On 7 July 2026, the Department for Science, Innovation and Technology formally launched the Cyber Resilience Pledge at a reception hosted by Technology Secretary Liz Kendall at Number 10 Downing Street. More than 60 organisations from across the British economy signed up on day one, committing to three specific, time-bound actions designed to raise the floor of cyber security practice across the private sector ahead of the mandatory duties the Cyber Security and Resilience Bill (CSRB) will introduce.
The launch arrived three weeks after the Cyber Security and Resilience Bill cleared the House of Commons and one week before the Lords held its Second Reading of HL Bill 32 on 14 July 2026. The timing is deliberate. The government's approach to cyber security runs on two parallel tracks: the mandatory track, driven by legislation moving through Parliament; and a voluntary track designed to move faster and reach further than legislation alone can achieve.
The Pledge is the most significant action on the voluntary track to date.
What Signatories Have Committed To
The Pledge sets out three actions, each with a defined timescale that begins on the date an organisation signs:
1. Make cyber a board-level responsibility
Organisations must implement the NCSC's Cyber Governance Code of Practice and ensure that all board members complete the NCSC's Cyber Governance Training within three months of signing, with annual refreshes thereafter. This goes further than simply appointing a CISO or reporting cyber risk to the audit committee. It requires the full board - not just the technology function - to engage directly with the NCSC's governance framework and to demonstrate that engagement through training and documented practice.
2. Register for the NCSC Early Warning service
Signatories must register for the NCSC's Early Warning service within one month. Early Warning provides real-time alerts about threats, vulnerabilities and attacks affecting an organisation's internet-facing systems and networks, drawing on NCSC's national-scale visibility of the UK threat landscape. Registration is free for eligible organisations.
3. Require Cyber Essentials across supply chains
Within two months of signing, organisations must register for the Cyber Essentials Supplier Check Tool - a government service that allows organisations to verify Cyber Essentials certification status across their supply chains. Signatories commit to applying that check as part of their supplier onboarding and review processes.
Who Signed - and Why Capita's Inclusion Matters
The founding cohort spans retail, finance, technology, utilities and media. Named signatories include Marks and Spencer, Nationwide, ITV, Microsoft UK, Cloudflare, Deloitte, Accenture UK, Vodafone Group, VodafoneThree and NCC Group. More than 20 of the 39 companies designated as strategic suppliers to government also signed as part of this first cohort.
The inclusion of Capita attracted considerable comment. The outsourcing company was fined by the Information Commissioner's Office following a 2023 ransomware attack that exposed the personal data of more than six million individuals. Earlier in 2026, Capita also disclosed a separate incident in which a pension portal had exposed personal information belonging to civil servants. The Register headlined its coverage with: "Government's cyber pledge lands 60 signatories, including M&S and, somehow, Capita."
The broader point the inclusion raises is an important one for understanding the Pledge's purpose. It is explicitly intended to drive improvement, not to certify current best practice. Organisations with recent security failures are precisely the audience the government wants to engage. Whether signing a voluntary pledge translates into durable improvement in governance and operational practice is a separate question - one that the Cyber Security and Resilience Bill's mandatory requirements are designed to answer more definitively once the Bill receives Royal Assent.
Technology Secretary Liz Kendall said at the launch: "Today, some of Britain's biggest businesses are taking action to strengthen their cyber defences and setting a powerful example for others to follow. By signing this Pledge, they are showing that cyber resilience is no longer just an IT issue - it is a business imperative. Cyber attacks can disrupt services, put customers' data at risk and have a real impact on the bottom line. As AI makes these threats more sophisticated and easier to launch, no organisation can afford to stand still."
How the Pledge Maps to the Cyber Security and Resilience Bill
The three Pledge commitments are not selected at random. Each maps directly to a provision in HL Bill 32 that will, once the Bill receives Royal Assent, become a legal duty for regulated organisations.
| Pledge commitment |
Corresponding CSRB provision |
| Board cyber governance (Code of Practice + training) |
Part 2 - duty to implement appropriate governance measures |
| NCSC Early Warning registration |
Part 2 - 24/72-hour incident notification regime |
| Cyber Essentials supply chain requirement |
Part 2 - critical supplier security requirements |
The alignment is deliberate. The Pledge allows organisations that are in scope of the Bill - managed service providers, data centre operators, operators of essential services and their suppliers - to begin working towards CSRB compliance now, under a voluntary framework, using infrastructure the NCSC already has in place.
