Cyber security is increasingly becoming part of procurement, supplier assurance and contractual requirements. For SMEs, cyber capability may affect not only resilience but access to customers, contracts and supply-chain opportunities.
Contents
- Contents
- Could Cyber Security Become a Barrier to Winning Business?
- Key Takeaways
- Larger Customers Are More Likely to Examine Supplier Security
- The Capability Gap Between Large and Small Businesses Is Real
- Cyber Essentials Is Becoming a Commercial Baseline
- Customer Questionnaires Are Evidence Requests, Not Exams
- Privileged Access Changes the Assurance Conversation
- Regulation Can Reach SMEs Indirectly Through Customers
- Manufacturing Supply Chains Make This Particularly Relevant to the West Midlands
- Security Requirements Can Affect Smaller Suppliers Disproportionately
- Cyber Maturity Can Become a Competitive Advantage
- Start with the Markets You Want to Enter
- Getting Ready Before the Questionnaire Arrives
- Cyber Is Becoming Part of the Cost of Entry to Some Markets
Could Cyber Security Become a Barrier to Winning Business?
Cyber security is increasingly becoming part of the commercial relationship between customers and suppliers. For many West Midlands SMEs, that changes the significance of security. Controls that were once considered primarily an internal matter can now affect whether a business satisfies procurement requirements, enters a supply chain or remains an acceptable supplier to a larger organisation.
This does not mean that every customer is about to impose sophisticated cyber requirements on every SME. The change is more gradual and uneven than that. Large organisations, regulated businesses and companies with significant digital dependencies are paying greater attention to the security of organisations on which they rely. Those expectations can then travel through supply chains through contracts, supplier questionnaires, certification requirements and requests for evidence about security practices.
The originating analysis, CYBERUK 2026: System Ambition vs Operational Reality and the Rise of a Two-Speed Cyber Economy, examined a wider problem: the UK is developing increasingly sophisticated cyber policy, regulation and assurance while organisational capability remains highly uneven. The commercial consequence is important for smaller businesses. When customers become more demanding faster than suppliers can improve their cyber capability, security can become a condition of market participation rather than simply a technical concern.
For West Midlands SMEs, the practical response is not to build enterprise-scale security functions. It is to understand which customers and markets are likely to expect demonstrable cyber maturity, establish a proportionate baseline and collect evidence of that capability before a commercial opportunity depends on it.
Read the wider regional analysis. The West Midlands Cyber Cluster examines the emergence of a two-speed cyber economy in which expectations are rising faster than the capability of many organisations to meet them, in the companion article “Britain’s Two-Speed Cyber Economy: The Regional Consequences”.
Key Takeaways
- Larger organisations are considerably more likely than smaller businesses to have formal cyber governance and supplier-assurance processes, creating a capability gap within supply chains.
- Only 15% of UK businesses review cyber risks associated with their immediate suppliers, but the figure rises to 48% among large businesses, making supplier assurance particularly relevant to SMEs selling into larger organisations.
- Cyber Essentials certification is becoming more common, especially among small and large businesses, and can provide a recognised baseline where customers or procurement processes require evidence of basic controls.
- SMEs should distinguish between reasonable assurance requirements and disproportionate requests, concentrating effort on the security controls relevant to the systems, information and access involved in the customer relationship.
- Preparing security evidence before a tender or customer review can turn cyber from a last-minute procurement obstacle into part of the business’s commercial readiness.
Larger Customers Are More Likely to Examine Supplier Security
The 2025/26 Cyber Security Breaches Survey shows a substantial difference between organisations of different sizes when it comes to supply-chain cyber risk.
Across all businesses, only 15% reported reviewing the cyber risks presented by immediate suppliers. Among microbusinesses the figure was 12%, rising to 22% among small businesses and 30% among medium-sized organisations.
Among large businesses, it reached 48%.
Only 6% of businesses overall reviewed cyber risks associated with their wider supply chains, so supplier assurance is far from universal. Nevertheless, the size gradient matters because SMEs seeking contracts with larger organisations are disproportionately likely to encounter customers with established cyber-security processes.
The reason is understandable.
