Research

Cyber Essentials Statistics
Certificates issued, July 2023 to June 2026

Data from the DSIT and DCMS management information, set against the UK business population.

46,245 Cyber Essentials certificates were issued in the UK between July 2025 and June 2026, and 15,185 of them went on to Cyber Essentials Plus. Set against the number of UK businesses with employees, that is about 52% of large employers, 24% of medium-sized firms, 7.4% of small firms and 1.4% of micro firms.

GOV.UK gives a total of 61,430 by adding the two levels together. Every Plus certificate starts with a standard one, so this page counts 46,245 certificates and treats Plus as a subset.

Data to April 2026 to June 2026 · published September 2026 · figures supplied by IASME to DSIT

46,245
Certificates issued, year to Apr–Jun 26
up 19.6% on the year
15,185 (32.8%)
Of which achieved Cyber Essentials Plus
up from 32.3% a year earlier
11,642
Latest quarter, Apr–Jun 26
up 16.8% on the same quarter a year earlier
85%
Implied renewal rate, latest quarter
85% to 90% across the series
3.26%
UK businesses with employees holding a certificate
up from 2.72% a year earlier

Key findings

Cyber Essentials is more widely used than a comparison with every UK business would suggest. The UK has about 5.5 million private sector businesses, but only about 1.4 million of them have employees, and those are the businesses this page compares against. On that basis, the 46,245 certificates issued in the year to June 2026 cover 3.26% of businesses with employees. Measured against all 5.5 million businesses, the figure would be under 1%.

This is an estimate, not an exact count of certified organisations. The data counts certificates, and one organisation can hold several. The gap is largest among smaller firms: 7.38% of small businesses and 1.44% of micro businesses hold a certificate.

Cyber Essentials is one part of a wider effort to make UK supply chains more resilient. Surveys such as the DSIT Cyber Security Breaches Survey ask organisations what controls they have in place and what has happened to them. They are useful, but on Cyber Essentials they ask people whether they hold a certificate rather than counting the certificates issued.

This page asks a different question: how widely is the scheme used, and what drives organisations to certify? It combines two government sources, the quarterly Cyber Essentials figures and the Department for Business and Trade's count of UK businesses, to estimate uptake by organisation size. It also looks at renewals against new certificates, the reasons organisations give, and what the Cyber Resilience Pledge might do to extend the scheme through supply chains.

The result rests on certificate records rather than on what organisations say about themselves. It has limits. The data counts certificates rather than organisations, and DSIT classes it as management information rather than official statistics. Even so, it gives a more direct view of who is taking part.

Year to June 2026, at a glance

  • 46,245 certificates achieved Cyber Essentials, July 2025 to June 2026
  • 15,185 of those went on to achieve Cyber Essentials Plus (32.8%), leaving 31,060 at Cyber Essentials only
  • Cyber Essentials by size, Plus holders included: micro 16,555, small 16,237, medium 9,151, large 4,302
  • Cyber Essentials Plus by size, a subset of the above: micro 4,555, small 4,801, medium 3,679, large 2,150
  • Uptake against UK businesses with employees: large 51.6%, medium 23.8%, small 7.38%, micro 1.44%
  • Implied renewal rate 85% in the latest quarter, the lowest in a range of 85% to 90% across the series
  • Certificates required by a third party: 29.2% of the four quarters to June 2026

Uptake against the UK business population

Certificate counts alone do not show how much of the economy is covered. To estimate that, we divide the certificates issued in a year by the number of UK private sector businesses with employees in each size band, using the Department for Business and Trade's business population estimates. A large employer is more than thirty times as likely to hold a certificate as a micro firm.

Uptake over time, by size band

Each bar is the certificates issued in the twelve months ending that quarter, divided by the business population for the calendar year the window ends in. Each band has its own scale, since the rates differ by two orders of magnitude.

How to read the uptake figures

These figures estimate how many UK private sector businesses with employees hold a certificate. They are not an exact count of certified organisations, because one organisation can hold several certificates for different parts of its business.

