Cyber Essentials, ISO 27001 & SOC 2 statistics UK 2026: how rare are they?
1 in 1,200: How Rare Cyber Essentials Plus, ISO 27001 and SOC 2 Really Are for Small UK Software Companies (2026 Data)#
Last updated 27 September 2026 · Cyber Essentials, Cyber Essentials Plus, ISO 27001, ISO 9001, SOC 2, PCI DSS and IASME Cyber Assurance statistics for the UK, built from government and ISO data rather than vendor marketing.
I run RODMENA, a software company in London, and I run it on my own. The products page lists nearly thirty services, from an authorisation service to a double-entry ledger. So I hear one question from nearly every serious buyer: how do we trust a one-person vendor?
My answer has been certification. I’ve been putting a lot of hours into Cyber Essentials and Cyber Essentials Plus, and eventually I had to ask whether it would actually set me apart or just tick a box nobody reads. So I went to the primary sources: the UK government’s quarterly certification data, the ISO Survey, the government’s own evaluation of the scheme, and its business population statistics. Then I worked out how rare each credential really is.
Contents#
- The short answer
- UK certification statistics at a glance
- How many UK companies have Cyber Essentials?
- What are the odds for a one-person company?
- Cyber Essentials for software companies
- How many UK companies are ISO 27001 certified?
- ISO 9001 in the UK
- How many companies have SOC 2?
- PCI DSS: not a badge, a boundary
- IASME Cyber Assurance
- Is Cyber Essentials worth it for a small software company?
- FAQ
- Methodology and caveats
- Sources
The short answer#
- Cyber Essentials: 46,245 UK certificates in the year to June 2026. That’s about 1 in 123 UK businesses, and at most 1 in 328 firms with fewer than ten staff.
- Cyber Essentials Plus: 15,185 certificates, about 1 in 375 UK businesses and at most 1 in 1,190 micro firms.
- ISO 27001: 4,455 accredited UK certificates, about 1 in 1,280 UK businesses.
- ISO 9001: 32,988 UK certificates, about 1 in 170.
- SOC 2, PCI DSS and IASME Cyber Assurance: no public counts exist. Anyone quoting one is guessing.
For a one-person software company, Cyber Essentials Plus gives the most rarity for the effort. ISO 27001 is rarer, but it costs far more to keep.
UK certification statistics at a glance#
| Credential | UK certificates | Share of UK businesses (5.69M) | Roughly 1 in… | Public count? |
|---|---|---|---|---|
| Cyber Essentials | 46,245 | 0.81% | 123 | Yes – DSIT, quarterly |
| ISO 9001 | 32,988 | 0.58% | 172 | Yes – ISO Survey |
| Cyber Essentials Plus | 15,185 | 0.27% | 375 | Yes – DSIT, quarterly |
| ISO/IEC 27001 (accredited) | 4,455 | 0.08% | 1,277 | Yes – ISO Survey |
| IASME Cyber Assurance | — | — | — | No |
| SOC 2 | — | — | — | No – reports are private |
| PCI DSS | — | — | — | Not meaningful – see below |
Cyber Essentials figures cover July 2025 – June 2026. ISO figures are valid certificates in 2024. The business population is the UK private sector at the start of 2025.
How many UK companies have Cyber Essentials?#
First, avoid the double-counting trap#
You’ll see “61,430 Cyber Essentials certificates” in the trade press. That number counts the same organisations twice. The government’s own dataset (Note 1) says that anyone who achieves Cyber Essentials Plus is also issued a standard Cyber Essentials certificate. The 15,185 Plus certificates are therefore already inside the 46,245.
Correct reading: 46,245 Cyber Essentials certificates were issued, and 15,185 of those organisations (33%) went on to Plus.
Cyber Essentials statistics by company size#
DSIT/IASME management information, July 2025 – June 2026. Uptake uses the number of UK private-sector businesses in each size band as the denominator.
| Size | Cyber Essentials | Uptake | …of which Plus | Plus uptake | Plus as share of CE |
|---|---|---|---|---|---|
| Large (250+) | 4,302 | 51.6% | 2,150 | 25.8% | 50% |
| Medium (50–249) | 9,151 | 23.8% | 3,679 | 9.6% | 40% |
| Small (10–49) | 16,237 | 7.4% | 4,801 | 2.2% | 30% |
| Micro (under 10) | 16,555 | 1.4% | 4,555 | 0.4% | 28% |
| Total | 46,245 | 15,185 | 33% |
About 73% of certificates are renewals; about 12,400 were first-time certifications. The quarterly numbers are growing steadily: 11,642 in April–June 2026, up from 9,967 a year earlier.
