Defence Cyber Certification is becoming central to how suppliers demonstrate cyber resilience when competing for and delivering UK Defence contracts. The Ministry of Defence has asked all Defence industry partners to achieve DCC Level 0 by 31 December 2026, placing a clear supply-chain deadline behind a scheme that was previously easier to view as optional preparation.
This guide explains what DCC is, why it was introduced, how it relates to CSMv4, Defence Standard 05-138 Issue 4 and DEFCON 658, what the four levels mean, how scope and evidence are assessed, and where technology such as DISX can contribute to the technical foundation behind certification.
Current position: August 2026 The MOD has asked all Defence industry partners to achieve DCC Level 0 by 31 December 2026. This includes Cyber Essentials for all applicable business-critical systems within scope. IASME’s public FAQ still states that DCC is not currently mandatory, so the deadline is not yet a universal contractual requirement. Suppliers should nevertheless treat 31 December 2026 as the operational deadline for establishing the Level 0 baseline. Higher levels continue to be determined by the Cyber Risk Profile of each contract.
What is Defence Cyber Certification?
Defence Cyber Certification (DCC) is an organisation-wide cyber security certification framework developed by the Ministry of Defence with IASME. It provides independent assurance that a supplier has implemented the controls required by Defence Standard 05-138 Issue 4 at the level for which it is certified.
The certification applies to a defined organisational scope rather than to a single MOD contract, project or technology platform. A valid certificate can therefore be presented in support of multiple UK Defence procurements up to the certified level. A higher-level certificate can also be accepted as evidence for the corresponding lower levels.
DCC is independently assessed at every level. Applicants explain how each applicable control is met, provide supporting evidence and demonstrate that the control operates in practice. Assessments are delivered through IASME-assured DCC Certification Bodies, with annual attestation and full recertification every three years.
Why DCC was introduced
DCC sits within a wider change in the way the MOD assesses cyber risk across its supply chain. The previous Cyber Security Model concentrated heavily on protecting electronic MOD Identifiable Information. CSMv4 broadens the focus to the security and resilience of the supplier organisation itself.
Defence Standard 05-138 Issue 4 describes the scope as the supplier’s overarching corporate or enterprise environment. It covers the organisations, systems, processes, procedures and data needed to protect essential functions and continue delivering contracted outputs. This moves cyber assurance beyond the security of a particular dataset or collaboration service and towards the resilience of the business that Defence depends upon.
The Supplier Assurance Questionnaire remains part of the procurement process, but it is a supplier self-assessment. DCC adds independent assessment and reusable evidence. The result is a stronger assurance mechanism that can be maintained at organisation level rather than reconstructed separately for every tender.
How DCC fits with CSMv4, Def Stan 05-138 and DEFCON 658
CSMv4 and Defence Standard 05-138 Issue 4 are closely connected, but they are not interchangeable terms. CSMv4 is the overall risk and procurement model. Def Stan 05-138 Issue 4 is the control standard used by that model. DEFCON 658 creates the contractual obligations, while DCC provides independently assessed evidence against the control level.
| Mechanism | Role within Defence cyber assurance |
| CSMv4 | The MOD’s overall risk-based process for building cyber security into Defence procurement and the supply chain. It assigns a Cyber Risk Profile from Level 0 to Level 3 and governs the Risk Assessment, Supplier Assurance Questionnaire, remediation and flow-down process. |
| Defence Standard 05-138 Issue 4 | The control standard used by CSMv4. It defines the Cyber Risk Profiles and the minimum cyber security controls a supplier must implement at each level. |
| DEFCON 658 | The contractual condition that applies the Cyber Security Model requirements to MOD contracts and requires relevant obligations to flow through subcontracting tiers. |
| DCC | The independent certification that can be submitted as assured evidence that the corresponding Def Stan 05-138 control level has been satisfied. |
How DCC fits into the procurement process
For a new or existing MOD activity, the contracting authority assigns a Cyber Risk Profile and provides a Risk Assessment Reference. The profile identifies the Def Stan 05-138 control level relevant to the work. A supplier bidding for the opportunity completes the corresponding Supplier Assurance Questionnaire through the Supplier Cyber Protection Service.
