- Best for
- Manufacturers
- The key ask
- CE across supply chains
- Driver
- Signatory supplier requirements
- Our position
- CE certified & IASME assessors
The Pledge, and what it means for manufacturers
Manufacturers are tier-on-tier suppliers to primes and OEMs — and when a prime signs the Pledge, Cyber Essentials flows all the way down the chain. The Cyber Resilience Pledge, launched by the government in July 2026, asks signatories to require Cyber Essentials across their supply chains — auditing which suppliers hold it and requiring it, risk-based, from those who don’t. For manufacturers, that turns Cyber Essentials into a practical condition of winning and keeping the work.
Why this matters — not just for government suppliers
It’s easy to read ‘government pledge’ and assume it’s someone else’s problem. It isn’t. The third commitment asks signatories to require Cyber Essentials across their supply chains — and the signatories are major private-sector companies, not just departments. As each one audits its suppliers and rolls the requirement out, Cyber Essentials becomes a condition of staying in the chain for manufacturers, whether or not you ever bid for a public contract.
This is the same direction of travel as the public-sector procurement rules (PPN 014) and the reason clients are already asking for Cyber Essentials. The Pledge accelerates it. The businesses that get ahead of it keep the work; the ones that wait get the awkward email asking for a certificate they don’t have.
Our position: we’re certified, and we certify
We don’t just help others meet this bar — we hold it ourselves. Solusec is Cyber Essentials certified, and our team are certified IASME assessors for both Cyber Essentials and Cyber Assurance. We practise what we preach, which means we know the assessment from both sides: what actually needs to change, and how to get you through it quickly rather than leaving you to wrestle a questionnaire alone.
So whichever side of the Pledge you’re on, we can help. If you supply an organisation that has signed — or is quietly adopting the same supply-chain approach — we get you Cyber Essentials certified, often in days. If you’re the larger organisation making the commitment, we can help you audit Cyber Essentials coverage across your suppliers and take the risk-based approach the Pledge asks for.
The right certification for manufacturers
For most manufacturers, Cyber Essentials is the answer the Pledge is driving demand for, and we’ll get you there fast. Where a client asks for the audited level we also support Cyber Essentials Plus. And if your work involves more than the basics — a product, an application, sensitive data — our sector guide for manufacturers covers the wider picture.
Common questions
Does the Pledge really affect manufacturers?
Yes — the signatories are committing to require Cyber Essentials of their suppliers, and manufacturers sit squarely in those supply chains. Even without a single government contract, the requirement reaches you through your commercial customers.
How fast can we certify?
Often within days if your controls are already in reasonable shape; if not, we tell you exactly what to fix first. Getting certified before you’re asked is far easier than reacting to a client deadline.
Do we need Cyber Essentials or Cyber Essentials Plus?
Usually the self-assessed Cyber Essentials satisfies a supply-chain request; larger or higher-risk clients sometimes specify the audited Plus. We check the wording with you before you commit.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day