News
Cyber Essentials Hits 61,430 Certificates in a Year
A quiet fortnight for breaches, a busy one for the machinery behind them. The government published fresh Cyber Essentials certification figures, added a dozen names to its Cyber Resilience Pledge, and the Cyber Security and Resilience Bill moved another stage closer to law. All three matter to anyone buying or renewing cyber insurance.
61,430 Cyber Essentials certificates in a year, and a claims figure to go with them
On 16 September DSIT updated its Cyber Essentials management information with data to June 2026. Over the twelve months from July 2025 to June 2026 the scheme awarded 61,430 certificates: 46,245 at Cyber Essentials Standard and 15,185 at Cyber Essentials Plus.
The quarterly detail is more useful than the headline. Standard certificates ran at 11,642 in April to June 2026 against 9,967 in the same quarter a year earlier, a rise of about 17 per cent. Plus certificates went from 3,142 to 3,857, up nearly 23 per cent. The last quarter was down on the January to March peak of 12,336, but the year-on-year trend is clearly up, and Plus is growing faster than Standard, which is what you would expect if insurers and buyers are asking for the audited version rather than the self-assessment.
The number worth quoting to a finance director is in the same publication: organisations with Cyber Essentials are 92 per cent less likely to make a claim on their cyber insurance. That is government’s own framing of the IASME data, not an insurer’s marketing line, and it is the clearest statement yet of why underwriters keep asking for the certificate. Our guides to Cyber Essentials certification explained and free cyber insurance with Cyber Essentials cover what the five controls are and what the certificate gets you. The dataset is on GOV.UK.
Twelve more organisations signed the Cyber Resilience Pledge
The Cyber Resilience Pledge, launched at Number 10 in July, added another twelve signatories on 14 September. It is a voluntary commitment to three actions aimed at improving an organisation’s own resilience and that of its supply chain. Signatories so far include Tesco, Harrods, Whitbread and Serco alongside a long tail of consultancies and technology firms.
A pledge is not a control and no insurer will price on it. Its real use is upstream: if your largest customer has signed, expect their procurement team to start asking you for evidence, and the cheapest credible answer to that question is still Cyber Essentials. The signatory list is on GOV.UK.
The Cyber Security and Resilience Bill reaches Lords report stage on 26 October
The Bill finished its Commons stages in June, had its Lords second reading on 14 July and has been in Lords committee since 1 September. Report stage is scheduled for 26 October 2026. It expands statutory cyber oversight well beyond the traditional utilities, bringing in data centres, medium and large managed service providers, large load controllers and designated critical suppliers.
If you use a managed security service provider, this is the part to watch. Once MSPs are regulated they will have reporting duties of their own, and the practical effect on customers tends to be contractual: new security schedules, new incident notification clauses, and in some cases new prices. Phased implementation means the full regime may not bite until 2028, so there is time, but the direction is set. The Bill and its stages are at UK Parliament.
Also this month
DSIT’s September cyber security newsletter, published 15 September, carries a call to action on post-quantum cryptography migration alongside the Cyber Essentials figures. Post-quantum is not an insurance question yet. It will be a renewal question within a few years, and the organisations that will find it cheapest are the ones that already know what cryptography they are running and where.