Your IT Department

The Cyber Resilience Pledge: What You’re Actually Signing Up For

UK firms suffered over 5 million cyber crimes last year, roughly one every 6 seconds, at an average cost of nearly £195,000 per significant attack. That’s the backdrop to the government’s Cyber Resilience Pledge, launched on 7 July 2026 with more than 60 founding signatories including M&S, Nationwide, Vodafone, Deloitte and Microsoft UK.

It’s voluntary. It’s also not just a logo for your website. Sign it, and you’ve committed to specific, dated actions, not a general promise to “take cyber seriously.”

The three things you actually commit to

The official pledge guidance sets out three core commitments, each with a clock attached.

  • Board ownership. Implement the Cyber Governance Code of Practice, and get every board member through NCSC Cyber Governance Training within 3 months, repeated annually after that.
  • Early Warning. Register for the NCSC’s Early Warning service within 1 month of signing.
  • Supply chain. Register with the Cyber Essentials Supplier Check Tool within 2 months, audit Cyber Essentials coverage across your supply chain, and take a risk-based approach where gaps exist.

None of that is optional once you’ve signed. The board training requirement in particular is a governance duty, not a technical one: directors need enough grounding to actually challenge risk, budget and supplier decisions, not just nod along to whatever IT presents.

Then there’s the part everyone forgets: you have to show your work

Beyond the three core actions, signatories are expected to publish their signed declaration publicly and push the same standard into their own supply chain. That’s a deliberate design choice. A private pledge nobody can check is just a good intention. A published one is something a customer, or a competitor, can hold you to.

Why boards specifically, not just IT

The pledge’s first commitment is to make cyber a board responsibility, not just an IT one. There’s a sound reason for that. Like finance or health and safety, the cost of getting it wrong lands on the whole business, not one department. A director who’s never done the training can’t meaningfully ask why a supplier was exempted from Cyber Essentials, or whether the incident response plan has actually been tested. They can only trust that someone else handled it.

What to actually do this week if you’re considering signing

  • Name one board member as the accountable owner, not “the IT team” as a collective shrug
  • Book NCSC Cyber Governance Training now (it’s free) rather than waiting for the 3-month clock to start feeling urgent
  • Map your suppliers by how critical they are and whether they currently hold Cyber Essentials, before you sign anything, so you know exactly what you’re committing to fix
  • Where a supplier doesn’t have Cyber Essentials, decide now whether that’s an accepted risk or a blocker, and write down why

That supplier map is usually where the pledge stops being theoretical. It’s one thing to agree cyber risk should sit with the board. It’s another to find out, mid-audit, that a payroll provider or a marketing agency handling customer data has no security certification at all.

This is the homework we help clients with. Our Cyber Essentials gap analysis shows where you stand against the requirements, with a costed action plan to close the gaps, and our cyber security assessment gives you the wider picture of your risks. Worth doing that quietly, before the declaration goes on your website, not after.

Common questions about the Cyber Resilience Pledge

What is the Cyber Resilience Pledge?

The Cyber Resilience Pledge is a voluntary UK government commitment, launched on 7 July 2026, that asks businesses to make cyber security a board responsibility, register for the NCSC’s Early Warning service and require Cyber Essentials across their supply chains. More than 60 businesses signed at launch, including M&S, Nationwide, Vodafone and Deloitte.

Is the Cyber Resilience Pledge mandatory?

No. The pledge is a voluntary initiative. Once you sign, though, you commit to specific actions with deadlines and publish your signed declaration on your website, so customers and suppliers can see what you have promised.

What are the Cyber Resilience Pledge deadlines?

The pledge sets three clocks. Register for the NCSC Early Warning service within 1 month of signing. Register for the Cyber Essentials Supplier Check Tool within 2 months. Have every board member complete NCSC Cyber Governance Training within 3 months, then repeat it every year.

What is the NCSC Early Warning service?

Early Warning is a free NCSC service that notifies UK organisations of cyber threats targeting their networks. It compares information from the NCSC and trusted public and commercial sources against your organisation’s registered IP addresses and domain names, then sends alerts about issues such as malware infections, network abuse and exposed vulnerabilities.

What is Cyber Essentials, and do all my suppliers need it?

Cyber Essentials is a government-backed scheme developed by the NCSC, built around five technical controls that protect against common internet threats. The pledge asks you to audit Cyber Essentials coverage across your supply chain and take a risk-based approach to requiring it, so decide which suppliers need it most and record why you accept any gaps.