Defence Cyber Certification (DCC): Who Needs It and Why
The MOD has asked every industry partner to hold DCC Level 0 by 31 December 2026. What the scheme is, why it exists and which businesses it reaches.
Nerdster Team
Defence Cyber Certification (DCC) is the Ministry of Defence’s cyber certification for the companies that supply it, delivered with IASME. In May 2026 the MOD asked all of its industry partners to hold Level 0 by 31 December 2026. That request reaches direct suppliers and the businesses behind them through prime contractors, whatever their trade. Whether it is written into your own contract depends on the cyber terms in that contract or in the prime’s purchase order, which is where this guide starts. If a letter, questionnaire or renewal mentioning DCC has landed on your desk, this is what it means and what to do about it.
What Defence Cyber Certification is
DCC is the way a defence supplier proves it runs the cyber controls the MOD expects, rather than saying so on a questionnaire. The controls come from DEF STAN 05-138 Issue 4, published in May 2024, and the assessment is carried out by an IASME-assured certification body.
There are four levels, from Level 0 to Level 3, with different control requirements. Every level requires Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus. A DCC certificate lasts three years, with an annual attestation in between.
Nerdster prepares suppliers and supports them through the assessment. We are not a certification body: the preparation and the certification decision sit with different organisations, and any proposal you receive should say which of the two it covers.
Why the MOD wants it
A defence programme is only as secure as the smallest company holding its drawings, delivery schedules or site access lists. A ten-person machining firm or a haulier with one MOD route is an easier target than the prime, and the information it holds is often the same. DCC gives the MOD and its primes one consistent way to check that every link in that chain runs the same baseline controls, instead of relying on each supplier’s own description of itself.
On 8 May 2026, Eleanor Fairford, the MOD’s Director of Cyber Defence and Risk, wrote in the Defence Digital blog:
“I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026”
That is a request from the MOD to its supply chain. It is not a statutory deadline and it is not automatically a clause in every contract. What binds you is the contract itself.
On a contract, the binding requirement is the Cyber Risk Profile and the Supplier Assurance Questionnaire under DEFCON 658. Since Cyber Security Model version 4 went live in October 2025, applying to new risk assessments and questionnaires from 3 December 2025, that profile is expressed as a level from 0 to 3. The questionnaire stays mandatory even when you hold a DCC certificate, and it is reviewed every year on the contract anniversary.
DEFCON 658 also requires primes to pass the cyber requirements down to their subcontractors, which is why a purchase order from a prime can carry the same clause as an MOD contract. Industry Security Notice 2026/02 closes the loop: a valid DCC certificate at or above the contract’s level is accepted as evidence of the DEF STAN 05-138 controls under DEFCON 658, and a higher-level certificate satisfies every lower level. It shortens the evidence, not the questionnaire.
Which businesses need it
The MOD’s request went to all of its industry partners, not to a sector. What brings a business into scope is an MOD contract or a prime’s purchase order carrying DEFCON 658, not the trade it is in. The businesses below are the ones the request most obviously reaches, with the defence information each tends to hold.
Engineering and precision manufacturing
Machined parts, fabrication, assemblies, test and calibration. The sensitive material is usually the drawings and specifications that arrive by email or portal, the CAD and CAM files derived from them, and the test and calibration records the customer will ask for. The workshop PCs and the file share behind them are the scope.
Electronics and electrical
PCBs, cable assemblies, power, connectors and repair. Schematics, bills of materials, firmware and repair histories are the information that matters, and they tend to live on engineering workstations and in whichever tool the customer uses to exchange them.
Software, data and IT services
Development, hosting, support and integration. Here the scope is the delivery environment itself: source code, build systems, hosting accounts, support tooling and anything holding customer data. Be clear about which systems you operate and which you only access on the customer’s behalf, because the answer changes what you are certifying.
Logistics, freight and warehousing
Haulage, forwarding, warehousing and the movement of vehicles and equipment. Movement instructions, schedules, consignment details and site access arrangements are the sensitive information, and they pass through booking systems, transport management software and a great deal of email.
Facilities, construction and estate maintenance
Works on bases and establishments, mechanical and electrical, grounds. Site plans, drawings, access lists and maintenance records are the material, often held by a small office team while the work itself happens on site. The office systems and the devices carried onto the site are what an assessor looks at.
