Defence Cyber Certification: Is your business ready?
24th September 2026
“Cyber security is becoming an increasingly important requirement across the defence sector. The MoD has encouraged organisations across the defence supply chain to achieve Defence Cyber Certification, and businesses that understand and address its requirements will be better placed to secure defence work and navigate evolving compliance expectations.”
Paul Armstrong, Director, Commercial, Digital & Technology Team
Cyber security has become a critical issue for organisations operating in the defence sector. As cyber threats continue to evolve, the UK’s Ministry of Defence (MoD) is strengthening its approach to supply chain security by implementing the Defence Cyber Certification (DCC), a cyber assurance framework for defence suppliers. Developed in partnership with IASME, DCC is designed to provide greater confidence in the cyber resilience of organisations across the defence supply chain.
In this article, we explain why DCC has been introduced, who it is likely to affect, and what businesses should be doing now to prepare for future defence procurement requirements.
Why is cyber security becoming such a priority in the defence sector?
Over the last few years cyber security has become increasingly important across all sectors. Whilst cyber security is now a major concern for businesses generally, it is particularly important for organisations involved in defence procurement and delivery.
Larger organisations may have extensive security measures, but vulnerabilities elsewhere in their supply chains can provide alternative routes for cyber attacks. The MOD’s approach, therefore, places increasing emphasis on organisational resilience throughout the defence supply chain.
The MoD recognises that the security of a defence programme can be undermined through smaller suppliers that provide components, services or specialist expertise. A business manufacturing a relatively small component may nevertheless have access to sensitive information, systems or networks that make it an attractive target.
As a result, the MoD’s cyber security strategy is increasingly focused on strengthening resilience across the entire supply chain rather than concentrating solely on prime contractors.
What is Defence Cyber Certification?
DCC is a cyber security certification framework developed by the MoD and delivered through IASME. It is designed to provide an independent assessment of an organisation’s cyber resilience and forms part of a wider programme to improve cyber security throughout the UK defence sector.
DCC is an organisation-wide certification that can be presented in support of UK defence procurements. This should provide more consistent and reusable assurance than relying exclusively on bespoke assessments for each opportunity.
The framework aligns with the MoD’s updated Cyber Security Model Version 4 (CSMv4), which represents a broader shift towards organisational cyber resilience and supply chain assurance.
How does the certification framework work?
DCC operates across four certification levels, ranging from Level 0 to Level 3. The level required will depend on the cyber risk associated with the relevant defence activity or contract.
The framework builds on existing cyber security standards that many organisations will already be familiar with. All certification levels require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus. Organisations must demonstrate compliance with a prescribed set of cyber security controls and provide supporting evidence as part of the assessment process.
Certification is valid for three years, although organisations must complete annual attestations to maintain their status.
Why should businesses be paying attention now?
The MoD has asked all industry partners to achieve Level 0 of the DCC by 31st December 2026, which includes the requirement to obtain Cyber Essentials for all applicable business-critical systems within scope. The MoD has also stated that suppliers should expect to see increasing requirements to hold valid certification as a condition of defence procurement and contract performance.
This is particularly relevant for organisations further down the supply chain. Many businesses do not consider themselves “defence contractors” because they do not contract directly with the MoD. However, suppliers of components, software, manufacturing services, engineering expertise or professional services may still find that DCC requirements flow down through contractual arrangements.
Businesses should therefore be considering:
Whether they currently form part of a defence supply chain.
What cyber security certifications do they already hold?
Whether additional controls may be needed to meet DCC requirements.
How cyber security obligations are allocated through their customer and supplier contracts.
Whether future tender opportunities are likely to require certification.
Organisations that are prepared are likely to be better placed to respond to future procurement opportunities and customer requirements.
How can we help?
The DCC reflects the MoD’s growing focus on cyber resilience throughout the defence supply chain. While the framework is rooted in cyber security, its implications extend beyond technical compliance and into procurement, contracting, risk management and supply chain governance.
For many businesses, the key challenge is understanding whether DCC applies to them and what practical steps are needed to prepare for future requirements. Organisations should identify potential gaps, review contractual obligations and position themselves for future defence opportunities.
If you’d like to discuss how DCC could affect your business, or need broader support managing the legal and commercial issues arising from cyber security requirements in the defence sector, we would be happy to help.
Our Clients
Resources
Services
Defence Cyber Certification: Is your business ready?
