Skip to main content

Framework · UK defence supply chain

Defence Cyber Certification (DCC)

The UK MoD supply chain cyber assurance scheme, structured across three tiers calibrated to the defence threat profile.

DCC is the procurement gate for Tier 2 and Tier 3 MoD supply chain organisations. Goldline calibrates ISO 27001 implementation scope to maximise overlap with DCC Level 1 and Level 2 control expectations.

What is Defence Cyber Certification?

Defence Cyber Certification is the UK MoD supply chain cyber assurance scheme, governed under DCPP (Defence Cyber Protection Partnership) and evolving DCC governance arrangements. The scheme structures supplier cyber expectations across three tiers (Level 0, 1, 2) calibrated to the threat profile of defence supply chain engagements. DCC is becoming the procurement gate for Tier 1 prime flowdown contracts to Tier 2 and Tier 3 suppliers.

What DCC covers

Three tiers across foundational cyber hygiene (L0), structured governance and controls (L1, 101 controls), and deeper assurance and monitoring (L2, 139 controls).

DCC Level 0

Entry tier covering foundational cyber hygiene controls expected of all defence supply chain organisations.

DCC Level 1

101 controls covering policy, governance, asset management, access control, and supplier security expectations.

DCC Level 2

139 controls extending Level 1 with deeper governance, monitoring, incident response, and assurance requirements.

Independent assurance

Certification by accredited bodies under DCPP and emerging DCC governance frameworks.

Defence-specific control sets

Calibrated to the threat profile and supplier security expectations across the UK MoD supply chain.

Mapping to ISO 27001 and CE+

Substantial overlap with ISO 27001 Annex A and Cyber Essentials Plus enables efficient parallel implementation.

Why UK organisations adopt DCC

DCC adoption is driven by Tier 1 prime flowdown, JOSCAR procurement integration, and the defence-specific threat profile not fully covered by ISO 27001 or CE+ alone.

Tier 1 MoD primes are flowing DCC expectations into Tier 2 and Tier 3 supplier contracts as a procurement gate.

Defence-specific threat profile expectations are not fully covered by ISO 27001 or CE+ alone.

JOSCAR registration and DefStan 05-138 alignment increasingly reference DCC progression.

DCC certification is becoming a pre-qualification standard for UK defence supply chain contracts.

Defence-adjacent commercial organisations face DCC expectations through prime flowdown clauses.

Demonstrable defence-grade cyber posture supports broader UK public sector and regulated procurement.

DCC vs ISO 27001 vs Cyber Essentials Plus

 DCCISO 27001Cyber Essentials Plus
TypeUK Defence Cyber Certification scheme.International ISMS standard.UK government baseline cyber hygiene scheme.
ScopeThree tiers (L0, L1, L2) with defence-calibrated controls.Risk-based with 93 Annex A controls.Five technical controls with independent audit.
CycleIndependent assurance under DCPP / emerging DCC governance.Three-year certification cycle.Annual renewal cycle.
RecognitionRequired across UK MoD supply chain procurement.Globally recognised; foundational for DCC progression.Frequently a CE+ prerequisite for DCC progression.

DCC scheme structure

DCC operates as a structured ecosystem with four parties carrying distinct responsibilities. Goldline operates as the implementation partner preparing your organisation for certification body assessment.

  • DefStan 05-138 Issue 4: the Ministry of Defence security standard defining the control set and four risk levels. The technical standard against which DCC certification is assessed.
  • IASME: the scheme operator. IASME operates the DCC scheme on behalf of the Ministry of Defence and licenses accredited Certification Bodies to deliver DCC assessments.
  • UKAS-accredited Certification Bodies: independent assessment bodies licensed by IASME. CBs deliver the formal DCC assessment, apply professional judgement against DefStan 05-138, and issue certification. CB accreditation operates under ISO/IEC 17021-1 to maintain impartiality.
  • Implementation partners: organisations preparing suppliers for CB assessment. Goldline operates in this role. Implementation partners do not issue certificates and maintain separation from CB assessment to preserve scheme impartiality.

METHODOLOGY

How Goldline delivers DCC certification readiness

The Goldline Method applied to Defence Cyber Certification. Five phases from CRP scoping through certification body assessment, calibrated to your target DCC level and prime contractor flowdown requirements.

  1. 01

    Phase 1

    CRP scoping and DCC level confirmation

    Senior practitioner evaluation against CSMv4 Cyber Risk Profiles. Target DCC level (Level 0 or Level 1) confirmed against prime contractor flowdown requirements. Organisational boundary defined. Cyber Essentials currency verified as DCC precondition.

    • CRP attestation
    • Level confirmation
    • Scope boundary
  2. 02

    Phase 2

    DefStan 05-138 control mapping and gap analysis

    Comprehensive gap analysis against DefStan 05-138 Issue 4 controls at target level. Level 0 covers three foundational controls. Level 1 covers one hundred and one controls across five control objectives. Existing posture mapped to determine implementation effort.

    • Gap analysis
    • Control mapping
    • Effort estimation
  3. 03

    Phase 3

    Control implementation and policy framework

    Management policy framework, risk methodology, asset inventory, and technical controls implemented against the target DCC level. Implementation calibrated to existing security maturity and ISO 27001 status where applicable. ISO 27001:2022 evidence reuse compresses Level 1 timelines materially.

    • DefStan controls
    • Policy framework
    • Technical controls
  4. 04

    Phase 4

    Internal review and evidence pack assembly

    Senior practitioner-led internal review against DCC assessment criteria. Evidence pack assembled to certification body submission standard. Nonconformities remediated prior to CB engagement. Readiness validated to ensure no surprises at assessment.

    • Evidence pack
    • Internal review
    • Remediation closure
  5. 05

    Phase 5

    Certification body assessment support

    IASME-accredited certification body partner engaged. Submission to CB managed. Theoretical scoring phase, practical scoring phase including assessor interviews, and assessor day support delivered. Annual attestation cycle preparation included post-certification.

    • CB submission
    • Assessor day
    • Certification

Related reading

  • Defence Cyber Readiness Check, twelve questions that map your posture to a Def Stan 05-138 risk profile.
  • DEFCON 658, the contract condition that makes cyber risk assessment and supplier assurance contractual.
  • Def Stan 05-138, the standard that sets the risk levels and the control set behind DCC.

Frequently asked

Explore the DCC Acceleration Programme

Goldline delivers the DCC Acceleration Programme as a productised fixed-scope engagement for UK Tier 2 and Tier 3 MoD suppliers facing DCC Level 0 or Level 1 flowdown.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.