Defence Cyber Certification for Defence Suppliers
DCC Level 0 and the Cyber Essentials it requires, for defence suppliers in the defence supply chain, from one Certification Body.
DCC Level 0 and the Cyber Essentials it requires, for defence suppliers in the defence supply chain, from one Certification Body.
Why defence suppliers need Defence Cyber Certification
If you sell goods or services into the UK defence sector, this is for you. Defence buyers increasingly expect suppliers to evidence their cyber security through Defence Cyber Certification, and individual MoD contracts are already specifying a required level. If you supply the defence sector, or want to, DCC is becoming part of the price of entry.
The four DCC levels, and where Cyber Essentials fits
Defence Cyber Certification has four levels, set by the cyber risk profile of the contract. Level 0 is the supply chain floor for very low assessed risk and has just three controls: hold Cyber Essentials covering the contract scope, process personal data in compliance with UK GDPR, and build resilience into your systems. Level 1 jumps to 101 controls, Level 2 to 139 and Level 3 to 144, so the step from Level 0 to Level 1 is far larger than the numbering suggests. Your level is assigned by the MoD delivery team through the contract's Cyber Risk Profile rather than chosen by you. Crucially, every level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. Cyber Essentials is the technical baseline for every level.
How Solusec helps
We are a Defence Cyber Certification Body appointed to assess and certify Level 0, and we are a Cyber Essentials Certification Body too, so we can certify the Cyber Essentials that Level 0 requires at the same time, with no handoffs. For Level 1 we provide scope reviews, gap analysis across the controls and evidence preparation. Level 2 and Level 3 assessments, which require Cyber Essentials Plus, we refer to a body appointed for those levels.
The defence supply chain in defence suppliers
If you supply the MoD directly or sit anywhere in a defence supply chain, Defence Cyber Certification is becoming the common language for cyber assurance in the sector, replacing a patchwork of bespoke questionnaires from individual primes. Level 0 is the supply chain floor and the MoD has asked industry partners to reach it by 31 December 2026.
What defence suppliers suppliers most often have to fix first
These are the blockers that come up repeatedly here. All three are worth checking before you start an application, because each one is a remediation project rather than a paperwork exercise.
- Bespoke prime questionnaires answered inconsistently over the years, with no single source of truth.
- Cyber Essentials allowed to lapse, which removes the foundation every DCC level sits on.
- Scope drawn around the contract rather than around the organisation, which rarely survives scrutiny.
None of these stops you certifying. All of them decide whether you certify in two weeks or two months, which is the difference that matters with the MoD's 31 December 2026 expectation in view.
Why this matters now
The Ministry of Defence has asked all industry partners to achieve DCC Level 0 by 31 December 2026. It is an ask rather than a contractual mandate: IASME, which runs the scheme, states that DCC is not currently mandatory, and holding it does not yet exempt you from the Supplier Assurance Questionnaire. The requirement that binds you contractually today is DEFCON 658 and the Cyber Security Model. Individual MoD contracts are already specifying a required DCC level, and you cannot bid above your certified level. Getting Level 0 and your Cyber Essentials in place now keeps you eligible and ahead of the rush.
What Level 0 looks like for a defence supplier
For any supplier in the MoD chain the useful first step is confirming the level assigned to your contract, because Level 0 and Level 1 are three controls and a hundred and one. After that, Level 0 is mostly the Cyber Essentials: scope it to what the contract touches, and commit to maintaining it for the contract's duration rather than certifying once.
Talk to us about DCC Level 0
Tell us your requirement and we will agree the work and the assessment route. We assess and certify DCC Level 0, and we can certify the Cyber Essentials it requires at the same time, so it is one provider with no handoffs.
Common questions
Do Defence Suppliers suppliers need Cyber Essentials for DCC?
Yes. every level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. We can certify the Cyber Essentials you need alongside your DCC Level 0.
Which DCC level does a Defence Suppliers supplier need?
It depends on the cyber risk profile assigned to the contract you are bidding for. You must be certified to that level or above. Tell us the contract and we will help you work it out.
Can you certify DCC Level 2 and 3 for Defence Suppliers?
We assess and certify Level 0, and support Level 1. Levels 2 and 3 require Cyber Essentials Plus as well and are referred to a body appointed for those levels.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Ready for Defence Cyber Certification?
DCC Level 0 and the Cyber Essentials it requires, from one Certification Body.