Cyber Security for the Defence Supply Chain

Stay on the programme. Defence primes flow cyber requirements down their supply chains — Cyber Essentials, often CE Plus, and the Defence Cyber Certification — and no certificate can mean no purchase order.

Best for
MOD suppliers & subcontractors
Usual driver
Prime flow-down (Cyber Security Model)
Certification
CE Plus / DCC
Also relevant
Penetration testing

How requirements flow down to you

The MOD manages supply-chain cyber risk through its Cyber Security Model: each contract is given a cyber risk profile, and suppliers must meet the controls for that profile — then flow the same requirements down to their own subcontractors. In practice that means:

  • Cyber Essentials as the floor. Lower-risk contracts require Cyber Essentials; higher-risk contracts require Cyber Essentials Plus, the independently audited level. The tender or prime tells you which profile applies.
  • Defence Cyber Certification (DCC). For contracts handling more sensitive information, the DCC builds on Cyber Essentials with additional controls — it's increasingly written into defence agreements.
  • Flow-down is mandatory. If you subcontract, you're expected to require the same of your suppliers. Primes audit this.
  • OFFICIAL-SENSITIVE data. Handling controlled information raises the bar; getting the scope and level right first time saves an expensive re-test.

Get the level right the first time

The commonest and costliest mistake is certifying at the wrong level — getting Cyber Essentials when the contract needed Plus, or vice versa. We read the actual requirement in your tender or prime's flow-down and tell you exactly what to pursue, rather than selling you the higher tier by default.

Certification and testing under one roof

You're guided by a certified IASME assessor for Cyber Essentials and CE Plus, and where a contract calls for a penetration test of a product or system, a CREST-accredited tester delivers it. One relationship from scoping to certificate to test report.

Common questions

Do I need Cyber Essentials or Cyber Essentials Plus for MOD work?

It depends on the contract's cyber risk profile. Lower-risk contracts accept Cyber Essentials; higher-risk defence contracts require the audited Cyber Essentials Plus. The tender states which — we help you read it before you invest in the wrong level.

What is the Defence Cyber Certification (DCC)?

It's a certification that builds on Cyber Essentials with extra controls for defence suppliers handling more sensitive information. It's increasingly written into MOD agreements; we advise on whether your contract needs it.

We're a subcontractor, not a prime — does this apply?

Yes. Requirements flow down the chain: primes must require the same standards of their subcontractors, and they audit it. If you handle programme data, you'll be asked to certify.

How fast can we certify if a prime sets a deadline?

Cyber Essentials can often be turned around in days; Cyber Essentials Plus needs a scheduled technical audit, so it needs more runway. Tell us the deadline and we'll be straight about what's achievable.

Related

Stay on the defence programme

Tell us the prime, the contract's risk profile or the flow-down clause. We'll tell you exactly which level you need and how fast it's achievable.