Defence Cyber Certification

Defence Cyber Certification for MOD Suppliers and Subcontractors

From Cyber Essentials to DCC Level 0 before the December deadline. Kept current for the full three-year cycle.

Your prime contractor, or the Ministry of Defence itself, has asked for Defence Cyber Certification and given you a date. DCC is the MOD's supply-chain assurance scheme, and Level 0 is what every industry partner has been asked to hold by 31 December 2026. It starts from Cyber Essentials, adds data protection and tested business resilience, and is verified by an independent certification body rather than a form you fill in yourself. HGC scopes it, closes the gaps, builds the evidence and manages the assessment, then keeps you compliant through the annual attestations that follow. We already support businesses in the defence supply chain, and we work with suppliers across the UK.

  • Cyber Essentials certified ourselves
  • Microsoft CSP Cloud Solution Provider partner
  • UK team remote first, nationwide
  • 3 years kept current through every attestation

Book a DCC readiness call Download the DCC Level 0 readiness checklist

Engineer in a UK precision engineering workshop reviewing a Defence Cyber Certification checklist on a laptop

Who assesses and issues your certificate

HGC prepares, remediates and evidences. Your Defence Cyber Certification is assessed and issued by CyberSmart, an IASME-accredited DCC certification body for Levels 0 and 1, which is the same accredited route we use for Cyber Essentials. You deal with one UK team throughout: we do the work that gets you there and the work that keeps you there.

Why Defence Suppliers Need DCC Now

Defence Cyber Certification arrived in May 2025 and became urgent in 2026. If any of these sound familiar, this is the pressure we take off your desk.

The December 2026 ask

The Ministry of Defence has asked all industry partners to achieve Level 0 Defence Cyber Certification by 31 December 2026, including Cyber Essentials for all applicable business-critical systems in scope. Prime contractors are now passing that ask down to every tier, and certification body capacity will tighten as the date approaches.

It flows down whether or not you contract with MOD directly

If DEFCON 658 sits in your subcontract, the cyber security controls in Def Stan 05-138 are a contractual obligation, and DCC is now the recognised way to evidence them. Your prime has very little room to waive a condition that MOD placed on them. The requirement reaching you from three tiers up is normal, and negotiating it away is not realistic.

Cyber Essentials is the first control, and the scope has to match

The first Level 0 control is a current Cyber Essentials certificate covering every internet-connected device inside your DCC scope. A certificate that covers a subset of the business, or that has lapsed, fails that control outright. Many suppliers who "already have Cyber Essentials" discover the scope does not line up.

A backup policy is not evidence

Level 0 asks for a documented resilience assessment that names your essential systems, and then for proof the protection actually runs: backup logs, tested restore reports, redundancy records. A policy document on its own does not pass. This is the control that catches otherwise well-run firms.

Level 1 is coming for many of you in 2027

IT support providers, software suppliers, consultancies, trainers and logistics firms with access to MOD systems or OFFICIAL data are typically assigned Level 1: 101 controls, verified by interview, demonstration and review of operational evidence. MOD has said higher levels at lower tiers should be scheduled after December 2026, so Level 0 now is the sensible first step.

Nobody in the business owns it

DCC needs a named individual responsible for cyber security, current data protection paperwork and a working relationship with a certification body. In a thirty-person engineering firm that usually lands on the operations or quality manager, on top of the day job. We take the coordination, the evidence and the assessment liaison off that desk.

How HGC Gets You to Defence Cyber Certification

We cover Level 0 and Level 1. If your contract points to Level 2 or 3 we will say so on the first call and help you scope Cyber Essentials Plus, which is the prerequisite either way. Everything starts with a short readiness call, so you know what is needed before you commit to anything.

Scope and level check

Which tier you sit in, what your prime has actually asked for in writing, which level your contract's Cyber Risk Profile points to, and which systems are in scope. We help you ask your prime the right questions and get the answers on record before any work starts.

Cyber Essentials first, scoped to match

Achieve Cyber Essentials, or re-scope the certificate you hold, so it covers every internet-connected device inside the DCC boundary. This is the control that underpins every level, and it is the one we already run every day for the businesses we look after.

