DIAGNOSE
Establish your DCC position before the 31 December 2026 deadline forces it.
A fixed-scope diagnostic for UK defence suppliers. Confirms the Defence Cyber Certification level your contracts actually require, tests your current posture against the Level 0 control set, and sets out a costed route to assessment by an accredited body.
Scoped on the free 45 minute diagnostic
THE ENGAGEMENT
A documented position on DCC, before you spend on remediation.
Most defence SMEs first hear about DCC through a flowdown clause or a supplier questionnaire, with no clarity on which level applies to them. Work then starts in the wrong place: remediating controls that were never in scope, or assuming Level 0 when the Def Stan 05-138 risk profile points higher. The assessment settles the level first.
A senior, SC Cleared practitioner reviews your contract pipeline and prime flowdown obligations, confirms the target DCC level, verifies Cyber Essentials currency and scope against the intended organisational boundary, and runs a gap analysis against the applicable Def Stan 05-138 Issue 4 controls.
The output is a short report a board can act on: the level required, the gaps that matter, the effort to close them, and the sequencing to assessment. Where you are already close, the report says so rather than manufacturing a programme.
DELIVERABLES
What you receive.
Target DCC level confirmed against contracts and prime flowdown obligations
Organisational boundary and assessment scope defined
Cyber Essentials currency and scope verified against the DCC boundary
Gap analysis against the applicable Def Stan 05-138 Issue 4 controls
Prioritised remediation plan with indicative effort and sequencing
Costed route to assessment, including introduction to an accredited Certification Body
FIT
Who this is for.
- You supply into the MOD supply chain directly or through a Tier 1 prime.
- DCC, DEFCON 658, or Def Stan 05-138 has appeared in a contract, questionnaire, or supplier review.
- You need a defensible position on the 31 December 2026 Level 0 expectation before budget is committed.
This is not for organisations with no MOD or defence supply chain exposure. If DCC has not been asked of you and is not coming through a prime, the assessment has nothing to measure.
WHAT COMES NEXT
Where organisations go from here.
Once the level and the gaps are settled, the work splits two ways: closing the Cyber Essentials and control gaps, and routing to an accredited Certification Body for assessment. Goldline delivers the first and coordinates the second. Certification itself is issued by the accredited body, not by Goldline.
DEFENCE SUPPLY CHAIN
Defence Cyber Certification hub
What DCC requires, the four levels, the Cyber Essentials prerequisite, and how preparation runs to the 31 December 2026 deadline.
Read the DCC hubIMPLEMENTATION
ISO 27001 Sprint
ISO 27001 covers a substantial share of the DCC Level 1 and Level 2 control sets, and is often the efficient route where higher levels are in scope.
Explore the ISO 27001 SprintQUESTIONS
Common questions.
Settle the DCC question before a prime settles it for you.
Thirty minutes to establish your contract exposure, your current certification position, and whether the readiness assessment is the right next step.
Prefer email? Write to info@goldlineconsultancy.co.uk.
