Skip to content
Ministry of Defence, Defence Cyber Certification

Defence Cyber Certification Explained: What the New Standard Means for You

Cyber threats are accelerating, and the UK defence sector is responding decisively. If you are a supplier to the Ministry of Defence (MoD), or planning to become one, the new Defence Cyber Certification (DCC) scheme is something you’ll need to understand sooner rather than later. 

At first glance, DCC can feel like yet another compliance hurdle. But it’s more than that.  It represents a fundamental shift in how cyber security is assessed across the defence supply chain, moving away from self-attestation and towards independently assured cyber resilience.  

At C3IA, we help organisations make sense of this change, understand what’s really required, and approach certification with confidence rather than uncertainty. 

Securing the Defence Supply Chain: A New Cyber Security Model  

On 3 December 2025, the MoD Chief Information Security Officer, Eleanor Fairford wrote to all defence suppliers with a clear message: the cyber threat landscape has changed, and the way we manage cyber risk needs to change with it.  

Her letter highlighted several important realities: 

  • Cyber threats have continued to worsen steadily over the past five years. 
  • High-profile cyber attacks on major UK organisations have dominated the headlines this year, reminding us that no organisation is too large – or too small – to be targeted. 
  • UK Defence continues to carry unacceptable levels of cyber risk. 
  • The defence supply chain remains a priority target for adversaries, making robust cyber security more critical than ever. 

In response, the MoD has introduced a new standard: the Cyber Security Model version 4 (CSMv4). Compliance with this model is demonstrated through Defence Cyber Certification. 

The message from the MoD is clear. While DCC is not yet mandatory, suppliers are strongly encouraged to begin seeking certification now, starting with Level 0 as a minimum, with the expectation that higher levels may be required as business needs evolve. 

So, What is Defence Cyber Certification? 

The DCC is a comprehensive cyber security certification developed by the MoD in partnership with IASME. Its goal is straightforward: to make sure organisations across the defence supply chain are genuinely resilient to cyber attack, not just compliant on paper. 

If you’re a defence supplier, here’s how DCC works in practice, and what it means for your organisation: 

Certification as a Contract Requirement 

DCC is set to become a standard contractual requirement. Over time, defence contracts will increasingly specify a required DCC level. That level will be determined by the cyber risk of the work involved and set by individual MoD delivery teams.  

In other words, cyber security is now being treated as a core delivery risk, not an afterthought. 

Organisation-Wide Assessment 

Unlike previous approaches, DCC covers your entire organisation in a single assessment. This is a big change. In the past, suppliers often had to complete separate assessments for each contract or project, duplicating effort and creating unnecessary administrative overhead. 

With DCC, one certification can be used across multiple contracts, streamlining the process and saving time, while still providing the MoD with confidence that your organisation is genuinely resilient. 

Focus on Resilience, Not Just Protection 

DCC isn’t only about protecting sensitive information. The emphasis is on resilience: your ability to continue delivering a reliable, high-quality service even when cyber threats are elevated, or when an incident has occurred. 

It’s about asking: “Can you keep operating when things go wrong?” – not just “Can you prevent attacks?” 

Independent Assessment 

Another key change is how assurance is provided. DCC is independently assessed. Accredited Certification Bodies, such as C3IA, review evidence through a combination of remote and on-site assessment. This replaces self-attestation with independent scrutiny, giving both suppliers and buyers far great confidence in the outcome. 

Risk-Based Levels 

DCC is risk-based, with four certification levels. The level required may be specified by the MoD, or chosen by you based on the type of work you expect to bid for:  

  • Level 0: Baseline security practices. This is expected for all MoD contracts. 
  • Level 1: Good cyber hygiene, covering 101 controls. Most contracts are expected to require Level 0 or Level 1. 
  • Level 2: Enhanced security with 139 controls, typically for higher-risk or more critical contracts. 
  • Level 3: Advanced resilience with 144 controls. This level is for the most sensitive or operationally critical activities. 

Cyber Essentials and Certification Duration 

Cyber Essentials sits underneath all of this. You’ll need Cyber Essentials certification for every DCC level, with Cyber Essentials Plus required for Levels 2 and 3. 

Once achieved, DCC certification lasts three years and is supported by annual reviews to ensure cyber resilience continues to reflect how your organisation actually operates. 

Why This Change Matters 

Before DCC, defence suppliers relied on Supplier Assurance Questionnaires (SAQs) and Cyber Implementation Plans (CIPs). In reality, these approaches varied widely in quality and interpretation. This created uncertainty: buyers weren’t always confident in suppliers’ resilience, and supplier weren’t always sure they were meeting expectations. 

DCC changes that. It introduces a consistent, independently verified standard that replaces ambiguity with clarity. 

The Benefits of Certification 

Getting certified isn’t just about meeting a requirement. It can also bring real, tangible benefits to your organisation: 

  • Simplified compliance: One certification can support multiple contracts, reducing duplicated effort. 
  • Stronger positioning: Demonstrates to the MoD and prime contractors that cyber resilience is taken seriously. 
  • Future readiness:  Helps you stay ahead as defence cyber standards continue to evolve. 
  • Structured improvement: Gives you a clear framework to strengthen processes, technology and people. 

In other words, DCC isn’t just a checkbox. It’s an opportunity to embed better cyber practices across your organisation in a way that actually makes business sense. 

Why Work with C3IA? 

We are not approaching DCC from the sidelines. C3IA was one of only five organisations that worked directly with IASME and the MoD during the development of the scheme. This gives us an insider’s perspective on the intent behind the controls and what “good evidence” really looks like. 

When you work with us, you get more than compliance support: 

  • Practical guidance: Clear, actionable advice on interpreting and implementing the controls 
  • Full readiness support: Gap analysis, evidence preparation, and ongoing guidance 
  • End-to-end certification help: From Cyber Essentials through Cyber Essentials Plus and DCC 
  • Experienced partner: NCSC Assured Cyber Security Consultancy status and extensive experience with GovAssure and other high-assurance frameworks 

Most importantly, we work alongside you. Helping you navigate the process efficiently, reduce unnecessary effort and cost, and build cyber resilience that actually lasts. 

Ready to Get Started? 

DCC may not be mandatory yet, but the direction of travel is clear. Getting started now puts you in control, rather than reacting under pressure later. 

If you’d like to discuss your readiness, understand which level applies to you, or take your first steps towards certification, get in touch with us at info@c3ia.co.uk. 

Back To Top