The short version

Need DCC for a defence contract? We are a DCC Level 0 Certification Body. See Level 0 assessment prices, with or without Cyber Essentials, or compare our Level 0 and Level 1 services if you are still confirming the required level with your buyer.

The MOD’s Cyber Security Model addresses risk across the supply chain. A prime contractor passes relevant requirements to subcontractors, who may need to assess their own subcontracted activity in turn. A tier-2 or tier-3 business can therefore receive a defence security requirement without contracting directly with the MOD.

Three things define how this works in practice. Def Stan 05-138 is the standard that sets out the cyber security controls by risk level. DEFCON 658 is the contract condition that makes those controls binding and pushes them down the chain. Cyber Essentials, and often Cyber Essentials Plus, is the baseline certification that sits at the entry levels. Get those three straight and the rest follows.

  • The requirement flows down the supply chain through the contract, not just to the prime.
  • Cyber Essentials is required at every DCC level; Levels 2 and 3 require Cyber Essentials Plus.
  • The buyer's risk assessment determines the required level, including for tier-2 and tier-3 suppliers.

Def Stan 05-138: the standard that sets the bar

Defence Standard 05-138 is the Ministry of Defence's standard for the cyber security controls expected of suppliers. Rather than a single fixed bar, it sets out escalating levels of control based on the risk attached to the information and the contract. The risk level is assessed for each contract, commonly through a risk assessment process the buyer runs, and that level then dictates which controls you must hold.

The principle is proportionality. CSMv4 considers organisational security and resilience; the risk assessment is not determined only by the classification of information handled. As the risk level rises, the controls move from the Cyber Essentials baseline up through more demanding frameworks. The current issue of the standard aligns these higher levels with recognised frameworks, so the controls map to things like ISO 27001:2022 and the NCSC Cyber Assessment Framework rather than inventing a separate scheme.

DCC level Controls to evidence Certification prerequisite
Level 0 3 controls Cyber Essentials
Level 1 101 controls Cyber Essentials
Levels 2 and 3 139 and 144 controls respectively Cyber Essentials Plus

Source: IASME's DCC level requirements. Cyber Essentials is a prerequisite; it does not meet the remaining DCC controls on its own. CSM version 4 uses Levels 0 to 3. The legacy risk labels do not map directly to them.

DEFCON 658: how the requirement reaches you

Def Stan 05-138 says what good looks like. DEFCON 658 is the contract condition that makes it binding. DEFCON clauses are the standardised conditions the Ministry of Defence includes in its contracts, and 658 is the one dealing with cyber security. When it is in a contract, it requires the supplier to meet the risk based controls and, critically, to flow the same obligation down to any subcontractors whose work touches the relevant information.

That flow down is the part smaller firms miss. If you subcontract part of a defence job, you are expected to place the required condition on your own suppliers. It is also why a tier-3 firm can receive the requirement from a tier-2 firm it does not think of as "defence" at all. DEFCON 659 concerns Security Measures; current MOD guidance refers to DEFCON 659A for SECRET or above. DEFCON 658 governs the cyber flow-down. Check the clauses actually incorporated into your contract.

The Supplier Cyber Protection Service

The buyer provides a Cyber Risk Profile and Risk Assessment Reference. You complete the Supplier Assurance Questionnaire through the Supplier Cyber Protection Service against that requirement. If you subcontract work, you carry out the downstream risk assessment for your supplier. Holding DCC does not currently remove the full questionnaire requirement. See the MOD's CSM version 4 process.

If the SAQ identifies non-compliance, the MOD’s process (opens in new tab) requires a Cyber Improvement Plan for the authority to consider. A DCC certificate currently does not exempt the supplier from completing the required SAQ. Confirm annual SAQ renewal and any agreed CIP obligations as part of ongoing contract management.

Where Cyber Essentials and Cyber Essentials Plus fit

Cyber Essentials is required at every DCC level. Cyber Essentials Plus is required at Levels 2 and 3 and may be requested separately by your customer. It adds technical testing, in which an assessor checks a sample of your devices and accounts, on top of the Cyber Essentials self-assessment.

There is now a further layer. Defence Cyber Certification is the independent certificate that evidences compliance with the Cyber Security Model, and the MOD has asked industry partners to hold DCC Level 0 by 31 December 2026. Every level of DCC requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus, so the certification you already hold is the foundation for it rather than a separate exercise. Our comparison of DCC and Cyber Essentials sets out how the two relate.