24th September 2026
“Cyber security is becoming an increasingly important requirement across the defence sector. The MoD has encouraged organisations across the defence supply chain to achieve Defence Cyber Certification, and businesses that understand and address its requirements will be better placed to secure defence work and navigate evolving compliance expectations.”
Cyber security has become a critical issue for organisations operating in the defence sector. As cyber threats continue to evolve, the UK’s Ministry of Defence (MoD) is strengthening its approach to supply chain security by implementing the Defence Cyber Certification (DCC), a cyber assurance framework for defence suppliers. Developed in partnership with IASME, DCC is designed to provide greater confidence in the cyber resilience of organisations across the defence supply chain.
In this article, we explain why DCC has been introduced, who it is likely to affect, and what businesses should be doing now to prepare for future defence procurement requirements.
Why is cyber security becoming such a priority in the defence sector?
Over the last few years cyber security has become increasingly important across all sectors. Whilst cyber security is now a major concern for businesses generally, it is particularly important for organisations involved in defence procurement and delivery.
Larger organisations may have extensive security measures, but vulnerabilities elsewhere in their supply chains can provide alternative routes for cyber attacks. The MOD’s approach, therefore, places increasing emphasis on organisational resilience throughout the defence supply chain.
The MoD recognises that the security of a defence programme can be undermined through smaller suppliers that provide components, services or specialist expertise. A business manufacturing a relatively small component may nevertheless have access to sensitive information, systems or networks that make it an attractive target.
As a result, the MoD’s cyber security strategy is increasingly focused on strengthening resilience across the entire supply chain rather than concentrating solely on prime contractors.
What is Defence Cyber Certification?
DCC is a cyber security certification framework developed by the MoD and delivered through IASME. It is designed to provide an independent assessment of an organisation’s cyber resilience and forms part of a wider programme to improve cyber security throughout the UK defence sector.
DCC is an organisation-wide certification that can be presented in support of UK defence procurements. This should provide more consistent and reusable assurance than relying exclusively on bespoke assessments for each opportunity.
The framework aligns with the MoD’s updated Cyber Security Model Version 4 (CSMv4), which represents a broader shift towards organisational cyber resilience and supply chain assurance.
How does the certification framework work?
DCC operates across four certification levels, ranging from Level 0 to Level 3. The level required will depend on the cyber risk associated with the relevant defence activity or contract.
The framework builds on existing cyber security standards that many organisations will already be familiar with. All certification levels require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus. Organisations must demonstrate compliance with a prescribed set of cyber security controls and provide supporting evidence as part of the assessment process.
Certification is valid for three years, although organisations must complete annual attestations to maintain their status.
Why should businesses be paying attention now?
The MoD has asked all industry partners to achieve Level 0 of the DCC by 31st December 2026, which includes the requirement to obtain Cyber Essentials for all applicable business-critical systems within scope. The MoD has also stated that suppliers should expect to see increasing requirements to hold valid certification as a condition of defence procurement and contract performance.
This is particularly relevant for organisations further down the supply chain. Many businesses do not consider themselves “defence contractors” because they do not contract directly with the MoD. However, suppliers of components, software, manufacturing services, engineering expertise or professional services may still find that DCC requirements flow down through contractual arrangements.
Businesses should therefore be considering:
Organisations that are prepared are likely to be better placed to respond to future procurement opportunities and customer requirements.
How can we help?
The DCC reflects the MoD’s growing focus on cyber resilience throughout the defence supply chain. While the framework is rooted in cyber security, its implications extend beyond technical compliance and into procurement, contracting, risk management and supply chain governance.
For many businesses, the key challenge is understanding whether DCC applies to them and what practical steps are needed to prepare for future requirements. Organisations should identify potential gaps, review contractual obligations and position themselves for future defence opportunities.
If you’d like to discuss how DCC could affect your business, or need broader support managing the legal and commercial issues arising from cyber security requirements in the defence sector, we would be happy to help.
How the Defence Investment Plan could reshape the UK’s economy
Closing the AI gender gap in retirement and healthcare
Technology & Digital round-up: August 2026
Greenwashing and Consumer Protection: What businesses need to know
Legal Horizon August 2026
Paul
Armstrong
Director
Commercial
Paul 's contact details
paul.armstrong@walkermorris.co.uk
Della
Heptinstall
Defence Sector Lead
Associate
Della 's contact details
della.heptinstall@walkermorris.co.uk
Paul
Armstrong
Director
Commercial
Paul 's contact details
Email me
Della
Heptinstall
Defence Sector Lead
Associate
Della 's contact details
Email me