Logo Transparent
Organisation-wide cyber resilience assurance for suppliers in the defence sector

What is Defence Cyber Certification

Defence Cyber Certification (DCC) is an organisation-wide cyber security certification designed specifically for suppliers operating within the UK defence sector. Established by the UK Ministry of Defence (MOD) in partnership with IASME, the scheme forms part of a wider programme aimed at strengthening cyber resilience across the defence supply chain.

The certification focuses on the maturity and effectiveness of an organisation’s overall cyber security posture, providing a single, recognised assurance at the organisational level. This assurance can be used to support participation in UK defence procurement activities.

Achieving and maintaining DCC certification demonstrates a sustained commitment to robust cyber security practices and continuous improvement, supporting the long-term resilience and security of the UK defence ecosystem.

The Defence Standard

The Defence Cyber Security Standard (Def Stan 05-138) sits at the heart of the DCC programme. Its latest release, Issue 4, represents a major evolution—broadening its focus from simply safeguarding MOD-identifiable data to strengthening an organisation’s overall cyber resilience.

This enhanced standard sets out the security measures required from suppliers at each stage of the Cyber Risk Profile. It has been designed to align with recognised national and international frameworks, including the CAF, as well as NIST and ISO standards.

Defence Cyber Certification Scope

The scope of your DCC assessment must include all processes, systems and business parts that are required for the business to function and deliver in a secure and resilient manner. 

KEYSIGMA will work closely with you to define the right scope before submission, ensuring nothing critical is missed and your assessment is neither under-scoped nor at risk of rejection.

Strengthening Cyber Essentials foundations

The DCC scheme provides defence suppliers with a trusted, recognised way to demonstrate cyber maturity to the MOD. Certification is awarded through a comprehensive, point-in-time assessment against the Defence Cyber Certification standard, giving assurance that your organisation meets the security expectations required to operate in the defence supply chain.

All organisations start with Cyber Essentials, with Levels 2 and 3 progressing to Cyber Essentials Plus. 

Defence Cyber Certification is available in four levels:

Aligned to MOD Requirements

Every new MOD contract is assigned a Cyber Risk Profile level, which defines the cyber controls a supplier must meet. The DCC scheme verifies that those requirements have been satisfied.

Crucially, suppliers can certify at any level, meaning you can demonstrate readiness ahead of bidding. Once certified, you will not need to undergo repeat assessments for future contracts at the same or lower level, saving time and accelerating opportunity

Level 0: Applies where cyber risk is minimal and requires organisations to demonstrate essential cyber hygiene, forming the foundation for all higher levels.

Level 1: Is used when risk is low to moderate and expects suppliers to operate a comprehensive, well-managed cyber security programme.

Level 2: Is assigned where risk is high and requires advanced oversight, mature governance and proactive planning that strengthen organisational resilience.

Level 3: Covers substantial cyber risk and demands expert capability, using a full defence-in-depth approach to protect against sophisticated and evolving threats.

 

Level 0

Essential cyber hygiene for suppliers supporting contracts with minimal cyber risk.
Learn More

Level Zero

3 Controls

Level 2

Mature oversight, governance and proactive planning for high-risk delivery.

Level Two

139 Controls

Level 1

Essential cyber hygiene for suppliers supporting contracts with minimal cyber risk.
Learn More

Level One

101 Controls

Level 3

Demonstrates advanced, defence-in-depth capability suitable for substantial cyber risk suppliers.

Level Three

144 Controls

How KEYSIGMA Supports You

To protect the integrity of the scheme, DCC rules state that Certification Bodies may offer advice, but they cannot implement controls or carry out any work they will later assess.

To give you complete flexibility, KEYSIGMA provides two clear routes:

Implementation Support – We can help you plan, build and implement the controls needed to meet the DCC standard, engaging a trusted, independent partner certificaiton body to conduct the assessment independently.

Independent Certification – When you’re ready, we can arrange and deliver your DCC assessment and certification.

Whether you need help achieving compliance, require certification, or both, KEYSIGMA ensures the right expertise is in place, without compromising impartiality.

Schedule a free 30 minute consultation with a KEYSIGMA Defence Cyber Certification Specialist