Research

Cyber Essentials Statistics
Certificates issued, July 2023 to March 2026

Data from the DSIT and DCMS management information, set against the UK business population.

44,608 Cyber Essentials certificates were issued in the UK between April 2025 and March 2026, of which 14,482 also achieved Cyber Essentials Plus. Set against UK businesses with employees, that is about 50% of large employers, 23% of medium-sized firms, 7.1% of small and 1.4% of micro.

GOV.UK reports a total of 59,090 by adding the two levels. A standard certificate is a prerequisite for Plus, so the figures here count 44,608 Cyber Essentials certificates with Plus as a subset.

Data to January 2026 to March 2026 · published June 2026 · figures supplied by IASME to DSIT

44,472
Certificates issued, 12 months to Jan–Mar 26
up 19.2% on the year
14,440 (32.5%)
Of which achieved Cyber Essentials Plus
up from 32.0% a year earlier
12,336
Latest quarter, Jan–Mar 26
up 8.4% on the quarter
90%
Implied renewal rate, latest quarter
86% to 90% across the series
3.14%
UK businesses with employees holding a certificate
up from 2.63% a year earlier

Key findings

Cyber Essentials uptake is higher than a simple comparison with the full UK business population would suggest. The UK has around 5.5 million private sector businesses, but only about 1.4 million have employees and form the basis of analysis here. Against that base, the rolling-year total of 44,472 certificates represents 3.14% of businesses with employees. A comparison with all 5.5 million businesses would imply uptake below 1%.

This is an estimate rather than a precise share of organisations, since the source counts certificates and one organisation may hold several. The remaining gap is concentrated among smaller employers, with uptake of 7.11% among small businesses and 1.37% among micro businesses.

Cyber Essentials sits within a wider effort to improve cyber resilience across UK supply chains. Survey-based studies, including the DSIT Cyber Security Breaches Survey, record what organisations report about their controls, policies and experiences. They are useful for understanding practice and behaviour, but where they cover Cyber Essentials they ask respondents whether they hold it, rather than counting certificates issued.

This analysis asks a different question: how widely is the scheme being used, and what is driving adoption? It brings together two government-published sources, the quarterly Cyber Essentials management information and the Department for Business and Trade business population estimates, to assess uptake by organisation size. It also looks at the balance between new certificates and renewals, the reasons organisations give for certifying, and the potential role of the Cyber Resilience Pledge in extending adoption through supply chains.

The result is an estimate based on published certificate records rather than self-reported behaviour. It has limits: the source counts certificates rather than unique organisations, and DSIT classifies the series as management information rather than official statistics. It nevertheless gives a more direct view of participation in the scheme.

Year to March 2026, at a glance

  • 44,608 certificates issued at Cyber Essentials level, April 2025 to March 2026
  • 14,482 of those also achieved Cyber Essentials Plus (32.5%)
  • Cyber Essentials by size: micro 15,823, small 15,666, medium 8,897, large 4,222
  • Cyber Essentials Plus by size: micro 4,396, small 4,479, medium 3,505, large 2,102
  • Uptake against UK businesses with employees: large 49.9%, medium 23.0%, small 7.11%, micro 1.37%
  • Implied renewal rate 90% in the latest quarter, in a range of 86% to 90% across the series
  • Certificates required by a third party: 29.3% of the year to March 2026

Uptake against the UK business population

Certificate counts alone do not show coverage. To estimate uptake, we divide certificates issued in the rolling year by the number of UK private sector businesses with employees in each size band, using the Department for Business and Trade's business population estimates. Uptake among large employers is more than thirty times the rate among micro firms.

Uptake over time, by size band

Each bar is the certificates issued in the twelve months ending that quarter, divided by the business population for the calendar year the window ends in. Each band has its own scale, since the rates differ by two orders of magnitude.

How to read the uptake figures

These figures estimate uptake among UK private-sector businesses with employees. They are not an exact measure of how many organisations are certified because one organisation may hold several certificates for different entities.

Businesses with no employees, public-sector bodies and charities are not included. The rates describe uptake among businesses with employees and cannot be compared directly with figures based on the full business population of around 5.5 million.

The two sources use the same size bands: under 10 employees, 10 to 49, 50 to 249, and 250 or more.

Certificates last 12 months. The rolling 12-month total therefore gives a reasonable estimate of the number of live certificates at the end of the period, although renewal dates vary.

Recertification and renewal

Cyber Essentials certificates lapse after 12 months. The proportion of certificates issued in a quarter that are shows how much of the quarterly activity comes from existing participants. Dividing recertifications in a quarter by all certificates issued in the same quarter a year earlier gives an implied . In the latest quarter, 9,065 of 12,336 certificates were recertifications, or 73% of all certificates issued. Against the 10,064 certificates issued in the same quarter a year earlier, that implies a renewal rate of about 90%.