Businesses with no employees, public sector bodies and charities are not included. The rates apply to businesses with employees only, and cannot be compared directly with figures based on all 5.5 million UK businesses.

Both sources use the same size bands: under 10 employees, 10 to 49, 50 to 249, and 250 or more.

Certificates last 12 months, so the total issued over 12 months is a reasonable estimate of how many were live at the end of the period, although renewal dates vary.

The release gives figures on two bases. Its annual tables show 46,245 certificates for July 2025 to June 2026, while the four quarters covering the same period add up to 46,147. The difference of 98 comes from revisions to the quarterly series. Annual figures on this page use the annual tables; anything shown by quarter, and any earlier twelve-month window, uses the quarterly series.

Recertification and renewal

A Cyber Essentials certificate lasts 12 months. Looking at how many of the certificates issued in a quarter are shows how much of the activity comes from organisations already in the scheme. Dividing those recertifications by all the certificates issued in the same quarter a year earlier gives an implied : roughly, how many of the certificates due to expire were renewed. In the latest quarter, 8,455 of the 11,642 certificates were recertifications, or 73%. Set against the 9,967 certificates issued in the same quarter a year earlier, that is a renewal rate of about 85%, the lowest so far in the series.

Why organisations certify

Organisations give a reason when they apply for a standard certificate. Sorting those reasons by whether someone else required the certificate separates commercial or regulatory pressure from a free choice. Over the four quarters to June 2026, about 71% of certificates were given a reason the organisation chose for itself, and about 29% followed a requirement from a customer, regulator, insurer, grant provider or contract. The split should be read with care. A firm that certifies to reassure its customers may be feeling the same pressure as one named in a contract clause, so the voluntary share probably overstates how much demand is unprompted. That is one reason the Cyber Resilience Pledge matters: it puts supply chain expectations in writing, and the effect should show up in these categories over time.

Explore the quarters

What the data shows

Cyber Essentials has a settled base of organisations that renew reliably, but it still reaches only a small part of the wider economy. In the year to June 2026, about 52% of large employers held a certificate, along with 24% of medium-sized firms, 7.4% of small firms and 1.4% of micro firms.

Micro and small businesses make up 96.7% of UK businesses with employees. They take about 71% of certificates, yet only a small share of them are certified. Certificate counts alone therefore give a misleading picture of how far the scheme has spread. It is far better established among large employers than among the firms that make up most of the economy.

The renewal figures suggest that organisations that join tend to stay. Quarterly implied renewal rates have ranged from about 85% to 90%. The latest quarter, April to June 2026, is the lowest at 85%. One quarter does not make a trend, but it is the figure to watch in the next release. This is not a true retention measure, because the data does not follow the same organisations from one year to the next. Even so, it points to a scheme that keeps the organisations it has, and whose main limit is reach.

The reasons given show a mix of choice and pressure. The single largest reason was to give customers confidence: 18,301 certificates, or 39.7% of the four quarters to June 2026. That is recorded as a voluntary reason, but it may still reflect customers expecting suppliers to show basic controls without writing it into a contract.

Cyber Essentials Plus made up 32.8% of certificates in the year to June 2026. Among large employers that certified, about half went on to Plus. Larger organisations are more likely to certify, and more likely to pay for the extra technical check that Plus adds.

The Cyber Resilience Pledge and practical starting points

The Cyber Resilience Pledge offers a route from large organisations to their suppliers. Signatories commit to board-level responsibility for cyber security, to joining the NCSC's Early Warning service, to checking Cyber Essentials coverage across their supply chains with the Cyber Essentials Supplier Check Tool, and to requiring Cyber Essentials from suppliers where the risk warrants it.

The pledge will do most good if those commitments raise certification among smaller suppliers, rather than adding to adoption among large organisations. Future releases of this data can test that. The micro and small business uptake rates above are the figures to watch.

For organisations starting out, and for sole traders and businesses without employees who fall outside the comparison used here, the NCSC Cyber Action Toolkit is a practical first step. It gives free, tailored baseline guidance, and the NCSC describes it as a pathway towards Cyber Essentials. It does not replace certification, but it helps organisations take the first steps.

