Cyber Essentials certification has reached a record number, yet only 12% of small businesses report adhering to the government-backed scheme, while almost half (46%) of small businesses identified a cyber breach or attack in the previous 12 months.
New figures published by the Government show that 61,430 Cyber Essentials certificates were awarded in the 12 months to June 2026, up from 59,090 in the previous rolling 12-month period, showing an increase of around 4%.
However, the latest Government Cyber Security Breaches Survey highlights continuing gaps in cyber readiness among smaller organisations. Only 41% of small businesses conducted cyber-security risk assessments in 2025/26, down from 48% in 2024/25.
IT expert John Pepper, CEO and founder of Managed247 comments on the findings and the importance of SMEs getting the fundamentals right:
“The figures highlight a significant gap between the level of cyber risk facing smaller businesses and the steps many are taking to manage that risk.
“For many SMEs, cyber security competes with the immediate pressures of running and growing a business. But smaller organisations are not operating outside the threat landscape, and increasingly they are also part of larger organisations’ supply chains, where customers and partners may expect them to demonstrate that they have basic security controls in place.
“SMEs should start with the fundamentals: secure configurations, strong access controls, software updates and protection against malware. Good cyber hygiene should be treated as part of running a business, rather than something to address after an incident.”
The latest Government survey found that the proportion of small businesses reporting adherence to Cyber Essentials increased from 5% in 2024/25 to 12% in 2025/26. However, awareness of the scheme remains relatively low, with only 25% of small businesses reporting that they were aware of Cyber Essentials.
The issue is also becoming increasingly commercial. The National Cyber Security Centre is encouraging organisations to use Cyber Essentials as part of their supply-chain requirements, meaning SMEs could face growing pressure from customers and procurement teams to demonstrate that they have basic cyber security controls in place. For smaller businesses, this means cyber security could increasingly influence their ability to win and retain contracts, as well as protect their own operations.
Pepper added: “For SMEs, cyber security can affect whether they can win and retain business. As supply-chain expectations rise, being able to demonstrate that the basics are in place could become an increasingly important part of being a trusted supplier.”
Sources:
1.Cyber Essentials management information
2.Cyber security breaches survey 2025-2026
To learn more visit here https://managed.co.uk/services/cyber-security





