What does Defence Cyber Certification require?

Establishing the requirement, applicable level and scope.

What DCC Requires

Looking at the journey from understanding a DCC requirement to being ready for independent certification


Defence Cyber Certification has created a deceptively simple question for suppliers: what do we actually have to do? The answer starts with the Cyber Security Model and Defence Standard 05-138 Issue 4. Assessment bookings and new policy documents come later.

DCC provides independent assurance that an organisation meets the controls associated with a defined Cyber Risk Profile. It is an organisation-level certification, designed to give UK Defence confidence in the resilience of the supplier as a whole. That scope is wider than the network used for a single contract and wider than the handling of MOD-identifiable information alone.

For suppliers, this changes the shape of the work. DCC reaches into governance, risk, people, technology, physical security, supply-chain management, incident response and business continuity. Cyber teams will carry a significant share of the activity, but they cannot complete it alone.

The requirement begins with the level

DCC has four levels. Each corresponds to the degree of cyber risk associated with the supplier’s role in the defence supply chain. The applicable level for a contract is decided by MOD or the Prime, using the Cyber Security Model. It is not set by the supplier’s own internal risk assessment.

DCC levelTypical risk profileControlsPrerequisite
Level 0Very low / Basic3Cyber Essentials
Level 1Low to moderate / Foundational101Cyber Essentials
Level 2High / Advanced139Cyber Essentials Plus
Level 3Substantial / Expert144Cyber Essentials Plus

Source: IASME DCC scheme information and Def Stan 05-138 Issue 4.

A supplier working across several MOD contracts should plan around the highest applicable level. Current MOD guidance confirms that certification at a higher level satisfies the control requirement for lower levels. The reverse does not apply. Level 0 may establish a baseline, but it will not satisfy a contract that requires Level 1, 2 or 3.

MOD asked all industry partners to achieve DCC Level 0 by 31 December 2026, including Cyber Essentials for the applicable business-critical systems within scope. IASME’s current scheme FAQ still describes DCC as not mandatory in every case. These statements can sit together: Level 0 is the direction of travel for the defence industrial base, while the enforceable requirement for an individual supplier depends on the procurement or contract.

The scope is organisation-wide

The most common early mistake is to treat DCC as certification of the system used to deliver one MOD contract. The current scope is built around the organisation’s business-critical operations. It should include the activities, systems, assets, processes and dependencies whose loss or compromise would have a material effect on the supplier’s ability to operate securely and resiliently.

That may include corporate IT, identity services, finance and payroll platforms, operational technology, physical premises, outsourced IT, cloud services and other third parties. A service does not fall outside the assessment simply because another company runs it. Where an essential control depends on a managed service provider or cloud platform, the supplier still needs to show how the control is met and may need supporting evidence from that provider.

The DCC scope must also align adequately with the organisation’s Cyber Essentials or Cyber Essentials Plus scope. Every internet-connected device or network within the DCC scope must be covered in line with the Cyber Essentials scheme rules. IASME recommends discussing DCC scope with the chosen Certification Body early, before a full submission is prepared.

The controls need to be documented, implemented and evidenced

Defence Standard 05-138 is explicit: every applicable control needs a documented and implemented control with auditable evidence. A written policy can establish intent and responsibility. The assessment also needs to establish that the control operates across the agreed scope.

The control set is organised around four broad objectives: managing security risk, protecting against cyber attack, detecting cyber security events and minimising the impact of incidents. At the higher levels, the detail is substantial. It covers board direction, risk management, assets, suppliers, physical access, identity and access management, data security, secure configuration, vulnerability management, security monitoring, incident response, recovery and the testing of those arrangements.

Existing certifications and frameworks can contribute useful evidence. ISO 27001, Cyber Essentials, NIST-aligned controls and other assurance work may shorten the journey. They do not automatically establish DCC compliance, because the organisation still has to answer the DCC controls within the agreed scope and provide evidence that satisfies the assessment.

DCC does not replace every contract requirement

A valid DCC certificate at the appropriate level can be submitted as assured evidence that the corresponding Def Stan 05-138 controls have been met under DEFCON 658. Current MOD guidance also says that suppliers must still complete the full Supplier Assurance Questionnaire through the Supplier Cyber Protection Service where required.

DCC is also separate from additional requirements for classified information, specific systems, operational technology and Secure by Design. Those obligations may appear in procurement notices, other Defence Standards, DEFCONs or a Security Aspects Letter. Readiness therefore begins with the complete contractual picture, rather than the DCC certificate in isolation.

A useful first answer

A supplier should be able to state its assigned or target level, explain its proposed scope, identify the applicable controls, confirm the Cyber Essentials prerequisite and describe how compliance will be evidenced. If those answers are still uncertain, the organisation is at the start of its DCC journey. That is precisely where a structured readiness assessment adds value.

Next: Prepare
How to find and close your DCC readiness gaps


How Logiq can help

Logiq’s Managed DCC Readiness service takes suppliers from the first interpretation of their requirement through scope definition, gap assessment, remediation planning, evidence preparation and readiness review. Where technical or operational controls need to change, Logiq can help design, implement and manage the work. Independent certification remains with an authorised DCC Certification Body.

Where Cyber Essentials readiness forms part of the route, Logiq can draw on its NCSC Cyber Advisor service to help identify and address the technical measures required before certification.


Subscribe to stay updated

Stay up to date with the latest articles, guidance, expert insight, and more.

Follow us