Conclusion

Cyber Essentials is well established in parts of the market, above all among large employers, and organisations that hold it tend to renew. It has not yet become normal practice across the wider business population.

CyberSmart is a founding signatory of the Cyber Resilience Pledge.

Data tables

The figures behind the charts above. Certificate counts are Crown copyright under the Open Government Licence; the uptake and renewal rates are CyberSmart's calculation.

Cyber Essentials uptake by organisation size, year to June 2026 Certificates from the annual tables in the release. The prior-year column sums four quarters, since the release publishes annual figures for the latest year only.
Size bandDefinitionCertificatesOf which PlusBusinessesUptakeYear earlier
Large250 or more employees4,3022,1508,33551.61%45.59%
Medium50 to 249 employees9,1513,67938,43523.81%20.22%
Small10 to 49 employees16,2374,801220,0857.38%6.18%
Microunder 10 employees16,5554,5551,150,8751.44%1.17%
All with employees46,24515,1851,417,7303.26%2.72%
Uptake over rolling twelve-month windows, by size band Each window sums four quarters, except the year to June 2026, which uses the annual tables.
Size bandto Jun 24to Sep 24to Dec 24to Mar 25to Jun 25to Sep 25to Dec 25to Mar 26to Jun 26
Large, any level40.39%41.77%43.55%44.63%45.59%46.95%47.99%49.86%51.61%
Medium, any level17.62%18.45%19.17%19.55%20.22%21.15%21.82%23.03%23.81%
Small, any level5.21%5.44%5.70%5.93%6.18%6.47%6.74%7.11%7.38%
Micro, any level0.99%1.03%1.07%1.13%1.17%1.25%1.30%1.37%1.44%
Large, Plus18.47%19.54%20.75%21.19%21.91%22.80%23.66%24.93%25.79%
Medium, Plus6.35%6.76%7.23%7.36%7.64%8.07%8.46%9.09%9.57%
Small, Plus1.39%1.50%1.58%1.63%1.72%1.80%1.99%2.12%2.18%
Micro, Plus0.30%0.31%0.32%0.33%0.34%0.36%0.35%0.36%0.40%
Implied renewal rate by quarter
QuarterRecertificationsCertificates a year earlierImplied renewal rate
Jul–Sep 246,5907,31490.1%
Oct–Dec 247,3448,39087.5%
Jan–Mar 257,5578,54588.4%
Apr–Jun 257,4978,68486.3%
Jul–Sep 257,7498,76288.4%
Oct–Dec 258,4769,79086.6%
Jan–Mar 269,06510,06490.1%
Apr–Jun 268,4559,96784.8%
Certificates issued by level and quarter, as published Plus holders are also counted in the standard row, so the two rows should not be added together.
LevelJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26Apr–Jun 26
Cyber Essentials Standard (CE)7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,33611,642
Cyber Essentials Plus (CE+)2,0742,8302,9862,6232,6603,3883,2733,1423,2544,0084,0363,857
Standard certificates: new issues and recertifications
Issue typeJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26Apr–Jun 26
Recertifications5,3056,2586,3086,3726,5907,3447,5577,4977,7498,4769,0658,455
New issues2,0092,1322,2372,3122,1722,4462,5072,4703,0372,9073,2713,187
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,33611,642
Standard certificates by organisation size and quarter
Size bandJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26Apr–Jun 26
Large7818138229168959609499961,0081,0471,1051,091
Medium1,5161,6481,7081,7801,8281,9221,9852,0352,1872,1782,4532,301
Small2,6382,7622,9853,0703,1543,3263,5103,6033,7953,9244,3274,182
Micro2,3793,1673,0302,9182,8853,5823,6203,3333,7964,2344,4514,068
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,33611,642
Cyber Essentials Plus by organisation size and quarter
Size bandJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26Apr–Jun 26
Large338382378426426482432486500554538542
Medium509571610709663748709818826897954992
Small6407838547868779589669921,0541,3771,2461,319
Micro5871,0941,1447026941,2001,1668468741,1801,2981,004
Total2,0742,8302,9862,6232,6603,3883,2733,1423,2544,0084,0363,857
Reasons given for seeking a standard certificate
ReasonJul–Sep 23Oct–Dec 23Jan–Mar 24Apr–Jun 24Jul–Sep 24Oct–Dec 24Jan–Mar 25Apr–Jun 25Jul–Sep 25Oct–Dec 25Jan–Mar 26Apr–Jun 26
Required by a customer94386210600000
Required by a regulatory body207417272238193393346237274445369259
Required by an insurer149161155173183204189210214243238199
Required for a grant292932393127324147364656
Required for commercial contract9361,0451,1741,0061,1121,2791,2621,1741,2541,4131,6401,429
Required for government contract1,0921,1091,0741,0771,0781,1401,1861,1821,3621,2731,3361,320
To generally improve our security2,6092,8332,8452,9442,8553,0603,1803,1643,2553,3943,6283,488
To give confidence to our Customers1,9272,4982,7883,0063,1613,4923,6913,7974,2124,4094,9424,738
To meet Data Protection Requirements84319300200000
Other187229190196148195170162168170137153
Total7,3148,3908,5458,6848,7629,79010,0649,96710,78611,38312,33611,642

