Thursday, 1 October 2026

Where technology leaders come to think out loud

ColumnCybersecurity

Whitehall’s cyber plan makes every supplier part of the audit

The Government Cyber Action Plan sets out how Whitehall will police cyber risk in its own estate. But its supplier clauses turn mid-sized contractors into part of the assurance chain

Ian Murray, minister of state for digital government and data
Image: GOV.UK (OGL)
In brief
  • The plan targets an annual Cyber Essentials check, at minimum, in supply chain assurance by most government departments from April 2029.
  • It aims for 80% of new managed service and digital service contracts to carry security schedules in the same phase.
  • Only about a third of mid-sized firms review their immediate suppliers’ cyber risk, so primes should start mapping their supply chains now.

On 6 January the Department for Science, Innovation and Technology (DSIT) published the Government Cyber Action Plan, presented to Parliament by Ian Murray, minister of state for digital government and data. Most of it concerns Whitehall’s own estate: a new Government Cyber Unit, led by the government chief information security officer and backed by more than £210m of central investment, and an admission that the 2022 target for all government organizations to be resilient to known vulnerabilities and attack methods is “not achievable by the original target date of 2030”.

The plan explains why. It describes cyber risk to the public sector as “critically high” and estimates that nearly a third (28%) of the government technology estate is legacy technology. It cites the cyberattack on Synnovis, which halted blood testing and forced the cancellation of surgeries across London, and the 2024 CrowdStrike outage, which it says cost the UK economy between £1.7bn and £2.3bn and “showed how a single supplier dependency can create widespread disruption”.

That last line is the one suppliers should read twice. The plan states plainly that “every supplier that delivers for government holds some cyber risk”, and it sets out what follows from that.

For security leaders at mid-sized IT, managed service and software firms selling into departments and arm’s-length bodies, the plan sets a course for Cyber Essentials to become a recurring check rather than a tender document – and pushes the same question one tier further down, to their own suppliers.

Assurance moves down the chain

Under the plan, government organizations are responsible for applying “good procurement practices, contractual security and resilience terms and audit and review processes” to their supply chains. Strategic suppliers, chosen for the scale or criticality of what they provide, will sign formal partnerships with the Government Cyber Unit. For every other supplier, the risk sits with the organization that buys from it.

The milestones make the direction concrete. In the plan’s third phase, from April 2029, at least 90% of lead government departments and 50% of arm’s-length bodies are to run some form of supply chain assurance, which “at a minimum” shall include an annual Cyber Essentials check. In the same phase, 80% of new government contracts with a managed service provider or digital service provider are to carry framework or tailored security schedules covering cyber and digital resilience risks.

April 2029 sounds distant. For a supplier on a multi-year framework it is not: contracts signed in 2026 and 2027 may well still be running when those milestones are measured.

The baseline is lower than it looks

DSIT’s own Cyber Security Breaches Survey 2025 shows how far many firms have to travel. Only 3% of businesses said they adhered to Cyber Essentials, rising to 21% of large businesses. Awareness of the scheme stood at 43% among medium businesses and 51% among large ones. A quarter (25%) of businesses did not know whether they held Cyber Essentials, Cyber Essentials Plus or ISO 27001, even though the survey spoke to the person responsible for cybersecurity.

Supplier oversight is thinner still. Of medium businesses, 32% formally reviewed the cyber risks posed by their immediate suppliers, and 15% looked at their wider supply chain. The survey’s interviews found some smaller firms leaving decisions on accreditation to their IT providers, and found it rare for cybersecurity to drive the choice of provider at all.

Put those numbers next to the plan and the gap is plain. A department asked to assure its supply chain will ask its prime suppliers. On the survey’s evidence, most mid-sized firms could not yet answer the same question about their own.

Suppliers should start now

First, treat Cyber Essentials as an operating control. If a buyer checks it every year, a lapsed certificate stops being a tender-stage problem and becomes a contract-management one, raised by the customer rather than discovered by the bid team.

Second, map the suppliers that touch government work – hosting, remote management tools, subcontracted engineers, software dependencies – and ask them the question a department will eventually ask the prime. The plan holds government organizations accountable for their supply chains. The obvious way for them to discharge that is to ask primes to vouch for theirs.

Third, expect security schedules in managed service and digital service contracts, and price them. Evidence requests, incident reporting and restoration planning cost time. Firms that build that cost into their rates will be better placed than those that absorb it and resent it.

None of this requires waiting for 2029. The plan is a statement of where government buying is heading, published with a minister’s name on it. Whitehall has admitted it will miss its own 2030 target. Its suppliers should assume the shortfall will be written into their contracts.

AdvertisementZoomInfo

Get The VETTDD BriefingThe week in the technology channel, every week.

Subscribe free
Sources
  1. Department for Science, Innovation and Technology, “Government Cyber Action Plan” (CP1473), policy paper, 6 January 2026. https://www.gov.uk/government/publications/government-cyber-action-plan/government-cyber-action-plan
  2. Department for Science, Innovation and Technology, “Government Cyber Action Plan” (web optimised PDF), 6 January 2026. https://assets.publishing.service.gov.uk/media/695cfb1534c664251c38a0f9/E03515734_-_Government_Cyber_Action_Plan_ACCESSIBLE.pdf
  3. Department for Science, Innovation and Technology and Home Office, “Cyber security breaches survey 2025”, official statistics, 10 April 2025 (updated 19 June 2025). https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025
About the author

Editor

The VETTDD editorial desk. Interviews, analysis, columns and news on the decisions shaping UK B2B technology.

More from Editor →