Regulation

Securing the defence sector supply chain

July 28, 2026
12 min read

Key Insights:

  • The UK's Ministry of Defence have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026
  • Supplier certification includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope
  • Globally, there is increased focus on hardening defence sector supply chains and improving cyber resilience through certification
  • The UK's DCC scheme is similar to the US Cybersecurity Maturity Model Certification (CMMC) applied to the nation's Defense Industrial Base and Australia and New Zealand's Defence Industry Security Programmes (DISP).

UK Government champions supply chain security for the defence sector

The UK's Ministry of Defence (MOD) have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026 to ensure that key subcontractors and suppliers remain eligible to work across military projects.

As conflict escalates across the globe, the MOD is seeking to uphold the highest level of cyber security across its supply chain by ensuring suppliers adhere to the Defence Standard (Def Stan) 05-138.

Introduced in 2015 as part of the UK government’s national cyber security programme, escalating cyber threats have seen the Standard revised to version four with the criteria for suppliers documented in 148 controls which are applied into four progressively more stringent levels.

Undergoing certification for Defence procurement

UK suppliers are expected to attain a level of security specified in their contracts with the MOD - the resulting level is referred to as the Cyber Risk Profile.

Defence Cyber Certification is run through IASME, the MOD’s official cyber certification partner, and emphasises the overall security and resilience of the organisation being assessed.

It provides a single, organisation-level, assurance which can be presented in support of tender bids and and is subject to annual attestation and re-certification every three years.

Working towards DCC certification

"The DCC is a badge of excellence in cyber resilience for all Defence industry partners.  Assured cyber resilience across suppliers will help UK Defence rise to the challenge of the escalating cyber threat."
Eleanor Fairford, Director of Cyber Defence & Risk, Ministry of Defence

As a point in time assessment, all four levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus.

Level 0 DCC certification - which only mandates three controls - is normally assigned where there is a very low level of assessed cyber risk to a supplier. It requires organisations to demonstrate basic cyber security practices and forms the foundation level for all future higher tier assessments.

To certify under the associated UK Government Cyber Essentials scheme, there are five technical controls designed to prevent the most common internet based cyber security threats and these are combined with governance, risk, and resilience measures.

For organisation looking to win defence contracts, DCC is a valuable way for organisations to proactively demonstrate cyber resilience and commitment to good security practice when bidding for, or delivering, defence or public sector contracts.

Defence supply chain certification globally

The UK scheme was introduced in May 2025 and is starting to reach critical mass where cyber risk assurance is increasingly demanded by governments and prime contractors supplying armaments and logistic support to militaries around the world.

In the United States, Cybersecurity Maturity Model Certification (CMMC) has required third-party assessments of defence contractors for some time across three levels:

  • Level 1 (Foundational): Annual self-assessment covering 17 basic cyber practices for Federal Contract Information (FCI)
  • Level 2 (Advanced): Compliance with 110 controls from NIST SP 800-171 for Controlled Unclassified Information (CUI)
  • Level 3 (Expert): Government-led assessments for high-value critical programs using enhanced NIST SP 800-172 standards

CMMC applies a similar tiered assurance model, depending on the type and sensitivity information handled and outlines protection requirements for subcontractors.

The Department of War recently announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements and thus development of the programme has reached an impasse.

Defence security downunder

The Defence Industry Security Program, a security assurance service for Australian businesses and other entities wishing to partner with Defence

In Australia, the Defence Industry Security Program (DISP) operates as an active assurance and uplift programme over the military supply chain to ensure that organisations meet and maintain security responsibilities matched to their level of DISP membership.

There are circa 2000 accredited members with four membership levels within each security domain matched to the Australian Classification System:

  • Entry - Official / Official: Sensitive
  • One - Protected
  • Two - Secret
  • Three - Top Secret

All Defence Industry Security Program (DISP) members are now required to achieve and maintain compliance with the full Essential Eigh Maturity Level 2 standard.

Overcyte assists with Essential Eight Compliance for Critical Infrastructure and can provide guidance on reaching the Level 2 standard.

There is also the Cyber Framework for Defence Industry (CFDI) Cyber Security Questionnaire to help Australian small and medium-sized enterprises who want to work in the defence industry.

In New Zealand, the Defence Industry Security Guide provides an overview of a similar assurance scheme for defence contractors.

DISP Accreditation provides assurance to the NZDF that contracted partners comply with the requisite security policies and suppliers need to be DISP-Accredited if they access defence areas or classified material, provide a guard force or security services to the military or store, transport, handle or manage NZDF weapons, munitions or other sensitive items.

The Industry Security team manage the local scheme for NZ and there is alignment with the New Zealand Security Intelligence Service (NZSIS)'s Protective Security Requirements (PSR). The NZ Minimum Cyber Security Standards now also provide security guidance for meeting assurance levels.

Securing the defence sector supply chain

Overall, all of these global schemes are designed to provide assurance of organisational cyber resilience where suppliers must meet international security standards. As spending grows in the defence sector, strengthening the cyber resilience and security of the supply chain has become more critical than ever before.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo