Defence Cyber Certification (DCC) is a cyber assurance framework designed to help organisations demonstrate that they have implemented appropriate cyber security controls when working within the defence supply chain. The framework helps organisations protect sensitive information, improve cyber resilience, and satisfy contractual cyber security requirements.
Cyber threats targeting supply chains continue to increase in frequency and sophistication. Defence Cyber Certification helps organisations demonstrate that they can appropriately protect sensitive information, systems, and services while improving trust across the supply chain. Valantus helps organisations understand and implement the controls needed to meet these requirements.
Any organisation bidding for, delivering, or supporting defence-related contracts may be required to achieve Defence Cyber Certification. Requirements are generally specified by the customer, contracting authority, or prime contractor.
The required certification level is usually defined in contract documentation. Valantus can help review your contractual requirements and determine which DCC level applies to your organisation.
Defence Cyber Certification is a cyber security assurance framework that enables organisations to demonstrate that appropriate security controls are in place when supporting defence contracts and handling defence-related information.
Defence Cyber Certification was introduced to strengthen cyber resilience across the defence supply chain and reduce the risk of cyber attacks impacting defence programmes, suppliers, and sensitive information.
Defence Cyber Certification supports cyber assurance requirements throughout the defence supply chain and provides a structured approach for suppliers to demonstrate cyber security capability.
Any organisation that stores, processes, accesses, or transmits information related to defence contracts may require Defence Cyber Certification depending on the nature of their services and contractual obligations.
Defence Cyber Certification requirements can apply across many industries including manufacturing, engineering, aerospace, software development, professional services, logistics, facilities management, and consultancy services supporting defence customers.
The Defence Cyber Certification framework includes multiple certification levels designed to align cyber security requirements with the risk associated with a particular contract or service.
Certification requirements are generally determined by contract conditions and the type of information or systems involved. Valantus can review your requirements and identify the most appropriate compliance route.
Defence Cyber Certification becomes mandatory when it is specified within a defence contract, supplier onboarding process, or customer assurance requirement.
DCC encourages organisations to implement appropriate cyber security controls, governance arrangements, risk management processes, security awareness programmes, and technical safeguards to reduce cyber risk.
Benefits often include improved cyber resilience, increased customer confidence, enhanced supply chain assurance, reduced cyber risk, stronger governance, and access to defence-related business opportunities.
No. Cyber Essentials and Defence Cyber Certification are separate frameworks. Depending on customer requirements, organisations may need to demonstrate compliance with multiple assurance schemes.
Yes. Defence Cyber Certification has been designed to be achievable for organisations of all sizes, including sole traders, start-ups, SMEs, and larger enterprises. Valantus regularly supports small businesses through the DCC certification journey.
The timescale depends on the required certification level, organisational size, and the maturity of existing cyber security controls. Well-prepared organisations can often achieve certification much more quickly, particularly with support from Valantus.
Certification costs vary depending on the certification level required, the complexity of the environment, and whether remediation work is necessary before assessment. Valantus can help identify the most cost-effective route to certification.
Documentation may include policies, procedures, asset inventories, risk assessments, training records, access control processes, and evidence demonstrating that cyber security controls are operating effectively.
Yes. Achieving DCC certification demonstrates commitment to cyber security and can help organisations meet supplier assurance requirements when competing for defence opportunities.
If gaps are identified during assessment, organisations can typically address the findings through corrective actions and remediation activities before pursuing certification again. Valantus can provide practical guidance to help close compliance gaps.
Yes. Valantus provides Defence Cyber Certification gap assessments, readiness reviews, evidence reviews, remediation planning, policy development support, and consultancy services to help organisations achieve certification efficiently.
Yes. Cloud environments such as Microsoft 365 and other cloud platforms may fall within scope where they are used to store, process, or transmit information associated with defence contracts.
Valantus combines practical cyber security expertise with extensive experience supporting organisations throughout compliance and assurance programmes. Our consultants provide clear, pragmatic guidance to help businesses achieve Defence Cyber Certification while strengthening their overall security posture.