Data protection evidence

ICO registration, UK GDPR policies sized to your business rather than copied from a corporate template, and a Data Protection Impact Assessment procedure with a template you can actually use. Written once, kept current, ready for the assessor.

Business resilience you can prove

A resilience needs assessment naming your essential systems and their cyber risks, backups that are tested with the restore logs to show it, and continuity documentation that reflects how the business really runs. Our managed cloud backup produces this evidence as a by-product of working properly.

Assessment managed end to end

We assemble the evidence pack, handle the submission and liaise with CyberSmart, the IASME-accredited certification body, through the assessment. You answer questions about your business; we handle the questions about the controls.

Kept current for three years

A DCC certificate lasts three years with an annual attestation in between, and Cyber Essentials has to be renewed every year throughout. We keep the controls and the evidence in the passing state so each attestation is a formality, and we are ready when your prime asks for Level 1.

Why Choose HGC for Defence Cyber Certification

Specialist defence consultancies can certify you. What they cannot do is run your IT. Our advantage is that the evidence DCC asks for exists because the work is already being done, not because it was written for the audit.

We already run the controls DCC checks

Patching, multi-factor authentication, backups, Microsoft 365 configuration and device management are what we operate every day for the businesses we manage. For a DCC assessment that means configuration records, backup logs and access controls that already exist, rather than a scramble to create them.

We hold Cyber Essentials ourselves

The first DCC control is Cyber Essentials, and we have been through that certification for our own business. We know the scoping questions, the evidence and the renewal cycle from the inside, and we hold ourselves to the same standard we set for you.

Microsoft Cloud Solution Provider (CSP) partner

The identity, access and secure configuration controls in Def Stan 05-138 live inside your Microsoft 365 tenant. As a Microsoft Cloud Solution Provider partner we configure and manage that tenant directly, so the controls you are assessed against are ones we own, not ones we describe.

You deal with HGC, not a portal

One relationship and one accountable UK team. CyberSmart is the IASME-accredited certification body that assesses and issues your Defence Cyber Certification, and we manage the whole process with them on your behalf. Think of us as your accountant and CyberSmart as the system we file through.

We already support the defence supply chain

We support businesses in the defence supply chain today, and we are based near Dorchester, in the middle of the Bovington, Blandford, Portland and Winfrith defence footprint. We deliver remotely first, to suppliers anywhere in the UK, with local visits where they are useful.

Straight answers on level and timing

If your contract needs Level 2 or 3, we will tell you and point you to a specialist rather than stretch. If December is not realistic for where you are today, we will tell you that too, and help you show your prime a credible plan instead.

Defence Cyber Certification: Frequently Asked Questions

Plain answers to what MOD suppliers and subcontractors ask us most.

What is Defence Cyber Certification?

Defence Cyber Certification (DCC) is the UK Ministry of Defence's cyber security certification for its suppliers, developed with IASME and launched in May 2025. It has four levels, from Level 0 to Level 3, matched to the Cyber Risk Profile of each contract. It is the way suppliers evidence the controls in Def Stan 05-138 Issue 4 that DEFCON 658 places in defence contracts, and it is assessed by an independent, IASME-accredited certification body rather than by self-assessment alone.

Is Defence Cyber Certification mandatory?

Not in law. The Ministry of Defence has asked all industry partners to achieve Level 0 by 31 December 2026, and MOD buyers have been instructed to accept a valid DCC certificate as satisfying the Def Stan 05-138 controls required under DEFCON 658. Where DEFCON 658 is in your contract or subcontract, the underlying controls are already a contractual obligation, and DCC is the recognised way to prove you meet them. In practice, if your prime has asked, you need it.

What does DCC Level 0 require?

Three controls, all of which must be fully met. First, a current Cyber Essentials certificate that covers every internet-connected device inside your DCC scope, with a commitment to keep it current. Second, UK GDPR evidence: ICO registration, data protection policies sized to your business, and a Data Protection Impact Assessment procedure. Third, business resilience: a documented assessment of your essential systems and their cyber risks, plus proof that your backups and recovery actually work, such as tested restore logs. It is a documentation-led review by the certification body.

What is the difference between Level 0 and Level 1, and which do I need?