A supplier can create several forms of dependency. It may process customer information, provide software, maintain systems remotely, host important services or hold privileged access. In manufacturing and engineering, a supplier may also be operationally important even without direct access to the customer’s network because its prolonged disruption could interrupt production.
Customers therefore have legitimate reasons to understand whether important suppliers can protect the systems, information or services on which they depend.
For an SME, the resulting assurance process may arrive as a questionnaire, a contractual schedule, a requirement for certification or questions during procurement.
The difficulty arises when the requirement appears late.
A business that discovers during a tender that it needs multi-factor authentication, documented policies, an incident-response process or Cyber Essentials certification may have little time to establish those controls properly.
Commercial preparation should therefore include understanding likely cyber requirements before the opportunity reaches procurement.
The Capability Gap Between Large and Small Businesses Is Real
Supplier assurance becomes more difficult because customers and suppliers often operate at very different levels of cyber maturity.
The 2025/26 survey found that 70% of large businesses had a formal cyber-security strategy, compared with 27% of businesses overall. Formal incident-response plans were reported by 76% of large businesses and 57% of medium-sized businesses, but only 21% of microbusinesses.
Board-level responsibility shows a similar difference. Sixty-eight per cent of large businesses had a board member or trustee responsible for cyber security, compared with 31% of businesses overall.
These differences do not necessarily mean that smaller organisations are behaving irresponsibly.
A microbusiness does not need the same governance structure as a large enterprise. It may have a much simpler technology environment, fewer employees and substantially less capacity for specialist security management.
The problem occurs when enterprise procurement processes assume that smaller suppliers should demonstrate maturity using the same organisational structures as large companies.
A requirement for proportionate technical controls may be reasonable. A demand for extensive committees, documentation and governance processes may add cost without materially reducing the risk created by a small supplier.
SMEs should therefore understand both their security position and the reason behind customer requirements.
Where a customer asks how cyber risk is governed, a smaller business may be able to demonstrate clear director-level responsibility without maintaining a separate security committee. Where a customer wants evidence of incident preparedness, a concise and tested response plan may be more meaningful than a lengthy document produced solely for procurement.
Proportionate assurance should establish whether the relevant risk is being managed, not whether every supplier resembles the customer organisationally.
Cyber Essentials Is Becoming a Commercial Baseline
Cyber Essentials is one of the clearest mechanisms through which cyber security can become part of procurement.
The scheme establishes a recognised baseline around common technical controls. It does not provide comprehensive assurance against every cyber risk, but it gives customers an independent mechanism for establishing that a supplier has addressed a defined set of basic security requirements.
Adoption increased in the 2025/26 survey.
Five per cent of businesses reported holding Cyber Essentials certification, compared with 3% in the previous year. Among small businesses, certification increased from 5% to 12%, while among large businesses it rose from 21% to 35%.
The growth among small businesses is particularly relevant.
Certification can be valuable where it is required by a customer, recognised within a procurement framework or useful in demonstrating that the organisation has established a basic technical standard.
That does not mean every SME should pursue certification solely because adoption is increasing.
A business should consider the markets it serves, the sensitivity of the information it handles and the expectations of existing and prospective customers. If target customers routinely request Cyber Essentials, obtaining it before the next procurement process is likely to be more efficient than responding repeatedly to the same requirement.
Certification should also reflect genuine implementation.
Treating Cyber Essentials purely as a badge misses much of its value. The underlying controls around secure configuration, access, malware protection, firewalls and software updates address common routes through which organisations are compromised.
For businesses that need a practical starting structure, that baseline can be useful even before procurement enters the discussion.
Customer Questionnaires Are Evidence Requests, Not Exams
Supplier-security questionnaires can be frustrating for smaller businesses.
Questions may use unfamiliar terminology, request information about processes the SME has never formalised or appear designed for organisations much larger than the supplier completing them.
The worst response is to treat the questionnaire as an exam in which every answer must sound as sophisticated as possible.
Customers are trying to understand risk. Inaccurate answers create a commercial and potentially contractual problem because the supplier may be representing that controls exist when they do not.
A better approach is to answer accurately, explain proportionate arrangements and identify where improvements are already planned.
Businesses can also prepare reusable evidence.
