- Best for
- MOD suppliers & subcontractors
- Usual driver
- Prime flow-down (Cyber Security Model)
- Certification
- CE Plus / DCC
- Also relevant
- Penetration testing
How requirements flow down to you
The MOD manages supply-chain cyber risk through its Cyber Security Model: each contract is given a cyber risk profile, and suppliers must meet the controls for that profile — then flow the same requirements down to their own subcontractors. In practice that means:
- Cyber Essentials as the floor. Lower-risk contracts require Cyber Essentials; higher-risk contracts require Cyber Essentials Plus, the independently audited level. The tender or prime tells you which profile applies.
- Defence Cyber Certification (DCC). For contracts handling more sensitive information, the DCC builds on Cyber Essentials with additional controls — it's increasingly written into defence agreements.
- Flow-down is mandatory. If you subcontract, you're expected to require the same of your suppliers. Primes audit this.
- OFFICIAL-SENSITIVE data. Handling controlled information raises the bar; getting the scope and level right first time saves an expensive re-test.
Get the level right the first time
The commonest and costliest mistake is certifying at the wrong level — getting Cyber Essentials when the contract needed Plus, or vice versa. We read the actual requirement in your tender or prime's flow-down and tell you exactly what to pursue, rather than selling you the higher tier by default.
Certification and testing under one roof
You're guided by a certified IASME assessor for Cyber Essentials and CE Plus, and where a contract calls for a penetration test of a product or system, a CREST-accredited tester delivers it. One relationship from scoping to certificate to test report.
Common questions
Do I need Cyber Essentials or Cyber Essentials Plus for MOD work?
It depends on the contract's cyber risk profile. Lower-risk contracts accept Cyber Essentials; higher-risk defence contracts require the audited Cyber Essentials Plus. The tender states which — we help you read it before you invest in the wrong level.
What is the Defence Cyber Certification (DCC)?
It's a certification that builds on Cyber Essentials with extra controls for defence suppliers handling more sensitive information. It's increasingly written into MOD agreements; we advise on whether your contract needs it.
We're a subcontractor, not a prime — does this apply?
Yes. Requirements flow down the chain: primes must require the same standards of their subcontractors, and they audit it. If you handle programme data, you'll be asked to certify.
How fast can we certify if a prime sets a deadline?
Cyber Essentials can often be turned around in days; Cyber Essentials Plus needs a scheduled technical audit, so it needs more runway. Tell us the deadline and we'll be straight about what's achievable.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day