Why organisations certify

The reason for certification is recorded for standard certificates only. Grouping the responses by whether a third party required certification separates commercial or regulatory pressure from organisations choosing to certify. In the year to March 2026, around 71% of standard certificates were attributed to reasons chosen by the organisation, and around 29% followed a requirement from a customer, regulator, insurer, grant provider or contract. The split should be read with care. An organisation certifying to give customers confidence may be responding to the same commercial pressure as one named in a contract clause, so the voluntary share probably overstates how much of the demand is unprompted. That is one reason the Cyber Resilience Pledge matters: it makes supply chain expectations explicit, and the effect should show up in these categories over time.

Explore the quarters

What the data shows

The gap between retention and reach.

Cyber Essentials has an established base of participants, but coverage remains limited across the wider business population. In the year to March 2026, certificates represented about 50% of large employers, 23% of medium-sized firms, 7.1% of small businesses and 1.4% of micro businesses.

Micro and small businesses make up 96.7% of UK private sector businesses with employees. They account for around 71% of certificates issued, but their coverage remains low. Certificate counts therefore give a misleading impression of broad adoption. The scheme is more established among larger employers than among the businesses that make up most of the economy.

The renewal figures suggest that existing participants are generally staying engaged. Quarterly implied renewal rates range from about 86% to 90%. This is not a cohort retention measure, because the data does not follow the same organisations over time. It is nevertheless consistent with stronger retention among existing participants than first-time adoption. The main constraint appears to be reach, rather than organisations leaving the scheme.

The reasons for certification show a mixture of voluntary demand and commercial pressure. The largest individual reason was giving customers confidence, at 17,360 certificates, or 39.0% of the year to March 2026. Although recorded as voluntary, that category may still reflect market pressure where customers expect suppliers to show basic controls without making certification a formal contractual requirement.

Cyber Essentials Plus represented 32.5% of standard certificates in the rolling quarterly series, but about half of certificates issued to large employers. Larger organisations are therefore more likely both to certify and to buy the additional technical assurance that Plus provides.

The Cyber Resilience Pledge and practical starting points

The Cyber Resilience Pledge provides a potential route from larger organisations to their suppliers. Signatories commit to board-level responsibility for cyber security, joining the NCSC's Early Warning service, auditing Cyber Essentials coverage across their supply chains through the Cyber Essentials Supplier Check Tool, and taking a risk-based approach to requiring Cyber Essentials from suppliers.

The pledge will have the greatest effect if those commitments increase certification among smaller suppliers, rather than reinforcing adoption among large organisations. Future releases of this data can test that. The micro and small business uptake rates above are the main figures to watch.

For organisations starting out, and for sole traders and businesses without employees that sit outside the denominator used here, the NCSC Cyber Action Toolkit is a practical starting point. It offers free, tailored baseline guidance and the NCSC describes it as a pathway towards Cyber Essentials certification. It does not replace certification, but it can help organisations take the first steps.

Conclusion

Cyber Essentials is established in parts of the market, particularly among larger employers, and existing participants show high levels of renewal. It has not yet become normal practice across the wider business population.

CyberSmart is a founding signatory of the Cyber Resilience Pledge.

Data tables

The figures behind the charts above. Certificate counts are Crown copyright under the Open Government Licence; the uptake and renewal rates are CyberSmart's calculation.

Cyber Essentials uptake by organisation size, year to March 2026
Size bandDefinitionCertificatesOf which PlusBusinessesUptakeYear earlier
Large250 or more employees4,1562,0788,33549.86%44.63%
Medium50 to 249 employees8,8533,49538,43523.03%19.55%
Small10 to 49 employees15,6494,669220,0857.11%5.93%
Microunder 10 employees15,8144,1981,150,8751.37%1.13%
All with employees44,47214,4401,417,7303.14%2.63%
Uptake over rolling twelve-month windows, by size band
Size bandto Jun 24to Sep 24to Dec 24to Mar 25to Jun 25to Sep 25to Dec 25to Mar 26
Large, any level40.39%41.77%43.55%44.63%45.59%46.95%47.99%49.86%
Medium, any level17.62%18.45%19.17%19.55%20.22%21.15%21.82%23.03%
Small, any level5.21%5.44%5.70%5.93%6.18%6.47%6.74%7.11%
Micro, any level0.99%1.03%1.07%1.13%1.17%1.25%1.30%1.37%
Large, Plus18.47%19.54%20.75%21.19%21.91%22.80%23.66%24.93%
Medium, Plus6.35%6.76%7.23%7.36%7.64%8.07%8.46%9.09%
Small, Plus1.39%1.50%1.58%1.63%1.72%1.80%1.99%2.12%
Micro, Plus0.30%0.31%0.32%0.33%0.34%0.36%0.35%0.36%
Implied renewal rate by quarter
QuarterRecertificationsCertificates a year earlierImplied renewal rate
Jul–Sep 246,5907,31490.1%
Oct–Dec 247,3448,39087.5%
Jan–Mar 257,5578,54588.4%
Apr–Jun 257,4978,68486.3%
Jul–Sep 257,7498,76288.4%
Oct–Dec 258,4769,79086.6%
Jan–Mar 269,06510,06490.1%
Certificates issued by level and quarter
LevelJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26
Cyber Essentials Standard (CE)7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,336
Cyber Essentials Plus (CE+)2,0742,8302,9862,6232,6603,3883,2733,1423,2544,0084,036
Standard certificates: new issues and recertifications
Issue typeJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26
Recertifications5,3056,2586,3086,3726,5907,3447,5577,4977,7498,4769,065
New issues2,0092,1322,2372,3122,1722,4462,5072,4703,0372,9073,271
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,336
Standard certificates by organisation size and quarter
Size bandJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26
Large7818138229168959609499961,0081,0471,105
Medium1,5161,6481,7081,7801,8281,9221,9852,0352,1872,1782,453
Small2,6382,7622,9853,0703,1543,3263,5103,6033,7953,9244,327
Micro2,3793,1673,0302,9182,8853,5823,6203,3333,7964,2344,451
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,336
Cyber Essentials Plus by organisation size and quarter
Size bandJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26
Large338382378426426482432486500554538
Medium509571610709663748709818826897954
Small6407838547868779589669921,0541,3771,246
Micro5871,0941,1447026941,2001,1668468741,1801,298
Total2,0742,8302,9862,6232,6603,3883,2733,1423,2544,0084,036
Reasons given for seeking a standard certificate
ReasonJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26
Required by a customer9438621060000
Required by a regulatory body207417272238193393346237274445369
Required by an insurer149161155173183204189210214243238
Required for a grant2929323931273241473646
Required for commercial contract9361,0451,1741,0061,1121,2791,2621,1741,2541,4131,640
Required for government contract1,0921,1091,0741,0771,0781,1401,1861,1821,3621,2731,336
To generally improve our security2,6092,8332,8452,9442,8553,0603,1803,1643,2553,3943,628
To give confidence to our Customers1,9272,4982,7883,0063,1613,4923,6913,7974,2124,4094,942
To meet Data Protection Requirements8431930020000
Other187229190196148195170162168170137
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,336

Sources

Cyber Essentials management information

DSIT publishes this information quarterly with DCMS under the Open Government Licence v3.0. It is management information, not official statistics. The underlying data is supplied by IASME, the scheme's delivery partner. Each release restates the series back to July 2023, so the figures on this page come from the January to March 2026 release, published in June 2026. Queries on the source data should be sent to statistics@dsit.gov.uk.

Business population estimates

The uptake denominators come from Table C of the Department for Business and Trade's business population estimates, which reports UK private sector businesses by size at the start of the year. Each rolling window uses the estimate for the calendar year in which it ends. The series is updated annually, in the autumn.

What the figures mean

Cyber Essentials is a government-backed scheme covering five basic technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The NCSC owns the scheme. IASME delivers it through licensed certification bodies. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit by the certification body.

A standard certificate is a prerequisite for Plus, so every Plus certificate also generates a standard certificate and Plus holders are counted in both figures. The two levels should not be added together to count organisations. We do not track unique organisations in this dataset, and a large organisation may hold several certificates for different networks. Certificates last 12 months.

How organisation size is defined

Size is based on the number of employees across the UK:

  • micro: under 10 employees
  • small: 10 to 49
  • medium: 50 to 249
  • large: 250 or more
Why some reason categories fall to zero

Categories such as "required by a customer" and "to meet data protection requirements" fall to zero from 2024 onwards. This suggests that the available answer options changed rather than that the underlying behaviour disappeared. Reasons are collected for Cyber Essentials only, not Plus.

Status of these statistics

DSIT publishes these as management information, not official statistics. The underlying data comes from IASME as the scheme's delivery partner.

Analysis, charts and derived measures © CyberSmart Ltd 2026. The uptake rates, the implied renewal rate and the required-or-chosen grouping are original research by CyberSmart and are not published by government. Reuse them with attribution to CyberSmart, linking to this page, under the Creative Commons Attribution 4.0 licence.

The underlying figures are Crown copyright and reproduced under the Open Government Licence v3.0: Cyber Essentials management information from the Department for Science, Innovation and Technology and the Department for Digital, Culture, Media and Sport, with data supplied by IASME; business population estimates from the Department for Business and Trade. Those figures remain the property of their publishers and carry their own caveats, including that the Cyber Essentials release is management information rather than official statistics.

Cyber Essentials is a scheme owned by the National Cyber Security Centre and delivered by IASME. This page is independent research and is not affiliated with, endorsed by, or produced in cooperation with the NCSC, IASME, DSIT, DCMS or DBT. Any errors in the derived figures are ours; the source data is unmodified.

Published by CyberSmart, London. Figures parsed from the January to March 2026 release, published June 2026. Page last revised August 2026.