Sources

Cyber Essentials management information

DSIT publishes this information quarterly with DCMS under the Open Government Licence v3.0. It is management information, not official statistics. The underlying data is supplied by IASME, the scheme's delivery partner. Each release restates the series back to July 2023, so the figures on this page come from the April to June 2026 release, published in September 2026. Queries on the source data should be sent to statistics@dsit.gov.uk.

Business population estimates

The uptake denominators come from Table C of the Department for Business and Trade's business population estimates, which reports UK private sector businesses by size at the start of the year. Each rolling window uses the estimate for the calendar year in which it ends. The series is updated annually, in the autumn.

What the figures mean

Cyber Essentials is a government-backed scheme covering five basic technical controls: firewalls, secure configuration, security update management, user access control and malware protection. The NCSC owns the scheme. IASME delivers it through licensed certification bodies. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds an independent technical audit by the certification body.

A standard certificate is a prerequisite for Plus, so every Plus certificate also generates a standard certificate and Plus holders are counted in both figures. The two levels should not be added together to count organisations. We do not track unique organisations in this dataset, and a large organisation may hold several certificates for different networks. Certificates last 12 months.

How organisation size is defined

Size is based on the number of employees across the UK:

  • micro: under 10 employees
  • small: 10 to 49
  • medium: 50 to 249
  • large: 250 or more
Why some reason categories fall to zero

Categories such as "required by a customer" and "to meet data protection requirements" fall to zero from 2024 onwards. This suggests that the available answer options changed rather than that the underlying behaviour disappeared. Reasons are collected for Cyber Essentials only, not Plus.

Status of these statistics

DSIT publishes these as management information, not official statistics. The underlying data comes from IASME as the scheme's delivery partner.

Analysis, charts and derived measures © CyberSmart Ltd 2026. The uptake rates, the implied renewal rate and the required-or-chosen grouping are original research by CyberSmart and are not published by government. Reuse them with attribution to CyberSmart, linking to this page, under the Creative Commons Attribution 4.0 licence.

The underlying figures are Crown copyright and reproduced under the Open Government Licence v3.0: Cyber Essentials management information from the Department for Science, Innovation and Technology and the Department for Digital, Culture, Media and Sport, with data supplied by IASME; business population estimates from the Department for Business and Trade. Those figures remain the property of their publishers and carry their own caveats, including that the Cyber Essentials release is management information rather than official statistics.

Cyber Essentials is a scheme owned by the National Cyber Security Centre and delivered by IASME. This page is independent research and is not affiliated with, endorsed by, or produced in cooperation with the NCSC, IASME, DSIT, DCMS or DBT. Any errors in the derived figures are ours; the source data is unmodified.

Published by CyberSmart, London. Figures parsed from the April to June 2026 release, published September 2026. Page last revised September 2026.