The Cyber Resilience Pledge: What It Actually Means for Your Small Business
· 6 min read
This week, the government launched the Cyber Resilience Pledge. It is a public commitment from more than 60 major businesses, including M&S, Nationwide, ITV, Microsoft UK, and Cloudflare, to strengthen their cyber defences. The initiative is backed by the Department for Science, Innovation and Technology and the National Cyber Security Centre (NCSC).
At first glance, this looks like big-business news. The signatories are household names, and the language focuses on boards, governance, and national resilience. If you run a 10, 50, or 150-person company, it would be easy to file this under “not my problem.”
That would be a mistake. Buried in the pledge is a commitment that will land squarely on small and medium businesses over the next 12 to 24 months. It will not happen through regulation, but through something far more immediate: your customers’ procurement teams.
What the pledge actually says
Organisations signing the pledge commit to three things:
- Board-level cyber governance. Signatories adopt the Cyber Governance Code of Practice and put their board members through the NCSC’s Cyber Governance Training. Cyber risk becomes a director’s responsibility, not something delegated to IT and forgotten.
- Signing up to NCSC Early Warning. This is a free NCSC service that monitors for signs of compromise, vulnerabilities, and suspicious activity affecting an organisation’s networks, alerting them if something is found.
- Requiring Cyber Essentials across their supply chain. Signatories commit to taking a risk-based approach to requiring Cyber Essentials (the government-backed certification covering five fundamental technical controls) from the businesses that supply them.
It is this third commitment that changes things for SMBs.
Why the supply chain commitment matters to you
Here is how the mechanism works. Large organisations, including more than half of the government’s 39 strategic suppliers, are now publicly committed to asking their suppliers about Cyber Essentials.
The pressure behind this is real. A significant cyber attack now costs an average UK business almost £195,000, with the annual cost to UK organisations estimated at £14.7 billion. Those large organisations rely on suppliers like marketing agencies, software houses, recruiters, logistics firms, accountants, and component manufacturers. In other words: businesses like yours.
Cyber Essentials has existed since 2014. For most of that time, it has been a “nice to have” badge that helped with the occasional public sector bid. What the pledge does is progressively convert it into a condition of doing business with a growing share of the UK’s largest buyers.
Attackers understood this dynamic long before policymakers did. If you cannot breach a major enterprise directly, you breach the small supplier with access to their systems, data, or invoicing. Supply chain attacks have become one of the most common routes into large organisations, which is exactly why those businesses are now being asked to push security requirements downstream.
The practical consequence: at some point in the next year or two, a customer or a prospect you are pitching is going to send you a security questionnaire asking whether you hold Cyber Essentials. Your answer will influence whether you win or keep the work.
The bar is higher than it used to be
If you looked at Cyber Essentials a few years ago and decided it was straightforward, it is worth looking again. The current question set (version 3.3, live since April 2026) raised the bar in several ways that frequently catch SMBs out:
- Multi-factor authentication (MFA) is mandatory across all cloud services. Not just email. Every cloud service your business uses, like accounting software, file storage, CRM, and design tools, needs MFA enforced for every user.
- AI tools are now in scope. Cloud-based AI services count as cloud services. If your team uses ChatGPT, Copilot, or AI coding assistants for work purposes, even on personal logins, they are part of your assessed estate.
- No cloud services can be excluded. Previously, businesses could quietly draw a boundary around the systems they had already secured. That is no longer allowed. You have to declare everything, which means you have to know about everything. For most SMBs, the honest answer to “list all your cloud services” is “we are not entirely sure.” Figuring that out is now the real first step.
- Patching within 14 days. High and critical security updates must be applied within 14 days of release across your entire estate. This is a discipline question, not a technology question, and it is one of the most common reasons businesses fail the assessment.
None of this is unreasonable. These controls genuinely stop the majority of commodity attacks. However, “we will sort it when a customer asks” is no longer a viable strategy. Sorting it properly by discovering your estate, enforcing MFA everywhere, and establishing patching discipline takes weeks, not days. If the questionnaire arrives first, you will find yourself scrambling to fix issues under commercial pressure with a deal on the line.
What you can do this month
- Register for NCSC Early Warning. It is free, takes under an hour, and gives you national-level threat intelligence about your own domains and IP addresses. If the NCSC spots signs your network is compromised or exposed, you want to know.
- Work through the NCSC Cyber Action Toolkit. Also free, this is built specifically for smaller businesses without dedicated IT staff. It walks you through the fundamentals in plain English.
- Run a cloud services discovery exercise. Before you can meet the requirements, you need to know what you are running. Ask every team what tools they actually use, including AI tools and personal logins. If you are on Microsoft 365, your sign-in logs will reveal services your official software list missed. The gap between “what IT thinks we use” and “what we actually use” is almost always bigger than expected.
- Verify MFA, do not just assume it. “We have MFA” and “MFA is enforced for every user on every service, with no legacy exceptions” are very different statements. Check the actual enforcement, not just the intention.
- Establish where you stand before anyone asks. The businesses that will handle this transition comfortably are the ones who know their posture right now. Find out which controls you would pass, which you would fail, and what the path to fixing them looks like, rather than discovering it live during a customer’s due diligence process.
Certification vs. readiness: an honest distinction
One clarification is worth making: Cyber Essentials certificates can only be issued by certification bodies licensed through IASME. No consultancy, platform, or tool can certify you. Anyone implying otherwise should be treated with caution.
What you can do ahead of certification is establish an evidenced view of your posture. You can verify from your actual systems, rather than a hopeful self-assessment, whether your setup aligns with Cyber Essentials requirements for MFA, access control, updates, malware protection, and secure configuration.
Having that evidence serves three purposes: it tells you if you are ready to certify, it drastically reduces the risk of failing the assessment, and it gives you something substantive to show customers and insurers in the meantime.
For businesses running on Microsoft 365 and Intune, this is more achievable than most owners realise. The majority of what Cyber Essentials asks for is directly measurable from your tenant. No guesswork, no optimistic self-declarations.
The direction of travel is clear
The pledge will not transform supplier requirements overnight, but it sets a direction that is unlikely to reverse: cyber security requirements are flowing down supply chains, from the largest buyers to the smallest suppliers, with Cyber Essentials serving as the common language. A National Cyber Action Plan is expected to follow, and the Cyber Security and Resilience Bill is moving through Parliament, with Royal Assent expected later this year.
For SMBs, the choice isn’t whether to engage with this, it is whether to engage on your own timetable or your customers’ timetable. The first is a manageable project. The second is a scramble.
Foundry Cyber helps small and medium businesses on Microsoft 365 understand exactly where they stand against Cyber Essentials requirements, with evidence pulled from live tenant data, not questionnaires. If you’d rather know your posture before a customer asks, get in touch.