Certification · Last verified

Defence Cyber Certification

Defence Cyber Certification is the MOD's four-level certification route evidencing compliance with the UK Cyber Security Model, launched May 2025. A DCC certification at Level 3 is accepted as satisfying all lower levels, and it is granted in partnership with IASME as Certification Authority.

Class
Certification
Owner
Ministry of Defence (MOD); IASME is the scheme's Certification Authority
Last verified

What it is

Defence Cyber Certification is the MOD's certification route for evidencing compliance with the Cyber Security Model. GOV.UK describes it as having "been created in partnership with industry and IASME, the scheme's Certification Authority, as a way of independently evidencing compliance with the Cyber Security Model". The MOD records that the scheme "launched a year later in May 2025". Certification runs at four levels — DCC Level 0 through DCC Level 3 — mapped to the Cyber Risk Profiles of Defence Standard 05-138; in the MOD's own example, "A DCC certification held at Level 3 is to be accepted as full satisfaction of all lower levels (0, 1 and 2)."

Who owns it

Defence Cyber Certification is a Ministry of Defence (MOD) scheme, with IASME acting as the scheme's Certification Authority.

Who assesses it

GOV.UK states that the scheme "has been created in partnership with industry and IASME, the scheme's Certification Authority, as a way of independently evidencing compliance with the Cyber Security Model".

Levels

  • DCC Level 0
  • DCC Level 1
  • DCC Level 2
  • DCC Level 3

Who asks for it

Public procurement. Statutory contractual condition for MOD contracts within DEFCON 658's scope: "all suppliers engaged on contracts for which the UK MOD is a contracting party, or subcontracts thereof, where the contractor and/or their supply chain is required to comply with DEFSTAN 05-138." Outside MOD contracts and their supply chains, no obligation was identified in the sources reviewed as of 29 August 2026.

The demand comes from MOD contracts. DEFCON 658 "lays out the contractual terms for the Cyber Security Model" and "contains the contractual obligations that suppliers must place upon subcontractors", and ISN 2026/02 "applies to all suppliers engaged on contracts for which the UK MOD is a contracting party, or subcontracts thereof, where the contractor and/or their supply chain is required to comply with DEFSTAN 05-138." The MOD instructs buyers that valid DCC certification at or above the commensurate level "is to be considered in satisfaction of the control requirement to DEFSTAN 05-138". One limit is stated by the MOD itself: "Suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ through the Supplier Cyber Protection Service (SCPS)." Outside MOD contracts and their supply chains, no obligation was identified in the sources reviewed as of 29 August 2026 — confirm against the MOD Delivery Team named in the relevant contract.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Defence Cyber Certification." Certifidex, FutureTechnologies. Last verified 29 August 2026. https://certifidex.com/frameworks/uk-dcc

All frameworks & audits →