Bridging the gap between academic research and real-world solutions
In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by
Joshua Ashton
Insight
8 Sept 2026
4 min read

DCC Level 0: What UK Defence Suppliers Need to Know in 2026
Cyber security expectations across the UK Defence supply chain are changing.
The Ministry of Defence has asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) scheme by 31 December 2026. This includes obtaining Cyber Essentials for all applicable business-critical systems within scope.
For businesses supplying directly to the MOD, prime contractors, or organisations further down the Defence supply chain, the practical question is simple:
Are you ready?
What is Defence Cyber Certification?
Defence Cyber Certification, or DCC, is an organisation-wide cyber security certification designed to provide independent assurance of a supplier’s cyber resilience.
It was developed by the MOD in partnership with industry and IASME and is aligned with the MOD’s Cyber Security Model Version 4, or CSMv4.
There are four certification levels:
DCC Level 0
DCC Level 1
DCC Level 2
DCC Level 3
The appropriate level is linked to the cyber risk associated with the work being undertaken. Level 0 represents the baseline, while higher levels introduce significantly more controls and assurance requirements.
Why does DCC Level 0 matter now?
The key date is:
31 December 2026
The MOD has explicitly asked all industry partners to achieve DCC Level 0 certification by this date.
This is significant because Level 0 is expected to become the baseline level of cyber resilience across the Defence supply chain. Current MOD guidance also says suppliers should expect an increasing requirement to hold valid DCC certification for the duration of MOD contracts.
That means organisations should not view DCC simply as another compliance exercise.
It is becoming part of how Defence assesses whether suppliers are sufficiently cyber resilient to participate in the supply chain.
Is DCC currently mandatory?
This needs some nuance.
IASME currently states that DCC is not yet universally mandatory, and the level required for a specific contract will be determined by the MOD or the relevant prime contractor.
However, the direction of travel is clear.
The MOD has asked industry partners to reach Level 0 by the end of 2026, and suppliers should expect certification requirements to increasingly appear in procurement and contract conditions.
For businesses already operating within Defence, waiting until certification becomes an explicit tender requirement may leave very little time to identify and remediate gaps.
Is Cyber Essentials the same as DCC?
No.
Cyber Essentials is a prerequisite and important component of DCC, but holding Cyber Essentials does not automatically mean that an organisation is DCC certified.
All DCC levels begin with Cyber Essentials certification, while DCC Levels 2 and 3 require Cyber Essentials Plus.
DCC goes further by assessing organisational security and resilience against the controls contained within Defence Standard 05-138.
This is one of the most important distinctions for suppliers that already hold Cyber Essentials.
Cyber Essentials is an excellent starting point.
It is not the end of the journey.
What does DCC Level 0 involve?
Level 0 is the foundation level of the DCC scheme.
IASME currently describes it as comprising three controls, alongside the required Cyber Essentials certification. It is normally associated with work presenting a very low assessed level of cyber risk.
Although Level 0 is the entry level, organisations should still consider the scope of their certification carefully.
DCC is concerned with organisational security and resilience rather than simply isolating the systems used for one Defence contract.
The certification scope should include the functions and services essential for the organisation to operate securely and resiliently.
What should Defence suppliers be reviewing now?
The first step is to establish your current position.
A practical readiness review should consider areas including:
whether your Cyber Essentials certification is current;
whether the scope of Cyber Essentials aligns properly with the proposed DCC scope;
the systems and services essential to operating your business;
Microsoft 365 and cloud security;
identity and access management;
multi-factor authentication;
endpoint and device management;
patching and vulnerability management;
administrative privilege;
backup and recovery;
security monitoring;
supplier and third-party risk;
policies and governance;
incident response; and
any existing CSMv4, DEFSTAN 05-138 or DEFCON 658 obligations.
The objective is to find gaps before they become a problem during an assessment, tender or customer assurance process.
What happens if a supplier cannot meet the requirements?
The MOD has a formal mechanism called a Cyber Improvement Plan (CIP).
Where a supplier cannot meet the applicable Cyber Security Model requirements, including the required DCC certification level, they may be required to submit a CIP setting out what needs to be remediated and the timescales involved.
A CIP should not, however, be treated as an alternative to becoming compliant.
It is a mechanism for demonstrating how identified deficiencies will be addressed.
The earlier those deficiencies are understood, the easier it becomes to build a realistic remediation plan.
How does Microsoft 365 fit into DCC readiness?
For many SMEs in the Defence supply chain, Microsoft 365 sits at the centre of the organisation.
Email, identity, collaboration, file storage, endpoint management and security may all depend on technologies such as:
Microsoft 365;
Entra ID;
Intune;
Microsoft Defender;
SharePoint;
Teams; and
Azure.
That makes the configuration of the Microsoft environment an important part of overall cyber resilience.
Areas such as conditional access, privileged accounts, device compliance, endpoint protection, logging, information protection and recovery should therefore be reviewed as part of a wider DCC readiness exercise.
DCC should not be approached as paperwork alone.
The underlying environment needs to support the security controls being claimed.
What about subcontractors?
Cyber requirements can flow down the Defence supply chain.
Under CSMv4, where a supplier subcontracts work, the supplier completes a Flow Down Risk Assessment to establish the Cyber Risk Profile applicable to the subcontractor. The subcontractor must then meet the appropriate requirements.
This is particularly relevant to SMEs that may not contract directly with the MOD but instead work for a prime or another Defence supplier.
A business does not necessarily need a direct MOD contract for DCC to become commercially relevant.
How Symposium IT can help
Symposium IT helps organisations across the UK Defence supply chain understand their current cyber posture and prepare for evolving Defence cyber requirements.
Our work spans Microsoft 365, Azure, identity, endpoint management, cyber security, cloud governance and ongoing managed IT.
Through Symposium Defence, we help organisations identify technical and governance gaps, strengthen their security posture and build a practical route towards Defence cyber readiness.
The aim is not simply to help businesses pass an assessment.
It is to help create a more secure, resilient environment that can stand up to the increasing expectations being placed on Defence suppliers.
Preparing for DCC Level 0?
If you supply the MOD, a Defence prime, or another organisation within the UK Defence supply chain, now is a sensible time to understand your current position.
With the 31 December 2026 Level 0 objective approaching, identifying gaps early gives you more time to remediate them properly.
Explore Symposium Defence to learn more about DCC readiness and how we can help your organisation prepare.



