Skip to content
Compliance

Do I Need DCC for MOD Contracts? MOD Asks Suppliers for DCC Level 0 by End of 2026

The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems. This guide explains what the MOD has actually said, who it affects, how DCC levels map to your contract, and what suppliers should do now - with the primary gov.uk sources.

a large building with a clock on the top of i

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

9 min read

Share

Section 01

Do I Need DCC for MOD Contracts? The MOD Has Asked Suppliers to Achieve DCC Level 0 by End of 2026

In a MOD Defence Digital blog published on 8 May 2026, Eleanor Fairford, the Ministry of Defence's Director of Cyber Defence and Risk, stated: "I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems." Separately, Industry Security Notice (ISN) 2026/02 confirms that DCC is now the MOD-recognised way to evidence the controls required by DEFSTAN 05-138 under DEFCON 658, with the DCC level you need mapped to your contract's Cyber Risk Profile. Taken together, the direction of travel is clear: DCC Level 0 is becoming the baseline expectation across the MOD supplier base, with higher levels pulled by individual contract profiles on top. This guide explains what has actually been said, who it affects, and what to do now.

This is the most significant shift in UK defence supplier cyber assurance since the Defence Cyber Protection Partnership (DCPP) Supplier Assurance Questionnaire process gained independently assessed DCC evidence. The full SAQ remains mandatory under current CSMv4 guidance. The two primary sources are the MOD Defence Digital blog One year of Defence Cyber Certification (8 May 2026) and Industry Security Notice 2026/02 (30 March 2026). Everything in this guide is tied back to one of them, and where we give our own view of what happens next we say so explicitly.

Fig Compliance Ltd holds separate IASME Certification Body licences for Cyber Essentials, DCC Level 0, and DCC Level 1. The mandate is set by MOD; the scheme is delivered by IASME; assessments are delivered by IASME-licensed Certification Bodies including Fig Group. You can verify the Certification Body’s DCC licence scope.

Section 02

What the MOD has actually said

There are two distinct, officially published pieces to understand, and it is worth being precise because they say different things.

One: the MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026. This is a direct statement from Eleanor Fairford, Director of Cyber Defence and Risk, in the MOD's 8 May 2026 Defence Digital blog. Note the exact wording: the MOD has "asked" suppliers to achieve Level 0 - a clear directive with a firm date - and it explicitly includes obtaining Cyber Essentials for all applicable business-critical systems. It is framed as a request to the whole supplier base rather than, at this stage, a blanket contractual bar.

Two: DCC is the recognised way to evidence DEFSTAN 05-138 compliance, with the level tied to your Cyber Risk Profile. ISN 2026/02 (30 March 2026) confirms that a supplier holding valid DCC certification "at a level equal to, or greater than" the level required by their contract may submit it as evidence of satisfying DEFSTAN 05-138 under DEFCON 658. The required level is set by the contract's Cyber Risk Profile (CRP): a Level 0 requirement is met by DCC Level 0; a higher CRP needs the correspondingly higher level, up to Level 3. A higher-level certificate can evidence lower-level controls where its entity, scope and validity fit the contract; the full SAQ still applies.

Fig Group's read on where this goes. Combining the two: DCC Level 0 is becoming the effective baseline for the MOD supplier base, with higher levels pulled by individual contract CRPs on top. Our assessment is that, over time, DCC will function as a gating control - prime contractors verifying it down their supply chains, and suppliers without it increasingly unable to bid for or hold MOD work. That consequence is our view of the direction of travel, not a stated MOD position today. The firmly sourced facts are the 31 December 2026 Level 0 ask and the CRP-to-level mapping above.

Section 03

Why MOD is moving this way

DCC adds independent evidence against Def Stan 05-138 issue 4. CSMv4 broadens the focus from MOD-identifiable information to organisational security and resilience, using numeric Levels 0–3. It does not eliminate SAQs: the current full SAQ, annual contract maintenance and risk-based subcontract flow-down remain. CAF means Cyber Assessment Framework.