Level 0 is the baseline for very-low-risk contracts and the level MOD has asked everyone to reach by December 2026. Level 1 covers 101 controls across governance, identity and access, devices, secure configuration, incident response, training and supply chain, and is verified by interview, demonstration and review of operational evidence. Suppliers of IT support, software, consultancy, training and logistics with access to MOD systems or OFFICIAL data are typically Level 1. You do not choose the level: your contract's Cyber Risk Profile sets it, so ask your prime in writing. MOD has said Level 1 and above at lower tiers should be scheduled after December 2026.

Do I need Cyber Essentials or Cyber Essentials Plus first?

Levels 0 and 1 require Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus. In every case the scope of the certificate must cover every internet-connected device inside your DCC scope, so a certificate that covers only part of the business will not do. If you already hold Cyber Essentials, the first job is to check the scope lines up.

Does HGC issue the Defence Cyber Certification certificate?

No. HGC is not a certification body. We scope your environment, close the gaps, build and maintain the evidence, and manage the assessment on your behalf. Your certificate is assessed and issued by CyberSmart, an IASME-accredited DCC certification body for Levels 0 and 1. You get a properly accredited certificate, managed end to end by one UK team.

How long does Defence Cyber Certification take?

It depends on three things: whether you already hold Cyber Essentials with the right scope, how many evidence gaps there are, and certification body availability, which is expected to tighten towards December 2026. We will not put a number on it before we understand your setup, but on the readiness call we will tell you honestly whether your deadline is realistic and what has to happen first.

How much does Defence Cyber Certification cost?

There are three parts. The certification body charges an assessment fee for the level you need. Cyber Essentials, the prerequisite, carries its own assessment fee tiered by organisation size. And there is whatever remediation your business needs to get the controls and evidence into the passing state, which is the part that varies most. We scope all three after a short readiness call and tell you what is involved before you commit to anything, so there are no surprise bills.

How long is Defence Cyber Certification valid for?

Three years, provided you complete an annual attestation in years one and two confirming the controls are still in place, and keep your Cyber Essentials certificate renewed every year throughout. Keeping the controls and evidence current between those points is exactly what our ongoing service does.

We are a subcontractor, not a direct MOD supplier. Does this apply to us?

Very likely, yes. DEFCON 658 and the DCC requirement flow down the supply chain, so if your prime or the company above you has included them in your subcontract terms, you are in scope whether or not MOD is your customer. MOD has specifically asked primes to push Level 0 down the chain and set realistic timescales for their subcontractors. If you are not sure, the readiness call is the place to find out.

Does DCC replace the Supplier Assurance Questionnaire?

Not yet. A valid DCC certificate can be submitted as assured evidence that the corresponding Def Stan 05-138 controls are met, and MOD buyers have been told to accept it as such, but the Supplier Assurance Questionnaire process still exists alongside it. We help you keep both consistent so the story you tell your prime is the same in every document.

Do you only work with defence suppliers in Dorset?

No. We are based near Dorchester and we already support businesses in the defence supply chain, but Defence Cyber Certification work is delivered remotely first and we work with suppliers anywhere in the UK. Where an on-site visit is useful, for example to look at a workshop network, we arrange it.

Explore more

Defence Cyber Certification builds on the rest of your security and IT. The first control is Cyber Essentials certification, which we run as a dedicated service. The resilience evidence comes from managed cloud backup that is tested rather than assumed. Ongoing protection sits with our managed cybersecurity, and the identity and configuration controls live inside Microsoft 365 support. Many defence suppliers choose to have the whole estate looked after by one team through our managed IT support, and here is how we deliver local IT support across Dorset.

Not ready to book? Get the free DCC Level 0 readiness checklist

Get DCC ready before December

Book a short, no-obligation Defence Cyber Certification readiness call with our UK team. We will look at what your prime has asked for, where your Cyber Essentials scope stands today, and what evidence you already have, then give you a plain-English view of what it takes to reach Level 0 and stay there. No jargon, no pressure, and you will know what is involved before you commit to anything.

  • Free, no-obligation readiness call
  • We tell you which level applies and whether December is realistic
  • Done for you, by a UK team that already runs the controls
  • Kept current through every annual attestation

Call 01305 310006 · Email [email protected]