Skip to content
Home ยป Blog ยป What Is the DCC Scheme? Defence Cyber Certification Explained

What Is the DCC Scheme? Defence Cyber Certification Explained

If you supply the UK defence sector โ€“ directly to the Ministry of Defence or through a prime contractor โ€“ you have probably started to see three letters appear in tenders and supplier conversations: DCC. This guide explains what the DCC scheme is, how it works, and what it means for your business.


What is Defence Cyber Certification?

DCC stands for Defence Cyber Certification. It is an organisation-wide cyber security certification scheme developed by IASME and the Ministry of Defence (MOD) to provide assurance of cyber resilience across the defence supply chain.

The scheme was introduced alongside Cyber Security Model version 4 (CSMv4), which went live in December 2025. DCC certification is delivered by IASME, the same organisation that operates the Cyber Essentials scheme on behalf of the National Cyber Security Centre.

The aim is to give defence suppliers a standardised, independently assessed way to demonstrate that they meet the required cyber security controls.

Rather than having to demonstrate the same controls separately for different contracts, a DCC certificate can provide assurance across multiple contracts, up to the level at which you are certified.

DCC certification can cover multiple defence contracts at the same certification level, meaning suppliers can use one organisation-wide certification to provide assurance across multiple contracts rather than undergoing separate DCC assessments for each one. That’s one of the key benefits of DCC for suppliers working across the defence supply chain. Find out more about DCC at IASME.co.uk

DCC certification lasts three years, with an annual attestation confirming that you continue to meet and maintain the controls. You must also renew your Cyber Essentials or Cyber Essentials Plus certification annually, with full DCC recertification every three years.


The four DCC levels

The DCC scheme has four levels, numbered 0 to 3. Which level applies depends on the cyber risk associated with your role in the defence supply chain and the requirements of the contract.

As the risk rises, so does the number of controls you need to demonstrate and the depth of evidence an assessor will expect.

  • Level 0 โ€“ the entry point, normally assigned where there is a very low level of assessed cyber risk to a supplier delivering an output. This is the baseline the MOD is asking its industry partners to achieve by the end of 2026.
  • Level 1 โ€“ for low to moderate risk work, with a considerably larger set of controls to evidence.
  • Level 2 โ€“ for higher-risk work, requiring a larger control set and Cyber Essentials Plus as the foundation.
  • Level 3 โ€“ the most demanding level, for the highest-risk work, with the largest control set and Cyber Essentials Plus required.

Every level starts with Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus.


Do you actually need DCC?

At the moment, DCC is not universally mandatory. However, the MOD is encouraging its industry partners to achieve DCC Level 0 by 31 December 2026, and DCC requirements are already appearing in defence procurement and supplier conversations.

Strictly speaking, the December 2026 date is an expectation rather than a blanket contractual requirement for every defence supplier. Individual contracts can specify their own cyber security requirements, so the level you need depends on the contract and its Cyber Risk Profile.

That means it is worth checking your current and upcoming contracts rather than waiting until a tender specifically asks for certification.

Do you need a defence contract to take part in the DCC scheme?

No. You do not need to have a live defence contract to apply.

Organisations can apply for DCC certification at any level, allowing suppliers to get ahead of future requirements rather than scrambling to achieve certification when it appears in a tender.


Does DCC replace the MOD’s SAQ?

Not entirely.

The MOD’s Cyber Security Model still uses the Supplier Assurance Questionnaire (SAQ) as part of its contractual risk assessment and procurement process.

However, where a supplier holds current DCC certification at the required level, that certification provides organisation-level assurance against the relevant controls in Defence Standard 05-138 Issue 4 and can be presented in support of UK Defence procurements.

In practical terms, DCC gives suppliers a reusable, independently assessed way to demonstrate that they have met the relevant controls, rather than relying solely on self-assessment.

This is one of the main benefits of the scheme – particularly for suppliers working across multiple defence contracts.


How Base3 can help

Base3 is an appointed DCC Level 0 Certification Body, listed on IASME’s register, which means we can assess your organisation for DCC Level 0 certification.

We can also help you put your Cyber Essentials foundation in place, carry out a gap analysis against the relevant controls in Defence Standard 05-138 Issue 4, and prepare you for the higher DCC levels where required.

Since we have been through DCC ourselves, we are advising from experience, not theory.

Not sure which level applies to you, or ready to get certified at Level 0? Get in touch and we will help you work it out.

For the full picture of how we support defence suppliers โ€“ from Cyber Essentials through to DCC โ€“ see our MOD supplier cyber security services.