Home » What the Government’s Cyber Resilience Pledge means for businesses

News

What the Government’s Cyber Resilience Pledge means for businesses

The UK Government’s Cyber Resilience Pledge asks organisations to strengthen board oversight, use the NCSC’s Early Warning service and improve cyber assurance across their supply chains. Here is what the commitment involves – and how businesses can respond proportionately.

In July 2026, the UK Government formally launched its Cyber Resilience Pledge. The voluntary commitment is designed primarily for medium and large organisations, but it is open to organisations of every size and sector.

The pledge reflects a simple point: cyber security is not only an IT issue. It is a business-resilience and governance issue that affects operations, finances, reputation, customers and supply chains. AI may increase the speed and scale of some attacks, but the most effective response still begins with clear accountability, better visibility and consistent basic controls.

Key point: The pledge is one public commitment built around three practical actions. Signing it does not certify an organisation as secure, and it is not a substitute for a wider cyber-resilience programme.

What does the Cyber Resilience Pledge require?

Organisations that sign the pledge commit to the following actions.

1. Make cyber security a board responsibility

Signatories commit to implementing the actions in the NCSC’s Cyber Governance Code of Practice. They must also ensure that all board members complete the NCSC’s cyber-governance training within three months of signing and repeat it annually.

In practice, this means the board should understand the organisation’s most important cyber risks, agree its risk appetite, assign accountable ownership, review progress and test whether the organisation could continue operating through a serious incident.

2. Sign up to the NCSC’s Early Warning service

The pledge requires registration for the NCSC’s free Early Warning service within one month. The service can alert UK organisations to potentially malicious activity associated with their networks, helping them investigate and respond earlier.

Registration alone is not enough. Organisations need a named team or provider to receive, triage and act on alerts, with escalation routes for anything significant.

3. Strengthen supply-chain assurance using Cyber Essentials

Signatories commit to registering for the Cyber Essentials Supplier Check Tool within two months, auditing Cyber Essentials coverage across their supply chains and presenting the findings to the board.

The requirement is deliberately risk-based. An organisation does not necessarily have to demand certification from every supplier. Where Cyber Essentials is not required, the board should be satisfied that the decision is consistent with the organisation’s risk appetite and that suitable assurance is obtained in another way.

Signatories also commit to encouraging the same actions within their own supply chains and publishing their signed declaration on their website.

What should businesses do in practice?

The pledge is concise, but implementing it well requires more than completing three administrative tasks. A practical response should include the following steps.

1 Establish ownership and governance
Nominate a board sponsor and an operational owner. Agree how cyber risk will be reported, which decisions require board approval and how progress will be tracked. Cyber reporting should focus on business impact, material risks, control effectiveness and readiness to respond – not only technical activity.

 

2 Assess the current position
Compare existing governance, training, monitoring and supplier-assurance arrangements with the pledge declaration and the Cyber Governance Code of Practice. Record gaps, owners, deadlines and evidence. This provides a defensible basis for deciding whether and when to sign.

 

3 Make Early Warning operational
Register the organisation’s domains and static IP addresses, confirm who will receive alerts, and define response and escalation procedures. Where monitoring is outsourced, confirm that the provider can act on the notifications and report outcomes.

 

4 Segment the supply chain by risk
Identify suppliers that handle sensitive data, support critical services, connect to your systems or could materially disrupt operations. Set proportionate assurance requirements for each tier, including Cyber Essentials where appropriate, contractual obligations, evidence reviews and incident-notification expectations.

 

5 Test resilience, not just prevention
Review incident-response plans, backup restoration, crisis communications, decision-making and third-party dependencies. Use exercises, penetration testing and recovery testing to establish whether the organisation can detect, contain, recover from and learn after an incident.

 

What are the risks of not signing?

The pledge is voluntary, so there is no automatic legal penalty simply for choosing not to sign. Nor should an organisation sign merely to display a badge. A public commitment creates an expectation that the promised actions have genuinely been completed and are being maintained.

However, organisations that do not address the substance of the pledge may find it harder to demonstrate effective governance and supply-chain assurance to customers, investors, insurers, partners and procurement teams. They may also miss the value of free government services and a recognised baseline for common technical controls.

It is equally important not to overstate the pledge. The Government’s frequently asked questions make clear that taking the actions can improve resilience but does not guarantee protection from every cyber attack. An organisation that has not signed is not necessarily insecure, and a signatory is not necessarily mature. The quality of implementation matters.

Who should consider signing?

The pledge has been designed with medium and large organisations in mind, particularly those with substantial supply chains or strategic responsibilities, but it is open to all sectors and sizes. Smaller organisations can still benefit from its principles, provided they apply them proportionately and do not treat the pledge as a replacement for the NCSC’s practical guidance for smaller businesses.

Before signing, an organisation should be confident that it can meet the stated timescales, evidence its decisions and continue to maintain the commitments. Where gaps exist, it is better to create a credible implementation plan than to make a public promise prematurely.

What are the next steps?

Businesses considering the pledge should start with a focused gap assessment against the declaration, the Cyber Governance Code of Practice and their existing supplier-assurance process. The output should be a short, prioritised plan with clear owners, dates and evidence requirements.

The immediate actions are straightforward: brief the board, complete the governance training, register for Early Warning and understand Cyber Essentials coverage across the supply chain. The more important task is to embed those actions into an enduring programme of risk management, monitoring, testing, incident readiness and continuous improvement.

How Xypher can help

Xypher helps organisations assess cyber maturity, identify the controls that matter most and translate board-level commitments into a practical, proportionate resilience programme. To discuss how the Cyber Resilience Pledge applies to your organisation, contact the Xypher team.

Sources and further reading

UK Government: Cyber Resilience Pledge

UK Government: Cyber Resilience Pledge declaration

UK Government: Cyber Resilience Pledge frequently asked questions

NCSC: Cyber Governance Code of Practice

NCSC: Early Warning service

UK Government: Cyber Essentials scheme overview

Xypher Limited
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.