The Cyber Resilience Pledge

The government’s Cyber Resilience Pledge is quietly reshaping who has to hold Cyber Essentials — and the answer is fast becoming ‘everyone in a supply chain’, not just government suppliers. Here’s what it means, and where we fit.

Launched
10 Downing Street, 7 July 2026
Backed by
DSIT & DCMS
The key ask
Cyber Essentials across supply chains
Our position
CE certified & IASME assessors

What the Cyber Resilience Pledge is

The Cyber Resilience Pledge is a voluntary government commitment, developed by DSIT and DCMS, announced at CYBERUK in April 2026 and formally launched at 10 Downing Street on 7 July 2026 alongside a public list of signatories. Organisations that sign commit to three actions:

  • Make cyber a board responsibility — adopt the Cyber Governance Code of Practice and have every board member complete the NCSC’s Cyber Governance Training within three months, then annually.
  • Sign up to Early Warning — register for the NCSC’s free Early Warning service within a month.
  • Require Cyber Essentials across their supply chains — register to IASME’s Cyber Essentials Supplier Check Tool, audit how much of their supply chain is already certified, and take a risk-based approach to requiring it from the rest.

Signatories also commit to encouraging the same in their own supply chains and to publishing the signed declaration on their website. It’s voluntary — but for the businesses beneath a signatory, its effects are anything but.

Why this matters — not just for government suppliers

It’s easy to read ‘government pledge’ and assume it’s someone else’s problem. It isn’t. The third commitment asks signatories to require Cyber Essentials across their supply chains — and the signatories are major private-sector companies, not just departments. As each one audits its suppliers and rolls the requirement out, Cyber Essentials becomes a condition of staying in the chain for your business, whether or not you ever bid for a public contract.

This is the same direction of travel as the public-sector procurement rules (PPN 014) and the reason clients are already asking for Cyber Essentials. The Pledge accelerates it. The businesses that get ahead of it keep the work; the ones that wait get the awkward email asking for a certificate they don’t have.

Our position: we’re certified, and we certify

We don’t just help others meet this bar — we hold it ourselves. Solusec is Cyber Essentials certified, and our team are certified IASME assessors for both Cyber Essentials and Cyber Assurance. We practise what we preach, which means we know the assessment from both sides: what actually needs to change, and how to get you through it quickly rather than leaving you to wrestle a questionnaire alone.

So whichever side of the Pledge you’re on, we can help. If you supply an organisation that has signed — or is quietly adopting the same supply-chain approach — we get you Cyber Essentials certified, often in days. If you’re the larger organisation making the commitment, we can help you audit Cyber Essentials coverage across your suppliers and take the risk-based approach the Pledge asks for.

What to do now

If you supply larger organisations, the sensible move is to get Cyber Essentials in place before you’re asked — our checklist shows what’s involved and what it costs. If you’re a larger organisation weighing up the Pledge, we can help you meet the supply-chain commitment without it becoming a burden. Either way, start with a free scoping call and we’ll tell you honestly what you need.

Common questions

Is the Cyber Resilience Pledge mandatory?

No — signing is voluntary. But its third commitment asks signatories to require Cyber Essentials across their supply chains, so if your customer has signed (or is heading that way), holding Cyber Essentials effectively becomes a condition of keeping their work.

We don’t do government work — does the Pledge affect us?

Very likely, yes. The signatories are major private-sector companies as well as public bodies, and they’re committing to require Cyber Essentials of their suppliers. The requirement flows down private supply chains, not just public procurement.

What does the Pledge actually require about Cyber Essentials?

Signatories register to IASME’s Cyber Essentials Supplier Check Tool, audit how much of their supply chain already holds Cyber Essentials, and take a risk-based approach to requiring it from suppliers who don’t. In practice that means more of their suppliers being asked to certify.

Can you help us if we want to sign the Pledge ourselves?

Yes. As Cyber Essentials certified, certified IASME assessors, we can help you meet the supply-chain commitment — auditing coverage across your suppliers and taking the risk-based approach the Pledge asks for — as well as getting your own certification in order.

The Pledge by area

The Pledge by sector

Related

Get ahead of the Cyber Resilience Pledge

Whether you supply a signatory or want to sign it yourself, we’ll tell you exactly what you need. Scoping is free.