Cyber Essentials focuses on a baseline set of technical controls, whereas Defence Cyber Certification assesses a broader range of security, governance, and assurance requirements relevant to the defence supply chain.
Yes. Organisations with ISO 27001 certification may already have many of the governance and security controls required for DCC. However, a separate review should be performed to identify any additional DCC-specific requirements. Valantus can assist with this gap analysis.
Potentially. Subcontractors within the defence supply chain may also be required to demonstrate compliance where they have access to defence information, systems, or services.
Many preparation and assessment activities can be completed remotely, including evidence reviews, interviews, readiness assessments, and implementation support provided by Valantus.
DCC Level 0 is the entry point into the Defence Cyber Certification framework. It is designed for organisations that need to demonstrate basic cyber security controls and awareness when supporting defence-related activities. Level 0 focuses on establishing fundamental cyber security practices that help protect business systems and information.
DCC Level 0 is typically suitable for organisations that have limited exposure to defence information or systems. It is commonly required for suppliers providing lower-risk services where sensitive defence information is not routinely processed, stored, or transmitted.
Level 0 focuses on foundational cyber security measures such as password management, software updates, malware protection, access controls, cyber awareness training, and secure handling of business information. Organisations should be able to demonstrate that these controls are implemented and maintained.
Assessment times vary according to organisational size and readiness. Many organisations can achieve Level 0 relatively quickly if they already have basic cyber security controls in place. Valantus can help accelerate the process by identifying gaps early and supporting evidence collection.
No. Many organisations achieve DCC Level 0 without dedicated cyber security staff. Valantus provides practical guidance and support to help organisations understand requirements and implement the necessary controls.
Absolutely. DCC Level 0 has been designed to be achievable for SMEs, start-ups, and micro-businesses. Valantus regularly supports smaller organisations through the certification process using practical and proportionate approaches.
DCC Level 0 may become mandatory where it is specified by a customer, defence organisation, or prime contractor as part of a contract requirement. Suppliers should review contract documents carefully to understand their obligations.
Typical controls include secure passwords, anti-malware protection, software patching, access control management, user awareness training, secure configuration of devices, and basic information security procedures.
Yes. Start-ups and newly established organisations can achieve DCC Level 0 provided they implement the required security controls and can demonstrate compliance with the framework requirements.
The cost depends on organisational size, current cyber maturity, and whether external assistance is required. Valantus can conduct a readiness review and help identify the most cost-effective route to achieving compliance.
There are similarities between DCC Level 0 and Cyber Essentials, particularly around cyber hygiene and foundational security controls. However, organisations should review specific DCC requirements to ensure full compliance with contractual obligations.
Level 0 expects organisations to define basic security responsibilities and information protection measures. Having documented policies and procedures can help demonstrate that security controls are understood and consistently applied.
Yes. Remote workers can be included provided appropriate controls are implemented to protect devices, systems, accounts, and information accessed from home or remote locations.
Yes. Staff awareness is an important requirement. Employees should understand common cyber threats such as phishing, malware, password attacks, social engineering, and the importance of following company security procedures.
Achieving DCC Level 0 demonstrates a commitment to cyber security and may help satisfy supplier assurance requirements within the defence supply chain. This can improve customer confidence and strengthen bidding opportunities.
Organisations should maintain compliance throughout the duration of their contracts and regularly review cyber security controls. Certification validity requirements may vary depending on customer expectations and future framework updates.
Yes. Many organisations successfully achieve DCC Level 0 without employing dedicated IT personnel. Valantus can provide practical support and guidance to help organisations implement and evidence the required controls.
Evidence may include security policies, training records, password management procedures, software update processes, anti-malware protection records, device inventories, and documentation showing that security controls are operating as intended.
Yes. Organisations using cloud platforms such as Microsoft 365 can achieve DCC Level 0 provided suitable security controls, account protections, and management processes are implemented and maintained.
After certification, organisations should continue monitoring, reviewing, and improving their cyber security controls. Some suppliers may eventually require DCC Level 1 if they begin supporting contracts with higher security requirements.
