The UK government’s Cyber Essentials scheme has recorded a 20% increase in certifications over the past year, although uptake remains limited relative to the country’s SME population.
The UK government’s flagship cyber security certification scheme has recorded its highest annual number of certifications, with 61,430 certificates awarded between July 2025 and June 2026.
The newly published figures represent a 20% increase compared with the previous year, although the number of businesses participating in the scheme remains relatively small compared with the UK’s wider SME population.
Of the certificates awarded, 46,245 were at the basic Cyber Essentials (CE) level, which requires organisations to complete a self-assessment, while 15,185 were awarded at Cyber Essentials Plus (CE+), which involves an independent third-party audit.
However, nearly three-quarters of the basic-level CE certifications were recertifications rather than new organisations joining the scheme.
The figures also highlight the scale of the challenge in expanding adoption. Government estimates suggest there are approximately 5.7 million SMEs in the UK, accounting for more than 99% of the private sector.
The latest certification figures come amid continued concerns over the cyber security risks facing smaller businesses.
Research published by cyber security vendor ESET found that almost half (49%) of UK SMEs experienced a cyber security incident over the past year.
Based on responses from 500 businesses, the company’s 2026 SMB Cyber Risk Report found that respondents took an average of more than four weeks to identify and recover from a breach.
The research identified phishing, unpatched vulnerabilities, weak passwords and insufficient monitoring as the primary causes of incidents, highlighting the importance of fundamental security practices of the kind advocated by Cyber Essentials.
John Pepper, CEO and founder of Managed 247, said a significant gap remains between the cyber risks facing smaller businesses and the measures many have implemented to address them.
“For many SMEs, cyber security competes with the immediate pressures of running and growing a business. But smaller organizations are not operating outside the threat landscape,” he said.
“SMEs should start with the fundamentals: secure configurations, strong access controls, software updates and protection against malware. Good cyber hygiene should be treated as part of running a business, rather than something to address after an incident.”
Supply Chain Requirements Could Drive Adoption
The government is seeking to encourage wider adoption of Cyber Essentials through initiatives aimed at strengthening supply chain security.
According to the latest government figures, none of the organisations seeking certification over the past year reported doing so because they had been asked to by a customer.
However, several government initiatives are intended to increase the role of certification in procurement and supplier relationships.
Under the voluntary Cyber Resilience Pledge, organisations that sign up are required to demand Cyber Essentials certification throughout their supply chains.
Meanwhile, the Cyber Security and Resilience Bill includes provisions that would create a legal duty for organisations to manage cyber risk within their supply chains, potentially encouraging more businesses to introduce certification requirements for suppliers.
In December 2025, the National Cyber Security Centre (NCSC) also published its Cyber Essentials Supply Chain Playbook, urging organisations to establish certification as a baseline requirement across their supplier networks.
Recommended reading
- Elevator Targets Scotland’s ‘Growth Gap’ With New SME Survey
- Edinburgh-founded Quorum Cyber Appoints New CEO
- 81% of Scottish Businesses Seeing AI Productivity Gains
- Majority of Scottish SMEs Expect AI to Boost Productivity
These measures could make Cyber Essentials increasingly relevant for smaller businesses seeking to secure contracts with larger organisations.
“For SMEs, cybersecurity can affect whether they can win and retain business,” said Pepper. “As supply-chain expectations rise, being able to demonstrate that the basics are in place could become an increasingly important part of being a trusted supplier.”
The government has also claimed that organisations holding Cyber Essentials certification are 92% less likely to make a claim on their cyber insurance.
Despite the record number of certificates awarded over the past year, the high proportion of recertifications and the size of the UK’s SME population suggest that expanding participation among businesses not yet certified remains a significant challenge for the scheme.





