What’s changed from the Supplier Assurance Questionnaire?

  • Applicant guide

    This document helps your organisation to compile and map documented evidence to the DefStan 05-138 Issue 4 controls.

  • Compliance is no longer contract-by-contract

    Unlike the SAQ, once certified, DCC is valid for three years aside from annual check-ups.

  • Governance-focused

    DCC requires your business to show that cybersecurity is embedded across essential organisational functions, moving from narrow, contract-scoped SAQs to a single, evidence-based certification.

Why your organisation needs DCC

  • To bid for MoD contracts

    Although not yet mandatory for all MoD contracts, most require DCC compliance, and it’s likely to become mandatory as the scheme is rolled out.

  • Win contracts and credibility

    DCC compliance goes beyond MoD tenders; it can also help you win credibility and contracts throughout the defence sector.

  • Improve your organisation’s cybersecurity posture

    DCC is more than just a tick in a box; it can help improve your organisation’s day-to-day cybersecurity, ultimately protecting you from attack.

  • Level 0

    3 controls, 6 questions – Cyber Essentials required

  • Level 1

    101 controls, 236 questions – Cyber Essentials required

  • Level 2

    139 controls, 328 questions – Cyber Essentials Plus required

  • Level 3

    144 controls, 337 questions – Cyber Essentials Plus required

Rapid turnaround

Our experienced assessors will help you get DCC certified quickly.

DCC and Cyber Essentials in one package

With our Defence Readiness Package, you’ll get DCC, Cyber Essentials certification, and year-round assurance in a single purchase.

Expert support

Get expert support from our team of cybersecurity experts, including technical queries, guidance on preparing evidence for the Applicant Guide and renewal advice.

Continuous protection and monitoring

We go beyond assessment day with continuous monitoring, actionable alerts, and regular compliance reporting to help maintain your cybersecurity posture year-round.

Pre-assessment preparation

Benefit from pre-assessment support to review your current cybersecurity posture and identify any vulnerabilities or gaps.

We’re the UK’s leading certification body

CyberSmart is the UK’s most trusted certification body, delivering more certifications than anyone else.

Need help with certification?

Whether you’re a MOD supplier or aiming to be, CyberSmart can help.

Frequently asked questions

  • The DCC is a new cybersecurity certification developed by the MoD and IASME to replace the contract-by-contract SAQ process with a single, per organisation assessment valid for 3 years.

  • Yes, depending on the level you need to be certified to, you’ll need at least a Cyber Essentials certification. Levels 2 and 3 also require Cyber Essentials Plus.

  • All MOD contracts undergo a cyber risk profile (CRP) assessment based on the four levels outlined by Defence Standard 05-138. Each contract is then given a level based on the CRP assessment, which suppliers must demonstrate they can meet when bidding for the contract.

    For example, if the contract you wish to bid for has been designated at Level 1, your organisation must be DCC certified to the same level or above.

  • The Applicant Guide is a structured document that helps your organisation to compile and map documented evidence to the DefStan 05-138 controls. It will provided by the certification body assessing your organisation.

  • Due to the complexity of DCC, there’s no defined timescale as it can depend on your preparedness, the security gaps you need to remediate, and assessor availability.

  • Not for all MoD contracts yet. However, this is likely to change as the scheme is rolled out. 

  • The certification lasts three years, but an annual review is required to maintain the certificate, along with annual recertification to Cyber Essentials or Cyber Essentials Plus.