
The UK's Ministry of Defence (MOD) have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026 to ensure that key subcontractors and suppliers remain eligible to work across military projects.
As conflict escalates across the globe, the MOD is seeking to uphold the highest level of cyber security across its supply chain by ensuring suppliers adhere to the Defence Standard (Def Stan) 05-138.
Introduced in 2015 as part of the UK government’s national cyber security programme, escalating cyber threats have seen the Standard revised to version four with the criteria for suppliers documented in 148 controls which are applied into four progressively more stringent levels.
UK suppliers are expected to attain a level of security specified in their contracts with the MOD - the resulting level is referred to as the Cyber Risk Profile.
Defence Cyber Certification is run through IASME, the MOD’s official cyber certification partner, and emphasises the overall security and resilience of the organisation being assessed.
It provides a single, organisation-level, assurance which can be presented in support of tender bids and and is subject to annual attestation and re-certification every three years.

"The DCC is a badge of excellence in cyber resilience for all Defence industry partners. Assured cyber resilience across suppliers will help UK Defence rise to the challenge of the escalating cyber threat."
Eleanor Fairford, Director of Cyber Defence & Risk, Ministry of Defence
As a point in time assessment, all four levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus.
Level 0 DCC certification - which only mandates three controls - is normally assigned where there is a very low level of assessed cyber risk to a supplier. It requires organisations to demonstrate basic cyber security practices and forms the foundation level for all future higher tier assessments.
To certify under the associated UK Government Cyber Essentials scheme, there are five technical controls designed to prevent the most common internet based cyber security threats and these are combined with governance, risk, and resilience measures.
For organisation looking to win defence contracts, DCC is a valuable way for organisations to proactively demonstrate cyber resilience and commitment to good security practice when bidding for, or delivering, defence or public sector contracts.
The UK scheme was introduced in May 2025 and is starting to reach critical mass where cyber risk assurance is increasingly demanded by governments and prime contractors supplying armaments and logistic support to militaries around the world.
In the United States, Cybersecurity Maturity Model Certification (CMMC) has required third-party assessments of defence contractors for some time across three levels:
CMMC applies a similar tiered assurance model, depending on the type and sensitivity information handled and outlines protection requirements for subcontractors.
The Department of War recently announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements and thus development of the programme has reached an impasse.

In Australia, the Defence Industry Security Program (DISP) operates as an active assurance and uplift programme over the military supply chain to ensure that organisations meet and maintain security responsibilities matched to their level of DISP membership.
There are circa 2000 accredited members with four membership levels within each security domain matched to the Australian Classification System:
All Defence Industry Security Program (DISP) members are now required to achieve and maintain compliance with the full Essential Eigh Maturity Level 2 standard.
Overcyte assists with Essential Eight Compliance for Critical Infrastructure and can provide guidance on reaching the Level 2 standard.
There is also the Cyber Framework for Defence Industry (CFDI) Cyber Security Questionnaire to help Australian small and medium-sized enterprises who want to work in the defence industry.
In New Zealand, the Defence Industry Security Guide provides an overview of a similar assurance scheme for defence contractors.
DISP Accreditation provides assurance to the NZDF that contracted partners comply with the requisite security policies and suppliers need to be DISP-Accredited if they access defence areas or classified material, provide a guard force or security services to the military or store, transport, handle or manage NZDF weapons, munitions or other sensitive items.
The Industry Security team manage the local scheme for NZ and there is alignment with the New Zealand Security Intelligence Service (NZSIS)'s Protective Security Requirements (PSR). The NZ Minimum Cyber Security Standards now also provide security guidance for meeting assurance levels.
Overall, all of these global schemes are designed to provide assurance of organisational cyber resilience where suppliers must meet international security standards. As spending grows in the defence sector, strengthening the cyber resilience and security of the supply chain has become more critical than ever before.