Defence suppliers / Engineering businesses

IT and cyber security for defence and aerospace

Support your people, protect engineering data and prepare the evidence your customer requires.

Managed IT, cyber security and supplier assurance, with responsibilities agreed around your contract and existing internal team.

An engineer working on electronic components under a task light.
Verified
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body Cyber Essentials PlusCertified NCSC AssuredCyber Advisor scheme CISSPHeld by Daniel McClure Fisher

Contract requirements

Your Cyber Risk Profile and assessment route

Start with the Cyber Risk Profile, Risk Assessment Reference and security instructions supplied by your customer. These determine the controls and evidence to review.

Def Stan 05-138 sets out supplier cyber controls. DEFCON 658 covers the MOD Cyber Security Model, including subcontractor obligations; DEFCON 659 addresses security measures. Check the conditions and editions incorporated into your contract.

CSMv4 uses Levels 0 to 3. Older profile names do not map directly to those levels. If your requirement is unclear, confirm it with your customer before choosing an assessment.

DCC Level 0

Assessment and certification

DSC is a Defence Cyber Certification body for Level 0. Confirm your organisation’s scope and the current scheme requirements before starting.

Level 0 route
DCC Level 1

Scope, gaps and preparation

Level 1 services are available, including review, remediation and evidence preparation. The engagement agrees the appointed body and formal assessment arrangements.

Level 1 services
Customer assurance

Questionnaires and supporting records

A DCC certificate does not currently replace the full Supplier Assurance Questionnaire. We help organise the controls and records relevant to your answers.

Compare DCC routes

Engineering information

Access, recovery and supplier evidence

Design files, test results and customer material need named owners, controlled access and a recovery plan.

Customer questionnaires

Match each answer to an implemented control, its owner and a dated record. JOSCAR registrations, renewals and prime-specific reviews can use an organised evidence index.

Design and test data

Identify who can change, share and recover each dataset. Include external partners, engineering workstations, shared storage and the interfaces to flight systems in the scope discussion.

Quality and cyber records

Where AS9100 or the Cyber Assessment Framework (CAF) is relevant, agree how IT records support the review. Certification or conformance is not implied by a service engagement.

Services

Support for the agreed environment

Choose the work your organisation needs. Projects, managed services, preparation and formal assessments have their own scope.

Build

Software and systems integration

Connect business systems and reduce repeated data entry, with permissions, change approval and logging considered during discovery. UK-hosted deployment options are available.

Prove

Governance and supplier assurance

Review policies, technical evidence and outstanding actions. Agree who approves questionnaire answers and how evidence will be kept current after the initial review.

Our appointments and certification An appointed certification body for Cyber Essentials and Cyber Essentials Plus. Assured under the NCSC Cyber Advisor scheme. ISO 27001 certified by a UKAS-accredited certification body.

Handling and access

Agree the working boundary

OFFICIAL and OFFICIAL-SENSITIVE information is handled against your contract and customer instructions. Scope can include encryption, need-to-know access, logging, secure disposal and hosting locations.

Our team is UK-based. SC and DV clearance are not held. Any work requiring clearance depends on the appropriate sponsorship, vetting and approval before that work starts.

UK-hosted options are available. ITAR, EAR and UK export control requirements are determined with your specialist advisers; we implement the agreed technical controls.

Questions

Before you start

Do we definitely need Cyber Essentials for MOD work?

Check the Cyber Risk Profile and security requirements supplied by your customer. We help you identify the relevant Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification route. Preparation and formal assessment are scoped separately.

What is the difference between DEFCON 658 and 659?

DEFCON 658 covers cyber obligations, including requirements passed to subcontractors. DEFCON 659 addresses security measures. Review the conditions and editions in your contract alongside any Security Aspects Letter. We identify the IT controls and evidence within our agreed scope.

What security clearances do your staff hold?

We do not hold SC or DV clearance. Our team is UK-based. We confirm the permitted scope before accepting work; any task requiring clearance depends on appropriate sponsorship, vetting and approval.

How do you handle OFFICIAL-SENSITIVE material?

We agree handling controls with you against the contract, information sensitivity and customer instructions. The scope can include access, encryption, logging, disposal and approved hosting locations. The marking alone does not impose a universal UK-only hosting requirement.

Can you help us complete a JOSCAR registration?

We can help organise the cyber security answers and supporting records for JOSCAR registration, renewal and related customer questionnaires. Your organisation approves the submission. We distinguish controls already in place from actions still outstanding.

We handle ITAR controlled data. Can you support us?

We review the technical requirements with your export control advisers before accepting the work. Hosting, administrative access and audit records are agreed for the systems in scope. UK staffing or hosting alone does not establish ITAR or EAR compliance.

Next step

Discuss your contract and IT requirements

Tell us the required assessment, systems involved and target date. We can agree the review needed, the people involved and the basis for a quote.

0118 359 2220 · Reading, Berkshire