The Cyber Resilience Pledge landed on 7 July 2026 with a Downing Street launch, sixty-odd corporate logos and a set of commitments that sound modest until you try to evidence them. Since then it has been turning up where these things always turn up first: in supplier questionnaires, in procurement calls, and in the awkward part of a board meeting where somebody asks whether the company has signed.

This guide answers the questions businesses are actually asking about the Cyber Resilience Pledge. Not the press-release version, but the practical one. What does it commit you to, what does it cost, who is checking, and does signing it make you measurably harder to attack? The short answer is that the Cyber Resilience Pledge is three specific actions dressed as a statement of intent, and the actions are worth more than the statement.

We work with organisations across the North West that are now fielding pledge questions from customers who signed before they did. The pattern is consistent: the commitment itself takes an afternoon, and the supply chain clause takes a quarter. Understanding which is which before you sign is most of the battle.

What the Cyber Resilience Pledge Actually Is

cyber resilience pledge faq guide b three glowing pillars under shield

The Cyber Resilience Pledge is a voluntary commitment run by the Department for Science, Innovation and Technology alongside the National Cyber Security Centre. Technology Secretary Liz Kendall launched it at 10 Downing Street, framing it as a response to a year in which several household-name British businesses were taken offline by criminal intrusion.

It had been trailed months earlier. The government signalled the initiative at the CYBERUK conference in Glasgow in April 2026, packaged alongside a £90 million funding commitment for the wider national cyber programme. The July launch turned the signal into something organisations could actually put their name to.

Is the Cyber Resilience Pledge a law or a certification?

Neither, and this is the single most common misunderstanding. The Cyber Resilience Pledge is not legislation, it carries no statutory penalty, and it is not a certificate you display. Nobody audits you against it. There is no assessor, no pass mark, and no expiry date on a wall plaque.

What it is instead is a public declaration, backed by three named actions, published on a government list. That makes it closer to a commitment register than a compliance regime, which is exactly why some security professionals are sceptical of it and exactly why procurement teams have taken to it so quickly.

Who is the Cyber Resilience Pledge aimed at?

Officially it is designed with medium and large organisations in mind, but it is open to any organisation of any size or sector. In practice the pull is coming from two directions: government strategic suppliers, who face direct pressure to demonstrate maturity, and companies sitting in the supply chains of firms that have already signed.

If your business bids for public contracts, sells into regulated sectors, or supplies enterprise customers, the Cyber Resilience Pledge will reach you whether or not you go looking for it.

Why does it use the word “resilience” rather than “security”?

The wording is deliberate. Security implies keeping attackers out; resilience assumes some of them get in and asks how quickly you notice, contain and recover. The Cyber Resilience Pledge is built around detection, governance and supply chain hygiene rather than around perimeter defence, which tells you something about how the NCSC now expects incidents to unfold.

The Three Commitments Inside the Cyber Resilience Pledge

cyber resilience pledge faq guide c round table with floating shield

Strip away the launch language and the Cyber Resilience Pledge contains exactly three actions. Each one maps to an existing government scheme, which is the point: the pledge is a distribution mechanism for tools that already existed and were being under-used.

Commitment one: make cyber security a board-level responsibility

Signatories commit to treating cyber risk as a board matter, using the Cyber Governance Code of Practice as the reference framework, and to having board members complete the NCSC’s Cyber Governance Training.

The Code was published on 8 April 2025 and sets out five principles: risk management, cyber strategy, people, incident planning, and assurance and oversight. The training runs as a set of interactive modules built around those same principles, delivered in partnership with the Institute of Directors. It is aimed at directors rather than engineers, and it is short enough that “the board was too busy” is a difficult position to defend.

Commitment two: register for the NCSC Early Warning service

Early Warning is a free NCSC service that notifies your organisation when it spots signs of compromise, vulnerable services or emerging threats affecting your networks and domains. You register through a MyNCSC account, confirm ownership of your IP ranges and domains, and alerts start arriving.

This is the cheapest commitment in the Cyber Resilience Pledge and arguably the highest value per hour spent. It costs nothing, takes under an hour, and gives you an external source of truth about your own estate. The only real work is deciding who reads the alerts and what happens when one arrives at 4pm on a Friday.

