Article by IASME.
IASME is the Cyber Essentials Partner for the National Cyber Security Centre (NCSC), their network of Certification Bodies support organisations across the UK economy to implement the Cyber Essentials controls and build practical cyber resilience.
The Cyber Resilience Pledge is a new voluntary government commitment to strengthen cyber resilience across the economy. Signatories commit to three practical actions:
- Make cyber security a board-level responsibility (using the Cyber Governance Code of Practice and NCSC training)
- Sign up to the NCSC Early Warning service
- Take a risk-based approach to securing supply chains, including requiring Cyber Essentials where appropriate.
While aimed primarily at medium and large organisations (including FTSE 350), the Pledge is open to all sizes and sectors, with early signatories including M&S, Nationwide, ITV, Microsoft UK and Cloudflare.
Building on its three commitments, the Cyber Resilience Pledge sets an expectation for cyber security leadership: move beyond one-off assurance exercises and towards repeatable, board-owned practices that strengthen resilience not just within organisations, but across their supply chains too.
For CIISec members, the Pledge has three immediate implications:
- Some CIISec corporate member organisations are already signatories, and others will be watching closely as the Pledge rolls out across sectors.
- Many members work in organisations that supply signatories (directly or indirectly), so customer and procurement expectations around baseline cyber assurance are likely to become more consistent—and more explicit.
- And because the Pledge includes a commitment on risk-based supply chain security, it’s particularly relevant to the teams CIISec members work alongside—security leadership, third‑party/supplier risk, governance and procurement—as they consider when to require Cyber Essentials (or Cyber Essentials Plus) from suppliers.
This article focuses on that supply-chain commitment—what it means in practice, why it’s effective, and how IASME can help organisations implement it in a way that is robust, achievable and fair.
The supply-chain problem
Most organisations have made progress on their own internal cyber hygiene—patching regimes, multi-factor authentication, endpoint protection, secure configurations and backups. Yet cyber risk does not stop at the perimeter.
Modern organisations depend on a network of suppliers and partners: IT providers, managed service providers, cloud platforms, specialist consultancies, payroll and HR systems, marketing and analytics tools, facilities and operational technology suppliers, and countless niche software vendors. Each relationship introduces potential exposure—through access to systems, sensitive data, or critical service dependencies.
Even when your own controls are strong, threat actors will often look for the weakest link. That can be a supplier with the same level of access but fewer resources, less mature governance, or more inconsistent technical controls.
According to the Cyber Security Breaches Survey 2025/26, relatively few organisations formally review cyber risks in their supply chains: 15% of businesses assess the risks posed by their immediate suppliers, and only  6% look beyond to the wider supply chain.
Why supplier assurance is hard
Organisations have long tried to manage supplier risk with questionnaires and bespoke assessments. In principle, that makes sense: you want assurance tailored to the service being provided.
In practice, this approach often breaks down because of:
- Questionnaire overload: Large organisations sometimes push enterprise-grade requirements onto small suppliers. Suppliers who serve multiple large customers can end up completing near-identical questionnaires repeatedly, consuming time that could be spent improving security.
- Inconsistent expectations: Different customers ask different things in different formats. The result is fragmented assurance with limited comparability.
- Low signal-to-noise: Long questionnaires do not always verify that fundamental technical controls are actually in place.
- A bottleneck to business: Excessive or unclear requirements slow onboarding and contract renewal, and can create friction between security, procurement and commercial teams.
The outcome is familiar to many CIISec members: lots of documentation, not enough confidence.
Cyber Essentials is a baseline that’s robust, recognised and achievable
Cyber Essentials is the UK Government-backed, annually renewable baseline cyber security certification. It was designed to help organisations of all sizes implement a core set of technical controls that reduce exposure to common, internet-based attacks.
There are two levels:
- Cyber Essentials — an independently verified assessment based on a self-assessment questionnaire signed off at board level.
- Cyber Essentials Plus — the same controls, with the addition of an external technical audit to verify implementation.
For supply-chain assurance, Cyber Essentials has a key advantage: it provides a standardised, repeatable minimum expectation that can be applied consistently across suppliers, without the overhead and subjectivity of bespoke checks for every relationship.
It is also widely recognised. Cyber Essentials is frequently requested in procurement, funding and grant applications, and in many government contract contexts. In other words, it is increasingly becoming part of the language of assurance in the UK market.
One of the UK’s largest pensions and life companies, St. James’s Place mandated Cyber Essentials Plus certification for over 2,800 independent businesses in its network. Overnight they saw an 80% reduction in cyber security incidents.
The power of Cyber Essentials through the supply chain
The supply-chain commitment in the Cyber Resilience Pledge is intentionally risk-based. That matters because supply chains are not uniform: a supplier that remotely administers your IT environment is not the same as a low-touch supplier with no system access and minimal data handling.
Used well, Cyber Essentials becomes a practical tool that scales because it can:
- Raise the minimum standard, consistently — a clear baseline suppliers can demonstrate through certification.
- Reduce friction in due diligence — a recognised, repeatable minimum expectation that can streamline assurance for lower- and medium-risk suppliers, while leaving room for deeper checks where risk justifies it.
- Support SMEs rather than overwhelm them — achievable requirements and a shared reference point, rather than a different questionnaire for every customer.
- Build confidence across complex, global supplier networks — a baseline that can be applied consistently even when suppliers operate internationally.
For organisations looking to implement a proportionate approach, the NCSC’s Cyber Essentials supply chain playbook will support you to embed Cyber Essentials in your supply chain. This practical guide sets out a step-by-step approach: assess supply-chain risks, profile suppliers, set minimum security requirements, communicate expectations, incentivise adoption, embed requirements into procurement and contracts, and monitor ongoing adoption.
What this means for CIISec members who are suppliers
If you work for an organisation that supplies services to larger customers—or to government—Cyber Essentials is likely to feature more often in procurement and assurance conversations.
Three practical actions:
- Prepare your narrative: Be ready to explain how you meet baseline technical controls, how you manage vulnerabilities, and what your incident response looks like.
- Plan certification proactively: Treat Cyber Essentials as a business readiness activity.
- Use certification as evidence: A current Cyber Essentials (or Plus) certificate reduces friction, speeds up bids, and can simplify repeated assurance requests.
For buying organisations: verifying Cyber Essentials across your supplier base
If you’re a customer organisation embedding Cyber Essentials into supplier expectations, you’ll also need a straightforward way to verify certification status over time—not just at onboarding.
IASME provides tools to help organisations verify Cyber Essentials and Cyber Essentials Plus certifications:
- Cyber Essentials Certificate Search — to check the status of individual suppliers.
- Supplier Check Tool — for organisations with large supplier lists, enabling bulk checks to identify which suppliers hold current certifications.
These tools can reduce manual effort and help you maintain a clearer picture of baseline assurance across your supplier ecosystem.
Find out more
- Cyber Resilience Pledge
- Talk to IASME about supply-chain adoption of Cyber Essentials: info@iasme.co.uk
- For more on the Cyber Resilience Pledge read our CEO Viewpoint: The Cyber Resilience Pledge over coffee