Why do organisations get Cyber Essentials?#
Reasons are self-reported when applying for the standard certificate (last four quarters, 46,147 certificates):
| Reason | Certificates | Share |
|---|---|---|
| To give confidence to our customers | 18,301 | 39.7% |
| To generally improve our security | 13,765 | 29.8% |
| Required for a commercial contract | 5,736 | 12.4% |
| Required for a government contract | 5,291 | 11.5% |
| Required by a regulator | 1,347 | 2.9% |
| Required by an insurer | 894 | 1.9% |
| Other | 628 | 1.4% |
| Required for a grant | 185 | 0.4% |
Seven in ten organisations certify voluntarily. For most of them it’s a trust signal to customers, not a mandate.
One practical note: the Cyber Essentials questionnaire asks you to list the devices, operating systems and cloud services in scope. If you don’t already keep an asset register, you’ll end up building one. A spreadsheet works. If you’d rather have something that also produces a software bill of materials for every release, that’s what Provenance does. Either way, keep the list current, because you’ll need it again at renewal.
What are the odds for a one-person company?#
The “1.44% of micro businesses” figure you’ll see quoted uses only firms with 1–9 employees (1.15 million businesses) as the denominator. But the government’s business statistics put a limited company with a single working director in the “no employees” group. There are 4.27 million of those, 75% of all UK businesses, and none of them count towards that 1.44%.
Put all firms with 0–9 staff (5.42 million) in the denominator and you get:
| Credential | Certificates held by firms under 10 staff | Share of firms with 0–9 staff | Roughly 1 in… |
|---|---|---|---|
| Cyber Essentials | 16,555 | 0.31% | 328 |
| Cyber Essentials Plus | 4,555 | 0.08% | 1,191 |
These are ceilings: they assume every micro certificate went to a tiny firm. The real share for genuine one-person companies is lower, so Cyber Essentials Plus puts a solo company in well under the top 0.1% of its peer group.
Awareness is low too. Only 14% of micro businesses have even heard of Cyber Essentials, against 64% of large businesses (Cyber Security Breaches Survey 2025/26).
Cyber Essentials for software companies#
The quarterly government data has no split by sector. The best available figures come from the government’s 2024 impact evaluation:
- IT is the largest single sector, holding about 12% of Cyber Essentials certificates, ahead of finance (10%) and consultancy (7%). This comes from IASME’s 2023 annual review.
- Certified micro businesses said about 36% of the contracts they won in the previous year required Cyber Essentials. That was the highest of any size band.
- 75% of certified organisations said they have more confidence working with certified suppliers, and 61% are more likely to choose them.
- Cyber Essentials is mandatory for UK government contracts that involve handling sensitive or personal information or supplying certain technical products and services.
If your buyers are UK public sector bodies or companies with a procurement checklist, those figures are the business case.
How many UK companies are ISO 27001 certified?#
4,455 valid ISO/IEC 27001 certificates in the UK (ISO Survey 2024), placing the UK fourth in the world:
| Rank | Country | ISO 27001 certificates |
|---|---|---|
| 1 | China | 33,359 |
| 2 | India | 6,758 |
| 3 | Japan | 6,644 |
| 4 | United Kingdom | 4,455 |
| 5 | United States | 4,260 |
That’s 3.4× rarer than Cyber Essentials Plus and about 0.08% of UK businesses. The survey counts only accredited certificates, and 2024 is the first year built from mandatory reporting to the IAF CertSearch database, so earlier years aren’t comparable.
There’s no official UK split by company size, but the government’s 2024 evaluation shows who uses ISO 27001. Using it is not the same as being certified:
| Uses ISO 27001 | Micro | Small | Medium | Large |
|---|---|---|---|---|
| Organisations with Cyber Essentials | 14% | 26% | 36% | 38% |
| Organisations that never had Cyber Essentials | 4% | 6% | 17% | 25% |
It leans heavily towards larger firms. My estimate is that at most a few hundred UK one-person companies hold accredited ISO 27001, somewhere around 1 in 10,000 or rarer. Nobody publishes this figure, so treat it as an inference.
