Cyber Security Blog - Cyber Tec Security

Why DCC Matters Across the Entire Defence Supply Chain

Written by Louise Ralston | Sept 1, 2026

For businesses several tiers removed from the Ministry of Defence, it can be easy to assume that Defence Cyber Certification is mainly a concern for prime contractors.

In practice, that is not how the MOD’s cyber assurance model works.

You may manufacture components for a larger engineering business, provide specialist software to a Tier 1 supplier, or support a Defence programme without ever holding a direct MOD contract. Yet, where Defence work is subcontracted, the cyber requirements associated with that work can follow it through the supply chain.

That is what makes the Defence Cyber Certification supply chain relevant well beyond the largest contractors. The important question is not simply whether you contract directly with the MOD, but what part of the work you are responsible for, what level of cyber risk is attached to it and what your customer will need you to demonstrate.
For suppliers that have not yet worked through those questions, doing so before a tender or customer request arrives gives you considerably more room to act.

Contents

The DCC Level 0 deadline: what 31 December 2026 actually means

Why DEFCON 658 reaches beyond the prime contractor

How is the level of cyber risk actually decided?

What could this look like in practice for a subcontractor?

Why Cyber Essentials comes first

What has DCC done for organisations that have already achieved it?

Act before you ask

FAQs

 

 

 

The DCC Level 0 deadline: what 31 December 2026 actually means

The direction from the MOD is clear, although the status of the date itself needs some care.

In May 2026, Eleanor Fairford, the MOD’s Director of Cyber Defence & Risk, asked all industry partners to achieve Level 0 Defence Cyber Certification by 31 December 2026. The MOD subsequently reinforced that position, including the expectation that applicable business-critical systems within scope should hold Cyber Essentials

That makes the DCC Level 0 deadline an important planning date for businesses working in Defence. It does not, however, mean that DCC is currently a blanket legal requirement for every supplier.

IASME’s present guidance states that DCC is not yet mandatory across the board. The MOD’s own Cyber Security Model guidance, meanwhile, tells suppliers to expect certification to feature increasingly in tender conditions. (iasme.co.uk)

For suppliers, the broader position is clear. You may not be contractually required to hold DCC today; if Defence is part of your future pipeline, however, it is sensible to understand what will be expected before certification becomes part of a live opportunity.

 

Why DEFCON 658 reaches beyond the prime contractor

The MOD’s approach to supply chain cyber security is based on a simple principle: the security of a Defence programme depends not only on the prime, but on the organisations that support it.

That is where DEFCON 658 becomes important.

Where relevant work is subcontracted, the applicable cyber requirements must be passed into the subcontracting arrangement. If that subcontractor then passes relevant work further down the chain, the same process continues.

What does not happen is a simple copying of the prime contractor’s DCC level from one tier to the next.

Instead, when part of the contract is subcontracted, a new Cyber Security Model Risk Assessment is carried out for that particular activity. The result is a Cyber Risk Profile and Risk Assessment Reference specific to the work being passed down. The subcontractor then responds to the Supplier Assurance Questionnaire that corresponds to that profile.

The obligation therefore flows through the supply chain, but the risk is considered in the context of each subcontract.

For smaller suppliers, this is a useful distinction. A 20-person engineering company does not automatically have to meet the same requirement as a multinational prime simply because it sits beneath it in the chain. Equally, being smaller or further removed from the MOD does not automatically mean a lower standard will apply.

The determining factor is the work itself.

 

How is the level of cyber risk actually decided?

Rather than starting with the size of the supplier, the MOD’s Cyber Security Model looks at the risk created by the activity being contracted.

Among the factors considered are the value and criticality of the subcontract, the impact if the supplier cannot deliver, whether the supplier needs access to MOD or parent-contractor systems, and the type and sensitivity of information that will pass through its environment.

Consider two businesses with similar turnover and headcount.

One supplies a physical component that can readily be sourced elsewhere, with no access to private systems and little sensitive information involved. The other administers systems used in delivery of the contract and handles sensitive Defence data as part of its role.

From an organisational point of view, they may look very similar. From a cyber-risk point of view, they are not.

Nor should businesses assume that risk automatically reduces as work moves further down the supply chain. The MOD has specifically acknowledged that there may be cases where a supplier at a lower tier requires a higher level of certification because of the nature of the work it performs.

For a supplier trying to work out what DCC means for them, this is probably the most useful starting point: your tier does not determine your requirement; your role, access and exposure do.

 

What could this look like in practice for a subcontractor?

If a prime passes part of an MOD contract to your business, it carries out a Cyber Security Model Risk Assessment for that subcontract. This sets the Cyber Risk Profile and Risk Assessment Reference you need to respond to through the MOD’s Supplier Cyber Protection Service.

If you do not yet meet all the required controls, you can submit a Cyber Improvement Plan setting out what needs to change and when. If accepted, it can form part of the contractual arrangement while you work towards compliance.

The earlier those gaps are identified, the more options you have.

A missing policy, an incorrectly scoped certificate or an undocumented control can often be resolved but it’s more difficult if they’re discovered once a customer has already asked for evidence.

 

Why Cyber Essentials comes first

Whatever DCC level ultimately applies, the starting point is Cyber Essentials.

Levels 0 and 1 require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus. IASME also allows organisations to apply directly for the DCC level appropriate to them rather than working sequentially through every level.

For a defence subcontractor, Cyber Essentials has a very practical role, as it’s the technical foundation on which DCC builds.

If you do not yet hold Cyber Essentials, the next step is to establish the correct scope, review the five technical control areas and resolve gaps progressing with the DCC process.

If you are already certified, you’ll need to check if the certificate is current, if its scope covers the infrastructure you use for Defence work, and have changes to your systems since certification altered your position.

A valid certificate is useful. A valid certificate that accurately reflects the environment involved in the contract is essential.

 

What has DCC done for organisations that have already achieved it?

DCC is still relatively new, but early adopters show how it can be used beyond a single contract.

Morgan Sindall Group became the first organisation to achieve DCC certification in 2025, using it proactively rather than waiting for a specific contract requirement.

Lockheed Martin progressed from Level 0 to Level 3 in July 2026. It cited independent validation of its controls, a consistent internal benchmark, clearer assurance for customers and a stronger basis for assessing subcontractors.

For smaller suppliers, the scale is different, but the value is similar: DCC turns internal controls into independently assessed evidence that Defence customers can recognise.

 

Act before you ask

For new opportunities under Cyber Security Model v4, the Cyber Risk Profile and Risk Assessment Reference should be made available during early market engagement and will normally appear in the invitation to tender. A supplier then completes the appropriate Supplier Assurance Questionnaire, with its compliance or any proposed Cyber Improvement Plan forming part of the procurement picture.

By that stage, cyber assurance is no longer an internal improvement project, but an expected part of the commercial process.

A supplier that already understands its Cyber Essentials scope, knows its controls and has evidence organised can concentrate on responding to new Defence opportunities. A supplier encountering those requirements for the first time may need to understand the framework, fix technical problems and assemble evidence while the procurement timetable is already running.

Both may eventually reach the same standard; one has given itself considerably more room to do it properly.

 

Where should a defence supplier start?

The right starting point depends on the Defence work your business is doing, or intends to pursue, and the requirements attached to that work.

If you already support a Defence contract, establish the Cyber Risk Profile and Risk Assessment Reference that apply to your activity. If you do not have them, ask the customer or contractor above you in the chain. After this, you can review your current certification position.

No Cyber Essentials? Start there.

Or, if you’re already certified, check whether it is current, correctly scoped and aligned with the infrastructure involved in your Defence work.

Once the relevant DCC level is clear, you can assess the additional controls and identify where evidence already exists.

For organisations with wider assurance requirements, IASME Cyber Assurance can provide a broader framework around governance, policies, risk and resilience. It should not be treated as a substitute for DCC, though; IASME confirms that other certifications may support the evidence required, but DCC remains a distinct Defence standard. 

Rather than collecting standards indiscriminately, the aim is to understand what your customers need you to prove and where Cyber Tec can help you meet those requirements.

If Defence is part of your current or future supply chain, contact Cyber Tec to understand the certification you need and the route to achieving it.

 

FAQs

What is Defence Cyber Certification?

Defence Cyber Certification is an organisation-level cyber security certification framework developed for suppliers to UK Defence. Owned by the MOD and managed by IASME, it provides independent assurance against the cyber controls associated with four levels of risk, from Level 0 through to Level 3.

Its practical value is that the certification belongs to the organisation rather than to a single contract. A valid DCC certificate can therefore support multiple Defence opportunities up to the level at which the organisation is certified.

Do I need DCC if I am not a prime contractor?

You may do.

Under DEFCON 658, relevant cyber requirements can flow from the prime through subcontractors and onwards through subsequent tiers. If Defence-related work is passed to your organisation, the supplier above you can carry out a Cyber Security Model Risk Assessment for that activity and assign the resulting Cyber Risk Profile. 

Your distance from the MOD is therefore not the deciding factor.

If you are unsure whether DCC affects you, ask the customer above you what Cyber Risk Profile and Risk Assessment Reference apply to the work you are carrying out. That will give you a much more useful answer than trying to infer your requirement from your position in the supply chain.

How is my DCC level decided?

The level required for a particular piece of work comes from its Cyber Risk Profile.

Rather than simply classifying suppliers by size or tier, the MOD’s risk-assessment process considers what the supplier is being asked to do, how important that activity is to the wider contract, what would happen if delivery failed, which systems the supplier can access and what types of information it will hold or process.

This can produce quite different outcomes for superficially similar businesses.

A small manufacturer with no access to Defence systems may carry a relatively limited cyber exposure. A business of the same size that administers systems or handles sensitive information may present a much higher one.

If you want to understand what level you are likely to need, start with the work and the information involved, not the number of people you employ.

Can a subcontractor need a higher level than the supplier above it?

Potentially, yes.

Because the risk is assessed for the subcontracted activity, the requirement is not simply inherited from the organisation above. A lower-tier supplier performing particularly sensitive, critical or technically privileged work can therefore face a stronger requirement.

The MOD has specifically acknowledged circumstances in which higher certification levels may be required at lower tiers of the supply chain.

This is why using supply-chain position as a proxy for cyber risk can be misleading.

What happens if I do not currently meet the required Cyber Risk Profile?

Failure to meet requirements does not necessarily prevent the procurement from progressing, but it does need to be dealt with formally.

Under the Cyber Security Model, a supplier that does not yet meet all the required controls can submit a Cyber Improvement Plan. This sets out the areas of non-compliance, the remediation work required and the proposed timetable. The contracting authority can then consider that plan as part of supplier selection and, if it is accepted, incorporate it into the contract. 

That makes early assessment worthwhile. If you know where the gaps are before a tender is live, you can decide whether to fix them first or prepare a credible improvement plan. Discovering the same issues once the procurement timetable is already running gives you fewer options.

Does a defence subcontractor need Cyber Essentials?

If you want to achieve DCC, yes.

Cyber Essentials underpins every DCC level, while Levels 2 and 3 require Cyber Essentials Plus.

For organisations without certification in place, Cyber Essentials is therefore the sensible first step, which should go some way towards covering the systems and services involved in your Defence activity.

What is the DCC Level 0 deadline?

The MOD has asked all industry partners to achieve Level 0 by 31 December 2026, including Cyber Essentials for applicable business-critical systems within scope. 

Can one DCC certificate support more than one contract?

Yes. IASME states that a valid DCC certificate can support multiple contracts up to the level at which the organisation is certified.

That is particularly relevant for suppliers expecting to work across several Defence programmes. Rather than treating cyber assurance as a separate certification project for each opportunity, DCC provides organisation-level evidence that can be reused.

There is still contract-specific administration. At present, DCC-certified organisations must continue to complete the relevant Supplier Assurance Questionnaire through the MOD’s Supplier Cyber Protection Service.

Can I get a higher DCC level than my current contract requires?

Yes. IASME allows organisations to apply directly for any DCC level, including businesses that do not currently hold an MOD contract.

Whether that is worthwhile is another question.

If your pipeline includes contracts likely to carry higher Cyber Risk Profiles, achieving stronger assurance in advance may reduce future work and demonstrate greater readiness. If there is no realistic requirement for the higher level, the additional controls, evidence and assessment effort may not be commercially justified.

What benefits have organisations seen after achieving DCC?

Lockheed Martin provides the clearest published example to date. After progressing from Level 0 to Level 3, the company said DCC had given it independent validation of its controls, , stronger evidence for customers and a more consistent basis for assessing the security posture of its own subcontractors. The process also supported internal governance by making control ownership and evidence more visible across the organisation.

Those benefits should not be translated too literally from a large prime to an SME. The underlying principle is relevant, though: DCC gives a supplier a recognised way to demonstrate that its controls have been independently assessed, instead of asking each customer to rely solely on its own assurances.

Has DCC replaced the Supplier Assurance Questionnaire?

No. At present, suppliers with DCC certification still need to complete the relevant elements of the Supplier Assurance Questionnaire through the MOD’s Supplier Cyber Protection Service.

The two serve different purposes. DCC gives independent organisation-level assurance; the Supplier Assurance Questionnaire applies that assurance process to the requirements of a particular procurement.

So, if you are planning for DCC, do not assume the certificate removes all contract-specific cyber administration.

How can Cyber Tec help?

The useful first step is usually not to begin an assessment immediately, but to establish what your organisation needs.

Cyber Tec can help you review whether your Cyber Essentials certification is current and correctly scoped, understand the DCC requirement attached to your work, identify which controls and evidence are already in place, and work through the gaps that remain.

This is most important wherever a requirement has come through a prime or customer and the terminology is unfamiliar. Rather than trying to interpret the framework alone, Cyber Tec can translate that requirement into the specific evidence, certification and remediation work your business needs.

If Defence is already part of your supply chain, or you want it to be, establish your position before the next tender or supplier review requires you to evidence it.

Get in touch with Cyber Tec today.