What is the Defence Cyber Certification? A plain-English guide for UK defence suppliers

The Defence Cyber Certification is the Ministry of Defence's supplier security standard, and it is assessed by someone else rather than declared by you. If a contract or a prime has told you that you need it, this is what it involves.

Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026

The short version

The Defence Cyber Certification, usually shortened to DCC, is a certification scheme for organisations in the UK defence supply chain. It sits under the Defence Cyber Protection Partnership, the joint MOD and industry body that has set defence supplier security expectations for the last decade. Its defining feature is not the control list. It is that an assessor checks your answers rather than accepting them.

That is the change worth understanding. For years, defence supplier assurance ran on self-declaration: a contract was risk-assessed, you were told which cyber risk profile applied, and you completed a Supplier Assurance Questionnaire about your controls. The questionnaire was honest work for most suppliers, but nobody verified it. A prime contractor had no practical way to test whether a third-tier supplier’s claim about multi-factor authentication was true. DCC replaces that gap with an independent assessment.

Who is actually being asked for it

Almost nobody pursues DCC voluntarily. It arrives one of two ways: a clause in an MOD contract, or an email from a prime saying their flow-down obligations now reach you. Which contracts require it, at which level, and by when, is being introduced progressively. Your contract and the buying authority are the source of truth on that. If you are unsure whether you are in scope, ask the commercial contact who sent you the requirement rather than inferring it, because the answer varies by contract and by the sensitivity of the information you handle.

Two things are worth confirming in the same conversation: which level you need, and which parts of your business are in scope. Scope is where cost is decided. A certification covering one segregated project environment is a different exercise from one covering your whole estate, and the difference is often six figures of effort over the life of the contract.

How the levels work

DCC is tiered, and the tier is driven by the risk profile assigned to the work rather than by the size of your company. A low-risk contract carries a lower level with fewer requirements. More sensitive work carries a higher level, and the requirements are cumulative: a higher level includes everything below it and adds to it.

Level 2 is the one most small and medium suppliers are asked for, and it is a substantial step up from a questionnaire. It runs to roughly 149 individual requirements. That number alarms people until they see the shape of it: many requirements are small, several are satisfied by one piece of configuration, and a well-run IT estate will already meet a meaningful share of them without knowing it. The work is usually less about buying things and more about proving things.

What Level 2 actually asks for

The requirements group into recognisable themes. In rough order of how much trouble they cause suppliers who have not done this before:

  • Governance and risk management. A named owner, a risk assessment that is reviewed rather than written once, and documented policies that match what you actually do.
  • Asset management. An inventory of hardware, software and data that is current. This is the single most common failure, because most organisations have an inventory that was accurate on the day it was made.
  • Identity and access control. Multi-factor authentication, least privilege, separated administrative accounts, and a joiners-movers-leavers process that is evidenced.
  • Secure configuration and vulnerability management. Hardened builds, removal of default credentials, and patching within defined timeframes, with the scan results to show it.
  • Logging and monitoring. Collecting security-relevant logs, retaining them for a defined period, and being able to demonstrate that somebody looks at them.
  • Incident management, backup and resilience. A response plan, tested backups, and evidence that the test happened.
  • People and physical security. Screening appropriate to the role, security awareness training, and control of physical access to the areas where defence information is handled.
  • Supply chain. Your own suppliers, and what you require of them.

The supply chain requirements catch people out

DCC does not stop at your perimeter. It asks how you assess the security of the suppliers you pass defence information to, what you require of them contractually, and how you know they are still meeting it. If your subcontractor list lives in an accounts system and nobody has ever assessed any of them, this is the part that takes longest, because you cannot complete it alone. You are dependent on other organisations answering questions, and they are not in a hurry.

Start it first. Sending supplier assessments in week one, while you fix your own controls in parallel, is the difference between a three-month programme and a six-month one.

How it relates to Cyber Essentials and ISO 27001

Cyber Essentials remains the baseline for most MOD contracts and is a sensible first step, but it is not a substitute. Its five technical control themes - firewalls, secure configuration, security update management, user access control and malware protection - cover a slice of what DCC asks for and nothing of the governance, logging, incident response or supply chain requirements.

ISO 27001 pulls in the other direction. If you already run a certified information security management system, you will have the governance, risk treatment and internal audit evidence that DCC wants, and you will find the gap is mostly in the specific technical requirements and the defence-specific handling of information. Neither certification maps to DCC one-for-one, but neither is wasted effort. Most suppliers who hold both find they are two-thirds of the way there.

How long it takes

It depends on your starting point, and the honest variables are these: whether you have a real asset inventory, whether multi-factor authentication is deployed everywhere rather than mostly, whether you retain logs, whether your policies describe your actual practice, and whether anyone has ever assessed a supplier. A supplier with Cyber Essentials, managed endpoints and Microsoft 365 configured properly is usually looking at two to four months of remediation. A supplier with none of that, and a mixture of unmanaged devices, should plan for longer.

A gap analysis against the requirement set takes one or two days of someone’s attention and is worth doing before you commit to a date with a customer. The assessment itself is short compared with the preparation, which is the usual shape of these things.

What to do this week

Get the contract clause in writing and confirm the level. Agree the scope boundary and write it down. Build or refresh the asset inventory, because every other requirement refers back to it. Name one person as owner. Then run the requirement list as a gap analysis and sort it into three piles: already met and evidenced, already met but not evidenced, and not met. The middle pile is usually the largest, and it is the cheapest to clear.

Apexward Assure tracks the Defence Cyber Certification Level 2 requirement set alongside Cyber Essentials and ISO 27001 in a single compliance programme, so evidence gathered for one counts against the others rather than being collected twice, and supplier assessments run through login-free portals in the organisation module. The platform is free, so finding out whether it fits your programme costs nothing beyond the time it takes to scope it.