Valantus provides DCC readiness assessments, gap analysis, policy reviews, evidence validation, remediation planning, and practical implementation support. Our consultants help organisations understand requirements, address gaps, and achieve certification with confidence.
Common gaps include missing cyber security policies, weak password controls, inconsistent software patching, inadequate staff awareness training, poor asset management, and a lack of documented security procedures. Valantus can help identify and address these gaps before assessment.
Not necessarily. However, organisations that have already implemented Cyber Essentials often find that they have many of the fundamental technical controls that support DCC Level 0 compliance.
Preparation typically includes reviewing existing cyber security controls, documenting procedures, ensuring systems are patched, providing staff awareness training, and gathering evidence that demonstrates compliance. Valantus can conduct a readiness review to identify any areas requiring improvement.
The timeframe depends on your organisation's existing cyber maturity. Businesses with established controls may achieve compliance within a few weeks, while those starting from scratch may require additional time for remediation and evidence gathering.
Organisations should implement appropriate malware protection across all devices used for business purposes. Effective anti-malware protection is a fundamental component of good cyber hygiene.
Microsoft 365 provides a range of security capabilities including multi-factor authentication, account protection, email security, device management, and security monitoring that can support DCC Level 0 compliance when properly configured.
Multi-factor authentication is considered a cyber security best practice and significantly reduces the risk of unauthorised access. Many organisations implement MFA as part of their DCC Level 0 compliance programme.
Yes. Home workers are commonly included within scope. Organisations should ensure that devices, user accounts, remote access methods, and information handling practices are adequately protected.
Typical documents include acceptable use policies, password policies, user access records, employee training records, software update procedures, device inventories, and basic cyber security policies.
Yes. Sole traders supporting defence contracts may be required to demonstrate cyber security compliance. DCC Level 0 has been designed to be achievable regardless of organisational size.
Yes. Independent consultants, contractors, and specialist advisers frequently require DCC Level 0 when supporting defence programmes, projects, or organisations.
DCC Level 0 focuses on fundamental cyber security controls and awareness. DCC Level 1 generally requires additional governance, formal documentation, risk management processes, and stronger evidence demonstrating that controls are operating effectively.
Yes. Valantus can assess your current cyber security posture, identify compliance gaps, review available evidence, and provide a practical roadmap to help your organisation achieve DCC Level 0 certification efficiently.
Defence customers require assurance that suppliers have implemented appropriate cyber security controls to reduce the likelihood of cyber attacks, information compromise, and supply chain vulnerabilities.
Yes. Many organisations find that implementing DCC Level 0 controls improves password security, patch management, employee awareness, access control, and overall cyber resilience across the business.
DCC Level 1 is a higher level of Defence Cyber Certification that requires organisations to demonstrate a more mature cyber security capability. In addition to implementing controls, organisations must provide evidence that security processes are documented, maintained, and operating effectively.
DCC Level 0 focuses on fundamental cyber security controls and awareness. DCC Level 1 introduces additional governance, documented processes, risk management activities, and evidence requirements to demonstrate ongoing cyber security management.
DCC Level 1 is typically required where organisations have increased exposure to defence information, systems, or services and need to demonstrate a stronger level of cyber assurance.
Evidence may include policies, procedures, risk assessments, training records, vulnerability management activities, access control documentation, asset inventories, incident management processes, and management reviews.
Preparation typically involves reviewing requirements, documenting processes, gathering evidence, conducting internal reviews, addressing compliance gaps, and ensuring security controls are operating effectively. Valantus can help organisations prepare through readiness assessments and gap analyses.
Any identified gaps should be addressed through corrective actions and remediation activities. Valantus can help organisations prioritise findings and implement practical improvements before reassessment.
Timescales depend on existing cyber maturity, available evidence, and organisational complexity. Some businesses may be ready within a few weeks, while others require a longer remediation programme.
Yes. Level 1 organisations should maintain documented and controlled security policies that define responsibilities, expectations, and security requirements across the organisation.