The 8 May industry request sets a clear planning target. It does not by itself establish that every framework rejects every uncertified supplier or that there are no contract-specific transition arrangements. Procurement conditions come from the actual tender, DEFCON 658, applicable notices and buyer instructions. A non-compliant SAQ requires a CIP for the authority to consider.

Outside defence, PPN 014 applies to central-government departments, their executive agencies, non-departmental public bodies and NHS bodies for relevant procurements commenced from 24 February 2025. Cyber controls must be relevant and proportionate; the policy allows equivalent controls and does not require certification for every public contract.

Section 04

Who should plan for the industry request

The MOD request addresses all industry partners. Direct suppliers, subcontractors and prospective suppliers should ask their buyer how the requirement applies to their legal entity, contract and operational scope. Flow-down needs the assigned CSMv4 profile and RAR; each subcontract has its own risk assessment. An adjacent NHS or infrastructure contract does not automatically inherit DCC merely because the work is defence-related. Confirm its actual terms.

Section 05

Plan against a confirmed deadline

Assessment availability depends on the chosen body, scope and readiness. Obtain a written schedule and leave buffer for remediation and supplier responses. This guide has no authenticated capacity dataset establishing a national shortage, rising-price forecast or guaranteed booking window.

Early DCC scoping may proceed while Cyber Essentials is prepared. Current CE is required before DCC certification; arrange CE certification separately if needed. A current certificate can support several contracts where entity, scope, level and dates fit, but each still needs its SAQ.

Section 06

What suppliers should do before end of 2026

Six concrete actions, in order.

One: confirm your Cyber Essentials status today. If you do not hold a current CE certificate, get one. Fig Group issues CE in six working hours of a compliant submission from £299.99 + VAT for Micro organisations. See Cyber Essentials.

The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.

Two: read your existing MOD contracts and prime flow-downs for a CRP. Three patterns appear: the clause names the CRP explicitly, the clause names a DCC level explicitly, or the clause uses vague language without naming the level. If your clause is vague, ask the contracting authority in writing before incurring assessment cost.

Three: book scoping against your confirmed deadline. Ask for available assessment dates now and agree a realistic preparation schedule. Earlier H1 booking advice is no longer actionable in the second half of 2026.

Four: build the three-year DCC renewal cycle into your calendar. DCC certificates are valid for three years with annual attestation at the end of years one and two. The end-of-2026 deadline is the first deadline, not the only one. Build the annual cadence into the same calendar that holds your CE renewal.

Five: confirm whether Level 0 is enough. Use the buyer’s numeric profile and written DCC conditions. If your pipeline includes a confirmed Level 1 requirement, assess the timing and cost of Level 1. Uncertainty alone does not justify an upsell; see the level comparison.

Six: read the standard. The substantive requirements are in Defence Standard (Def Stan) 05-138 issue 4. The DEFSTAN 05-138 supplier guide covers what the standard requires, what evidence the assessor wants, and how the four control sets map onto the four DCC levels.

Section 07

DCC pricing under the mandate

Fig Group publishes DCC pricing openly so suppliers can budget before scoping. Pricing structure does not change with the mandate; what changes is the size of the population in scope.

DCC Level 0 is flat-priced by organisation size, delivered in 2-3 weeks for prepared organisations:

  • Micro (1-9 employees): £499.99 + VAT
  • Small (10-49 employees): £599.99 + VAT
  • Medium (50-249 employees): £699.99 + VAT
  • Large (250+ employees): £799.99 + VAT

DCC Level 1 is range-priced from £9,999 + VAT (Micro, simple scope) to £49,999 + VAT (Large, complex scope), delivered in 6-10 weeks for prepared organisations. Variance drivers: site count, cloud footprint, legacy system presence, supply-chain depth, staff population, existing maturity.

