Cyber Essentials just had its best year. It still reaches a sliver of British business.
Cyber Security

Cyber Essentials just had its best year. It still reaches a sliver of British business.

61,430 certificates in the year to June, up a fifth on the year before. There are around 5.7 million SMEs in the UK. The gap matters more now that customers have started asking.

21 September 20265 min read

The government updated its Cyber Essentials figures on 16 September. The page reads: "The latest figures show 61,430 Cyber Essentials certificates have been awarded over the past year (July 2025 to June 2026); 46,245 at CE level and 15,185 at CE +." Infosecurity Magazine reported that as a 20 per cent rise on the year before, and a record for the scheme.

The second number is the one to hold next to it. The government estimates there are around 5.7 million SMEs in the UK, over 99 per cent of the private sector. Set 61,430 certificates against 5.7 million businesses and the scheme covers roughly one per cent of them, and that is before you allow for the fact that nearly three quarters of the certificates were recertifications rather than new organisations signing up, as Infosecurity Magazine reported.

The difference between the two levels

Cyber Essentials is self assessed. You answer a question set about a basic set of technical controls and an assessor reviews the answers. Cyber Essentials Plus covers the same ground, but an assessor tests the controls on your actual machines. Of the past year's certificates, 46,245 were at the basic level and 15,185 at Plus. The government's page notes that certificates are valid for 12 months, which is why recertifications make up so much of the annual total.

Why this stops being optional

Infosecurity Magazine reported that, according to the government, none of the organisations that sought a certificate over the past year did so because a customer asked them to, and that the government wants that to change. Its voluntary Cyber Resilience Pledge requires organisations that sign up to demand Cyber Essentials through their supply chains, and the Cyber Security and Resilience Bill creates a legal duty to manage cyber risk in the supply chain. In December 2025 the NCSC published a Cyber Essentials Supply Chain Playbook urging organisations to require certification as a baseline across their supplier base.

John Pepper, chief executive and founder of Managed 247, told Infosecurity Magazine that there is still too big a gap between the risk smaller businesses face and what they do about it. His starting point: "SMEs should start with the fundamentals: secure configurations, strong access controls, software updates and protection against malware."

What the incident numbers look like underneath

New figures from ESET, reported by Infosecurity Magazine the same day, found that 49 per cent of UK SMEs suffered a cyber security incident over the past year. The 2026 SMB Cyber Risk Report, based on 500 responses, found the average respondent took over four weeks to identify and recover from a breach, and that most incidents were caused by phishing, unpatched vulnerabilities, weak passwords and a lack of monitoring. Those four are exactly what the Cyber Essentials controls are aimed at.

The insurance line

The government's own page makes a claim worth taking to your broker: "Organisations with Cyber Essentials are 92% less likely to make a claim on their cyber insurance." Read it for what it is. It is the government's figure rather than an insurer's, and it describes claims made rather than premiums charged. It is still a number your renewal conversation can use.

What this means for your business

If you sell to anyone bigger than you, treat Cyber Essentials as a sales document as much as a security one. A certificate costs a fraction of a lost tender, and the controls behind it cover the same failures that cause most SME incidents anyway: phishing, missing updates, weak passwords and nobody watching. Start with basic Cyber Essentials if you have never done it, because filling in the self assessment will find your gaps faster than any audit. Move to Plus when a customer contract asks for it, or when you would rather somebody tested the controls than took your word for them. Either way the 12 month expiry is real, so put next year's date in the calendar the day you pass.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.