Bridging the gap between academic research and real-world solutions

In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by

Joshua Ashton

Insight

8 Sept 2026

4 min read

Post Image

Cyber Essentials vs DCC: What’s the Difference for Defence Suppliers?

If your organisation already holds Cyber Essentials, it can be tempting to assume that you are already covered for the Ministry of Defence’s evolving cyber requirements.

That is not quite the case.

Cyber Essentials and Defence Cyber Certification (DCC) are closely connected, but they are not the same certification.

Cyber Essentials provides an important baseline of technical cyber security. DCC builds on that foundation and provides broader, organisation-level assurance against the cyber resilience requirements used across the UK Defence supply chain.

For organisations supplying the MOD, a prime contractor or another Defence supplier, understanding the distinction is increasingly important.

What is Cyber Essentials?

Cyber Essentials is the UK Government-backed cyber security certification scheme designed to protect organisations against common cyber attacks.

The scheme focuses on five core technical areas:

  • firewalls;

  • secure configuration;

  • security update management;

  • user access control; and

  • malware protection.

There are two levels of certification:

Cyber Essentials involves a verified self-assessment of the organisation’s cyber security controls.

Cyber Essentials Plus begins with the same requirements but adds an independent technical audit to verify that those controls are operating effectively.

Cyber Essentials is widely used across UK Government procurement and already forms an important part of cyber assurance within the Defence supply chain.

What is Defence Cyber Certification?

Defence Cyber Certification is a separate certification scheme developed by the Ministry of Defence and IASME.

DCC is designed to provide independent assurance that an organisation meets the cyber security and resilience requirements contained within Defence Standard 05-138 Issue 4.

Unlike Cyber Essentials, the focus is not limited to a relatively small set of technical controls.

DCC looks more broadly at the security and resilience of the organisation.

There are four levels:

  • DCC Level 0 – 3 controls

  • DCC Level 1 – 101 controls

  • DCC Level 2 – 139 controls

  • DCC Level 3 – 144 controls

The appropriate level reflects the cyber risk associated with the supplier’s role and the work being delivered into Defence.

So, is Cyber Essentials part of DCC?

Yes.

All four DCC levels start with Cyber Essentials.

For DCC Levels 0 and 1, Cyber Essentials forms the prerequisite baseline.

For DCC Levels 2 and 3, organisations are required to hold Cyber Essentials Plus.

This makes Cyber Essentials an important part of DCC readiness.

But it is important to understand the distinction:

Cyber Essentials is a requirement within the DCC framework. It is not a substitute for DCC certification.

An organisation can therefore be Cyber Essentials certified without being DCC certified.

Cyber Essentials vs DCC at a glance




Cyber Essentials

Defence Cyber Certification

Primary purpose

Protection against common cyber attacks

Assurance of organisational cyber resilience for Defence

Audience

Organisations across the UK economy

Primarily organisations operating in or preparing for the Defence supply chain

Scope

Internet-connected IT infrastructure within the defined scope

Essential organisational functions, systems, processes and services

Assessment

Verified self-assessment

Independent DCC assessment

Technical audit

Cyber Essentials Plus only

Evidence is independently assessed as part of DCC

Levels

Cyber Essentials and Cyber Essentials Plus

Levels 0, 1, 2 and 3

Relationship

Forms the technical foundation

Builds on Cyber Essentials/Plus

Defence-specific

No

Yes

Why isn’t Cyber Essentials alone enough?

The key difference is scope and purpose.

Cyber Essentials is focused primarily on securing internet-connected systems against common threats.

DCC is concerned with whether the organisation itself can operate securely and resiliently.

Under CSMv4, the MOD has deliberately moved away from focusing principally on protecting specific items of MOD-identifiable information towards assessing wider organisational security and resilience.

That means areas outside the traditional Cyber Essentials assessment can become relevant.

Depending on the DCC level, this can include areas such as:

  • governance;

  • risk management;

  • incident response;

  • business resilience;

  • security monitoring;

  • supply-chain management;

  • policies and procedures;

  • privileged access;

  • cloud security;

  • identity management;

  • backup and recovery; and

  • evidence that controls operate effectively in practice.

Cyber Essentials remains extremely valuable.

DCC asks a broader question:

Can Defence have confidence in the cyber resilience of the organisation as a whole?

The scope is also different

This is an important point for businesses preparing for DCC.

The scope of Cyber Essentials and the scope of DCC are related, but they are not necessarily identical.

IASME states that the DCC scope should include the essential functions and services necessary for the organisation to operate securely and resiliently.

