You have had the letter
It came from procurement at your prime, or from a contracts manager you have dealt with for years. It says that all suppliers are expected to hold Defence Cyber Certification Level 0 by 31 December 2026, and it may ask you to confirm your plan by a date that is uncomfortably close. There is probably no explanation attached, and the person who sent it may not be able to tell you much more than the deadline.
If you supply into defence at any tier, read this before you reply. Most of what has been written about Defence Cyber Certification is aimed at compliance teams inside large primes, not at a forty person engineering, software or services business with no security team. This is the plain English version: what the scheme is, what the Ministry of Defence has actually asked for in its own words, what the four levels mean, why it reaches you even if MOD is not your customer, and what to do this month.
We have written before about what to do when a prime asks you for Cyber Essentials. Treat this as the sequel, because Cyber Essentials turns out to be the first thing Defence Cyber Certification asks for.
What Defence Cyber Certification is
Defence Cyber Certification, usually shortened to DCC, is an organisation-wide cyber security certification for suppliers to the UK Ministry of Defence. It was developed by MOD with IASME and launched on 8 May 2025. IASME runs it through licensed certification bodies.
MOD manages supply chain cyber risk through its Cyber Security Model, now at version 4. The controls a supplier must meet are set out in a defence standard, Def Stan 05-138 Issue 4, published in May 2024. The clause that puts those controls into your contract is DEFCON 658. DCC is the assurance route for all of that: the recognised way of proving, to MOD or to your prime, that the controls in Def Stan 05-138 are in place.
Three things about it matter more than the rest.
It is organisation-wide. The scope is your business's essential functions: corporate IT, user identities, endpoints, connectivity, cloud services, backup and continuity. You cannot carve out the team that does the MOD work and certify only that, and a standalone software product cannot satisfy the scope on its own.
It is independently assessed. Every level is verified by a certification body licensed by IASME. It is not a self-assessment you sign and file.
It lasts three years. The certificate comes with an annual attestation in years one and two, and the Cyber Essentials certificate beneath it has to be renewed every year throughout.
What MOD has actually asked, in its own words
The word MOD uses is asked, and we will come back to why that word is less comforting than it sounds. First, the ask itself.
On 8 May 2026, Eleanor Fairford, MOD's Director of Cyber Defence and Risk, wrote on the Defence Digital blog: "I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope."
That is where the date in your letter comes from. It is addressed to all industry partners, not only the primes.
On 13 July 2026 the same blog set out how the ask should move down the chain. Primes should push Level 0 to their subcontractors and set timescales for them. Higher levels come later: "where higher levels of certification are required at lower tiers in the supply chain, these should be scheduled for delivery after 31 December 2026." And to anyone below a prime: "If you are a subcontractor to a Prime, engage with your Prime and discuss what level you should be looking to achieve."
Read the two posts together and the picture is clear. Level 0 is the December priority for the whole supply chain. Level 1 and above at lower tiers is a 2027 conversation. If your letter asks for Level 1 by December, that is a question to put back to your prime, politely, with the July guidance in hand.
The four levels in plain English
DCC has four levels. Which one you need is set by the Cyber Risk Profile attached to your contract, which grades the cyber risk of that piece of work from very low to high. You do not choose your level. A certificate at a higher level satisfies every lower one.
Level 0, Basic, is for very low risk contracts and is the December baseline for everyone. It has three controls and six questions, and the prerequisite is a current Cyber Essentials certificate. All three controls must be fully met. Assessment is a documentation-led review.
Level 1, Foundational, is for low to moderate risk contracts. It has 101 controls, again on top of Cyber Essentials. This is the level typically expected of IT support providers, software companies, training and consultancy firms and logistics suppliers with some access to MOD systems or OFFICIAL data. Assessment adds interviews, demonstrations and a review of operational evidence: how you actually do things, not what your policy says you do.
Level 2, Advanced, is for moderate to high risk contracts. It has 139 controls and the prerequisite steps up to Cyber Essentials Plus. Assessment adds hands-on technical verification.
Level 3, Expert, is for high risk contracts. It has 144 controls, requires Cyber Essentials Plus, and is where the primes and critical suppliers sit. Lockheed Martin UK was the first defence company to reach it, in July 2026.
For most suppliers of 10 to 100 people, Level 0 is now and Level 1 is next. Levels 2 and 3 belong to a different kind of business.
Why it reaches you even if MOD is not your customer
Many of the businesses receiving these letters have never held an MOD contract. So why does it land on them?
Because DEFCON 658 flows down. When the clause sits in a prime's contract with MOD, the cyber controls behind it are passed to the subcontractors doing the work, and on again below them. If DEFCON 658, or a DCC requirement, is in your subcontract, the controls in Def Stan 05-138 are contractual for you, whoever your invoice goes to.