ISO 9001 in the UK#
32,988 valid ISO 9001 certificates in the UK (ISO Survey 2024), eighth in the world and about 7.4× more common than ISO 27001. Worldwide it’s concentrated in metal fabrication, wholesale and retail, electrical equipment and machinery. In the UK it’s a supply-chain requirement in construction, manufacturing and defence. Software buyers rarely ask for it.
How many companies have SOC 2?#
Nobody knows, and that includes anyone quoting a figure. SOC 2 isn’t a certification with a register. It’s a confidential attestation report, issued by a US-licensed CPA firm under AICPA standards and shared with customers under NDA. No public count of reports exists.
What is known:
| Type 1 | Type 2 | |
|---|---|---|
| Median audit fee (planning estimate) | ~$35,000 | ~$55,000 |
| Typical range | $17.5k–$55k | $30k–$100k |
Source: soc2auditors.org planning estimates. These are not observed prices, and they exclude your own time and tooling.
SOC 2 is the US enterprise buyer’s checkbox; UK buyers ask for Cyber Essentials or ISO 27001. It’s also awkward for a company of one, because many controls assume segregation of duties: someone independent approving a change or reviewing access. The usual workaround is to make the second pair of eyes a recorded step. Changes and access grants go through an explicit approval that leaves a trail an auditor can sample, and access decisions live in one place rather than scattered across config files. At RODMENA those are Futex (policy-driven human approvals with audit trails) and Auth (one service that decides who may do what). To be clear about limits: no tool makes you compliant. The auditor assesses the control, not the product, and a solo company should still expect some exceptions noted in the report.
PCI DSS: not a badge, a boundary#
PCI DSS doesn’t fit the “how many hold it” question:
- Every business that accepts card payments must comply and confirm compliance every year. Most small firms do this with a Self-Assessment Questionnaire. If you take payments through a hosted checkout such as Stripe’s, you’re usually on the shortest one, SAQ A. That’s basic hygiene, not something that sets you apart.
- Service providers that store, process or transmit card data for other businesses must be assessed by a Qualified Security Assessor and can appear on Visa’s Global Registry of Service Providers. That credential is genuinely rare, but it only applies if you handle cardholder data, and Visa publishes no UK total.
- Staying compliant is hard. Verizon’s 2019 Payment Security Report found that only 27.9% of the organisations it assessed kept full compliance between annual validations.
For a software company, the smart move is to keep card data out of your systems entirely.
IASME Cyber Assurance#
IASME Cyber Assurance (formerly IASME Governance) is the UK’s SME-sized alternative to ISO 27001. It’s run by IASME, the same body that delivers Cyber Essentials.
| Detail | |
|---|---|
| Prerequisite | Cyber Essentials |
| Levels | Level 1 (verified assessment), Level 2 (audit) |
| Requirements for 1–2 people | 20 |
| Requirements for 50+ people | 65 |
| Public certificate count | None |
The only proxy for adoption is the government’s 2024 evaluation: 10% of Cyber Essentials holders, and 14% of micro ones, said they use IASME Cyber Assurance. That was a small survey measuring use, not certification, so treat it as a loose upper bound.
Where it differs most from Cyber Essentials is privacy and data protection alongside security. For small firms, the gap usually shows up in unglamorous places. If a customer’s end user sent you a subject access request tomorrow, could you find, redact and disclose their data within the one-month legal deadline under UK GDPR, and prove you did? We built Vellum for exactly that workflow. A written procedure you’ve actually rehearsed also counts.
