Bid Ready
Prevent cyber assurance from becoming the issue that slows down your next defence opportunity.
DCC is changing how organisations demonstrate cyber resilience across the UK defence supply chain.
2-sec helps you understand how DCC applies to your organisation, define the appropriate scope, identify and close any gaps, and prepare for independent assessment before it becomes a requirement of a customer, prime contractor or tender opportunity.
Prevent cyber assurance from becoming the issue that slows down your next defence opportunity.
Identify scope, control and evidence gaps before you enter the formal assessment process.
Turn complex requirements into workable policies, technical controls and evidence your organisation can demonstrate.
Defence Cyber Certification (DCC) is an organisation-wide cyber security certification developed by the Ministry of Defence and IASME. It provides independent assurance that a supplier meets the relevant cyber security controls in Defence Standard 05-138 Issue 4.
DCC is not only for businesses that manufacture weapons or handle highly classified technology. The defence supply chain also includes architects, construction firms, facilities providers, caterers, logistics companies, software businesses, professional advisers and many other specialist suppliers. If you work for the MOD, a Defence organisation or a Prime contractor, DCC may become relevant to your contracts or future bids.
The MOD or your Prime determines the required level for a contract based on its Cyber Risk Profile, not simply your company size or industry. Any organisation can apply proactively, whether or not it is currently delivering a defence contract.
DCC has four levels aligned to the assessed cyber risk of the work being delivered. Every level requires Cyber Essentials, with Levels 2 and 3 requiring Cyber Essentials Plus. You do not have to work through the levels in order, but the scope must reflect the functions and services essential to your organisation’s secure and resilient operation.
| Level | Assessed risk | Controls | Prerequisite | What it demonstrates |
|---|---|---|---|---|
| Level 0 | Very low | 3 | Cyber Essentials | Basic cyber security practices and the foundation for higher levels. |
| Level 1 | Low to moderate | 101 | Cyber Essentials | A comprehensive cyber security programme with good practices. |
| Level 2 | High | 139 | Cyber Essentials Plus | Advanced oversight and planning that drives robust organisational and cyber practices. |
| Level 3 | Substantial | 144 | Cyber Essentials Plus | Expert capability and defence-in-depth protection against new and evolving threats. |
Start with a DCC Readiness Review to understand where DCC could affect your organisation, what is already in place and what requires investigation.
Define scope and complete a structured gap and readiness assessment against the level you need to prepare for.
Prioritise and implement the policies, processes, technical controls and evidence needed to close the gaps.
Check that controls can be demonstrated in practice and organise a coherent evidence pack for formal assessment.
2-sec will help you prepare for assessment, introduce you to an appropriate independent Certification Body and support you throughout the certification process. Following certification, we'll help you maintain the required controls, Cyber Essentials certification and ongoing attestations.
Defence Cyber Certification is a cyber security certification developed by the Ministry of Defence and IASME. It provides independent assurance that a supplier meets the cyber security controls relevant to its DCC level under Defence Standard 05-138 Issue 4.
IASME currently states that DCC is not mandatory across the board and organisations can still tender through the normal MOD process. However, the MOD has asked all industry partners to achieve Level 0 by 31 December 2026, and individual contracts or Prime contractors may set specific requirements according to cyber risk.
Existing MOD suppliers, subcontractors working through Defence Primes, lower-tier suppliers and organisations planning to enter the defence supply chain should all understand DCC. It can be relevant to construction, facilities, catering, logistics, professional services, technology and many other suppliers, not only traditional defence manufacturers.
The MOD or your Prime determines the level required for a contract through its Cyber Risk Profile. If you have not been assigned a level, do not guess. Review current and planned Defence relationships and ask the relevant customer or Prime what requirement is expected.
Yes. Cyber Essentials is required for Levels 0 and 1. Cyber Essentials Plus is required for Levels 2 and 3. The relevant Cyber Essentials certification must adequately cover the internet-connected networks and devices within your DCC scope.
No. IASME states that none of the DCC levels are self-assessment certifications. An independent DCC Assessor verifies that the applicable requirements have been met.
Existing certifications and frameworks provide useful controls and evidence, and 2-sec can help map them to the relevant DCC requirements. However, IASME states that no other certification currently provides direct compliance with the Defence Standard controls.
DCC scope should include the essential functions and services your organisation needs to operate securely and resiliently. This can extend beyond systems used for one Defence contract and may include cloud services, operational technology and third parties that perform controls on your behalf.
For Levels 1 to 3, the process includes theoretical and practical phases. You explain how controls are met and provide evidence, then the Assessor verifies that the controls are implemented and effective in practice. Level 0 also requires independent assessment and is not self-assessed.
IASME does not define a standard timescale. It depends on your preparedness, the gaps that need to be remediated and Certification Body availability. Starting with scope and readiness early reduces the risk of discovering significant work against a live contract deadline.
DCC requires an annual attestation and full recertification every three years. Cyber Essentials or Cyber Essentials Plus must also be renewed annually, and you should discuss significant scope changes with the assessing Certification Body.
A Certification Body can identify gaps and may provide consultancy in a distinct role. However, if it is acting as your DCC Assessor, it cannot implement or manage your security defences. 2-sec focuses on readiness, remediation and evidence, then helps you engage an appropriate independent Certification Body for formal assessment.
No. DCC does not guarantee a contract award or automatic preference. It can provide reusable, independently verified evidence of cyber resilience at the certified level, strengthen credibility and reduce assurance friction when a customer asks you to prove your position.
We discuss your Defence relationships and timing, any assigned Cyber Risk Profile, your Cyber Essentials or ISO 27001 position, likely scope complexity, evidence maturity and known gaps. The review gives you a clearer view of the next step. It does not assign a definitive contract level where the MOD or your Prime has not.
No credible adviser can guarantee an independent Assessor's decision. 2-sec helps you identify and remediate gaps before formal assessment, giving you the strongest practical chance of passing the first time.
Understand your Defence relationships, likely scope, existing Cyber Essentials or ISO 27001 position, evidence maturity and known gaps before a live tender or customer deadline makes the work urgent.
Speak with 2-sec about the right next step for your organisation.
Book a DCC Readiness Review ↗The DCC Guide CTA can be connected to the client’s lead-magnet landing page as soon as that URL is available.