Every MOD Supplier Needs DCC Level 0 By December – The Smart Ones Aren’t Stopping There

The Ministry of Defence has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems in scope. The requirement reaches the full supply chain, not only prime contractors. UK aerospace, defence, security and space added £46.8 billion to the economy in 2025, a 65% rise over the decade. This article covers what certification requires and what it opens.

Every organisation in the UK defence supply chain now has a date in the diary. Eleanor Fairford, the Ministry of Defence’s Director of Cyber Defence and Risk, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026 – including Cyber Essentials for all applicable business-critical systems in scope.

That leaves roughly four months.

Where higher levels are required further down the supply chain, the MOD has said those should be scheduled for delivery after December, rather than squeezed in alongside. Level 0 is the priority for everyone, from the primes at the top to the specialist SMEs three tiers down.

Is it actually mandatory?

This is the question that stops most suppliers acting, so it is worth answering plainly.

IASME, the scheme’s Certification Authority, still describes DCC as not universally mandatory. But that distinction matters far less than it sounds. Where a contract invokes DEFCON 658 and Defence Standard 05-138, DCC at the level set by the contract’s Cyber Risk Profile is now the recognised route to evidencing compliance.

DEFCON 658 is the MOD’s contractual condition on managing cyber risk through the supply chain. Defence Standard 05-138 sets out the controls expected at each Cyber Risk Profile level.

Combine that with a stated MOD expectation covering the whole industry base, and Level 0 becomes the practical floor for holding or bidding for defence work – whether or not the word “mandatory” appears in the paperwork.

Suppliers waiting for a tender condition to force the issue are taking a timing risk. Scoping, closing Cyber Essentials gaps, gathering evidence and booking an assessment slot do not compress neatly into a procurement window.

The downside risk here is not a fine. It is being unable to bid, or being quietly dropped from a prime’s approved supplier list because you cannot evidence a level the contract now assumes.

The commercial case is stronger than the compliance case

It is easy to read DCC as another cost of doing business. That reading misses what the scheme actually changes.

It replaces per-contract paperwork with one organisational assurance.

DCC supersedes the legacy Supplier Assurance Questionnaire process. A single certification is valid for three years, subject to annual attestation, and covers multiple contracts at or below your certified level. For suppliers who have spent years re-evidencing the same controls contract by contract, that is a direct reduction in bid overhead.

It is a live differentiator while adoption is still uneven.

Lockheed Martin UK became the first company to reach Level 3 in July 2026. The top of the market is moving; most of the tail has not started. Certification held ahead of the deadline is something to put in front of a prime’s supply chain team now, while it still distinguishes you.

The market it opens is growing.

ADS data published in July 2026 puts the combined contribution of the UK’s aerospace, defence, security and space sectors at £46.8 billion in 2025 – a 65% rise over the decade — on turnover approaching £110 billion.

Within that, the defence sector alone added £15.8 billion, up 70% since 2015, with private defence R&D investment reaching £4.3 billion, an increase of 187% over ten years. The government has committed to 2.5% of GDP on defence by 2027 and 3.5% by 2035 in line with the NATO target.

Much of that new money is flowing towards AI, autonomy and other areas where the credible bidders are technology firms with no defence track record.

For those companies, certification is the entry ticket. 

What each level asks of you

All four levels build on Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus.

Cyber Essentials is a self-assessment against five technical controls. Cyber Essentials Plus is the same five controls, independently verified by technical audit — which is why Levels 2 and 3 take considerably longer to reach from a standing start.

LevelControlsTypically assigned where
03
Very low assessed cyber risk. Basic practices: the foundation for everything above it.
1101
Low to moderate risk. A comprehensive programme built on good practice.
2139High risk. Advanced oversight and planning to drive robust organisational practice.
3144
Substantial risk. Expert capability using defence-in-depth against evolving threats.

Control objectives fall into four domains: managing security risk, protecting against cyberattacks, detecting cybersecurity events, and minimising the impact of incidents.

One point catches organisations out.

Unlike Cyber Essentials, DCC does not let you carve parts of the business out of scope – it covers everything essential to your operation, and the scope stays the same at every level.

Choosing Level 0 reduces the number of controls you evidence. It does not reduce the footprint you evidence them across. Get the Statement of Scope right first; an assessor will challenge it.

What certification actually changes

We have taken organisations through DCC ranging from specialist SMEs to international defence primes. The pattern is consistent: the controls that generate the most work in assessment — asset inventory, logging and monitoring, incident response — are the ones that were weakest going in, and the ones that make the most difference afterwards.

Organisations that finish certification are able to see what they own, spot when something is wrong, and respond without improvising.

That is the resilience argument, and it is not incidental. The MOD supply chain faces capable, motivated adversaries pursuing sensitive information and intellectual property. DCC’s risk-based approach applies controls proportionate to what you actually do for defence.

How long it takes

Two weeks to six months, depending on your starting maturity, the level you are targeting, and how much internal priority you give it.

The short end assumes Level 0 with Cyber Essentials already in place and a clean scope. The long end is Level 2 or 3 from a standing start. Steps three to five are where the time goes — scoping arguments, evidence gathering, and closing whatever the gap analysis turns up. The assessment itself is fast by comparison.

1

Engage a DCC Certification Body

2

Confirm your target level – and whether you are going straight there or stepping up iteratively

3

Define and document your scope

4

Gap analysis against the controls for your level

5

Implement a prioritised improvement plan

6

Theoretical assessment

7

Practical assessment

8

Certification


The theoretical assessment reviews your documented evidence against the controls for your level. The practical assessment verifies that what you have documented is what is actually running.

Where to start

If you are not certified and you supply into defence, the useful next step is a scoping conversation and gap analysis: what level you need, whether your Cyber Essentials coverage is sufficient, and what stands between you and an assessment slot before December.

AMR CyberSecurity is a certified DCC assessor organisation for Levels 0 to 3, with extensive MOD and MOD supply chain experience.

Assessment slots tighten as December approaches. Get in touch and we’ll scope what your gap analysis needs to cover.