Commitment three: push Cyber Essentials through your supply chain

The third commitment asks signatories to take a risk-based approach to requiring Cyber Essentials certification from their suppliers. Note the phrasing carefully. It is not “require Cyber Essentials from everyone”, it is “decide, based on risk, which suppliers must hold it”.

This is where the Cyber Resilience Pledge stops being an afternoon’s work. Segmenting a supplier base by risk, writing the requirement into contracts, and tracking certification status across renewal cycles is a programme, not a task. It is also the commitment most likely to change behaviour, because it propagates outward to organisations that never signed anything.

Who Has Signed the Cyber Resilience Pledge So Far

cyber resilience pledge faq guide d chain of cubes with padlocks

More than sixty organisations signed at launch, and the list has grown since. The founding cohort deliberately spans sectors rather than concentrating in technology, which was clearly the intention.

Which companies were founding signatories?

Named founding signatories include Marks & Spencer, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte LLP, Accenture UK, Vodafone Group and VodafoneThree, alongside the Autotech Group and cyber specialists such as NCC Group. Later additions reported through July 2026 include Tesco, Harrods, Whitbread, Serco Group, Bridewell and Meta Defence Labs.

Around twenty of the government’s thirty-nine strategic suppliers also signed. That figure is worth sitting with. Roughly half the companies the state depends on most did not sign in the first wave.

Does the signatory list include companies that have been breached?

Yes, and this drew immediate comment. Several signatories have been through significant public incidents, and critics noted the awkwardness of a resilience pledge signed by organisations whose resilience had recently been tested in public and found wanting.

The counter-argument is more persuasive than it first appears. Organisations that have been breached tend to have spent heavily on remediation and to understand the governance gaps intimately. A Cyber Resilience Pledge signed only by companies with unblemished records would be a pledge signed by companies that have not yet been caught.

Is there a cost to appearing on the list?

No. Signing the Cyber Resilience Pledge is free. The costs are downstream: the training time, the supplier programme, and any Cyber Essentials certification you end up funding or requiring. Government publishes the signatory list on GOV.UK and updates it as organisations join.

Why the Government Launched the Cyber Resilience Pledge Now

cyber resilience pledge faq guide e radar beacon with alert rings

The timing was not arbitrary. The launch material carried a set of numbers designed to make the case that voluntary action is cheaper than the alternative.

What do the numbers say about UK cyber risk?

Government figures put the cost of cyber attacks to the UK economy at around £14.7 billion a year. The same material cites roughly five million cyber crimes committed against UK firms in the preceding year, which works out at about one every six seconds, and an average cost of £195,000 for each significant attack.

The NCSC’s own incident data moves in the same direction: 204 nationally significant incidents handled in the reporting period, against 89 previously. That is not a gentle upward trend, and it explains why the Cyber Resilience Pledge leans so heavily on detection and governance rather than on tooling.

Why lean on Cyber Essentials specifically?

Because adoption has been dismal relative to the size of the economy. Around 35,000 organisations hold Cyber Essentials certification against a business population north of five million. The scheme works, the controls are sensible, and almost nobody has it.

The supply chain clause in the Cyber Resilience Pledge is an attempt to fix that through commercial pressure rather than regulation. If a few hundred large buyers make certification a condition of doing business, the number moves in a way that ten years of awareness campaigns did not.

What did ministers and industry say at launch?

Liz Kendall’s line was that cyber resilience “is no longer just an IT issue — it is a business imperative”, and that other organisations should follow the signatories’ example. Microsoft UK chief executive Darren Hardman framed the initiative around board-level accountability and supply chain security as the mechanisms by which the UK stays competitive.

Both statements point at the same target: the decision-makers who sign off budgets, not the teams who spend them.

What the Cyber Resilience Pledge Costs in Practice

The pledge itself is free. The commitments are not, and the honest budgeting conversation happens before you sign rather than after.

How much does Cyber Essentials cost?

Self-assessed Cyber Essentials certification is typically priced between roughly £300 and £600 plus VAT depending on organisation size. Cyber Essentials Plus, which adds hands-on technical verification, generally runs from around £1,500 to £8,000 plus VAT.

