, and it has long been required for many government contracts. 
  2. What is the Cyber Resilience Pledge? 
    A voluntary commitment developed by the Department for Science, Innovation and Technology (DSIT) and backed by the NCSC. Signatories commit to making cyber a board-level responsibility, registering for the NCSC’s Early Warning service, and taking a risk-based approach to requiring Cyber Essentials across their supply chain. 
  3. Do small businesses in Basildon and Essex actually need Cyber Essentials? 
    Not every small business is required to hold it, but that’s changing quickly. If you supply to an organisation, bid for public sector contracts, or sit in a regulated supply chain, you’re increasingly likely to be asked for it, whether by a client, an insurer or a procurement team. 
  4. What’s the difference between Cyber Essentials and Cyber Essentials Plus? 
    Cyber Essentials is self-assessed: you complete a questionnaire confirming your controls are in place. Cyber Essentials Plus adds an technical audit, including a vulnerability scan, carried out by a licensed assessor. It gives clients and partners assurance that doesn’t rely on taking your word for it. 
  5. How quickly can an Essex business get Cyber Essentials certified? 
    A business can get Cyber Essentials certification in as little as 3 to 5 working days if it’s technical controls are already compliant, and sometimes sooner with the right support. We can provide step-by-step support through the process, ensuring you have expert advice and guidance along the way. 

Looking for something specific?