Yes. Organisations should have a structured process for identifying, assessing, recording, and managing cyber security risks affecting systems, information, and services.
Multi-factor authentication is widely recognised as a security best practice and is strongly recommended for privileged accounts, cloud services, remote access, and critical systems.
Yes. Employees should receive regular awareness training to understand cyber threats, phishing attacks, password security, information handling requirements, and their security responsibilities.
Organisations should identify, assess, prioritise, and remediate vulnerabilities in a timely manner to reduce cyber security risk and maintain a secure operating environment.
Yes. Organisations should maintain an inventory of hardware, software, and information assets so they can understand what needs to be protected and managed.
Yes. Organisations should have clear procedures for identifying, reporting, responding to, and recovering from cyber security incidents.
Yes. Cloud platforms such as Microsoft 365 can support DCC Level 1 compliance when configured and managed securely with appropriate security controls.
Most organisations should have policies, procedures, risk assessments, training records, user access records, asset inventories, vulnerability management activities, and evidence showing controls are operating effectively.
Yes. Organisations should define requirements for password creation, management, protection, and periodic review to help reduce the risk of unauthorised access.
Yes. However, organisations should ensure devices, user accounts, communications, and remote access methods are protected appropriately.
Absolutely. Many SMEs successfully achieve DCC Level 1. Valantus works with organisations of all sizes to develop practical and achievable compliance programmes.
Costs vary according to organisational size, complexity, current cyber maturity, and the amount of remediation work required. Valantus can help identify the most efficient certification pathway.
The assessment duration depends on organisational scope, available evidence, and the maturity of security controls. Preparation is often the most time-consuming element.
Yes. Organisations with ISO 27001 certification often already have many of the management system and governance controls expected within DCC Level 1.
Yes. Cyber Essentials provides a strong foundation of technical controls which can support DCC Level 1 preparation.
Yes. Features such as multi-factor authentication, conditional access, device management, auditing, and security monitoring can contribute to Level 1 compliance when implemented correctly.
Yes. Security controls should be reviewed regularly to ensure they remain effective and continue to address evolving threats and business risks.
Yes. Organisations should periodically review user access rights to ensure individuals only have access to systems and information required for their roles.
Common gaps include missing documentation, incomplete risk assessments, weak asset management, inconsistent vulnerability remediation, poor access reviews, and insufficient evidence collection.
Yes. Contractors, consultants, and specialist service providers may require DCC Level 1 certification depending on the nature of the services they provide.
A readiness assessment reviews existing controls, identifies compliance gaps, assesses available evidence, and provides a roadmap towards successful certification.
Yes. Valantus can review your current environment against DCC Level 1 requirements, identify compliance gaps, and provide practical remediation recommendations.
Yes. Valantus supports organisations through readiness assessments, gap analyses, policy development, risk management activities, evidence reviews, remediation planning, and certification preparation.
Defence customers require assurance that suppliers can adequately protect sensitive information, systems, and services from cyber threats and security incidents.
Yes. Demonstrating DCC Level 1 compliance can help satisfy supplier assurance requirements, strengthen customer confidence, and improve competitiveness within the defence sector.
Potentially. Subcontractors may also need to demonstrate compliance where they have access to defence information, systems, or services.
Yes. Organisations often find that implementing DCC Level 1 controls improves governance, risk management, incident response, user management, and overall cyber resilience.
Benefits can include reduced cyber risk, improved customer confidence, enhanced supply chain assurance, stronger governance, and increased eligibility for defence sector opportunities.
Most organisations begin by carrying out a readiness assessment. Valantus can review your current position, identify compliance gaps, and develop a practical roadmap towards successful DCC Level 1 certification.
Valantus is an IASME Approved Certification Body authorised to assess and certify organisations against Defence Cyber Certification (DCC) requirements. Our experienced assessors provide practical, jargon-free guidance to help organisations understand the requirements, prepare evidence, and achieve certification efficiently. As specialists in cyber assurance, compliance, and defence sector requirements, we support businesses throughout the entire certification journey