Is Cyber Essentials worth it for a small software company?#
My ranking for a one-person UK software business:
| Priority | Credential | When it pays off |
|---|---|---|
| 1 | Cyber Essentials + Plus | Any UK public-sector or procurement-led buyer. It gives the most rarity per hour: under 1 in 1,000 micro firms hold Plus |
| 2 | IASME Cyber Assurance | UK public sector and regulated supply chains that want more than Plus |
| 3 | ISO 27001 | When an enterprise or international deal asks for it |
| 4 | SOC 2 | When a US customer asks and the contract pays for the audit |
| — | ISO 9001 | Skip, unless you bid into construction, manufacturing or defence |
| — | PCI DSS | Stay out of scope: hosted checkout plus SAQ A |
Two honest caveats. Rarity isn’t the same as value. With only 14% of micro businesses aware of Cyber Essentials, a certificate on its own won’t win over a small-business customer. It pays off when your buyer has a procurement team and a checklist. And the scope for a solo company is small. If Cyber Essentials is taking weeks, you’ve probably drawn the scope too wide.
FAQ#
How many UK companies have Cyber Essentials? 46,245 certificates were issued in the year to June 2026, and 15,185 of those organisations also achieved Cyber Essentials Plus (DSIT). That’s about 0.8% of UK private-sector businesses.
What percentage of small businesses have Cyber Essentials? 7.4% of small businesses (10–49 staff) and 1.4% of micro businesses (1–9 staff) hold it. Among firms with 0–9 staff it’s at most 0.3%.
Is Cyber Essentials Plus rare? Yes. 15,185 certificates in a year, about 1 in 375 UK businesses and at most about 1 in 1,190 firms with fewer than ten staff.
How many UK companies are ISO 27001 certified? 4,455 accredited certificates according to the ISO Survey 2024. That’s fourth in the world, and about 3.4× rarer than Cyber Essentials Plus.
Is Cyber Essentials the same as ISO 27001? No. Cyber Essentials checks five technical controls: firewalls, secure configuration, user access control, malware protection and patching. ISO 27001 certifies a whole information security management system, with risk assessment, policies, internal audits and annual surveillance audits over a three-year cycle.
Can a sole trader or one-person company get Cyber Essentials? Yes. The scheme covers organisations of any size, and IASME Cyber Assurance now has a tailored standard for one- and two-person businesses with just 20 requirements.
How many companies have SOC 2? No public count exists. SOC 2 reports are private attestations by US CPA firms, so any published total is an estimate.
Is the “61,430 Cyber Essentials certificates” figure correct? No. It adds Plus certificates on top of standard certificates, but every Plus holder is already counted in the standard figure.
Methodology and caveats#
- All counts are certificates, not unique organisations. Large organisations sometimes hold several.
- Business population: 5,690,265 UK private-sector businesses at the start of 2025, of which 4,272,535 had no employees and 1,150,875 had 1–9 (DBT Business Population Estimates 2025). “No employees” includes companies whose only employee is a working proprietor.
- Cyber Essentials certificates also go to charities and public bodies. Dividing by the private-sector population slightly overstates uptake, so the odds above lean generous.
- Why the Cyber Security Breaches Survey says 5% hold Cyber Essentials: that survey excludes businesses without employees and relies on self-report. Against the 1.42 million employer businesses, the official 46,245 certificates work out to 3.3%, which is broadly consistent.
- The ISO figures are accredited certificates only. Non-accredited certificates exist but aren’t counted, and are worth less to buyers.
- No official source splits any credential by one-person companies. Figures for one-person firms are ceilings or clearly labelled estimates.
- Sector data for Cyber Essentials (IT 12%) comes from 2023 and is the latest published.
Sources#
- DSIT – Cyber Essentials management information (April–June 2026 dataset)
- Cyber Essentials Scheme Impact Evaluation, July 2024 (PDF)
- Cyber Security Breaches Survey 2025/2026
- Business population estimates for the UK and regions 2025
- ISO Survey 2024 infographic
- Parola – ISO Survey 2018–2024 and methodology notes (PDF)
- CyberSmart – Cyber Essentials statistics
- Infosecurity Magazine – the double-counted 61,430 figure
- soc2auditors.org – SOC 2 cost estimates
- Visa Global Registry of Service Providers
- Verizon Payment Security Report
- IASME – Cyber Assurance updates and milestones in 2025
- UK Cyber Security Group – Cyber Essentials as a prerequisite for IASME Cyber Assurance
About the author: I build and run RODMENA, a one-person London software company making infrastructure services: authorisation, approvals, workflows, ledgers, secrets and more. I wrote this because I needed the numbers myself. If you spot an error, tell me and I’ll correct it.