Cyber Essentials, on the other hand, specifically concentrates on relevant internet-connected networks and systems.

Internet-connected infrastructure within the DCC scope should therefore also be appropriately covered by Cyber Essentials or Cyber Essentials Plus.

This is why simply producing an existing Cyber Essentials certificate at the beginning of a DCC project may not be enough.

The scope itself needs to make sense.

Does DCC replace Cyber Essentials?

No.

The two schemes work together.

An organisation wishing to maintain DCC certification must continue to maintain the appropriate Cyber Essentials certification.

IASME states that DCC certification is valid for three years, subject to annual attestation and the annual renewal of Cyber Essentials or Cyber Essentials Plus.

So rather than thinking:

Cyber Essentials OR DCC

Defence suppliers should think:

Cyber Essentials + DCC

with the required Cyber Essentials level depending on the DCC level being pursued.

Do all Defence suppliers need DCC today?

Not universally.

IASME currently states that DCC is not yet mandatory for every organisation, and the level required for a particular contract will be determined by the MOD or the relevant prime contractor.

However, the direction from Defence is increasingly clear.

The MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026, including obtaining Cyber Essentials for applicable business-critical systems within scope.

The MOD also says suppliers should expect an increasing requirement to hold valid DCC certification for the duration of contracts, where specified through procurement conditions.

For businesses already involved in Defence, the sensible approach is therefore to establish readiness before a customer or tender makes it urgent.

What if we already have Cyber Essentials?

You are starting from a better position.

The next step is not necessarily to rebuild your security environment from scratch.

Instead, establish:

  • whether your Cyber Essentials certification is current;

  • whether its scope aligns with the systems that would fall within DCC;

  • which DCC level is relevant to your organisation or contracts;

  • whether the additional DCC controls are already being met;

  • whether you can evidence those controls;

  • whether there are governance or resilience gaps; and

  • what remediation would be required before assessment.

Many organisations already have more of the required capability than they initially realise.

The challenge is often bringing together technology, process, governance and evidence into a coherent assurance position.

What if we have Cyber Essentials Plus?

Cyber Essentials Plus provides stronger technical assurance than standard Cyber Essentials because an independent assessor tests the implementation of the controls.

It is also a prerequisite for DCC Levels 2 and 3.

However, Cyber Essentials Plus still does not automatically confer DCC certification.

The additional Defence Standard controls applicable to the required DCC level must still be assessed.

What if we cannot meet every DCC requirement?

The Cyber Security Model includes a mechanism called a Cyber Improvement Plan (CIP).

Where a supplier does not hold DCC at the required level, or cannot meet applicable CSM requirements, the supplier may need to submit a CIP showing what needs to be improved and when those improvements will be completed.

That reinforces the benefit of carrying out a readiness review early.

Identifying a control gap in September gives an organisation time to address it.

Identifying the same gap during a tender response or customer assessment creates a very different problem.

Where does Microsoft 365 fit?

For many Defence SMEs, a large proportion of the organisation’s operational environment sits inside Microsoft 365.

That might include:

  • Entra ID;

  • Exchange Online;

  • SharePoint;

  • Teams;

  • Intune;

  • Microsoft Defender; and

  • associated Azure services.

Cyber Essentials will assess relevant technical controls around devices, accounts, software, updates and internet-facing infrastructure.

A broader DCC readiness exercise may require organisations to consider how that Microsoft environment contributes to overall security and resilience.

That can include areas such as privileged access, conditional access, endpoint compliance, security monitoring, information protection, recovery and governance.

This is where treating DCC as purely a certification exercise can become problematic.

The technology needs to support the assurance being claimed.

How Symposium IT can help

Symposium IT helps UK Defence suppliers understand the gap between their existing cyber security position and the requirements associated with Defence Cyber Certification.

Through Symposium Defence, we work across Microsoft 365, Azure, identity, endpoint security, cloud governance and cyber resilience to help organisations establish where they currently stand and what needs to change.

For organisations that already hold Cyber Essentials, that means looking beyond the certificate itself.

We help identify whether the scope is appropriate, assess the wider technology environment, highlight security and governance gaps and build a practical route towards DCC readiness.

Already Cyber Essentials certified?

That is an excellent foundation.

But with the MOD asking industry partners to achieve DCC Level 0 by 31 December 2026, now is the time to establish whether Cyber Essentials represents the beginning of your DCC journey — or whether your organisation is already much closer to readiness than you think.

Explore Symposium Defence to find out more about Defence Cyber Certification and assess your organisation’s readiness.

Continue reading