Risk Crew launches Defence Cyber Certification assessments for MOD suppliers

Published: 29th September 2026

Organisations supplying the Ministry of Defence are being asked to demonstrate resilience across the business, not simply the security of information handled under one contract. To help suppliers meet this expectation, Risk Crew now provides Defence Cyber Certification (DCC) assessment and certification at Levels 0 and 1.

DCC is based on Defence Standard 05-138 issue 4 and delivered through IASME. It provides organisation-level assurance against controls appropriate to a supplier’s Cyber Risk Profile. That profile, and the level required for a particular contract, is set by the MOD or a prime contractor. A successful certificate can support more than one contract at or below the certified level.

The timing matters. The MOD has asked its industry partners to achieve at least DCC Level 0 by 31 December 2026, including Cyber Essentials for applicable business-critical systems. IASME says DCC is not generally mandatory for every tender at present, so suppliers should check the precise requirements and deadline for each contract or prime contractor relationship.

What do Levels 0 and 1 involve?

Level 0 covers three controls: Cyber Essentials, UK data protection obligations, and the resilience of networks and systems. It is intended for a very low assessed Cyber Risk Profile and establishes a foundation for subsequent levels.

Level 1 covers 101 controls and calls for evidence of a comprehensive cyber security programme. Following an assessment of the organisation’s answers and supporting evidence against an 80% theoretical pass mark, the applicant demonstrates that relevant controls work in practice. It is normally associated with a low to moderate assessed risk profile.

Both levels start with Cyber Essentials or Cyber Essentials Plus. DCC scope extends to the parts of the organisation necessary to function and deliver securely. An existing Cyber Essentials certificate may need review if it excludes essential systems or business functions. This is particularly relevant where a supplier has treated the MOD project as a self-contained environment while relying on shared IT, people, premises or operational technology.

A clear route through the assessment

Risk Crew’s assessors help applicants understand the required level, review their proposed scope and clarify what evidence is expected. For Level 0, we review the three controls and verify them. For Level 1, we score the submission, provide a clarification round and verify control effectiveness through a practical session. The engagement concludes with reporting, a debrief and, where the required standard is met, a certificate issued through the IASME scheme.

Certification must remain independent. Applicants own their scope, answers, policies and evidence. Risk Crew can explain the standard and findings, but as the assessing Certification Body cannot implement controls or write evidence it subsequently assesses. If gaps require hands-on work, that work needs an independent route and sufficient time before reassessment.

For an IT director facing a bid or renewal deadline, the best starting point is to confirm the level required by the MOD or prime, check the scope and status of Cyber Essentials, and identify who can supply evidence across the business. This quickly shows whether the organisation is ready for assessment or needs more preparation.