Compliance

Defence Cyber Certification (DCC): Who Needs It and Why

The MOD has asked every industry partner to hold DCC Level 0 by 31 December 2026. What the scheme is, why it exists and which businesses it reaches.

Nerdster Team

Defence Cyber Certification: Level 0 for MOD suppliers

Defence Cyber Certification (DCC) is the Ministry of Defence’s cyber certification for the companies that supply it, delivered with IASME. In May 2026 the MOD asked all of its industry partners to hold Level 0 by 31 December 2026. That request reaches direct suppliers and the businesses behind them through prime contractors, whatever their trade. Whether it is written into your own contract depends on the cyber terms in that contract or in the prime’s purchase order, which is where this guide starts. If a letter, questionnaire or renewal mentioning DCC has landed on your desk, this is what it means and what to do about it.

What Defence Cyber Certification is

DCC is the way a defence supplier proves it runs the cyber controls the MOD expects, rather than saying so on a questionnaire. The controls come from DEF STAN 05-138 Issue 4, published in May 2024, and the assessment is carried out by an IASME-assured certification body.

There are four levels, from Level 0 to Level 3, with different control requirements. Every level requires Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus. A DCC certificate lasts three years, with an annual attestation in between.

Nerdster prepares suppliers and supports them through the assessment. We are not a certification body: the preparation and the certification decision sit with different organisations, and any proposal you receive should say which of the two it covers.

Why the MOD wants it

A defence programme is only as secure as the smallest company holding its drawings, delivery schedules or site access lists. A ten-person machining firm or a haulier with one MOD route is an easier target than the prime, and the information it holds is often the same. DCC gives the MOD and its primes one consistent way to check that every link in that chain runs the same baseline controls, instead of relying on each supplier’s own description of itself.

On 8 May 2026, Eleanor Fairford, the MOD’s Director of Cyber Defence and Risk, wrote in the Defence Digital blog:

“I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026”

That is a request from the MOD to its supply chain. It is not a statutory deadline and it is not automatically a clause in every contract. What binds you is the contract itself.

On a contract, the binding requirement is the Cyber Risk Profile and the Supplier Assurance Questionnaire under DEFCON 658. Since Cyber Security Model version 4 went live in October 2025, applying to new risk assessments and questionnaires from 3 December 2025, that profile is expressed as a level from 0 to 3. The questionnaire stays mandatory even when you hold a DCC certificate, and it is reviewed every year on the contract anniversary.

DEFCON 658 also requires primes to pass the cyber requirements down to their subcontractors, which is why a purchase order from a prime can carry the same clause as an MOD contract. Industry Security Notice 2026/02 closes the loop: a valid DCC certificate at or above the contract’s level is accepted as evidence of the DEF STAN 05-138 controls under DEFCON 658, and a higher-level certificate satisfies every lower level. It shortens the evidence, not the questionnaire.

Which businesses need it

The MOD’s request went to all of its industry partners, not to a sector. What brings a business into scope is an MOD contract or a prime’s purchase order carrying DEFCON 658, not the trade it is in. The businesses below are the ones the request most obviously reaches, with the defence information each tends to hold.

Engineering and precision manufacturing

Machined parts, fabrication, assemblies, test and calibration. The sensitive material is usually the drawings and specifications that arrive by email or portal, the CAD and CAM files derived from them, and the test and calibration records the customer will ask for. The workshop PCs and the file share behind them are the scope.

Electronics and electrical

PCBs, cable assemblies, power, connectors and repair. Schematics, bills of materials, firmware and repair histories are the information that matters, and they tend to live on engineering workstations and in whichever tool the customer uses to exchange them.

Software, data and IT services

Development, hosting, support and integration. Here the scope is the delivery environment itself: source code, build systems, hosting accounts, support tooling and anything holding customer data. Be clear about which systems you operate and which you only access on the customer’s behalf, because the answer changes what you are certifying.

Logistics, freight and warehousing

Haulage, forwarding, warehousing and the movement of vehicles and equipment. Movement instructions, schedules, consignment details and site access arrangements are the sensitive information, and they pass through booking systems, transport management software and a great deal of email.

Facilities, construction and estate maintenance

Works on bases and establishments, mechanical and electrical, grounds. Site plans, drawings, access lists and maintenance records are the material, often held by a small office team while the work itself happens on site. The office systems and the devices carried onto the site are what an assessor looks at.

Training, consultancy and professional services

Technical training, engineering consultancy and project support. Course material, project documents and correspondence with the customer are the information, usually spread across laptops, Microsoft 365 or Google Workspace and a document store. The scope follows the people rather than a building.

Site services

Catering, cleaning, security and welfare contracts on defence sites. The work has little to do with IT, but the rostering, site instructions, staff vetting records and access arrangements behind it are exactly the kind of information the clause is there to protect, and the requirement flows down all the same.

Who does not need it

If you have no MOD contract and no prime’s purchase order carrying the cyber clause, there is no DCC requirement on you today. Cyber Essentials may still be worth holding for other customers and for insurers. Check the contract before commissioning DCC work on the strength of a general mention of defence.

