Published 24/09/2026 – est. 6 minutes to read.
Navigating the MOD’s New Verification Standard for Defence Suppliers
Securing the UK defence supply chain has never been more strategically important. With hostile nation-states and sophisticated threat actors continuously targeting tier-2 suppliers, sub-contractors, and engineering partners to penetrate sovereign programmes, paper-based compliance is no longer fit for purpose.
To establish verifiable cyber resilience across the defence industrial base, the Ministry of Defence (MOD), in partnership with the IASME Consortium, has introduced the Defence Cyber Certification (DCC) scheme.
Built on Defence Standard 05-138 (Def Stan 05-138), the DCC scheme marks a fundamental evolution: moving from subjective Supplier Assurance Questionnaires (SAQs) and Cyber Implementation Plans (CIPs) to an independent, evidence-based certification framework.
For prime contractors, mid-tier manufacturers, and specialised sub-contractors bidding for or delivering MOD contracts, understanding the DCC scheme is essential to remain procurement-eligible and retain contracts.
What is Defence Cyber Certification (DCC)?
The Defence Cyber Certification scheme provides a single, organisation-level assurance framework that suppliers present during UK defence procurements.
While Def Stan 05-138 specifies the technical and organisational security controls required based on a contract’s assessed risk, the DCC scheme introduces a formal audit mechanism to prove those controls are implemented, maintained, and operating effectively.
Certified organisations complete an annual check-in to confirm control hygiene, alongside a full re-certification assessment every three years.
The 4 Levels of DCC Compliance
The DCC scheme is structured across four progressive levels of cyber maturity, ranging from Level 0 (Basic) to Level 3 (Expert). The level an organisation requires is determined directly by the Cyber Risk Profile (CRP) assigned to the MOD contract or tender.
Level 0: Basic Assurance
Designed for suppliers associated with very low assessed cyber risk contracts:
- Scope: Written scope covering the 3 core Def Stan controls evaluated across 6 questions. If you fail to provide a written scope, it is an automatic fail.
- Prerequisites: A valid Cyber Essentials certificate.
- Requirement: 100% compliance pass mark. Focuses on foundational data protection baselines and UK GDPR compliance.
Level 1: Moderate Assurance
Aimed at organisations handling MOD identifiable information with low-to-moderate risk profiles:
- Scope: 101 controls evaluated across 236 questions.
- Prerequisites: A valid Cyber Essentials certificate.
- Requirement: Minimum 80% pass threshold per control objective, including annual external penetration testing.
Level 2: High Assurance
Applies to suppliers with high-risk contracts handling sensitive operational or technical data:
- Scope: 139 controls evaluated across 328 questions.
- Prerequisites: A valid Cyber Essentials Plus certificate (involving hands-on technical auditing).
- Requirement: Minimum 80% pass threshold per control objective, requiring automated asset discovery and robust network segmentation.
Level 3: Expert Assurance
Reserved for critical defence programmes and suppliers managing highest-tier sensitive defence assets:
- Scope: 144 controls (the complete Def Stan 05-138 framework) across 337 questions.
- Prerequisites: A valid Cyber Essentials Plus certificate.
- Requirement: 100% implementation across all controls, encompassing active threat intelligence capabilities and continuous perimeter monitoring.
The 4 Control Objectives of Def Stan 05-138
DCC audits assess security capabilities across the four core objectives defined within Def Stan 05-138:
- Objective A – Managing Security Risk: Establishing formal governance, board-level risk ownership, threat modelling, and supply chain due diligence.
- Objective B – Protecting Against Cyber Attack: Implementing robust technical perimeters, strict access controls, identity management (MFA), patch cycles, and endpoint hardening.
- Objective C – Detecting Cyber Events: Deploying centralised intrusion detection systems (IDS), security logging, and real-time telemetry monitoring to identify unauthorised network activity.
- Objective D – Minimising the Impact of Security Incidents: Maintaining tested disaster recovery protocols, immutable offline backups, and incident response playbooks aligned with defence reporting obligations.
7-Step Implementation: The Roadmap to DCC Certification
Achieving DCC certification requires an evidence-led implementation strategy. Organisations should follow this structured roadmap:
- Identify the Cyber Risk Profile (CRP): Review current MOD contracts and tender documentation to verify the exact CRP and corresponding DCC target level.
- Attain Cyber Essentials / Plus: Secure the required baseline certificate through an accredited Certification Body before initiating formal DCC audit steps.
- Conduct a Technical Gap Analysis: Benchmark existing technical controls, policies, and operational processes against the Def Stan 05-138 question set for your designated level.
- Compile Evidential Documentation: Assemble auditable technical artefacts—including patch management reports, RBAC logs, MFA configurations, incident response test records, and CREST penetration test findings.
- Review Downstream Suppliers: Defence primes and sub-contractors must ensure lower-tier suppliers handling contract data are also aligned with the necessary assurance baselines.
- Undergo DCC Assessment: Complete the formal assessment through an accredited Certification Body to validate compliance and remediate identified technical observations.
- Maintain Active Certification: Maintain continuous control hygiene, completing annual check-ins and preparing for full re-certification every three years.
Safeguarding MOD Programme Eligibility
Self-assessment is no longer sufficient to secure defence supply chains. By achieving formal Defence Cyber Certification, organisations validate their cyber maturity, protect sovereign data assets, and establish the high-assurance compliance needed to bid confidently for MOD contracts.
Achieve Defence Cyber Certification with Cyber Security Specialists
Cyber Security Specialists is an accredited Certification Body delivering end-to-end guidance, technical auditing, and readiness assessments for defence suppliers across the UK.
- CRP & Level Scoping: Determining exact contract requirements and Cyber Risk Profiles.
- Cyber Essentials & Plus Certification: Fast-track delivery of prerequisite foundational certifications.
- Def Stan 05-138 Gap Analysis & Remediation: Comprehensive technical reviews to identify and close compliance vulnerabilities before formal audit.
- CREST Penetration Testing: High-assurance security validation satisfying Def Stan testing mandates.
- Formal DCC Auditing: Independent verification delivering Level 0 through Level 3 certification.
To start your Defence Cyber Certification, or discuss our other services, connect directly with our technical team:
Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk
