Don’t wait for the National Cyber Action Plan: the pledge sets the bar
Security minister Dan Jarvis said on 30 September that a National Cyber Action Plan covering the private sector is coming soon. Its central pillar, the Cyber Resilience Pledge, already sets out what the government wants from boards

- The pledge puts deadlines on boards: director training within three months, Early Warning registration within one month and registration with the Cyber Essentials Supplier Check Tool within two.
- The signatory list recorded 149 organizations on 14 September, and more than 20 of the government’s 39 strategic suppliers signed in the first cohort.
- CISOs should put the pledge’s three checks on the board agenda now, whether or not their organization signs.
Security minister Dan Jarvis used the International Security Expo at Olympia on 30 September to say the government’s cyber agenda is about to reach beyond the state. The Cyber Action Plan published earlier this year covers public services and is backed by more than £210m, he said. Then came the line private-sector boards should note: “This will soon be followed by NCAP – the National Cyber Action Plan – bringing industry and the private sector within scope.”
Jarvis, security minister across the Home Office and the Cabinet Office since 21 July, also said the Cyber Security and Resilience Bill “will deliver the most significant update to the UK’s cyber regulatory framework for years”. The government’s September cyber newsletter, dated 15 September, says the bill had by then completed its Lords committee stage. The text of the speech, published by the Home Office, gives no date for the new plan.
Boards already have a strong clue to what it will ask of them. When the voluntary Cyber Resilience Pledge launched at 10 Downing Street on 7 July, the government’s announcement called it “a central pillar” of the National Cyber Action Plan. Jarvis did not mention the pledge on 30 September.
That is the case for acting now. The pledge’s three asks are the clearest statement yet of what the government expects from private-sector boards, and the plan is likely to build on them rather than replace them. Boards that wait for NCAP before moving will be starting work they could have finished by the time it lands.
Three asks with deadlines attached
The pledge page sets out the commitments. First, make cyber a board responsibility: implement all actions in the Cyber Governance Code of Practice and ensure every board member completes the National Cyber Security Centre’s (NCSC) Cyber Governance Training within three months, then annually. Second, register for the NCSC’s free Early Warning service, which alerts organizations to potentially suspicious activity on their networks, within one month of signing. Third, register with the Cyber Essentials Supplier Check Tool within two months, audit Cyber Essentials coverage and take a risk-based approach to requiring the certification across the supply chain. Signatories also publish the signed declaration on their website, and the pledge’s frequently asked questions (FAQ) say they commit to an annual public update on progress.
The three actions are not new. The Cyber Governance Code of Practice, published in April 2025, says Cyber Essentials and the code together “set out the minimum standard that organisations should have in place to manage their cyber risk”. The pledge page says ministers wrote to the chief executives and chairs of leading UK companies in October 2025 inviting them to take the same three actions. The pledge formalizes that letter.
The signatories so far
The signatory list, last updated on 14 September, gives a total of 149 organizations. Seventy are dated 7 July, among them M&S, Nationwide, ITV, Aviva, SSE and London Stock Exchange Group. Of the 79 added since, 21 have ‘cyber’, ‘security’ or ‘IT’ in their names; later additions also include Tesco, Whitbread, Harrods, Serco and Toyota (GB). The July announcement said more than 20 of the government’s 39 strategic suppliers signed in the first cohort, as part of a Cyber Charter the government was then developing with them.
Enforcement is light. The FAQ says there is “no formal assurance mechanism”, although officials can check Early Warning and Supplier Check Tool registrations, and it says that in some instances failing to complete an action could see an organization withdraw or be removed. Signed declarations now go to the cybersecurity team at the Department for Digital, Culture, Media and Sport (DCMS), which the September newsletter says leads cybersecurity policy for the economy after the team moved from the Department for Science, Innovation and Technology.
The case for moving first
A voluntary pledge with no assurance mechanism can look optional. The government’s own documents suggest otherwise. The FAQ calls the three steps “the foundational actions to building economy-wide cyber resilience”. It says the pledge was not designed specifically for organizations in scope of the bill, but that its actions can help achieve outcomes in the NCSC’s Cyber Assessment Framework, which the bill’s requirements, to be set in secondary legislation, are designed to be consistent with. It also says some organizations that have required Cyber Essentials from third parties see up to an 80% reduction in incidents, a figure the FAQ gives without a source.
The July announcement put the annual cost of cyberattacks to UK organizations at £14.7bn and said the NCSC handled 204 nationally significant incidents in the year to September 2025, up from 89 the year before.
For CISOs, the pledge is a board agenda written by the government, with dates attached. Three questions belong at the next board meeting, whether or not the organization signs:
- Has every director completed the NCSC’s Cyber Governance Training, and when is the annual refresh due?
- Is the organization registered for Early Warning, and who acts on its alerts?
- Which critical suppliers hold Cyber Essentials, and what is the plan for those that do not?
Jarvis said the National Cyber Action Plan will soon bring the private sector into scope. The government has been asking boards to take these three steps since October 2025. When the plan arrives, boards with an answer to all three will read it as confirmation rather than instruction.
Get The VETTDD BriefingThe week in the technology channel, every week.
Subscribe free- Home Office, “Security Minister’s speech at the International Security Expo”, speech (delivered 30 September 2026, published 15:41 BST), 30 September 2026. https://www.gov.uk/government/speeches/security-ministers-speech-at-the-international-security-expo
- GOV.UK, “The Rt Hon Dan Jarvis MBE MP”, ministerial profile, updated 2 September 2026. https://www.gov.uk/government/people/dan-jarvis
- Department for Science, Innovation and Technology and NCSC, “Businesses across Britain sign up to Cyber Resilience Pledge as ministers urge firms to strengthen cyber defences”, press release, 7 July 2026. https://www.gov.uk/government/news/businesses-across-britain-sign-up-to-cyber-resilience-pledge-as-ministers-urge-firms-to-strengthen-cyber-defences
- GOV.UK, “Cyber Resilience Pledge”, guidance page, first published 22 April 2026, updated 13 July 2026. https://www.gov.uk/government/publications/cyber-resilience-pledge
- GOV.UK, “Cyber Resilience Pledge: frequently asked questions”, guidance, updated 13 July 2026. https://www.gov.uk/government/publications/cyber-resilience-pledge/frequently-asked-questions
- GOV.UK, “Cyber Resilience Pledge signatories”, list, updated 14 September 2026. https://www.gov.uk/government/publications/cyber-resilience-pledge-list-of-signatories/cyber-resilience-pledge-signatories
- DCMS, “DCMS cyber security newsletter – September 2026”, newsletter, 15 September 2026. https://www.gov.uk/government/publications/dcms-cyber-security-newsletter-september-2026
- GOV.UK, “Cyber Governance Code of Practice”, code of practice, 8 April 2025. https://www.gov.uk/government/publications/cyber-governance-code-of-practice
- Department for Science, Innovation and Technology, “Government Cyber Action Plan”, policy paper, 6 January 2026 (updated 20 March 2026). https://www.gov.uk/government/publications/government-cyber-action-plan