Which level you need

The level is set by the Cyber Risk Profile on the contract. You do not choose it, and it does not follow from your industry. Level 0 is the floor, and the level the MOD has asked every partner to reach.

The controls grow with the level:

  • Level 0: 3 organisational controls plus Cyber Essentials.
  • Level 1: 101 controls, with Cyber Essentials required.
  • Level 2: 139 controls, with Cyber Essentials Plus required.
  • Level 3: 144 controls, with Cyber Essentials Plus required.

In the same post the MOD said that where higher levels are required at lower tiers of the supply chain, they should be scheduled for delivery after 31 December 2026. If a prime has named Level 1 or above for you, that is the timetable to discuss with them, and Level 0 is still the first step because every level builds on it.

What Level 0 involves

Level 0 is a valid Cyber Essentials certificate covering the systems the defence work touches, three organisational controls from DEF STAN 05-138 in place and evidenced, and an assessment by an approved certification body. If you already hold Cyber Essentials you are most of the way there, provided it covers the right systems and is current. We hold Cyber Essentials ourselves and take clients through it and through Cyber Essentials Plus, so that part of the work is familiar ground.

With Cyber Essentials current and the systems in order, Level 0 readiness is measured in weeks. If Cyber Essentials has lapsed, or devices need replacing to pass it, the technical work comes first and the plan is longer. Either way, agree a dated plan after a gap check rather than assuming an old certificate settles it.

Our Cyber Essentials support explains how we help with that part of the work. If you are reviewing a renewal, read our guide to the Cyber Essentials changes alongside it. You can also use our Cyber Essentials readiness check as a starting point for the conversation.

The certificate lasts three years, but there is an annual attestation in between and the contract questionnaire still comes round every year. Plan for both from the start; an assessor will notice controls that were written up once and never run.

What it costs

Treat these as indicative costs and keep readiness support separate from the assessment fee when you compare quotes. The certification body sets its own fee.

  • Nerdster Cyber Essentials: from £795 + VAT.
  • Nerdster Level 0 readiness: typically £1,500 to £3,000 + VAT, including the Cyber Essentials readiness work, fixed in writing after a scoping call.
  • Level 0 assessment: paid to the certification body; one body’s published 2026 list runs from £650 + VAT for 1 to 9 staff to £1,000 + VAT for 250 or more.
  • Level 1: the body’s fee is set per organisation, and we quote the readiness work only after a gap assessment.

Level 0 readiness already includes the Cyber Essentials readiness work, so check a proposal before adding the lines together. Our Defence Cyber Certification page has the full cost table and what each stage involves.

What to do this month

Five steps, best done by whoever owns the contract and whoever looks after the IT, together.

  1. Find the clause. Read the MOD contract or the prime’s purchase order for DEFCON 658 and the cyber requirements passed down to you.
  2. Confirm the level. Ask the customer which Cyber Risk Profile is attached to the work and where the Supplier Assurance Questionnaire stands.
  3. Check Cyber Essentials. Is it current, and does it cover the systems the defence work touches? If not, that is the first job.
  4. Fix the scope. List the systems that hold or move the defence information, and name the person who will gather the evidence.
  5. Book the assessment. Choose an IASME-assured certification body, confirm its fee and availability, and put the annual attestation and questionnaire review in the diary.

Official sources

If you have received a letter, a questionnaire or a renewal that mentions DCC, send it to us. We will tell you clearly which level it is asking for, what you already hold that counts and what is missing. We work with suppliers across London, the Thames Valley, Oxfordshire, Hampshire and Wiltshire: see our Defence Cyber Certification support or contact us.

Defence Cyber CertificationDCCDEF STAN 05-138Cyber EssentialsMOD suppliersDEFCON 658

FAQ

Defence Cyber Certification (DCC): your questions answered

Is DCC legally mandatory?

The MOD has asked all industry partners to achieve Level 0 DCC certification by 31 December 2026. This is a request, not a statutory deadline or automatically a clause in every contract. The binding cyber requirements come from the contract's Cyber Risk Profile and Supplier Assurance Questionnaire under DEFCON 658.

Does Cyber Essentials cover DCC Level 0?

Cyber Essentials is required for Level 0, alongside three organisational controls and the DCC assessment. Holding Cyber Essentials alone does not give you a DCC certificate.

Which DCC level does my business need?

The contract's Cyber Risk Profile sets the level. Level 0 is the floor in the MOD's request to industry partners. A valid certificate at or above the contract's level is accepted as evidence of the DEF STAN 05-138 controls under DEFCON 658.

How long does a DCC certificate last?

A DCC certificate lasts three years, with an annual attestation in between. The Supplier Assurance Questionnaire remains mandatory and is reviewed annually on the contract anniversary.

What does DCC Level 0 cost?

With Nerdster, Level 0 readiness is typically £1,500 to £3,000 + VAT including the Cyber Essentials readiness work, fixed in writing after a scoping call; Cyber Essentials itself is from £795 + VAT. The assessment fee is paid to the certification body, which sets its own price: one body's published 2026 list runs from £650 + VAT for 1 to 9 staff to £1,000 + VAT for 250 or more.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report