A current Cyber Essentials certificate, summary of security responsibilities, incident-response plan, backup approach, data-handling policy and description of multi-factor authentication can answer recurring questions without rebuilding the response for every customer.
The exact evidence required will depend on the relationship.
A supplier delivering catering services should not necessarily face the same cyber scrutiny as a managed service provider with administrator access to customer systems. A software company processing customer data creates different risks from a component supplier with no digital integration.
The most effective assurance processes reflect those differences.
SMEs can help by understanding the access and dependencies they create for the customer and being able to explain how those risks are controlled.
Privileged Access Changes the Assurance Conversation
Not all suppliers create equal cyber risk.
An organisation providing remote IT administration, cloud services or software support may possess credentials capable of accessing important customer systems. A compromise of that supplier can therefore become a route into the customer.
This is one reason managed service providers and other important digital suppliers have attracted increasing regulatory and policy attention.
For SMEs providing technology services, privileged customer access should consequently be treated as a significant business responsibility.
Strong authentication, separate administrative accounts, appropriate logging and disciplined management of customer credentials are not simply internal controls. They are part of the evidence customers may reasonably expect from a provider trusted with sensitive access.
The same principle applies to manufacturers using external engineering or maintenance suppliers.
If a third party can connect remotely to production technology, the manufacturer should understand how that access is authenticated, when it is available and what the supplier can reach.
Cyber assurance becomes most valuable when it follows actual dependency.
Rather than applying identical requirements to every supplier, customers can concentrate on relationships where compromise would create material consequences. SMEs can similarly prioritise controls around the services and access that make them important to their customers.
Regulation Can Reach SMEs Indirectly Through Customers
An SME does not need to be directly regulated for cyber-security regulation to affect it commercially.
The UK’s developing cyber-resilience regime illustrates why.
The Cyber Security and Resilience Bill broadens the regulatory approach to important digital services and supply-chain dependencies. Its direct requirements apply to defined categories of organisation rather than to every UK business.
Those regulated organisations nevertheless depend on suppliers.
Where a customer needs to demonstrate that it manages cyber risk across important dependencies, it may strengthen contractual requirements, supplier assessments or incident-notification expectations.
The practical effect can therefore extend beyond the formal regulatory perimeter.
This is common in regulated markets. Requirements imposed on a large organisation influence what that organisation expects from companies providing important products and services.
For West Midlands SMEs supplying infrastructure, health, digital services, manufacturing, defence or other security-conscious sectors, understanding the customer’s regulatory environment can therefore help anticipate future assurance requirements.
The objective is not for the SME to interpret legislation as though it were itself the regulated entity.
It is to understand which obligations are likely to influence customer behaviour.
Manufacturing Supply Chains Make This Particularly Relevant to the West Midlands
The relationship between cyber security and commercial participation has particular relevance in an industrial region.
West Midlands manufacturers and engineering businesses frequently operate within multi-tier supply chains containing organisations of very different sizes and levels of digital maturity.
Technology also connects these relationships more closely than before.
Customers and suppliers may exchange design information, access shared platforms, integrate production data or use remote engineering services. The commercial relationship can therefore include digital dependencies alongside the physical movement of products and components.
Cyber assurance is one mechanism through which customers attempt to manage those dependencies.
For smaller manufacturers, the challenge is proportionality.
A company should not divert disproportionate resources into producing documentation that has little relationship with the risk it creates. At the same time, dismissing customer security requirements as unnecessary bureaucracy can become commercially costly where competitors are better prepared to demonstrate their controls.
The strongest position is to understand the business’s actual cyber maturity and be able to evidence it efficiently.
That might include Cyber Essentials, multi-factor authentication, clear management responsibility, reliable backups, controlled remote access and a basic incident-response process.
Manufacturers with operational technology or sensitive customer information may need additional measures, but a credible baseline can address many common procurement questions.
Security Requirements Can Affect Smaller Suppliers Disproportionately
There is a legitimate risk that cyber assurance becomes a barrier rather than an enabler.
Large organisations can employ security teams, procurement specialists and compliance staff. Smaller suppliers often distribute those responsibilities among directors, operational managers and outsourced providers.
A lengthy questionnaire may therefore impose very different costs on a ten-person company and a multinational enterprise.
