Defence Cyber Certification in Plymouth

DCC Level 0 assessment and certification for defence suppliers in Plymouth, with the Cyber Essentials it requires, from one Certification Body.

DCC Level 0 assessment and certification for defence suppliers in Plymouth, with the Cyber Essentials it requires, from one Certification Body.

Defence Cyber Certification for Plymouth suppliers

Plymouth's naval base and its supply chain make cyber assurance a growing requirement locally. If you supply, or want to supply, the UK defence sector from Plymouth, Defence Cyber Certification is becoming essential: it is the MoD-backed scheme, delivered by IASME under Defence Standard 05-138, that evidences your cyber security to defence buyers. We help Plymouth businesses get certified without the usual runaround, working remotely first so location is no barrier.

The four DCC levels, and where Cyber Essentials fits

Defence Cyber Certification has four levels, set by the cyber risk profile of the contract. Level 0 is the supply chain floor for very low assessed risk and has just three controls: hold Cyber Essentials covering the contract scope, process personal data in compliance with UK GDPR, and build resilience into your systems. Level 1 jumps to 101 controls, Level 2 to 139 and Level 3 to 144, so the step from Level 0 to Level 1 is far larger than the numbering suggests. Your level is assigned by the MoD delivery team through the contract's Cyber Risk Profile rather than chosen by you. Crucially, every level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. Cyber Essentials is the technical baseline for every level.

How Solusec helps

We are a Defence Cyber Certification Body appointed to assess and certify Level 0, and we are a Cyber Essentials Certification Body too, so we can certify the Cyber Essentials that Level 0 requires at the same time, with no handoffs. For Level 1 we provide scope reviews, gap analysis across the controls and evidence preparation. Level 2 and Level 3 assessments, which require Cyber Essentials Plus, we refer to a body appointed for those levels.

The defence supply chain in Plymouth

Plymouth's defence economy runs on the naval base and the dockyard, and on the marine engineering, refit and support businesses around them. A great deal of that work is physical rather than digital, which is precisely why cyber requirements catch firms off guard: a company that has supplied the dockyard for thirty years may have no IT policy of any kind when the requirement arrives.

What Plymouth suppliers most often have to fix first

These are the blockers that come up repeatedly here. All three are worth checking before you start an application, because each one is a remediation project rather than a paperwork exercise.

  • Ruggedised or site laptops that go weeks without connecting to a network and therefore without patching.
  • Older marine and industrial control systems that cannot be patched and need to be segregated or scoped out with a defensible argument.
  • Office estates where every user is a local administrator because that is how they were built.

None of these stops you certifying. All of them decide whether you certify in two weeks or two months, which is the difference that matters with the MoD's 31 December 2026 expectation in view.

Why this matters now

The Ministry of Defence has asked all industry partners to achieve DCC Level 0 by 31 December 2026. It is an ask rather than a contractual mandate: IASME, which runs the scheme, states that DCC is not currently mandatory, and holding it does not yet exempt you from the Supplier Assurance Questionnaire. The requirement that binds you contractually today is DEFCON 658 and the Cyber Security Model. Individual MoD contracts are already specifying a required DCC level, and you cannot bid above your certified level. Getting Level 0 and your Cyber Essentials in place now keeps you eligible and ahead of the rush.

What Level 0 looks like for a Plymouth supplier

For Plymouth's dockyard and marine support suppliers the resilience control (2500) is the one worth thinking about properly rather than skating over. A great deal of the work is physical, and the systems that matter are the ones that schedule, track and certify it. Being able to say which of those you could not operate without, and what happens if one fails, is the substance of that control.

Talk to us about DCC Level 0

Tell us your requirement and we will agree the work and the assessment route. We assess and certify DCC Level 0, and we can certify the Cyber Essentials it requires at the same time, so it is one provider with no handoffs.

Your details are handled by a real person, never fed into AI.

Common questions

Do Plymouth suppliers need Cyber Essentials for DCC?

Yes. every level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. We can certify the Cyber Essentials you need alongside your DCC Level 0.

Which DCC level does a Plymouth supplier need?

It depends on the cyber risk profile assigned to the contract you are bidding for. You must be certified to that level or above. Tell us the contract and we will help you work it out.

Can you certify DCC Level 2 and 3 for Plymouth?

We assess and certify Level 0, and support Level 1. Levels 2 and 3 require Cyber Essentials Plus as well and are referred to a body appointed for those levels.

Related

Ready for Defence Cyber Certification?

DCC Level 0 and the Cyber Essentials it requires, from one Certification Body.