Skip to main content

Defence Cyber Certification (DCC): What You Need to Know

Defence Cyber Certification (DCC) is the Ministry of Defence's (MOD) new cybersecurity assurance scheme for organisations working directly or indirectly within the UK defence supply chain.

Developed by the MOD in collaboration with the IASME Consortium, DCC is designed to provide a consistent, organisation-wide approach to cybersecurity assurance across the defence supply chain.

If your organisation bids for, delivers, or supports MOD contracts, DCC may be a requirement for you.

What is Defence Cyber Certification?

DCC is a multi-level cybersecurity certification based on the MOD's Defence Standard 05-138 (Def Stan 05-138) requirements.

It is intended to replace the previous Cyber Security Model (CSM) approach, which required organisations to demonstrate compliance on a contract-by-contract basis.

Under DCC, certification applies to the organisation as a whole rather than being tied to an individual contract.

A DCC certification is valid for three years, subject to an annual attestation.

This provides a more consistent and streamlined way for organisations to demonstrate that they have appropriate cybersecurity controls in place.

Who needs Defence Cyber Certification?

DCC applies to organisations across the UK defence supply chain, from large defence primes through to smaller businesses and specialist suppliers.

More than 10,000 organisations are expected to be affected.

You may need DCC if your organisation:

  • Bids for MOD contracts

  • Supplies products or services to the MOD

  • Supports organisations within the MOD supply chain

  • Handles information or systems associated with MOD contracts

  • Is required to meet a specific Cyber Risk Profile (CRP) as part of a contract

The level of certification you need depends on the Cyber Risk Profile (CRP) of the contract you are pursuing.

Your contract documentation should indicate the applicable requirements.

What are the DCC certification levels?

DCC is structured across four certification levels: L0, L1, L2 and L3.

Each level introduces a different number and complexity of cybersecurity controls.

Level

Controls

Requirements

Pass mark

L0

3

Cyber Essentials + 3 additional controls

100%

L1

101

Cyber Essentials + 100 additional controls

80%

L2

139

Cyber Essentials & Cyber Essentials Plus

Subject to applicable requirements

L3

144

Cyber Essentials & Cyber Essentials Plus

Subject to applicable requirements

Level 0

L0 is the entry-level DCC certification.

It requires:

  • A valid Cyber Essentials certification

  • Three additional DCC controls

  • A 100% pass mark against the applicable controls

Level 1

L1 introduces a significantly broader set of cybersecurity requirements.

It requires:

  • A valid Cyber Essentials certification

  • 100 additional DCC controls

  • A total of 101 controls

  • An 80% pass mark

Level 2 and Level 3

L2 and L3 introduce more extensive cybersecurity requirements, with 139 and 144 controls respectively.

Both levels require Cyber Essentials and Cyber Essentials Plus.

The appropriate level will depend on the Cyber Risk Profile associated with the relevant MOD contract.

Why is Cyber Essentials important?

Cyber Essentials is a key component of the lower DCC levels.

Organisations pursuing L0 or L1 will need to hold Cyber Essentials as part of their certification requirements.

This means that businesses entering or progressing within the defence supply chain may need to consider Cyber Essentials alongside their DCC requirements.

For organisations that are not already Cyber Essentials certified, obtaining certification is therefore an important first step towards meeting the requirements of DCC L0 or L1.

How long does DCC certification last?

DCC certification is designed to provide longer-term assurance than the previous contract-by-contract CSM approach.

Certification is valid for three years, with organisations required to complete an annual attestation during that period.

This means organisations can maintain a single organisation-wide certification rather than repeatedly demonstrating compliance for individual contracts.

What does this mean for defence suppliers?

For businesses in the defence supply chain, DCC represents a shift towards a more standardised approach to cybersecurity assurance.

Rather than assessing cybersecurity requirements separately for each contract, organisations can work towards the certification level appropriate to their business and the contracts they want to pursue.

However, the level of certification required will depend on the specific Cyber Risk Profile (CRP) associated with a contract.

If you are unsure which level applies to your organisation, check the requirements of the relevant tender or speak to the organisation managing your contract.

CyberSmart and DCC

CyberSmart is working to help organisations achieve DCC by providing certification for L0 and L1. If an organisation has L2 and L3 requirements we are helping to support this option through a trusted certification partner.

If your organisation is preparing for DCC L0 or L1, Cyber Essentials will form an important part of your preparation.

We can help organisations understand their Cyber Essentials requirements and prepare for the additional controls required under DCC.

What should I do next?

If your organisation works within the UK defence supply chain, we recommend:

  1. Check your contract requirements - identify the Cyber Risk Profile (CRP) and DCC level required.

  2. Determine your current certification status - particularly whether you already hold Cyber Essentials.

  3. Identify any gaps - assess your existing cybersecurity controls against the requirements of your required DCC level.

  4. Plan your certification - allow sufficient time to address any gaps before you need to demonstrate compliance.

DCC requirements can feel complex, particularly if you're unsure which level applies to you or where to start with your preparation.

If you're stuck or have questions about DCC or Cyber Essentials, reach out to our support team. We're happy to help you understand the requirements and point you in the right direction.

Frequently Asked Questions

Is DCC replacing the Cyber Security Model (CSM)?

Yes. DCC is intended to replace the previous contract-by-contract CSM approach with an organisation-wide certification model.

Do I need Cyber Essentials for DCC?

Yes. Cyber Essentials is a mandatory component of the DCC requirements for L0 and L1.

How long is DCC certification valid?

DCC certification is valid for three years, with annual attestations required.

Which DCC level do I need?

The required level depends on the Cyber Risk Profile (CRP) of the MOD contract you are pursuing. Check your contract or tender documentation for the applicable requirement.

Can small businesses get DCC certified?

Yes. DCC is intended to apply across the defence supply chain, including smaller organisations and micro businesses.

Does CyberSmart provide all DCC levels?

CyberSmart intends to provide DCC L0 and L1 certification. L2 and L3 are not currently offered by CyberSmart and may be supported through a trusted partner.

Do I need DCC if I don't work directly for the MOD?

Potentially. DCC applies across the defence supply chain, so organisations supporting MOD contracts indirectly may also be required to meet DCC requirements. The specific requirement depends on the contract and its Cyber Risk Profile.

Did this answer your question?