This matters for planning, because Cyber Essentials Plus is verified on your live systems, not just declared on a form. The same issues that catch any business out, unpatched devices, everyday accounts with admin rights, unmanaged personal phones on company email, and missing multi factor authentication, will catch a defence supplier out too, with a contract deadline attached. The defence context raises the stakes of failing, not the nature of the controls.

At the higher risk levels the picture broadens beyond Cyber Essentials into fuller frameworks. Def Stan 05-138 Issue 4 maps its higher levels to ISO 27001:2022 and the NCSC Cyber Assessment Framework, so a supplier moving up the chain is moving from a technical baseline towards a managed information security system. That is a larger programme, and worth recognising early if your contracts are trending that way.

The path for a tier-2 or tier-3 supplier

If you are a smaller supplier who has just seen a defence security clause appear in a contract or a questionnaire, here is a sensible order to work in.

  • Read the clause and identify the standard. Confirm whether the contract cites DEFCON 658, references Def Stan 05-138, and names Cyber Essentials or Cyber Essentials Plus. Note any specific risk level given.
  • Confirm your required level. Obtain the Cyber Risk Profile and Risk Assessment Reference from your customer. Complete your Supplier Assurance Questionnaire against that requirement.
  • Map your gaps against that level. Check your real systems against the controls required. This is the same gap review any Cyber Essentials project starts with, scoped to the risk level the contract demands.
  • Get certified at the right level. Achieve Cyber Essentials, and Cyber Essentials Plus if required, before the deadline. Build in time for remediation, because the audit tests your live systems.
  • Flow the requirement down. If you subcontract relevant work, place the equivalent condition on your own suppliers, and keep the records that show you did.
  • Keep the evidence current. Certifications lapse and risk levels change between contracts. Treat this as something you maintain, not a one off hurdle.

A note on JOSCAR and supplier assurance

Many defence and aerospace primes also use supplier assurance registers such as JOSCAR to check who they are dealing with. Cyber Essentials and the Def Stan 05-138 controls tend to feed into that wider picture, alongside quality, financial, and other checks. The same discipline helps here: knowing your certifications, holding the evidence, and being able to answer a supplier assurance questionnaire without a last minute scramble before the prime's deadline.

How we approach it

As an appointed Cyber Essentials, Cyber Essentials Plus and DCC Level 0 certification body, we can discuss the assessment you need. Daniel McClure Fisher is a certified Cyber Essentials Assessor. We start with the requirement supplied by your customer and your existing evidence, then agree preparation work and formal assessment responsibilities. For Level 1, we provide preparation support and confirm the assessment route in the engagement.

FAQ

Common questions

What is DEFCON 658?

DEFCON 658 is the standardised cyber security condition the Ministry of Defence includes in its contracts. When it applies, the supplier must meet the risk based controls set out in Def Stan 05-138 and flow the same obligation down to any subcontractors whose work touches the relevant information. It is the contractual mechanism that pushes defence cyber security requirements down the supply chain, which is how a smaller supplier ends up subject to it.

What is Def Stan 05-138?

Defence Standard 05-138 specifies the controls required under the MOD's Cyber Security Model. Issue 4 supports CSM version 4. Cyber Essentials is a prerequisite at every DCC level, with additional controls to evidence. Existing work on ISO 27001:2022 or the NCSC Cyber Assessment Framework may help organise your evidence, but does not replace the required DCC assessment.

Do I need Cyber Essentials or Cyber Essentials Plus to supply defence?

Every DCC level requires Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus. A customer may also specify Plus separately. Confirm the required certification with your buyer before booking an assessment.

What is the difference between DEFCON 658 and DEFCON 659?

DEFCON 658 sets cyber security and supply-chain obligations. DEFCON 659 concerns Security Measures, and current MOD guidance refers to DEFCON 659A for contracts involving SECRET or above. Read the clauses in your contract. The MOD explains the current conditions in Industry Security Notice 2026/04.

I am a small subcontractor, why does a defence requirement apply to me?

Because the requirement flows down the supply chain. DEFCON 658 obliges each supplier to place the equivalent condition on its own subcontractors whose work touches the relevant information. So a tier-2 firm passes it to a tier-3 firm, and a small business can find a defence security clause in a contract without ever dealing directly with the Ministry of Defence. The controls are scaled to your risk level, so they are usually proportionate to the work you do.

How long does it take to get certified for a defence contract?

Timing depends on the required scheme, scope, evidence and remediation. Cyber Essentials may be ready quickly once its controls are met; Plus adds technical testing and scheduling. DCC Level 1 and higher levels need broader evidence. ISO 27001 and CAF work can support that evidence, but neither replaces the DCC assessment. Agree the buyer’s deadline and formal route before booking.