CYBER CERTIFICATION

Defence Cyber Certification (DCC)

Defence Cyber Certification (DCC) logo

What is Defence Cyber Certification (DCC)?

The Defence Cyber Certification (DCC) is a UK Ministry of Defence (MOD) endorsed scheme designed to improve the cyber resilience of the MOD supply chain. It ensures that all suppliers, regardless of size, meet proportionate levels of cybersecurity based on the sensitivity of the contracts they support. Managed by IASME, the scheme offers a clear framework to demonstrate compliance with MOD cyber requirements.

How does it work?

The DCC categorises suppliers into four certification levels (Level 0–3) based on the assessed cyber risk of the MOD contract. Each level reflects increasing expectations of cybersecurity controls, planning, and governance, from basic cyber hygiene at Level 0 to sophisticated “defence in depth” strategies at Level 3.

Each certification level is linked to a defined number of controls, combining technical measures with broader organisational security governance, and mapping to established frameworks like Cyber Essentials, GDPR, and Cyber Essentials Plus.

Why use StarSwift?

At StarSwift, we help defence suppliers of all sizes meet DCC requirements confidently. From initial risk mapping to evidence preparation and assessment readiness, we offer deep MOD and cyber compliance expertise. Whether you’re aiming for Level 0 certification or preparing a Level 3 audit, our tailored support ensures you meet your contract’s cyber expectations.

Downloads

  • tbc

Certification Levels

Each DCC level corresponds to the level of cyber risk identified in your MOD contract. The framework is structured as follows:

Level 0 – Basic (3 controls)

For very low risk contracts. Requires:

  • Cyber Essentials certification
  • GDPR compliance
  • Operation of a resilient network

The focus is on foundational cyber hygiene to protect minimal-risk data.

Level 1 – Enhanced (101 controls)

For low to moderate risk contracts.

Introduces governance controls including defined roles, responsibilities, and oversight structures.
Builds upon Level 0 by introducing layered organisational measures alongside technical controls.

Level 2 – Advanced (139 controls)

For high-risk contracts. Requires:

  • Cyber Essentials Plus certification
  • Advanced cybersecurity oversight, planning, and formal risk management.
  • Builds upon Levels 0 and 1 with extensive organisational and technical practices.

Level 3 – Expert (144 controls)

For substantial-risk contracts.

Designed to counter sophisticated threat actors, this level introduces an additional 5 complex controls beyond Level 2.

Emphasises a ‘defence-in-depth’ model and mature security capabilities across systems and people.

Meet MOD cyber obligations. Secure defence supply chain status. Protect critical systems and data.

Defence Cyber Certification enables suppliers to demonstrate operational resilience and cyber maturity to MOD buyers. StarSwift offers streamlined, expert-led pathways to compliance that align with evolving MOD expectations.

Aligned with MOD risk levels

Clear progression from basic to advanced cybersecurity controls depending on your contract’s sensitivity.

Mapped to Cyber Essentials and GDPR

Structured around industry-recognised frameworks that promote confidence in defence procurement.

Supports Def Stan 05-138 compliance

Enables organisations to meet cyber protection standards embedded in MOD contract clauses.

Mitigates cyber risk exposure

Drives continuous improvement in security governance, planning, and operational response.

Specialist defence sector guidance

StarSwift brings practical experience supporting MOD-aligned audits, supply chain reviews, and certifications.

Get A Quote

Get a Defence Cyber Certification (DCC) Quote

Get in touch today to find out more about the Defence Cyber Certification (DCC), and how the we can help your organisation.

Contact Us

Contact Form Demo

Have Any Questions?

Find the most frequently asked questions and find your answer

What is DCC and who is it for?

DCC is a MOD-backed certification for all suppliers that deliver outputs under MOD contracts, ensuring proportionate cybersecurity based on contract risk.

How many certification levels are there?

There are four: Level 0 (Basic), Level 1 (Enhanced), Level 2 (Advanced), and Level 3 (Expert), each with increasing control depth.

How do I know which level applies to me?

Your MOD contract will specify the Cyber Risk Level (Very Low to Substantial), which maps directly to a DCC certification level.

Do I need Cyber Essentials or Cyber Essentials Plus?

Yes. Level 0 requires Cyber Essentials, while Level 2 and above requires Cyber Essentials Plus.

What are the control counts for each level?

  • Level 0: 3 controls
  • Level 1: 101 controls
  • Level 2: 139 controls
  • Level 3: 144 controls

What’s included at Level 3?

Level 3 introduces five complex new controls for advanced threat detection, response planning, and operational resilience, on top of Levels 1 and 2.

Can I scale up if my contract changes?

Yes. You can move between levels if your contract scope or risk profile changes.

How long does certification take to achieve?

Level 0 and 1 may take a few days; Level 2 and 3 can take 2–6 weeks depending on readiness and audit requirements.

Can StarSwift handle the entire process?

Absolutely. From risk profiling and readiness reviews to submission and audit management, we support you end to end.

Does DCC apply to sub-contractors?

Yes. Sub-tier suppliers handling sensitive information or systems must also demonstrate compliance with the appropriate DCC level.

What our customers say

Musketeer Solutions

Business Director Peterborough, Management Consultancy East Anglia

We are incredibly pleased with the outstanding service provided by Rob Lancaster of StarSwift in supporting us through the Cyber Essentials certification process and delivering ongoing IT security services.  Rob has worked with us for several years and established an excellent understanding of our business and requirements.

Hallinans

Namita, Managing Director

We were fortunate to be invited to work with Rob and he made the process seamless, straightforward and without the jargon and complication that often comes which computers and technology. Rob’s knowledge is first rate as is his swift communication and competitive pricing. Options were always provided to us along with reasoning and recommendation. Cannot recommend Rob and StarSwift highly enough. 

Lone Star Analysis

Kat Simmonds, CoS

Well organised, Rob is very clear in his explanations and communicates well throughout the assessment.

Growth Studio Group

Andy Bennett, Director

Rob was extremely helpful and responsive to questions we had with our Cyber Essentials Certification. It made the whole process seamless. 

Related Articles