When people hear “Defence supplier”, they often think of organisations building aircraft, weapons systems or advanced military technology.

In reality, the UK defence supply chain is far broader than that.

Architects design defence facilities. Engineering firms deliver infrastructure projects. Facilities management providers maintain sites. Logistics companies move equipment. Recruiters handle personnel information. Training providers, surveyors, software companies and specialist contractors all support defence operations in some way.

As a result, many organisations that don't consider themselves “defence companies” may still find that defence cyber security requirements become relevant to their business.

What Is DCC?

Defence Cyber Certification (DCC) is an organisation-wide cyber security certification designed to provide independent assurance that suppliers have appropriate cyber resilience for the work they undertake within the defence supply chain. The scheme launched in May 2025 and is available at Levels 0 through 3.

The Ministry of Defence (MOD) has asked industry partners to achieve at least Level 0 by 31 December 2026, although DCC is not currently mandatory across all contracts. Requirements will depend on the cyber risk associated with a contract and may be flowed down through Prime contractors to their suppliers.

Why This Matters to Non-Traditional Suppliers

Many organisations assume DCC will only affect defence manufacturers or technology companies.

That assumption can be dangerous.

Defence relies on an extensive network of suppliers and subcontractors. Cyber risk is not determined by what a company manufactures. Instead, it is determined by the information, systems and services that support contract delivery.

For example:

-An architectural practice may hold sensitive building plans

  • A facilities management company may access operational systems
  • A logistics provider may manage movement schedules and inventory data
  • A recruitment business may process workforce and vetting information
  • A software provider may host business-critical services

In each case, cyber resilience could become a requirement because of the role that organisation plays within the wider supply chain.

DCC Is Based on Risk, Not Company Size

One of the biggest misconceptions about DCC is that larger organisations automatically need higher levels.

That's not how the scheme works.

The required DCC level is determined by the MOD or a Prime contractor, based on the cyber risk profile of the work being undertaken. A small specialist supplier may therefore face significant requirements if the contract involves higher levels of risk, while a larger organisation may only require a lower level for certain activities.

The important question isn't: “Are we a defence company?”

It's: “Could the systems, services or information we use to support defence delivery create cyber risk?”

The Jump From Level 0 to Level 1 Is Significant

Another common mistake is assuming DCC is simply an extension of Cyber Essentials.

Level 0 is deliberately straightforward, containing just three controls.

However, Level 1 requires 101 controls, while Levels 2 and 3 require 139 and 144 controls respectively. Higher levels involve governance, risk management, incident response, resilience, supplier management and evidence that controls are operating effectively in practice.

Organisations that wait until a customer requests Level 1 may find they have significantly more work to do than expected.

Cyber Essentials Is Only the Starting Point

Many organisations already hold Cyber Essentials and assume that will be enough.

Cyber Essentials remains an important foundation and Levels 2 and 3 require Cyber Essentials Plus. However, DCC looks at a much broader picture of organisational security and resilience. Existing work around Cyber Essentials, ISO 27001 and other security frameworks can help, but they do not automatically make an organisation DCC-ready.

The good news is that organisations with existing security controls often have a strong starting point from which to build.

Why Preparation Matters

One challenge many organisations underestimate is scope.

According to current guidance, DCC may include the essential functions and services required for an organisation to operate securely and resiliently. That can include cloud platforms, third-party providers, managed services and other business-critical dependencies.

The earlier organisations understand their likely scope, the easier it becomes to avoid surprises during assessment.

Similarly, DCC isn't just about having policies in place. Assessments require evidence that controls operate effectively in practice. Organisations that prepare early are generally in a much stronger position than those trying to gather evidence immediately before formal assessment.

What Should You Do Next?

If your organisation currently supplies the MOD, works with a Prime contractor, or is planning to enter the defence market, now is a good time to understand where DCC could affect your business.

Start by asking:

  • Who do we supply?
  • Are we involved in defence-related contracts?
  • What systems and services support that work?
  • Do we know what level of assurance may be required in future?
  • Are our current cyber controls sufficient?

Early preparation doesn't mean rushing into certification. It means understanding your starting point before DCC becomes a tender requirement or a customer question.

How 2-sec Can Help

At 2-sec, we help organisations understand where DCC may apply, identify gaps, assess existing controls and prepare for formal certification.

Our services include:

  • DCC readiness reviews
  • Gap assessments
  • Cyber Essentials and Cyber Essentials Plus support
  • Vulnerability management
  • ISO 27001 consultancy
  • Penetration testing
  • Virtual CISO services
  • Technical remediation and assurance support

The goal isn't simply to achieve certification. It's to build confidence that your organisation can demonstrate cyber resilience when customers, partners or contract requirements demand it.

Want to understand where your organisation stands? Book a DCC Readiness Review (opens in a new tab) with 2-sec and start the conversation before DCC becomes a bid issue.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top