Industry Security Notice 2026/02, issued by MOD on 30 March 2026, changed that. It instructs MOD buyers that a supplier holding current, valid DCC at a level equal to or above the contract's required level "is to be considered in satisfaction of the control requirement to DEFSTAN 05-138 (Issue 4, onwards), as specified under DEFCON 658". In plain terms, DCC is now the recognised proof.
That is why the word asked is less comforting than it sounds, and why primes have little room to waive it. Negotiating it away is not realistic. Planning for it is.
What Level 0 involves
Level 0 is deliberately small: three controls from Def Stan 05-138 Issue 4. For a business that already runs its IT reasonably well, none of them is exotic. Each has a detail that trips people.
The first control is Cyber Essentials. You need a current certificate covering every internet-connected device inside the DCC scope, plus a commitment to keep it current for the full three-year DCC period. The catch is scope. If your certificate covers a subset of the business and your DCC scope is the whole organisation, which it will be, the mismatch is an automatic fail. If you are not yet certified, or you are not sure what yours covers, Cyber Essentials is where the work starts.
The second control is UK GDPR and data protection. The assessor wants documented data protection policies, simplified for micro and small businesses, your ICO registration, and evidence that you have a process for Data Protection Impact Assessments. Most firms have some of this. Fewer have all of it written down and current.
The third control is business resilience, and this is the one we expect to catch most small firms out. You need a documented assessment of your resilience needs that names your essential systems and the cyber risks to them, and then evidence that the protective measures actually run: backup logs, reports from tested restores, records of redundancy. A backup policy is not evidence. A backup job that has never been restored is not evidence. The assessor wants proof that you could recover.
One structural point. DCC requires a named individual responsible for cyber security. In a small firm that is often the MD or the operations manager by default. Make it explicit.
Does it replace the Supplier Assurance Questionnaire?
Not yet. If you have completed a Supplier Assurance Questionnaire through the Supplier Cyber Protection Service for previous contracts, expect to keep doing so. DCC sits alongside it as assured, independently verified evidence of the controls the questionnaire asks about.
What to do this month
There are four months left. Whether that is enough depends on where you start, and it gets less likely with every week you wait. Here is the order we would work in.
Get the requirement in writing. Not a forwarded email with a date on it, the actual clause or letter. You need to know whether it cites DEFCON 658, whether it names a DCC level, and what the deadline is.
Ask your prime for the level and the Cyber Risk Profile. If the letter does not say, the prime should, and asking positions you as a supplier with a plan. A reply along these lines is enough:
"Thank you for the notification regarding Defence Cyber Certification. We are working towards DCC Level 0 in line with the MOD's 31 December 2026 ask and will confirm our target date once our readiness review is complete. Could you confirm the certification level and Cyber Risk Profile that apply to our contract, and whether a higher level is anticipated after December?"
Check your Cyber Essentials scope. If it is a subset, or it has lapsed, or you never had one, that is your critical path and it starts today.
Name an owner. One person, with the authority to get things done, who will be the named individual on the submission. Cyber security by committee misses deadlines.
Start on the resilience evidence now. This is the control that cannot be produced in a hurry, because it depends on tests you have to run and logs you have to accumulate. Test a restore this month. Write down what you found.
Book the certification body early. There is no fixed timescale for DCC: how long it takes depends on your preparedness, the gaps you need to close and assessor availability. Every supplier has the same December date, and certification body capacity is expected to tighten in the final quarter of the year. Book in September, not December.
On cost, the question everyone asks first, there are three components. The certification body sets its own assessment fee, since IASME does not set DCC fees. The Cyber Essentials prerequisite is a cost in its own right if you do not hold it or need to re-scope. And remediation, closing whatever the readiness review finds, is the real variable and cannot honestly be estimated before someone has looked.
Where we fit
HGC IT Solutions is a UK managed service provider based near Dorchester, working with businesses nationwide, and we already support businesses in the defence supply chain. For Defence Cyber Certification we do the part between the letter and the certificate: scope the work against your contract, get Cyber Essentials in place or re-scoped to match, close the data protection and resilience gaps, build the evidence pack, and manage the assessment through CyberSmart, an IASME-accredited DCC certification body for Levels 0 and 1. Then we keep you current through the annual attestations and the yearly Cyber Essentials renewal. The detail is on our Defence Cyber Certification page.
To be clear about roles: HGC does not issue, assess or certify DCC. The certificate comes from the certification body. We prepare, remediate, evidence and deal with the assessor so you do not have to. We hold Cyber Essentials ourselves, and we are a Microsoft Cloud Solution Provider (CSP) partner, which matters when Microsoft 365 is a large part of your scope. If your contract points to Level 2 or 3 we will say so and point you to a specialist. If your December date is not realistic from where you are starting, we will tell you on the first call, not in November. Send us the wording of your letter and we will tell you what it means and what it will take.