
Is your organisation ready for Defence Cyber Certification?
Logiq manages the DCC journey for organisations, from identifying the requirement to being ready for independent certification, then helping to maintain compliance over time. We help organisations in the defence supply chain establish what applies, define a workable scope, close gaps and prepare the evidence needed for certification, with ongoing support to maintain compliance as requirements evolve.
DCC – The requirement for all defence suppliers
The Ministry of Defence has asked all Defence industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026. That baseline includes Cyber Essentials for all applicable business-critical systems within the DCC scope.
Level 0 is the common starting point requested across industry. It does not replace the risk-based requirements of individual contracts. The MOD or relevant prime contractor may assign Level 1, Level 2 or Level 3 where the Cyber Risk Profile requires it.
Every DCC level is independently assessed. The certification applies to the supplier organisation and the essential functions and services within its defined boundary. Even where the control count is small, readiness depends on a defensible scope, current Cyber Essentials coverage and evidence that the stated controls operate in practice.



Certification is the endpoint. Readiness is the journey.
A Certification Body can assess the organisation once the boundary is clear, the required controls are operating and the supporting evidence is ready for review. Reaching that position can involve cyber assurance, governance, architecture, operational change, technical remediation, supplier management and clear ownership across the organisation.
Managed DCC Readiness from Logiq brings that work into one coordinated journey, from the first assessment through to independent certification and ongoing assurance.
DCC
A structured route to certification
Four connected stages. Clear ownership. Evidence that stands up to independent assessment.
1
Understand
Work out what applies before trying to solve it. Logiq helps interpret the requirement received from the MOD or a prime contractor, document the proposed certification boundary, review Cyber Essentials or Cyber Essentials Plus coverage and establish the organisation’s starting position.
- DCC scoping and dependency review
- NCSC-assured Cyber Advisor support for the Cyber Essentials baseline
- Readiness and gap assessment against the applicable DCC level
2
Prepare
Close the gaps and build the evidence. Identified issues are converted into a prioritised remediation plan with clear owners, realistic timescales and evidence requirements. Support can cover security governance, risk management, supply chain, training, architecture and technical controls.
- Advisory wrap and owned remediation planning
- Control mapping, evidence preparation and readiness tracking
- DISX Secure Collaboration where a controlled environment supports relevant technical requirements, personnel assurance, information assurance, and supplier assurance
3
Certify
Hand over to independent assessment at the right point. Logiq reviews the control and evidence position, helps resolve remaining readiness issues and coordinates a clear route into assessment with an IASME-assured Certification Body.
- Evidence mapping and pre-assessment readiness review
- Certification Body and partner coordination
- Clear separation between Logiq’s readiness role and the assessor’s certification decision
4
Maintain
Keep assurance alive after the certificate. Controls, services and evidence change over time. Logiq can support operational assurance, evidence maintenance, annual Cyber Essentials or Cyber Essentials Plus renewal, annual DCC attestation and preparation for full recertification.
- Ongoing operational assurance and evidence maintenance
- Periodic readiness reviews following material change
- Preparation for annual attestation and three-year DCC recertification
What Managed DCC Readiness can deliver
Keep assurance alive after the certificate. Controls, services and evidence change over time. Logiq can support operational assurance, evidence maintenance, annual Cyber Essentials or Cyber Essentials Plus renewal, annual DCC attestation and preparation for full recertification.
- A clear view of the applicable level, proposed boundary and critical dependencies
- A documented readiness baseline and gap register
- A prioritised remediation plan with actions, owners and timescales
- Control-to-evidence mapping and an organised evidence set
- A readiness review before engaging in formal assessment
- A coordinated hand-off to an independent Certification Body
- An ongoing assurance and evidence-maintenance plan


Where does DISX fit in?
DISX provides DCC controls and evidence
DISX Secure Collaboration can support relevant DCC controls where an organisation needs Microsoft 365 collaboration, managed endpoints, identity and access management, security configuration, monitoring, audit-ready logging, patching, vulnerability management and operational governance within a controlled service boundary.
DCC certification covers the supplier organisation as a whole. DISX can support relevant technical requirements, but the wider systems, services and processes within scope must also be assessed, remediated and evidenced. Logiq helps organisations understand where DISX contributes and what else is required on the route to certification.
INDEPENDENT CERTIFICATION Logiq does not award DCC certification. Assessment and certification are delivered by an IASME-assured Certification Body. Our role is to help you reach that point with a defensible scope, implemented controls and evidence that stands up to review.
Contact Us
Talk to us about DCC readiness.
If your organisation needs to define scope, close gaps, organise evidence or coordinate multiple remediation workstreams before formal assessment, get in touch with our team of defence cyber experts.
