Key points
  • More than 60 organisations have signed the government's Cyber Resilience Pledge, launched at 10 Downing Street on 7 July 2026.
  • The government's Cyber Security Breaches Survey 2025/2026 found 43% of UK businesses identified a breach or attack in the past 12 months.
  • The Cyber Security and Resilience Bill, cleared the Commons in June 2026 and had its Lords second reading in mid-July, extending statutory cyber duties to managed service providers for the first time.

More than 60 organisations — including several major UK employers — have signed the government's voluntary Cyber Resilience Pledge, according to reporting from Infosecurity Magazine, launched at 10 Downing Street on 7 July 2026.

What signing the Cyber Resilience Pledge actually commits an organisation to

Signatories commit to three specific things: board-level ownership of cyber risk, registering for the National Cyber Security Centre's (NCSC) Early Warning service, and applying Cyber Essentials across their supply chains. It's a voluntary pledge rather than a legal requirement, but the supply-chain element is the part most likely to reach small businesses indirectly — if a larger customer or partner has signed the pledge, they may increasingly expect the smaller suppliers in their chain to meet Cyber Essentials standards too.

Why the Cyber Security and Resilience Bill matters more for the supply chain

Running alongside the voluntary pledge is the Cyber Security and Resilience Bill, which cleared the House of Commons in June 2026 and had its Lords second reading in mid-July. Unlike the pledge, this is legislation — it extends statutory cyber duties to managed service providers and other critical suppliers for the first time. If your business provides IT services, hosting, or other managed services to larger clients, this Bill is worth tracking directly rather than relying on pledge coverage, since it introduces legal obligations rather than voluntary commitments.

Worth knowing The 43% breach figure comes from the government's own Cyber Security Breaches Survey 2025/2026 and covers businesses identifying any breach or attack attempt in 12 months — it doesn't mean 43% suffered serious financial or operational damage. Most reported incidents in this kind of survey are lower-severity events like phishing attempts, not successful major breaches.

What a small business can actually do without signing anything

You don't need to be a Cyber Resilience Pledge signatory to act on its substance. Cyber Essentials certification — the standard the pledge asks signatories to apply across their supply chains — is available to businesses of any size through the NCSC's certification process, and registering for the NCSC's free Early Warning service takes minutes. Given that larger clients may start expecting supply-chain compliance as their own pledge commitments bite, getting ahead of Cyber Essentials now is a reasonable precaution even for businesses with no direct pledge involvement.

No longer just an IT issue — it is a business imperative.

— Liz Kendall, Technology Secretary, via Infosecurity Magazine, July 2026

What the pledge doesn't guarantee

A voluntary pledge with 60+ signatories demonstrates intent among larger organisations, but it doesn't by itself change legal obligations for smaller suppliers — that's the Cyber Security and Resilience Bill's job, and the Bill is still progressing through Parliament rather than in force. It's also worth being cautious about reading the 43% breach figure as proof that cyberattacks are rising sharply year-on-year without checking the prior year's survey for comparison, since methodology and reporting behaviour can shift the headline number independently of actual attack volume.

Common questions

What is the UK government's Cyber Resilience Pledge?

It's a voluntary commitment launched on 7 July 2026 where signing organisations commit to board-level ownership of cyber risk, registering for the NCSC's Early Warning service, and applying Cyber Essentials standards across their supply chains.

How many organisations have signed the Cyber Resilience Pledge?

More than 60 organisations, including several major UK employers, had signed the pledge as reported in 2026.

What percentage of UK businesses reported a cyberattack in 2026?

43% of UK businesses identified a breach or attack in the past 12 months, according to the government's Cyber Security Breaches Survey 2025/2026.

What does the Cyber Security and Resilience Bill do?

The Bill extends statutory cyber duties to managed service providers and other critical suppliers for the first time. It cleared the Commons in June 2026 and had its Lords second reading in mid-July 2026.

Do small businesses need to sign the Cyber Resilience Pledge?

No, the pledge is aimed primarily at larger organisations, but small businesses can independently pursue Cyber Essentials certification and register for the NCSC's free Early Warning service, which cover the same ground the pledge asks signatories to apply to their supply chains.

In short

More than 60 organisations had signed the government's voluntary Cyber Resilience Pledge as of July 2026, alongside the Cyber Security and Resilience Bill progressing through Parliament, which will extend statutory cyber duties to managed service providers. With 43% of UK businesses reporting some form of breach or attack in the past year, the practical takeaway for small businesses is that Cyber Essentials certification is worth pursuing now, ahead of any supply-chain pressure from larger, pledge-signed clients.

Based on reporting by Infosecurity Magazine, 4 Aug 2026.