Those are the certification fees, not the total. For a typical twenty-five-person business, realistic first-year spend including remediation, multi-factor authentication tooling, endpoint protection licences and any consultancy support lands closer to £1,800 to £3,500. Ongoing costs depend heavily on what you already had in place.

What does the board training actually take?

Hours, not days. The NCSC Cyber Governance Training is modular and designed for non-technical directors. The real cost is not the training itself but the follow-on: someone has to own cyber risk at board level, the risk register has to be genuinely reviewed, and minutes have to show it happened.

That last point matters more than it sounds. If a customer or insurer later asks how your board discharged its cyber responsibilities, the evidence is your minutes, not your pledge.

What is the hidden cost of the supply chain commitment?

This is the line item people underestimate. Requiring Cyber Essentials across a supplier base means categorising suppliers by risk, updating contract templates, writing the requirement into procurement, chasing certificates, and handling the suppliers who refuse or cannot afford it.

For organisations with mature vendor management processes this is an extension of existing work. For everyone else it is a new capability, and the Cyber Resilience Pledge does not fund it.

Cyber Resilience Pledge vs the Cyber Security and Resilience Bill

Understanding how the pledge relates to forthcoming legislation is the difference between treating it as PR and treating it as preparation.

Are the two things connected?

Not formally, but they are pointing the same way. The Cyber Security and Resilience Bill has been working through Parliament, with a parliamentary call for evidence in January 2026, and is intended to modernise the UK’s network and information systems rules. It brings duties, scope expansion and enforcement in a way a voluntary pledge cannot.

The Cyber Resilience Pledge occupies the space before that arrives. The commonly quoted summary of the direction of travel is that these expectations are voluntary today, expected tomorrow, and regulated the day after.

Does signing the pledge help with future compliance?

Indirectly, and usefully. Board accountability, threat intelligence subscription and supplier assurance are the same three areas most regulatory regimes probe. An organisation that has genuinely implemented the Cyber Resilience Pledge has a head start on documentation when statutory duties land.

An organisation that signed and did nothing has a public statement on a government website that its regulator can read. That asymmetry is the strongest practical argument for taking the commitments seriously.

How does it compare with the EU Cyber Resilience Act?

They are frequently confused because the names overlap, but they do different jobs. The EU’s Cyber Resilience Act regulates security requirements for products with digital elements placed on the EU market. The UK’s Cyber Resilience Pledge is a voluntary organisational commitment with no product scope at all. If you manufacture connected products for the EU, the Act applies to you regardless of what you sign in the UK.

Does the Cyber Resilience Pledge Actually Improve Security?

This is the question most worth asking, and the answer is genuinely contested.

What is the main criticism?

That it is voluntary, lightly assured, and therefore vulnerable to becoming a signature without substance. Signatories are expected to publish their declaration and provide an annual public update, but there is no strong assurance mechanism sitting behind it. The commitments are easy to make and considerably harder to evidence.

There is also an accountability question. The Cyber Resilience Pledge elevates cyber to board level in language, but it cannot create enforceable duties or consequences. A board that names an accountable director and then never revisits the topic has technically complied.

What do practitioners say?

The most quoted response came from Northdoor’s AJ Thompson, whose position was blunt: a pledge is a piece of paper, and threat actors do not read paper. His conclusion was not to dismiss it but to bound it — sign the pledge, absolutely, but then do the work.

That work is unglamorous and familiar. Patch continuously, train staff against social engineering, build and actually test an incident response plan, and have the board ask hard questions quarterly rather than during a crisis. None of it is new, which is rather the point.

So is it worth signing?

For most organisations, yes, with a condition attached. Sign the Cyber Resilience Pledge if you intend to complete the three actions and can show evidence within ninety days. Do not sign it as a marketing exercise, because a public commitment you have not honoured is a liability in exactly the circumstances where you can least afford one.

The pledge is best understood as a forcing function. It gives a security lead a dated, externally visible reason to get three long-deferred items onto the board agenda. That is a real benefit even if the document itself changes nothing.

How to Sign the Cyber Resilience Pledge: A Practical Checklist

The mechanics are straightforward. The preparation is where the value sits.

What to do before you sign

Confirm who at board level will own cyber risk by name, not by committee. Check whether you already hold Cyber Essentials and when it expires. Pull a list of your suppliers and make a first pass at which ones touch sensitive data or hold privileged access into your systems. Establish who will receive and act on Early Warning alerts.