Training, consultancy and professional services
Technical training, engineering consultancy and project support. Course material, project documents and correspondence with the customer are the information, usually spread across laptops, Microsoft 365 or Google Workspace and a document store. The scope follows the people rather than a building.
Site services
Catering, cleaning, security and welfare contracts on defence sites. The work has little to do with IT, but the rostering, site instructions, staff vetting records and access arrangements behind it are exactly the kind of information the clause is there to protect, and the requirement flows down all the same.
Who does not need it
If you have no MOD contract and no prime’s purchase order carrying the cyber clause, there is no DCC requirement on you today. Cyber Essentials may still be worth holding for other customers and for insurers. Check the contract before commissioning DCC work on the strength of a general mention of defence.
Which level you need
The level is set by the Cyber Risk Profile on the contract. You do not choose it, and it does not follow from your industry. Level 0 is the floor, and the level the MOD has asked every partner to reach.
The controls grow with the level:
- Level 0: 3 organisational controls plus Cyber Essentials.
- Level 1: 101 controls, with Cyber Essentials required.
- Level 2: 139 controls, with Cyber Essentials Plus required.
- Level 3: 144 controls, with Cyber Essentials Plus required.
In the same post the MOD said that where higher levels are required at lower tiers of the supply chain, they should be scheduled for delivery after 31 December 2026. If a prime has named Level 1 or above for you, that is the timetable to discuss with them, and Level 0 is still the first step because every level builds on it.
What Level 0 involves
Level 0 is a valid Cyber Essentials certificate covering the systems the defence work touches, three organisational controls from DEF STAN 05-138 in place and evidenced, and an assessment by an approved certification body. If you already hold Cyber Essentials you are most of the way there, provided it covers the right systems and is current. We hold Cyber Essentials ourselves and take clients through it and through Cyber Essentials Plus, so that part of the work is familiar ground.
With Cyber Essentials current and the systems in order, Level 0 readiness is measured in weeks. If Cyber Essentials has lapsed, or devices need replacing to pass it, the technical work comes first and the plan is longer. Either way, agree a dated plan after a gap check rather than assuming an old certificate settles it.
Our Cyber Essentials support explains how we help with that part of the work. If you are reviewing a renewal, read our guide to the Cyber Essentials changes alongside it. You can also use our Cyber Essentials readiness check as a starting point for the conversation.
The certificate lasts three years, but there is an annual attestation in between and the contract questionnaire still comes round every year. Plan for both from the start; an assessor will notice controls that were written up once and never run.
What it costs
Treat these as indicative costs and keep readiness support separate from the assessment fee when you compare quotes. The certification body sets its own fee.
- Nerdster Cyber Essentials: from £795 + VAT.
- Nerdster Level 0 readiness: typically £1,500 to £3,000 + VAT, including the Cyber Essentials readiness work, fixed in writing after a scoping call.
- Level 0 assessment: paid to the certification body; one body’s published 2026 list runs from £650 + VAT for 1 to 9 staff to £1,000 + VAT for 250 or more.
- Level 1: the body’s fee is set per organisation, and we quote the readiness work only after a gap assessment.
Level 0 readiness already includes the Cyber Essentials readiness work, so check a proposal before adding the lines together. Our Defence Cyber Certification page has the full cost table and what each stage involves.
What to do this month
Five steps, best done by whoever owns the contract and whoever looks after the IT, together.
- Find the clause. Read the MOD contract or the prime’s purchase order for DEFCON 658 and the cyber requirements passed down to you.
- Confirm the level. Ask the customer which Cyber Risk Profile is attached to the work and where the Supplier Assurance Questionnaire stands.
- Check Cyber Essentials. Is it current, and does it cover the systems the defence work touches? If not, that is the first job.
- Fix the scope. List the systems that hold or move the defence information, and name the person who will gather the evidence.
- Book the assessment. Choose an IASME-assured certification body, confirm its fee and availability, and put the annual attestation and questionnaire review in the diary.
Official sources
- MOD Cyber Security Model guidance
- One year of Defence Cyber Certification
- Industry Security Notice 2026/02
- IASME Defence Cyber Certification
If you have received a letter, a questionnaire or a renewal that mentions DCC, send it to us. We will tell you clearly which level it is asking for, what you already hold that counts and what is missing. We work with suppliers across London, the Thames Valley, Oxfordshire, Hampshire and Wiltshire: see our Defence Cyber Certification support or contact us.