Skip to content
Defence Cyber Certification

Preparing for Defence Cyber Certification: What MoD Suppliers Need to Know Now

The new Defence Cyber Certification has officially launched. Whilst the scheme is new and evolving, there is plenty an organisation can do to prepare for this new framework. If you’re a current or aspiring defence supplier, read on to find out what steps you can be taking towards certification. 

What is the Defence Cyber Certification (DCC)? 

Developed by the Ministry of Defence (MoD) and IASME, the Defence Cyber Certification is a new, comprehensive, cyber security certification framework for UK defence suppliers. 

Designed to enhance the cyber resilience of the UK’s defence sector supply chain, the DCC focuses on the overall security of an organisation, offering a single, organisation-level assurance that can be used to support participation in UK defence procurements.  

The DCC isn’t entirely new. As before, cyber security standards for defence suppliers are founded on the principles of DEFSTAN 05-138. However, organisations will no longer demonstrate risk management through self-assessment, but through a formal certification process that is independently assessed. 

What this means for you 

While the Defence Cyber Certification is not yet mandatory for MoD suppliers and won’t affect your current contracts, it is expected to become a common requirement for suppliers engaging with the MoD. Getting ahead now means you’ll be ready to respond as soon as certification becomes necessary. 

Unlike existing assurance frameworks, the new scheme applies at the organisational level. This means that one certification can support multiple contracts; helping you streamline assurance across your MoD work and reduce duplicated effort. 

What you need to know 

The Defence Cyber Certification is designed to scale with the level of risk involved in the work you’re doing for the MoD. It’s split into four levels, from 0 to 3, with each level requiring more comprehensive controls. 

You don’t have to work through the levels in sequence. If your contracts or internal goals demand it, you can certify directly at the level that fits. 

Exactly where your organisation sits will depend on the Cyber Risk Profile assigned to your MoD contracts. The CRP reflects the level of cyber risk associated with the specific work, data, and services involved and will determine the minimum certification level required. 

Each level of the DCC includes Cyber Essentials (CE) as a baseline. Levels 2 and 3 also require Cyber Essentials Plus. If you don’t yet have CE in place, that’s the logical first step. If you’re already certified, check when it’s due for renewal – you’ll need to keep it current as part of DCC compliance. 

 

DCC Level  Controls Required  Cyber Risk Profile  Cyber Essentials Requirement 
Level 0  3 controls  Very Low  Cyber Essentials 
Level 1  101 controls  Low  Cyber Essentials 
Level 2  139 controls  Moderate  Cyber Essentials Plus 
Level 3  144 controls  High  Cyber Essentials Plus 

Once you have achieved your Defence Cyber Certification, it will be valid for three years, with a yearly attestation to confirm that your controls are still in place and Cyber Essentials is maintained. 

This isn’t a one-off exercise. It’s designed to promote long-term resilience, so building cyber assurance into your regular business operations (e.g., training, policy reviews, incident testing) will make ongoing compliance much easier. 

Your Next Steps 

Preparing for a new assurance framework can seem like a daunting challenge, but following the steps below will put you on the right path to certification. 

  1. Achieve Cyber Essentials: Ensure that your Cyber Essentials certification is up to date. If you’re aiming for DCC Levels 2 or 3, consider upgrading to Cyber Essentials Plus now to get ahead of the game 
  2. Identify where practices differ across teams or sites: Because DCC is assessed at organisation level, inconsistency is a common challenge. Policies that look good on paper often fall apart in practice when applied across multiple departments or locations. Start by reviewing where your approach to security differs internally and where it might need to be standardised 
  3. Look at evidence you could provide tomorrow: The DCC isn’t just about what’s in place – it’s about what you can prove. If you had to evidence your controls today, what could you actually show? Start with key documents like training records, access logs, incident response plans, and supplier checks. Gathering that now avoids time pressure later. 
  4. Talk to your contract managers about risk profiles: You don’t need a dedicated security team to start preparing. Contract owners or bid teams can often tell you which of your MoD contracts carry which cyber risk profiles. That knowledge helps you anticipate your likely certification level and where you’ll need to focus. 
  5. Need a hand? Contact C3IA: If you’re feeling a bit overwhelmed or just want some initial guidance, don’t hesitate to reach out. While we can only offer limited advisory support, we’re happy to help you understand the process and point you in the right direction. 

Why C3IA? 

C3IA is one of only five companies that worked with IASME and the MoD to help develop the DCC scheme. As an NCSC Assured Cyber Security Consultancy, and with extensive delivery experience of the Cabinet Office’s GovAssure scheme, we are very well placed to successfully guide you through the DCC process. We can help you assess your readiness and close the gaps so that you can conduct the certification with confidence.  

As a Cyber Essentials (CE) Certification Body, we can work with you prior to your DCC assessment to deliver this should your organisation not be CE certified already. 

Get in touch with C3IA today to begin your Defence Cyber Certification journey. 

 

c3ia.technicalservices@c3ia.co.uk

01202 721123

Back To Top