For organisations currently outside formal CSRB scope, signing the Pledge provides a meaningful baseline against an uncertain future. The Bill's critical supplier designation regime gives the Secretary of State broad powers to bring additional organisations into scope through secondary legislation. The categories subject to that regime have not yet been defined. An organisation that has already implemented the Pledge commitments has materially reduced its compliance risk if it is subsequently designated as a critical supplier.
The Cyber Shield Context
The Pledge launch coincided with renewed discussion of the NCSC and DSIT's Cyber Shield initiative. Cyber Shield was formally announced by GCHQ Director Anne Keast-Butler at Bletchley Park in May 2026. It aims to use agentic AI - autonomous AI agents operating at machine speed - to identify vulnerabilities and respond to threats across UK critical national infrastructure. The programme pairs offensive "red" agents that probe systems for weaknesses with defensive "blue" agents that detect and contain intrusions in real time.
Cyber Shield is a five-year programme that sits in the domain of national-level government capability rather than immediate organisational action. Its relevance to the Pledge is nonetheless real: the NCSC Early Warning service - one of the three Pledge commitments - feeds the same national-level visibility infrastructure that underpins Cyber Shield. Organisations that sign up to Early Warning both benefit from NCSC's threat intelligence and contribute to it, improving the data quality that makes national-scale AI-assisted defence more effective.
What the Bill Itself Is Costed At
The voluntary track exists partly because the mandatory track carries a measurable price. DSIT's Final Stage Impact Assessment for the Bill (IA number DSIT002(FIA)-25-DTI, published 12 November 2025) puts the equivalent annual net direct cost to business at £137.7 million in 2025 present value. The total net present social value is estimated at -£1,203 million, within a range of -£768 million to -£1,741 million.
That headline negative figure needs careful reading. The Impact Assessment is explicit that the principal benefits have not been monetised: DSIT states it is not possible to estimate accurately how many cyber attacks the measures will avoid, so the modelled costs are set against benefits the department describes as significant but unquantified. The scorecard rates the overall welfare impact as positive once non-monetised benefits are included.
The aggregate cost also conceals considerable variation between entity types. A managed service provider supporting critical infrastructure faces a materially different burden from a data centre serving a single large enterprise customer. For organisations weighing the Pledge, the relevant point is that the three Pledge commitments address the same governance, detection and supply chain foundations that drive most of the modelled compliance cost - so work done voluntarily now is not wasted when the statutory duties commence.
What This Means for Organisations in CSRB Scope
The Pledge is voluntary. The CSRB is not - at least, not once it receives Royal Assent, which the current Lords timetable places in late 2026 or early 2027. For organisations working through their CSRB preparation, the Pledge offers a practical near-term checklist:
If you are already doing all three things - board governance under the Cyber Governance Code of Practice, NCSC Early Warning registration, Cyber Essentials across your supply chain - then signing the Pledge costs little and signals proactive engagement with the regulatory agenda. It also demonstrates to customers, the NCSC and prospective competent authorities that your commitment to baseline cyber hygiene predates any legal compulsion.
If you are not yet doing all three things, the Pledge timescales - one to three months per commitment - are achievable and proportionate as starting points. They do not substitute for the full compliance programme the CSRB will require, but they address the most operationally critical foundations: governance, detection and supply chain visibility.
If you are a supplier to organisations that have signed the Pledge, expect to receive requests to evidence Cyber Essentials certification or an equivalent standard. Sixty-plus large organisations now have a formal commitment to check their suppliers' certification status using the Cyber Essentials Supplier Check Tool. Supply chain enquiries will follow.
The DSIT implementation consultation - expected during 2026 - will set out the detail of the secondary legislation that determines day-to-day compliance obligations under the CSRB. Organisations that have already begun aligning to the Pledge commitments will be better placed to engage constructively with that consultation.
The Lords Second Reading on 14 July 2026 is the next formal legislative milestone. The full text of HL Bill 32 and a summary of what the Bill changes are available on this site.
This article reflects the position as of 9 July 2026. Sources: GOV.UK press release, Department for Science, Innovation and Technology (7 July 2026); The Register, 7 July 2026; Infosecurity Magazine, 7 July 2026; BankInfoSecurity, 7 July 2026; NCSC Cyber Shield blog post (ncsc.gov.uk); GCHQ Annual Lecture, Bletchley Park, 27 May 2026.