The Foundry Cyber blog

The Cyber Resilience Pledge: What It Actually Means for Your Small Business

· 6 min read

This week, the government launched the Cyber Resilience Pledge. It is a public commitment from more than 60 major businesses, including M&S, Nationwide, ITV, Microsoft UK, and Cloudflare, to strengthen their cyber defences. The initiative is backed by the Department for Science, Innovation and Technology and the National Cyber Security Centre (NCSC).

At first glance, this looks like big-business news. The signatories are household names, and the language focuses on boards, governance, and national resilience. If you run a 10, 50, or 150-person company, it would be easy to file this under “not my problem.”

That would be a mistake. Buried in the pledge is a commitment that will land squarely on small and medium businesses over the next 12 to 24 months. It will not happen through regulation, but through something far more immediate: your customers’ procurement teams.

What the pledge actually says

Organisations signing the pledge commit to three things:

It is this third commitment that changes things for SMBs.

Why the supply chain commitment matters to you

Here is how the mechanism works. Large organisations, including more than half of the government’s 39 strategic suppliers, are now publicly committed to asking their suppliers about Cyber Essentials.

The pressure behind this is real. A significant cyber attack now costs an average UK business almost £195,000, with the annual cost to UK organisations estimated at £14.7 billion. Those large organisations rely on suppliers like marketing agencies, software houses, recruiters, logistics firms, accountants, and component manufacturers. In other words: businesses like yours.

Cyber Essentials has existed since 2014. For most of that time, it has been a “nice to have” badge that helped with the occasional public sector bid. What the pledge does is progressively convert it into a condition of doing business with a growing share of the UK’s largest buyers.

Attackers understood this dynamic long before policymakers did. If you cannot breach a major enterprise directly, you breach the small supplier with access to their systems, data, or invoicing. Supply chain attacks have become one of the most common routes into large organisations, which is exactly why those businesses are now being asked to push security requirements downstream.

The practical consequence: at some point in the next year or two, a customer or a prospect you are pitching is going to send you a security questionnaire asking whether you hold Cyber Essentials. Your answer will influence whether you win or keep the work.

The bar is higher than it used to be

If you looked at Cyber Essentials a few years ago and decided it was straightforward, it is worth looking again. The current question set (version 3.3, live since April 2026) raised the bar in several ways that frequently catch SMBs out:

None of this is unreasonable. These controls genuinely stop the majority of commodity attacks. However, “we will sort it when a customer asks” is no longer a viable strategy. Sorting it properly by discovering your estate, enforcing MFA everywhere, and establishing patching discipline takes weeks, not days. If the questionnaire arrives first, you will find yourself scrambling to fix issues under commercial pressure with a deal on the line.

What you can do this month

Certification vs. readiness: an honest distinction

One clarification is worth making: Cyber Essentials certificates can only be issued by certification bodies licensed through IASME. No consultancy, platform, or tool can certify you. Anyone implying otherwise should be treated with caution.

What you can do ahead of certification is establish an evidenced view of your posture. You can verify from your actual systems, rather than a hopeful self-assessment, whether your setup aligns with Cyber Essentials requirements for MFA, access control, updates, malware protection, and secure configuration.

Having that evidence serves three purposes: it tells you if you are ready to certify, it drastically reduces the risk of failing the assessment, and it gives you something substantive to show customers and insurers in the meantime.

For businesses running on Microsoft 365 and Intune, this is more achievable than most owners realise. The majority of what Cyber Essentials asks for is directly measurable from your tenant. No guesswork, no optimistic self-declarations.

The direction of travel is clear

The pledge will not transform supplier requirements overnight, but it sets a direction that is unlikely to reverse: cyber security requirements are flowing down supply chains, from the largest buyers to the smallest suppliers, with Cyber Essentials serving as the common language. A National Cyber Action Plan is expected to follow, and the Cyber Security and Resilience Bill is moving through Parliament, with Royal Assent expected later this year.

For SMBs, the choice isn’t whether to engage with this, it is whether to engage on your own timetable or your customers’ timetable. The first is a manageable project. The second is a scramble.

Foundry Cyber helps small and medium businesses on Microsoft 365 understand exactly where they stand against Cyber Essentials requirements, with evidence pulled from live tenant data, not questionnaires. If you’d rather know your posture before a customer asks, get in touch.

All posts

Onboarding new customers now

Let's start with a conversation.

Tell us a bit about your business and what you're worried about. We'll come back with a plain-English view of where you stand and what we'd suggest doing first. Real people, real answers.