The Countdown to DCC Level 0 Starts Now

The MoD has set 31 December 2026 as the deadline for every industry partner to achieve DCC Level 0 certification, five months from now. That reaches every organisation in the supply chain, not just the primes at the top. Five months sounds like plenty of time. It gets tighter fast once you count backwards from scoping, evidence gathering and booking an assessment slot.

What is DCC and what is Level 0?

Defence Cyber Certification is an organisation-wide certification aligned to the MoD's DEFSTAN 05-138, introduced through the Cyber Security Model version 4 (CSMv4) in December 2025. It is delivered through IASME's network of assured Certification Bodies, providing a single, independently assessed route to demonstrating cyber resilience, valid for three years with annual attestation. Certification is open to any organisation, regardless of whether it currently holds or is bidding for a defence contract.

There are four levels (0 to 3), each aligned to the cyber risk profile of the contracts an organisation holds. Level 0 is the entry point, designed for organisations with a very low contract risk profile. It is the baseline that every organisation in the defence supply chain is now expected to reach.

Level 0 has two core requirements: a current Cyber Essentials certification covering all applicable in-scope business-critical systems, and completion of the Level 0 Supplier Assurance Questionnaire assessed against DEFSTAN 05-138.

Who is in scope?

The MoD's ask covers all industry partners, not just prime contractors. Organisations further down the supply chain are also in scope. Prime contractors are expected to encourage their subcontractors to work towards Level 0 and to set appropriate timescales for higher levels where those are required at lower tiers.

The MoD already works with around 12,000 SMEs through its supply chain, which gives a sense of scale. Many of those 12,000 SMEs will need to meet the Level 0 deadline, not just tier-one contractors.

DCC is not currently a legal mandate, but the MoD has asked all partners to achieve Level 0. For organisations with DEFCON 658 in their contracts, DCC becomes a contractual requirement rather than a request. If you're not sure which camp you're in, your prime contractor or customer can tell you. That's the fastest way to find out.

For MSPs managing IT for defence sector clients, the question to ask is whether those clients understand their DCC obligations and have a plan in place to meet them. Many probably don't.

Why five months is shorter than it looks

The MoD used their recent announcement to share a success story: Lockheed Martin became the first company to achieve DCC Level 3, and their EMEA Information Security Officer, James Shortle, gave a detailed account of what preparing for certification actually involved. His opening point was direct: start with scoping. It determines everything that follows. Before gathering evidence or addressing gaps, an organisation needs to understand which systems are in scope, what data is handled, and how its infrastructure maps to the DCC controls. He also noted that engaging early with a certifying body, through IASME, helps avoid misinterpreting how controls apply to your specific organisation.

Five months sounds like plenty of time. But remove the time needed to scope, close gaps, gather evidence and book an assessment slot, and the window to act is measured in weeks, not months.

It's worth noting where DCC sits in the wider picture. The MoD's SME Action Plan, published on 21 July 2026, commits to increasing SME spend by an additional £2.5 billion by summer 2028, a 50% increase on the current £5 billion annual baseline. The plan doesn't reference DCC directly, but it confirms the defence supply chain UK SMEs operate in is growing, not shrinking, which is useful context when weighing up whether certification is worth the effort.

Where the lead time actually goes

The broader message was that even for Lockheed Martin, which already operates a strong internal governance model, scoping proved complex. For organisations approaching DCC for the first time, the process is likely to take longer than expected.

Their security lead's advice went beyond scoping. Get board-level buy-in early, not as a box to tick once assessment is already underway. A similar change is already happening on the Cyber Essentials side: since April, a director's signature on a CE self-assessment commits to maintaining compliance throughout the certification period, not just confirming it was accurate on the day they signed. Since CE certification is a prerequisite for DCC Level 0, organisations that already hold it have that board-level commitment in place before DCC preparation starts. Those that don't are effectively building it in as one of the first steps. Treat Level 0 as a chance to test how the controls apply to your organisation, rather than something to clear quickly and move on from. And start gathering evidence before an assessment is even booked: Level 3 certification alone carries more than 300 requirements, each needing multiple pieces of supporting evidence, which gives some sense of how fast the workload builds once you're past Level 0.

Their security lead's advice also touched on subcontractors further down the supply chain: not every supplier will need Level 2 or Level 3, and there is nothing wrong with treating those as a longer-term goal rather than an immediate requirement. For most organisations, Level 0 is the actual target for December, not a stepping stone to rush past.

What Cyber Essentials means in this context

CE certification covering all applicable in-scope systems is the starting requirement for DCC Level 0. Level 0 certification cannot be granted without it.

That has two practical knock-on effects. Organisations without CE need to give that process its own slot in the timeline, since CE requires its own preparation, submission and assessment before DCC can begin. Organisations that already hold CE but haven't reviewed their scope recently should check they're still compliant and that the certification covers every business-critical system DCC Level 0 needs in scope.

CE and DCC are designed to work together. CE handles the technical controls. DCC builds governance and assurance on top of that. Getting CE in place is still the most immediate, practical step any organisation in the defence supply chain can take right now.

For prime contractors

If your organisation sits above lower-tier suppliers, pushing Level 0 progress down the chain and setting realistic timescales for it is your responsibility under the MoD's ask.

The MoD is specific about sequencing. If a subcontractor needs a level above 0, that work is expected after 31 December 2026, not squeezed in before it. Level 0 is the December priority for the whole supply chain. Higher levels still matter. They're simply scheduled for after December rather than instead of it.

For MSPs with defence sector clients

The DCC deadline creates a direct obligation for many of your clients, and most probably don't know it yet. Some may not know they're in scope at all. The practical first step is helping clients identify whether DEFCON 658 applies to their contracts, what level they're required to achieve, and whether their current CE status is sufficient to begin the DCC process. From there, the route is the same for everyone: Cyber Essentials first, then DCC Level 0 or Level 1, depending on what the contract requires.

Eleanor Fairford, the MoD's Director of Cyber Defence & Risk, described DCC as "a badge of excellence in cyber resilience for all Defence industry partners." Earning it, for most organisations in this supply chain, starts with paperwork rather than ceremony: get Cyber Essentials in place, then work through Level 0 before December.


For organisations in the defence supply chain: CyberSmart is an IASME-accredited DCC certification body, assessing organisations for Level 0 and Level 1 certification. We confirm your scope, get you Cyber Essentials certified if you're not already, and take you through DCC certification ahead of the December deadline.

For MSPs with defence sector clients: CyberSmart gives you the DCC expertise and certification capability to support defence sector clients directly, from confirming scope and completing Cyber Essentials through to Level 0 or Level 1 assessment.

Start your DCC journey