If your organisation supplies into the defence sector, directly or indirectly, there is a deadline you should already be planning for. The Ministry of Defence (MoD) has announced that all industry partners are expected to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, marking a major step forward in strengthening cyber resilience across the UK defence supply chain see announcement here.
For many organisations, particularly SMEs, this could be the first time they’ve heard about DCC. Others may be aware of it but have assumed it’s something that only applies to major defence contractors.
The reality is very different. The MoD’s message is clear: cyber resilience is a supply chain responsibility, and organisations of all sizes are expected to play their part.
What Is Defence Cyber Certification?
Defence Cyber Certification (DCC) is a cyber security assurance framework aligned to DEFSTAN 05-138 and designed to provide an independently assessed route for organisations to demonstrate cyber resilience within the defence sector.
There are four certification levels, ranging from Level 0 through to Level 3, with the required level determined by the cyber risk profile of the contracts an organisation holds.
For now, the focus is firmly on Level 0.
To achieve DCC Level 0, organisations must:
- Hold a valid Cyber Essentials certification
- Ensure Cyber Essentials covers all applicable business-critical systems within scope
- Complete the Level 0 Supplier Assurance Questionnaire
- Demonstrate compliance with relevant DCC requirements
In simple terms, Cyber Essentials provides the technical foundation, while DCC adds an additional layer of governance, assurance and defence-sector confidence.
Who Needs to Comply?
One of the biggest misconceptions is that DCC only affects large defence contractors. The MoD has specifically stated that the requirement extends across its industry partners and wider supply chain, not just the prime contractors at the top.
That means businesses may be in scope if they:
- Hold defence contracts directly
- Supply to larger defence contractors
- Provide services to organisations operating within the defence sector
- Form part of a defence-related supply chain
The defence ecosystem includes thousands of SMEs, many of which will now need to consider their DCC obligations and timelines.
For organisations unsure whether DCC applies to them, now is the time to start asking questions, not in November.
Why This Matters
Cyber security has become a critical component of national security. Modern defence operations rely heavily on interconnected supply chains, digital systems and third-party providers. Attackers know this, and increasingly look beyond large organisations for opportunities to gain access through suppliers with weaker controls. That’s why we’re seeing growing emphasis on supply chain assurance, both in the UK and globally. The MoD’s latest announcement reflects a broader trend towards raising cyber security standards across critical industries. For businesses already operating in defence, DCC will increasingly become part of demonstrating trust, resilience and readiness to work within the sector. For organisations looking to enter defence markets, it may become a significant competitive advantage.
Five Months Sounds Like Plenty of Time. It Isn’t.
One of the most useful takeaways from recent industry commentary is the reminder that certification takes longer than many organisations expect.
Before certification can take place, organisations often need to:
- Confirm scope
- Review existing controls
- Achieve or renew Cyber Essentials
- Gather evidence
- Address any gaps
- Complete supplier assurance requirements
- Engage with a certification body
Even large organisations with mature cyber security programmes have highlighted how important early scoping and planning can be. The businesses that start preparing now are far more likely to experience a smooth certification journey than those who leave it until the final quarter of the year.
Practical Steps Organisations Should Be Taking Now
Rather than viewing DCC as another compliance exercise, organisations should use it as an opportunity to strengthen their overall cyber resilience.
A sensible starting point would be:
- Review Your Supply Chain Position. Understand whether you hold defence contracts directly or indirectly and whether customers are likely to require DCC certification.
- Check Your Cyber Essentials Status. Cyber Essentials is a prerequisite for DCC Level 0. If certification isn’t currently in place, this should be your first priority.
- Define Scope Early. The MoD and early adopters of the framework consistently highlight scoping as one of the most important parts of the process.
- Engage Leadership Teams. DCC is not purely an IT initiative. Like Cyber Essentials and ISO 27001, success depends on organisational commitment and governance.
- Seek Expert Guidance. Understanding requirements early can prevent delays, reduce unnecessary work and help ensure certification efforts focus on the right areas.
At Evolve North, we help organisations navigate cyber security and compliance requirements with a practical, business-focused approach. Whether you’re completely new to Defence Cyber Certification or already preparing for certification, we can support you with:
- DCC readiness assessments
- Defence Cyber Certification guidance
- Cyber Essentials and Cyber Essentials Plus
- Gap analysis and remediation planning
- Governance and policy support
- Ongoing cyber compliance advice
The December 2026 deadline may seem a long way off, but preparation takes time, especially for organisations that need to achieve Cyber Essentials first. If your organisation operates within the defence supply chain and you’re unsure where to start, now is the ideal time to begin the conversation.
To discuss Defence Cyber Certification and how Evolve North can support your journey, contact our team on 01748 905002 or email info@evolvenorth.com.
