ComplianceBack to Blog

UK Cyber Resilience Pledge: 60 Firms Commit Ahead of the Cyber Security and Resilience Bill

Technology Secretary Liz Kendall launched the Cyber Resilience Pledge at Number 10 on 7 July 2026, and more than 60 organisations signed on day one - M&S, Nationwide, Vodafone, NCC Group and, to some comment, Capita. Each of its three time-bound commitments maps onto a duty that the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, will make mandatory. Here is how to use the voluntary track to get ahead of the statutory one.

Precursor Security
9 July 2026
7 min read
1,650 words

Precursor Security

Precursor Security is a UK-based penetration testing and offensive security testing company with 24/7 security operations centres. We are CREST certified in both penetration testing and security operations, providing comprehensive cyber security services to help organisations achieve regulatory compliance and enhance their security posture.

Share:

On 7 July 2026, the Department for Science, Innovation and Technology formally launched the Cyber Resilience Pledge at a reception hosted by Technology Secretary Liz Kendall at Number 10 Downing Street. More than 60 organisations from across the British economy signed up on day one, committing to three specific, time-bound actions designed to raise the floor of cyber security practice across the private sector ahead of the mandatory duties the Cyber Security and Resilience Bill (CSRB) will introduce.

The launch arrived three weeks after the Cyber Security and Resilience Bill cleared the House of Commons and one week before the Lords held its Second Reading of HL Bill 32 on 14 July 2026. The timing is deliberate. The government's approach to cyber security runs on two parallel tracks: the mandatory track, driven by legislation moving through Parliament; and a voluntary track designed to move faster and reach further than legislation alone can achieve.

The Pledge is the most significant action on the voluntary track to date.

What Signatories Have Committed To

The Pledge sets out three actions, each with a defined timescale that begins on the date an organisation signs:

1. Make cyber a board-level responsibility

Organisations must implement the NCSC's Cyber Governance Code of Practice and ensure that all board members complete the NCSC's Cyber Governance Training within three months of signing, with annual refreshes thereafter. This goes further than simply appointing a CISO or reporting cyber risk to the audit committee. It requires the full board - not just the technology function - to engage directly with the NCSC's governance framework and to demonstrate that engagement through training and documented practice.

2. Register for the NCSC Early Warning service

Signatories must register for the NCSC's Early Warning service within one month. Early Warning provides real-time alerts about threats, vulnerabilities and attacks affecting an organisation's internet-facing systems and networks, drawing on NCSC's national-scale visibility of the UK threat landscape. Registration is free for eligible organisations.

3. Require Cyber Essentials across supply chains

Within two months of signing, organisations must register for the Cyber Essentials Supplier Check Tool - a government service that allows organisations to verify Cyber Essentials certification status across their supply chains. Signatories commit to applying that check as part of their supplier onboarding and review processes.

Who Signed - and Why Capita's Inclusion Matters

The founding cohort spans retail, finance, technology, utilities and media. Named signatories include Marks and Spencer, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK, Vodafone Group, VodafoneThree and NCC Group. More than 20 of the 39 companies designated as strategic suppliers to government also signed as part of this first cohort.

The inclusion of Capita attracted considerable comment. The outsourcing company was fined by the Information Commissioner's Office following a 2023 ransomware attack that exposed the personal data of more than six million individuals. Earlier in 2026, Capita also disclosed a separate incident in which a pension portal had exposed personal information belonging to civil servants. The Register headlined its coverage with: "Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita."

The broader point the inclusion raises is an important one for understanding the Pledge's purpose. It is explicitly intended to drive improvement, not to certify current best practice. Organisations with recent security failures are precisely the audience the government wants to engage. Whether signing a voluntary pledge translates into durable improvement in governance and operational practice is a separate question - one that the Cyber Security and Resilience Bill's mandatory requirements are designed to answer more definitively once the Bill receives Royal Assent.

Technology Secretary Liz Kendall said at the launch: "Today, some of Britain's biggest businesses are taking action to strengthen their cyber defences and setting a powerful example for others to follow. By signing this Pledge, they are showing that cyber resilience is no longer just an IT issue - it is a business imperative. Cyber attacks can disrupt services, put customers' data at risk and have a real impact on the bottom line. As AI makes these threats more sophisticated and easier to launch, no organisation can afford to stand still."

How the Pledge Maps to the Cyber Security and Resilience Bill

The three Pledge commitments are not selected at random. Each maps directly to a provision in HL Bill 32 that will, once the Bill receives Royal Assent, become a legal duty for regulated organisations.

Pledge commitment Corresponding CSRB provision
Board cyber governance (Code of Practice + training) Part 2 - duty to implement appropriate governance measures
NCSC Early Warning registration Part 2 - 24/72-hour incident notification regime
Cyber Essentials supply chain requirement Part 2 - critical supplier security requirements

The alignment is deliberate. The Pledge allows organisations that are in scope of the Bill - managed service providers, data centre operators, operators of essential services and their suppliers - to begin working towards CSRB compliance now, under a voluntary framework, using infrastructure the NCSC already has in place.

For organisations currently outside formal CSRB scope, signing the Pledge provides a meaningful baseline against an uncertain future. The Bill's critical supplier designation regime gives the Secretary of State broad powers to bring additional organisations into scope through secondary legislation. The categories subject to that regime have not yet been defined. An organisation that has already implemented the Pledge commitments has materially reduced its compliance risk if it is subsequently designated as a critical supplier.

The Cyber Shield Context

The Pledge launch coincided with renewed discussion of the NCSC and DSIT's Cyber Shield initiative. Cyber Shield was formally announced by GCHQ Director Anne Keast-Butler at Bletchley Park in May 2026. It aims to use agentic AI - autonomous AI agents operating at machine speed - to identify vulnerabilities and respond to threats across UK critical national infrastructure. The programme pairs offensive "red" agents that probe systems for weaknesses with defensive "blue" agents that detect and contain intrusions in real time.

Cyber Shield is a five-year programme that sits in the domain of national-level government capability rather than immediate organisational action. Its relevance to the Pledge is nonetheless real: the NCSC Early Warning service - one of the three Pledge commitments - feeds the same national-level visibility infrastructure that underpins Cyber Shield. Organisations that sign up to Early Warning both benefit from NCSC's threat intelligence and contribute to it, improving the data quality that makes national-scale AI-assisted defence more effective.

What the Bill Itself Is Costed At

The voluntary track exists partly because the mandatory track carries a measurable price. DSIT's Final Stage Impact Assessment for the Bill (IA number DSIT002(FIA)-25-DTI, published 12 November 2025) puts the equivalent annual net direct cost to business at £137.7 million in 2025 present value. The total net present social value is estimated at -£1,203 million, within a range of -£768 million to -£1,741 million.

That headline negative figure needs careful reading. The Impact Assessment is explicit that the principal benefits have not been monetised: DSIT states it is not possible to estimate accurately how many cyber attacks the measures will avoid, so the modelled costs are set against benefits the department describes as significant but unquantified. The scorecard rates the overall welfare impact as positive once non-monetised benefits are included.

The aggregate cost also conceals considerable variation between entity types. A managed service provider supporting critical infrastructure faces a materially different burden from a data centre serving a single large enterprise customer. For organisations weighing the Pledge, the relevant point is that the three Pledge commitments address the same governance, detection and supply chain foundations that drive most of the modelled compliance cost - so work done voluntarily now is not wasted when the statutory duties commence.

What This Means for Organisations in CSRB Scope

The Pledge is voluntary. The CSRB is not - at least, not once it receives Royal Assent, which the current Lords timetable places in late 2026 or early 2027. For organisations working through their CSRB preparation, the Pledge offers a practical near-term checklist:

If you are already doing all three things - board governance under the Cyber Governance Code of Practice, NCSC Early Warning registration, Cyber Essentials across your supply chain - then signing the Pledge costs little and signals proactive engagement with the regulatory agenda. It also demonstrates to customers, the NCSC and prospective competent authorities that your commitment to baseline cyber hygiene predates any legal compulsion.

If you are not yet doing all three things, the Pledge timescales - one to three months per commitment - are achievable and proportionate as starting points. They do not substitute for the full compliance programme the CSRB will require, but they address the most operationally critical foundations: governance, detection and supply chain visibility.

If you are a supplier to organisations that have signed the Pledge, expect to receive requests to evidence Cyber Essentials certification or an equivalent standard. Sixty-plus large organisations now have a formal commitment to check their suppliers' certification status using the Cyber Essentials Supplier Check Tool. Supply chain enquiries will follow.

The DSIT implementation consultation - expected during 2026 - will set out the detail of the secondary legislation that determines day-to-day compliance obligations under the CSRB. Organisations that have already begun aligning to the Pledge commitments will be better placed to engage constructively with that consultation.

The Lords Second Reading on 14 July 2026 is the next formal legislative milestone. The full text of HL Bill 32 and a summary of what the Bill changes are available on this site.

This article reflects the position as of 9 July 2026. Sources: GOV.UK press release, Department for Science, Innovation and Technology (7 July 2026); The Register, 7 July 2026; Infosecurity Magazine, 7 July 2026; BankInfoSecurity, 7 July 2026; NCSC Cyber Shield blog post (ncsc.gov.uk); GCHQ Annual Lecture, Bletchley Park, 27 May 2026.

Tags:
CSRBcyber securityUK legislationcomplianceCyber Resilience PledgeDSITNCSCCyber Essentialssupply chainboard governanceHL Bill 32Cyber Shieldagentic AIincident reporting
Last updated: 3 August 2026
Share:

You Might Also Like

Explore more insights and guidance on the Cyber Security and Resilience Bill.

Precursor Security
3 Jul 2026

UK Cyber Breaches Survey 2026: The Cyber Security and Resilience Bill Compliance Gap

DSIT's Cyber Security Breaches Survey 2025/2026 put 43% of UK businesses on the wrong end of a breach. The more revealing numbers sit beneath that headline: only 40% told anyone outside the organisation, and only 25% hold a formal incident response plan. Here is what that gap means once the Cyber Security and Resilience Bill (CSRB) makes 24/72-hour reporting a legal duty.

CSRBcyber security+12 more
Read Article
Precursor Security
28 Jul 2026

The Cyber Security and Resilience Bill Skills Gap: Can UK Firms Resource the New Duties?

A new think-tank report warns the Cyber Security and Resilience Bill (CSRB) risks becoming a "paper tiger" unless the UK's cyber skills shortage is addressed. With 49% of businesses and 58% of government bodies reporting a basic skills gap, the people needed to run 24/72-hour reporting and ongoing risk management may not be there. Here is what in-scope organisations should do about it before the duties commence.

CSRBcyber security+14 more
Read Article
Precursor Security
22 Jul 2026

Lords Complete Cyber Security and Resilience Bill Second Reading: Key Themes and Committee Stage on 1 September

The Lords gave the Cyber Security and Resilience Bill (CSRB), now HL Bill 32, cross-party support at Second Reading on 14 July 2026 without calling a division - but they put five pointed themes on the record, from the public sector exemption to the Bill's total silence on AI. Committee Stage begins on 1 September, and those themes are the working agenda. Here is what each one means for in-scope organisations.

CSRBcyber security+19 more
Read Article