If every customer also uses a different assurance process, the burden multiplies.
This is one reason recognised standards and certifications can be valuable. They allow some evidence to be reused rather than requiring every buyer to establish its own version of the same baseline.
Customers also have an interest in proportionality.
Excessive requirements can exclude capable smaller suppliers, reduce competition and make supply chains more dependent on a narrower group of larger providers. Requirements that suppliers cannot realistically maintain may also produce superficial compliance rather than better security.
Good assurance should therefore be risk-based.
The question should be whether the supplier can manage the cyber risk created by the relationship, not whether it can reproduce every feature of the customer’s own security programme.
Cyber Maturity Can Become a Competitive Advantage
If cyber requirements can prevent a business from winning work, the reverse is also true.
A supplier that can demonstrate credible security may be easier for a customer to approve.
That does not mean cyber security will become the primary reason most customers choose a supplier. Price, quality, capability, service and relationships remain central commercial factors.
Security can nevertheless influence whether the supplier passes the threshold required to compete.
For businesses targeting customers with developed assurance processes, preparing early can therefore remove friction from sales.
A company that already understands its security responsibilities, has evidence available and can answer customer questions confidently presents a different risk profile from one beginning its cyber programme only after procurement asks for it.
This can be particularly valuable for smaller businesses seeking to move into more demanding markets.
Cyber capability becomes part of professionalisation: one of the organisational capabilities required to work successfully with larger or more regulated customers.
Start with the Markets You Want to Enter
SMEs deciding how much to invest in cyber assurance should begin with commercial strategy.
Which customers does the business want to serve over the next two or three years? Do those customers operate in regulated sectors? Are they likely to require Cyber Essentials? Will the company handle sensitive data, provide software or receive privileged access? Are there established security clauses in the relevant supply chain?
Those questions help distinguish immediate requirements from hypothetical ones.
A business targeting large defence or infrastructure customers may need a more developed assurance position than one selling low-risk services to other small organisations. A technology company providing managed services will have different responsibilities from a manufacturer whose digital connection with customers is limited.
This commercial lens allows cyber improvement to be sequenced.
The organisation can establish a baseline now, address likely procurement requirements next and develop specialist capability as customer relationships require it.
That is generally more efficient than waiting for every requirement to arrive through an urgent tender.
Getting Ready Before the Questionnaire Arrives
For many SMEs, commercial cyber readiness can begin with a relatively manageable set of actions.
The business should know who is responsible for cyber security, protect important accounts with multi-factor authentication, maintain supported and updated systems, restrict unnecessary administrator access and ensure important data can be recovered.
It should understand which suppliers have critical or privileged access and maintain a basic incident-response process.
Where commercially relevant, Cyber Essentials can provide a recognised technical baseline.
The organisation should also retain evidence of these arrangements so that customer assurance does not require reconstructing the security programme from scratch.
Businesses do not need to navigate this alone. The West Midlands Cyber Hub can help regional SMEs understand available support, connect with relevant expertise and identify programmes that can assist with cyber resilience and business readiness.
The objective is not compliance for its own sake. It is to ensure that a preventable cyber capability gap does not become an avoidable commercial disadvantage.
Cyber Is Becoming Part of the Cost of Entry to Some Markets
Cyber security will not become an equal barrier across every sector or customer relationship. Many SMEs will continue to operate successfully without extensive formal assurance.
The direction of travel is nevertheless clear.
As organisations become more digitally dependent, they have stronger reasons to understand the security of suppliers on which important services, systems and information depend. Regulation reinforces that behaviour in parts of the economy, while certifications and supplier assessments provide mechanisms through which expectations are passed down the supply chain.
For West Midlands SMEs, the important distinction is between being forced into enterprise-scale security and being expected to demonstrate proportionate competence.
The former would be economically inefficient. The latter is increasingly a normal feature of doing business in digitally dependent supply chains.
Companies that prepare for that change can treat cyber security as part of commercial capability rather than discovering it as a procurement obstacle.
In some markets, the question is therefore moving beyond whether a business has experienced a serious cyber incident. It is becoming whether customers can obtain enough confidence in the business’s security to trust it with the contract.