If any of those four questions produces a shrug, the Cyber Resilience Pledge has already done something useful before you have signed it.

How the sign-up itself works

Sign-up runs through the government’s Cyber Resilience Pledge page, and the full signatory list is published on GOV.UK. Details for the current process are on the Cyber Resilience Pledge announcement on GOV.UK, which also carries the supporting statistics and the ministerial framing.

What evidence should you keep?

Keep a board-approved cyber security policy, minutes showing cyber risk was reviewed, the name of the accountable board member, a cyber risk register that is actually discussed, your Early Warning registration details, a supplier security policy referencing Cyber Essentials, and a register of supplier certification status.

None of that is submitted to anyone. All of it is what you will be asked for by a customer, an insurer or a regulator, and assembling it as you go is far cheaper than reconstructing it under pressure. A well-run managed IT service should be producing most of this evidence as a by-product of normal operation.

Cyber Resilience Pledge Questions Smaller Businesses Ask

Smaller organisations were not the primary audience for the launch, but they are feeling the effects first through their customers.

Should a small business sign the Cyber Resilience Pledge?

If you sell to organisations that have signed, seriously consider it. The supply chain commitment means your customers are being asked to assess you, and being able to point at your own pledge and your own Cyber Essentials certificate shortens that conversation considerably.

If you sell only to consumers and hold little sensitive data, the calculus is different. The three underlying actions are still worth doing; the public declaration adds less.

We have no board — does the first commitment apply?

The principle translates. Substitute your owner, directors or senior leadership team for “board” and the requirement is the same: a named person accountable for cyber risk, with the topic reviewed on a fixed schedule and the review recorded. The Cyber Resilience Pledge does not require a particular governance structure, only that someone senior owns the risk.

What if our suppliers refuse to get certified?

Then you make a risk decision and you write it down. The commitment is explicitly risk-based, which allows you to require certification from the supplier with administrative access to your systems while accepting a lower bar from the firm that services the air conditioning.

The failure mode is not having a documented position at all. If you need help drawing that line, our IT support team in Chester works through supplier risk tiering with clients regularly, and the exercise is usually less painful than expected.

What to Do in Your First 90 Days After Signing

Treat the signature as the start of a short programme rather than the end of a decision. Ninety days is enough to complete the easy commitments and make visible progress on the hard one.

Days 1 to 30: governance and detection

Register for Early Warning and confirm alerts are reaching a monitored inbox with a named owner. Book the board through the NCSC Cyber Governance Training. Add cyber risk as a standing board agenda item and hold the first review. Publish your declaration if you intend to make it public.

These are the fastest wins in the Cyber Resilience Pledge and they generate written evidence immediately.

Days 31 to 60: your own baseline

Assess yourself against Cyber Essentials, even if you do not certify straight away. Multi-factor authentication on cloud services and remote access, a patching commitment for critical vulnerabilities, and current endpoint protection cover most of the gaps that surface. Review your security posture against what you would need to demonstrate to a customer, not against what feels comfortable internally.

Days 61 to 90: the supply chain

Tier your suppliers by the access and data they hold. Draft the certification requirement into your standard contract terms and apply it at the next renewal rather than reopening every agreement at once. Start the register of who holds what.

By day ninety you should be able to answer, in one page, what you committed to and what you have evidence for. That page is the real output of the Cyber Resilience Pledge, and it is worth considerably more than a logo on a list.

The Honest Verdict on the Cyber Resilience Pledge

The Cyber Resilience Pledge is a modest instrument that arrived at a moment when modest instruments are unfashionable. It cannot compel anyone, it cannot verify anyone, and its critics are right that a voluntary commitment with no assurance mechanism invites exactly the superficial adoption they fear.

It is also three sensible actions, two of which are free, aimed at gaps that have proven stubbornly resistant to persuasion. Board ownership, external threat intelligence and supplier assurance are not fashionable, but they are what actually determines how badly an incident goes.

The signature is worth nothing. The three actions behind it are worth doing whether or not you ever sign. If putting your name on a government list is what finally gets them onto the board agenda, that is a reasonable trade, and the Cyber Resilience Pledge will have earned its keep.