A current DCC certificate at an equal or higher level can be submitted as assured evidence that the corresponding control requirements have been met. MOD guidance instructs buyers to accept valid certification in satisfaction of those control requirements. At present, suppliers must still complete the full Supplier Assurance Questionnaire because DCC has not yet been fully incorporated into the online procurement tooling.
Where a supplier cannot demonstrate compliance, it must submit a Cyber Improvement Plan. The plan sets out the gaps, the remediation activity and the timescales for reaching the required level. The contracting authority considers the supplier’s compliance position or proposed improvement plan during selection, and an agreed plan can become part of the contract.
The same model flows through the supply chain. Prime contractors assign appropriate Cyber Risk Profiles to subcontracted activities and pass the resulting requirements onwards. A supplier may therefore encounter DCC and CSMv4 requirements through a prime contractor even where it does not contract directly with the MOD.
The 31 December 2026 deadline
The MOD’s Director of Cyber Defence and Risk, Eleanor Fairford, has asked all Defence industry partners to achieve DCC Level 0 by 31 December 2026. The instruction includes obtaining Cyber Essentials for all applicable business-critical systems within the DCC scope.
IASME continues to state that DCC is not currently mandatory as a universal requirement. The MOD’s instruction nevertheless establishes a clear operational baseline for the supply chain. Suppliers that wait for a tender or contract condition to create urgency may find that scoping, Cyber Essentials coverage, evidence gathering and remediation cannot be completed within a procurement timetable.
Level 0 is the common baseline requested across industry. It does not replace the risk-based model: Level 1, Level 2 or Level 3 may still be required where the MOD or a prime contractor assigns a higher Cyber Risk Profile to the contracted activity.
What are the four DCC levels?
Each DCC level corresponds to the cyber risk associated with a supplier’s role and contracted activity. Organisations can apply directly for any level and do not need to work through the levels sequentially. The customer decides the level required for a contract, while the applicant decides whether to seek that level proactively before a specific procurement.
| DCC level | Typical assessed risk | Def Stan controls | Cyber Essentials requirement |
| Level 0 – Basic | Very low | 3 controls | Cyber Essentials |
| Level 1 – Foundational | Low to moderate | 101 controls | Cyber Essentials |
| Level 2 – Advanced | High | 139 controls | Cyber Essentials Plus |
| Level 3 – Expert | Substantial | 144 controls | Cyber Essentials Plus |
The number of controls changes between levels, while the organisational scope remains consistent. Essential functions and services do not become less important at a lower level; the level changes the depth and breadth of the controls assessed. A certificate at a higher level is accepted as satisfaction of the lower control levels.
How the DCC assessment works
The process begins by defining the applicant, the certification boundary and the essential functions and services that must remain secure and resilient. The applicant then selects an assured Certification Body, confirms the required Cyber Essentials or Cyber Essentials Plus prerequisite and prepares its responses and evidence against the relevant DCC questions.
IASME describes two scoring phases. The theoretical phase allows the applicant to explain how controls are implemented and submit evidence for review. The practical phase verifies that the controls operate as described and are sufficient to meet the standard. No DCC level is a self-assessment, including Level 0.
Once certified, the organisation must maintain the controls and the defined scope, renew Cyber Essentials or Cyber Essentials Plus annually, complete an annual DCC attestation and recertify to DCC every three years. Significant changes to the organisation or certification scope should be reviewed with the Certification Body.
What does DCC Level 0 mean?
Level 0 is the foundation of the DCC framework. It applies where the assessed cyber risk is very low and covers three Def Stan 05-138 controls alongside valid Cyber Essentials certification. The small control count can make Level 0 appear straightforward, but the certification still applies across an organisation-wide scope and requires independent assessment.
