The UK government's flagship cyber certification program awarded 61,430 certificates in the past year, a record high, but the total remains a fraction of the country's small business population, according to newly published figures from Infosecurity Magazine in September 2026. The data shows a 20% jump in Cyber Essentials certifications between July 2025 and June 2026 compared to the previous year. However, government estimates place the number of SMEs in the UK at roughly 5.7 million, meaning the certification figures represent a drop in the ocean.

Of the 61,430 certificates issued, 46,245 were at the basic Cyber Essentials level, which organizations can self-assess, while 15,185 were at the CE+ level, which demands a third-party audit. Nearly three-quarters of all certifications went to organizations renewing their credentials rather than first-time participants. Separate research published by ESET today found that half of UK SMEs experienced a cybersecurity incident in the past year. The vendor's 2026 SMB Cyber Risk Report, based on 500 responses, revealed that the typical respondent needed more than four weeks to detect and recover from a breach, with most incidents stemming from phishing, unpatched vulnerabilities, weak passwords, and insufficient monitoring.

John Pepper, CEO and founder of Managed 247, said there's still too big a gap between the cyber risk facing smaller businesses and the actions many take to manage it. "For many SMEs, cyber security competes with the immediate pressures of running and growing a business," he stated. "But smaller organizations are not operating outside the threat landscape." The government claims that organizations holding Cyber Essentials are 92% less likely to file a cyber insurance claim. According to the report, none of the organizations seeking certification over the past year did so because a customer requested it.

The government wants that to change. Its voluntary Cyber Resilience Pledge requires signatories to demand Cyber Essentials throughout their supply chains, while the Cyber Security and Resilience Bill currently under consideration would establish a legal obligation for organizations to manage cyber risk across their supplier networks. In December 2025, the National Cyber Security Centre published a Cyber Essentials Supply Chain Playbook encouraging organizations to mandate certification as a baseline for all suppliers. Pepper noted that as supply-chain expectations grow, demonstrating basic security controls could become an increasingly vital part of being a trusted supplier. The government's approach reflects a recognition that the certification gap won't close without external pressure—carrots alone haven't moved the needle. Whether regulatory sticks and contractual requirements will succeed where awareness campaigns have fallen short remains the critical test for UK cyber policy.