More than 60 UK businesses — including M&S, Nationwide, ITV, Microsoft UK and Cloudflare — have now signed the government’s Cyber Resilience Pledge, a voluntary commitment led by the Department for Science, Innovation and Technology and the National Cyber Security Centre. It’s officially aimed at medium and large organisations, but it’s open to businesses of any size, and it matters to SMEs for a reason that has nothing to do with signing up yourself: it’s a preview of what your bigger customers and partners are about to start expecting from you.
The pledge asks signatories to commit to three concrete actions: make cyber security a board-level responsibility by adopting the NCSC’s cyber governance code of practice, register for the NCSC’s early warning service to get alerted to suspicious network activity, and take a risk-based approach to requiring Cyber Essentials certification across their own supply chain. That last point is the one worth reading twice if you’re a smaller supplier — a large organisation that’s just publicly pledged to police its supply chain’s cyber hygiene is a large organisation that’s about to start asking its suppliers questions it wasn’t asking before.
Expect the questions before they arrive
If you supply goods or services to any organisation the size of a Cyber Resilience Pledge signatory — or one likely to sign in the coming months as the government’s National Cyber Action Plan builds momentum — expect procurement and renewal conversations to start including cyber security questions that didn’t used to come up. Getting Cyber Essentials certified now, before it’s demanded of you under time pressure, is far cheaper and less disruptive than scrambling to get it done to keep a contract. It’s a government-backed, relatively affordable certification specifically designed to be achievable for smaller businesses, not just enterprises.
The early warning service is free and worth having regardless
Separately from any pledge or supply-chain pressure, the NCSC’s early warning service is free to register for and flags potentially malicious activity — such as your systems appearing in known-bad-IP contact lists — that you’d otherwise have no visibility into. It’s one of the lowest-effort, highest-value steps a small business can take this week, pledge or no pledge, and it doesn’t require board sign-off or budget to set up.
Board-level ownership doesn’t need a big board
The “make it a board-level responsibility” ask sounds like it’s written for FTSE firms, but the underlying principle scales down fine: whoever makes decisions in your business — even if that’s just you — should understand your actual cyber exposure well enough to prioritise it, not delegate it entirely and hope. If you don’t currently have visibility into where your business is exposed, KeepSafe monitors for incidents and exposure so you’re not finding out about a problem from a customer or the news.
Why this is happening now
The pledge sits inside a wider National Cyber Action Plan the government has been building through 2026, following a run of high-profile breaches at UK retailers and public bodies that made supply-chain risk a boardroom topic rather than an IT one. The direction of travel is consistent across all of it: less tolerance for “we didn’t know our supplier was exposed,” more expectation that cyber hygiene is checked and documented before a contract is signed, not after an incident forces the question. Whether or not the pledge itself gains statutory teeth, the behaviour it’s modelling is likely to show up in procurement paperwork well before any regulation catches up.
The takeaway
You don’t need to sign the pledge to act on it. Cyber Essentials certification and NCSC early warning registration are two concrete, achievable steps that put you ahead of the supply-chain scrutiny that’s clearly coming, rather than reacting to it when a big customer asks.