The scope must include the functions and services essential for the organisation to operate securely and resiliently, whether they support MOD or non-MOD work. Internet-connected devices, networks and cloud services within the DCC scope must be covered appropriately by Cyber Essentials. The DCC Assessor reviews the relationship between both scopes and can challenge exclusions that leave essential services outside the assurance boundary.
For many suppliers, the main Level 0 task is therefore establishing a defensible boundary and proving that the Cyber Essentials scope covers the systems on which the business depends. Organisations also need clear ownership of third-party services and evidence that externally delivered controls are being managed effectively.
DCC scope: what needs to be included?
DCC is designed around essential organisational functions and services. This may include corporate IT, identity services, endpoints, connectivity, cloud platforms, security operations, business continuity arrangements and other systems or processes whose failure would prevent the organisation from operating securely or delivering its outputs.
The certification boundary can be defined around an appropriate legal entity or clearly described part of a wider group, provided the scope is coherent and the dependencies are understood. The scope remains the same across DCC Levels 0 to 3. Organisations cannot narrow the boundary simply because they are seeking a lower certification level.
Services delivered by a parent company, managed service provider, cloud provider or other third party still need to be addressed. The applicant remains accountable for demonstrating that the relevant control is met and may need evidence from the provider. Operational technology must also be considered where it is essential to the organisation, with appropriate compensating controls where standard IT measures cannot be applied directly.
What evidence does DCC require?
Def Stan 05-138 requires controls to be documented, implemented and supported by auditable evidence. Policies form part of that picture, but assessors also need evidence that the stated arrangements operate in practice. The evidence required depends on the level and control, and may include asset and service inventories, technical configuration records, identity and access records, patching and vulnerability information, monitoring outputs, incident records, continuity testing and supplier oversight.
Evidence should be attributable to the defined scope, current enough to reflect the operating environment and clear about who owns each control. Where evidence sits with a third party, the supplier needs a reliable route to obtain it. This is one reason why DCC preparation often exposes commercial and operational dependencies that were not visible through policy review alone.
Why a standalone cloud service cannot satisfy the full DCC scope
Cloud services can play an important role in a DCC-certified environment. Where a cloud service is essential to the organisation, it forms part of the DCC scope and may implement and evidence relevant controls through its platform, configuration and operating model.
The certification applies to the supplier organisation. A standalone SaaS collaboration service can evidence the security capabilities and configurations within that application, but it cannot demonstrate the security of the organisation’s end-user devices, identities, access arrangements, operating system configuration, security updates, malware protection, wider monitoring, incident processes or other essential services outside the application.
A cloud service can therefore cover part of the technical scope. The supplier remains responsible for the organisation-wide control environment and for demonstrating how the platform connects to the devices, identities, processes and third-party services around it.
What should Defence suppliers do now?
Preparation should begin before a live procurement creates a compressed deadline. The following steps provide a practical starting point:
- Confirm the legal entity and certification boundary, including the functions and services essential to secure and resilient operation.
- Review current and anticipated Defence work to understand the Cyber Risk Profiles that the MOD or prime contractors are likely to assign.
- Check the status and scope of Cyber Essentials or Cyber Essentials Plus, ensuring that applicable business-critical systems and end-user devices are covered.
- Map existing governance, technical controls and operational processes to the relevant Def Stan 05-138 requirements and identify missing or weak evidence.
- Review dependencies on cloud providers, managed service providers, parent companies and other third parties, including how evidence will be obtained.
- Create a proportionate remediation plan with named owners, realistic timescales and clear priorities. Where a Cyber Improvement Plan is needed for a procurement, it must be credible and contract-ready.
- Engage an assured DCC Certification Body early enough to validate the proposed scope and plan the assessment before the 31 December 2026 deadline.
