The Cost of Waiting: Why Backup Investment Cannot Be Deferred
Why Level 0 Cannot Wait Until December
The Ministry of Defence has set 31 December 2026 as the target for every industry partner to achieve Defence Cyber Certification Level 0. For organisations operating anywhere within the defence supply chain, the time to begin preparing is now.
Five months can sound like a comfortable amount of time.
But once an organisation accounts for defining its scope, identifying business-critical systems, addressing security gaps, completing Cyber Essentials, gathering evidence and securing an assessment slot, that window quickly begins to narrow.
The Ministry of Defence has asked all industry partners to achieve Level 0 of the Defence Cyber Certification scheme by 31 December 2026. This expectation extends beyond major defence contractors to the subcontractors, technology providers, manufacturers and professional services organisations supporting them.
What is Defence Cyber Certification?
Defence Cyber Certification, or DCC, is an organisation-wide assurance scheme designed to strengthen cyber resilience across the UK defence supply chain.
There are four certification levels, from Level 0 to Level 3, aligned to the cyber risk associated with the contracts an organisation holds. Level 0 is the baseline and is intended for organisations operating against contracts with a very low cyber-risk profile.
To achieve Level 0, an organisation must hold a current Cyber Essentials certification covering all applicable business-critical systems within scope. It must also complete the Level 0 Supplier Assurance Questionnaire against the requirements of DEFSTAN 05-138.
Although DCC is not currently a blanket legal requirement, the MoD has asked all industry partners to achieve Level 0. Where DEFCON 658 is included within a contract, DCC can become a contractual obligation rather than simply an expectation.
That distinction matters. Organisations that delay could find themselves facing questions from prime contractors, customers and procurement teams before they are ready to answer them.
Cyber Essentials comes first
For organisations without Cyber Essentials, this is the most immediate priority.
Cyber Essentials is not a separate, optional exercise running alongside DCC. It is a prerequisite. Level 0 certification cannot be awarded unless Cyber Essentials is already in place across the relevant systems.
Organisations that already hold Cyber Essentials should not automatically assume they are ready. The scope of their existing certification must include every applicable business-critical system required for DCC. Changes to infrastructure, remote working arrangements, cloud services, devices or operational processes may mean that the scope needs reviewing.
The process should therefore begin with three questions:
- Which contracts and customers place the organisation within scope?
- Which systems, users and locations support those contracts?
- Does the organisation’s existing Cyber Essentials certification cover them all?
A channel opportunity as well as a compliance deadline
For MSPs and cybersecurity partners, DCC creates an important opportunity to help customers understand a requirement they may not yet realise applies to them.
Smaller defence suppliers are unlikely to have large internal governance, risk and compliance teams. Many will look to their existing technology partner to help them identify their obligations, understand their readiness and complete the certification journey.
CyberSmart is an IASME-accredited DCC Certification Body and can assess organisations for Level 0 and Level 1. Its service can cover scope confirmation, Cyber Essentials certification and the subsequent DCC assessment process. CyberSmart also enables MSPs to support defence-sector customers through the same journey.
Through Hammer Cybersecurity and CyberSmart, partners can begin proactive conversations with customers before urgency turns into panic.
The message for the defence supply chain is straightforward: 31 December may be the deadline, but December is not the month to start.