For the full pricing detail and variance breakdown, see the DCC pricing detail on the hub.

Section 08

Frequently asked questions

Do I need DCC for MOD contracts?

If your MOD contract requires compliance with DEFSTAN 05-138 (under DEFCON 658), DCC is now the MOD-recognised route to evidence it, at the level matching your contract's Cyber Risk Profile (ISN 2026/02). Separately, the MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026. So for most MOD suppliers the practical answer is yes - Level 0 as a minimum, and a higher level if your contract's CRP calls for it.

Will DCC be mandatory?

The MOD's Director of Cyber Defence and Risk has asked all industry partners to achieve DCC Level 0 by 31 December 2026 - a firm date and a clear directive, though phrased as a request rather than, at this stage, a universal contractual bar. Where a contract requires DEFSTAN 05-138 compliance, DCC at the CRP-appropriate level is already the accepted way to evidence it. Fig Group's assessment is that DCC will increasingly function as a gating control for MOD work.

Is DCC Level 0 mandatory for all MOD suppliers by end of 2026?

The MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026 (MOD Defence Digital blog, 8 May 2026). It is a clear, dated directive to the whole supplier base; higher DCC levels are triggered by individual contract Cyber Risk Profiles. Treat Level 0 as the baseline to plan for.

What happens if I do not hold DCC Level 0 by end of 2026?

There is no published MOD statement that non-compliant suppliers will be barred. Fig Group's assessment, from the direction of travel, is that DCC Level 0 will increasingly become a condition of bidding for and holding MOD contracts, with prime contractors verifying certification down their supply chains. Planning to hold Level 0 by the 31 December 2026 date the MOD has set is the safe course.

Does the mandate apply to subcontractors as well as prime contractors?

The industry request addresses all partners, but contractual obligations and subcontract flow-down must be checked with the relevant buyer. Do not infer a universal no-exemption rule or automatic rejection from the request alone.

Can I be certified at a higher level instead of Level 0?

A higher-level certificate may evidence a lower-level requirement when entity, scope and validity fit. Current CSMv4 uses numeric levels; legacy verbal wording needs confirmation from the buyer rather than automatic conversion.

How long does DCC Level 0 take?

Fig Group's published Level 0 delivery is 2-3 weeks for prepared organisations. The variance lives in the Cyber Essentials prerequisite - suppliers without current CE need to add the CE engagement time.

What does DCC Level 0 cost?

Fig Group publishes Level 0 from £499.99 + VAT (Micro, 1-9 employees) to £799.99 + VAT (Large, 250+ employees). See the DCC pricing detail.

What is the difference between DCC and Cyber Essentials?

Cyber Essentials is the UK foundational cyber certification, required as a prerequisite at every DCC level. DCC is the MOD-specific organisation-wide certification built on top of CE, governed by Def Stan 05-138 issue 4. CE proves endpoint and network baseline; DCC adds organisation-level governance, supply-chain, and resilience controls.

What if my contract does not name a Cyber Risk Profile?

Read the contract clause carefully. If the CRP is genuinely not named and the clause refers to "defence standards" or "industry cyber security", ask the contracting authority in writing before incurring assessment cost. Regardless of an individual clause, the MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026; higher levels apply when a CRP is assigned.

Section 09

Where to start

The three practical entry points for suppliers facing the 2026 mandate are the same regardless of where the trigger came from.

1. Read the DCC scoping guide for the scope boundaries and the IASME-published scoping principles.

2. Read the Cyber Risk Profile reference for the contract-clause language that determines your level.

3. Book a 15-minute scoping call with an IASME-licensed assessor. We will confirm your CRP, review your existing Cyber Essentials evidence, and give you a realistic deadline-aware timeline before any fee is incurred.

The earlier in 2026 you start, the more options you have. The closer to end of 2026 you leave it, the fewer.

Section 10

Scheme sources and contract checks

Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.

IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.

The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.