How we can help
Logiq helps organisations interpret DCC and CSMv4 requirements, define a workable scope, map Def Stan 05-138 controls to existing evidence and identify the remediation needed before assessment or tender submission. This can include reviewing Cyber Essentials alignment, technical control coverage, third-party dependencies and the operational evidence behind the stated security position.
DISX Secure Collaboration can provide a controlled technical foundation for organisations that need Microsoft 365 collaboration together with managed endpoints, identity and access management, security configuration, monitoring, audit-ready logging, patching, vulnerability management and operational governance. This brings more of the collaboration environment and its supporting controls into a defined, evidence-friendly operating model.
DCC remains an organisation-level certification, so systems, services and processes outside the DISX environment must also be addressed. Logiq can help establish the wider readiness picture and show where DISX supports the technical scope without presenting the platform itself as a substitute for certification.
If DCC Level 0 is on your roadmap, or a forthcoming procurement is exposing questions about scope, controls or evidence, speak to Logiq about the practical steps required to prepare.
Frequently asked questions
Is DCC the same as CSMv4?
No. CSMv4 is the MOD’s overall risk-based cyber assurance and procurement model. Defence Standard 05-138 Issue 4 contains the control requirements used by that model. DCC is the independent certification used to evidence compliance with the corresponding control level.
Is DCC mandatory?
DCC is not yet universally mandatory according to IASME’s public FAQ. The MOD has asked all Defence industry partners to achieve Level 0 by 31 December 2026, and current MOD guidance says suppliers should expect increasing requirements to hold valid DCC certification through tender and contract conditions. The level required for a specific opportunity is determined by its Cyber Risk Profile and procurement terms.
Who needs DCC Level 0 by 31 December 2026?
The MOD has asked all Defence industry partners to achieve Level 0 by that date. The instruction includes Cyber Essentials for all applicable business-critical systems within the certification scope.
Does DCC replace the Supplier Assurance Questionnaire?
No. A valid DCC certificate can be submitted as assured evidence of the corresponding Def Stan 05-138 controls, but current GOV.UK guidance requires suppliers to complete the full Supplier Assurance Questionnaire through the Supplier Cyber Protection Service.
Can a supplier bid without DCC?
The current CSMv4 process allows a supplier that cannot demonstrate compliance to submit a Cyber Improvement Plan. The contracting authority considers that plan during supplier selection and may incorporate an agreed plan into the contract. A tender may also specify valid DCC certification as a condition, so suppliers must follow the requirements of the individual procurement.
Can a secure cloud collaboration service deliver DCC compliance?
A cloud service can support specific controls and provide useful evidence within its service boundary. DCC certifies the supplier organisation and covers its essential functions and services, so endpoints, identities, operational processes and other in-scope systems must also be protected and evidenced.
Who decides which DCC level is required?
The MOD or the relevant prime contractor determines the required level according to the Cyber Risk Profile of the contracted activity. An organisation can choose to certify proactively at any level, but it cannot choose a lower level for a contract that requires a higher one.
Do organisations have to complete the DCC levels in order?
No. Applicants can seek certification directly at any level. A valid higher-level certificate is accepted as evidence for the corresponding lower control levels.
How long does DCC certification last?
DCC certification is valid for three years, supported by annual attestation. Organisations must also maintain annual Cyber Essentials or Cyber Essentials Plus certification, depending on the DCC level held.
Sources:
- MOD Digital and Data: One Year of Defence Cyber Certification: Building Stronger Cyber Resilience Together
- MOD Digital and Data: Building cyber resilience in the UK one step at a time
- GOV.UK: Cyber Security Model
- GOV.UK: ISN 2026/02 – Use of DCC as assurance of control requirements under DEFCON 658
- GOV.UK: Defence Standard 05-138 Issue 4
- IASME: Defence Cyber Certification, Frequently Asked Questions and Help and Resources
Related Links:






