Defence Cyber Certification

Get DCC Ready Before It Becomes a Bid Problem

DCC is changing how organisations demonstrate cyber resilience across the UK defence supply chain.

2-sec helps you understand how DCC applies to your organisation, define the appropriate scope, identify and close any gaps, and prepare for independent assessment before it becomes a requirement of a customer, prime contractor or tender opportunity. 

CONSTRUCTIONLOGISTICSDIGITAL SERVICESENGINEERINGDCC READINESS

Bid Ready

Prevent cyber assurance from becoming the issue that slows down your next defence opportunity.

Fewer Surprises

Identify scope, control and evidence gaps before you enter the formal assessment process.

Practical Support

Turn complex requirements into workable policies, technical controls and evidence your organisation can demonstrate.

Stronger Defence Supply Chains

Independent Cyber Assurance for the Work You Do

Defence Cyber Certification (DCC) is an organisation-wide cyber security certification developed by the Ministry of Defence and IASME. It provides independent assurance that a supplier meets the relevant cyber security controls in Defence Standard 05-138 Issue 4.

DCC is not only for businesses that manufacture weapons or handle highly classified technology. The defence supply chain also includes architects, construction firms, facilities providers, caterers, logistics companies, software businesses, professional advisers and many other specialist suppliers. If you work for the MOD, a Defence organisation or a Prime contractor, DCC may become relevant to your contracts or future bids.

The MOD or your Prime determines the required level for a contract based on its Cyber Risk Profile, not simply your company size or industry. Any organisation can apply proactively, whether or not it is currently delivering a defence contract.

Why DCC Matters Now

Understand the Requirement Before You Start

DCC has four levels aligned to the assessed cyber risk of the work being delivered. Every level requires Cyber Essentials, with Levels 2 and 3 requiring Cyber Essentials Plus. You do not have to work through the levels in order, but the scope must reflect the functions and services essential to your organisation’s secure and resilient operation.

LevelAssessed riskControlsPrerequisiteWhat it demonstrates
Level 0Very low3Cyber EssentialsBasic cyber security practices and the foundation for higher levels.
Level 1Low to moderate101Cyber EssentialsA comprehensive cyber security programme with good practices.
Level 2High139Cyber Essentials PlusAdvanced oversight and planning that drives robust organisational and cyber practices.
Level 3Substantial144Cyber Essentials PlusExpert capability and defence-in-depth protection against new and evolving threats.
Discuss Your DCC Requirement ↗

A Clear Route to Independent Assessment

01

Review

Start with a DCC Readiness Review to understand where DCC could affect your organisation, what is already in place and what requires investigation.

02

Assess

Define scope and complete a structured gap and readiness assessment against the level you need to prepare for.

03

Remediate

Prioritise and implement the policies, processes, technical controls and evidence needed to close the gaps.

04

Prepare

Check that controls can be demonstrated in practice and organise a coherent evidence pack for formal assessment.

05

Certify and Maintain

2-sec will help you prepare for assessment, introduce you to an appropriate independent Certification Body and support you throughout the certification process. Following certification, we'll help you maintain the required controls, Cyber Essentials certification and ongoing attestations.

Get DCC Ready Before Your Next Defence Opportunity Makes It Urgent

Book a DCC Readiness Review ↗
Defence Cyber Certification

Frequently Asked Questions About Defence Cyber Certification

What is Defence Cyber Certification?

Defence Cyber Certification is a cyber security certification developed by the Ministry of Defence and IASME. It provides independent assurance that a supplier meets the cyber security controls relevant to its DCC level under Defence Standard 05-138 Issue 4.

Is DCC mandatory?

IASME currently states that DCC is not mandatory across the board and organisations can still tender through the normal MOD process. However, the MOD has asked all industry partners to achieve Level 0 by 31 December 2026, and individual contracts or Prime contractors may set specific requirements according to cyber risk.

Who should consider DCC?

Existing MOD suppliers, subcontractors working through Defence Primes, lower-tier suppliers and organisations planning to enter the defence supply chain should all understand DCC. It can be relevant to construction, facilities, catering, logistics, professional services, technology and many other suppliers, not only traditional defence manufacturers.

How do I know which DCC level I need?

The MOD or your Prime determines the level required for a contract through its Cyber Risk Profile. If you have not been assigned a level, do not guess. Review current and planned Defence relationships and ask the relevant customer or Prime what requirement is expected.

Do I need Cyber Essentials first?

Yes. Cyber Essentials is required for Levels 0 and 1. Cyber Essentials Plus is required for Levels 2 and 3. The relevant Cyber Essentials certification must adequately cover the internet-connected networks and devices within your DCC scope.

Is DCC Level 0 a self-assessment?

No. IASME states that none of the DCC levels are self-assessment certifications. An independent DCC Assessor verifies that the applicable requirements have been met.

Can ISO 27001 or another certification be used for DCC?

Existing certifications and frameworks provide useful controls and evidence, and 2-sec can help map them to the relevant DCC requirements. However, IASME states that no other certification currently provides direct compliance with the Defence Standard controls.

What is included in DCC scope?

DCC scope should include the essential functions and services your organisation needs to operate securely and resiliently. This can extend beyond systems used for one Defence contract and may include cloud services, operational technology and third parties that perform controls on your behalf.

What happens during a DCC assessment?

For Levels 1 to 3, the process includes theoretical and practical phases. You explain how controls are met and provide evidence, then the Assessor verifies that the controls are implemented and effective in practice. Level 0 also requires independent assessment and is not self-assessed.

How long does DCC certification take?

IASME does not define a standard timescale. It depends on your preparedness, the gaps that need to be remediated and Certification Body availability. Starting with scope and readiness early reduces the risk of discovering significant work against a live contract deadline.

How long does DCC certification last?

DCC requires an annual attestation and full recertification every three years. Cyber Essentials or Cyber Essentials Plus must also be renewed annually, and you should discuss significant scope changes with the assessing Certification Body.

Can the same organisation prepare us and assess us?

A Certification Body can identify gaps and may provide consultancy in a distinct role. However, if it is acting as your DCC Assessor, it cannot implement or manage your security defences. 2-sec focuses on readiness, remediation and evidence, then helps you engage an appropriate independent Certification Body for formal assessment.

Does DCC guarantee that we will win Defence work?

No. DCC does not guarantee a contract award or automatic preference. It can provide reusable, independently verified evidence of cyber resilience at the certified level, strengthen credibility and reduce assurance friction when a customer asks you to prove your position.

What happens in a 2-sec DCC Readiness Review?

We discuss your Defence relationships and timing, any assigned Cyber Risk Profile, your Cyber Essentials or ISO 27001 position, likely scope complexity, evidence maturity and known gaps. The review gives you a clearer view of the next step. It does not assign a definitive contract level where the MOD or your Prime has not.

Can 2-sec guarantee that we will pass first time?

No credible adviser can guarantee an independent Assessor's decision. 2-sec helps you identify and remediate gaps before formal assessment, giving you the strongest practical chance of passing the first time.

Start Here

Book Your DCC Readiness Review

Understand your Defence relationships, likely scope, existing Cyber Essentials or ISO 27001 position, evidence maturity and known gaps before a live tender or customer deadline makes the work urgent.

Discuss Your DCC Requirement

Speak with 2-sec about the right next step for your organisation.

Book a DCC Readiness Review ↗

The DCC Guide CTA can be connected to the client’s lead-magnet landing page as soon as that URL is available.