Loading...
Defence Cyber Certification (DCC) is the Ministry of Defence's cyber assurance framework for organisations operating within the UK defence supply chain. It helps demonstrate that suppliers have appropriate cyber security controls and organisational resilience in place
DCC helps demonstrate that your organisation can manage cyber security risks effectively, meet defence industry requirements, and protect information from cyber threats.
Any organisation that works with defence customers, prime contractors, or handles defence-related information may be required to obtain an appropriate level of certification.
The required level is typically determined by your customer, contract requirements, or the sensitivity of the information you manage. If you are unsure, we can help you identify the appropriate level.
DCC stands for Defence Cyber Certification
DCC was introduced to improve cyber resilience throughout the defence supply chain and reduce cyber risks affecting MOD suppliers
Any organisation supplying products or services to defence may be required to obtain DCC certification depending on contractual requirements and risk assessment
The MOD has directed defence industry partners to achieve at least DCC Level 0 by 31 December 2026. Contractual requirements will continue to determine specific certification levels.
The level required depends on the cyber risk associated with the contract and information being handled
Only IASME-approved Certification Bodies like Valantus can assess and certify organisations against the DCC framework.
DCC consists of Levels 0, 1, 2 and 3, each introducing additional cyber security requirements and controls
DCC Level 0 is the entry-level certification designed for organisations that do not routinely handle sensitive defence information but still need to demonstrate basic cyber security practices.
Level 0 is suitable for organisations providing low-risk services where little or no defence-sensitive information is processed, stored, or transmitted.
Typical requirements include:
The assessment duration depends on the size and complexity of your organisation. Many small businesses can complete the process within a few weeks if the required controls are already in place.
Not necessarily. Many Level 0 requirements are based on implementing practical cyber security measures and documenting processes. Guidance and support are available throughout the process.
Yes. DCC Level 0 is specifically designed to be proportionate and achievable for small and medium-sized organisations.
Costs vary between Certification Bodies and depend on organisational size and scope.
Evidence typically includes Cyber Essentials certification, policies, governance arrangements and resilience documentation
Most organisations can achieve Level 0 within 1-2 weeks provided required evidence is available.
Yes. Cyber Essentials is a prerequisite for DCC Level 0 certification
Yes. The certification is designed to be accessible to organisations of all sizes
DCC Level 1 is designed for organisations that process, store, or transmit defence-related information and require a higher level of cyber security assurance.
Level 1 requires more formalised cyber security controls, documented procedures, risk management processes, and evidence that controls are operating effectively. There are 101 controls
Organisations working directly with defence contracts, handling controlled information, or supporting critical defence supply chains are often required to achieve Level 1.
Examples of evidence may include:
We recommend:
Any identified gaps will be discussed with you, and you may be given the opportunity to address them before certification can be awarded.
Timescales vary depending on your current cyber security maturity. Organisations with existing security controls in place can often achieve certification more quickly.
The assessment typically includes a review of documentation, supporting evidence, and interviews with relevant personnel to confirm that required controls are implemented and effective.
No. Certification must be maintained, and organisations should continuously manage and improve their cyber security controls.
Security controls should be reviewed regularly and whenever significant changes occur within the organisation, such as new systems, services, or business processes.
Yes. We can provide readiness reviews, gap assessments, remediation guidance, and support throughout the certification journey.
Benefits include:
Contact us for an initial consultation. We will review your requirements, determine the appropriate certification level, and provide a clear roadmap to certification.