Skip to main content

DEFENCE SUPPLY CHAIN

DCC readiness for the defence supply chain.

Protect defence eligibility with a proportionate route to DCC readiness. The Ministry of Defence has asked all industry partners to achieve Level 0 by 31 December 2026.

ISO 42001 Lead Implementer (PECB)ISO 42001 Lead Auditor (PECB)ISO 27001 Senior Lead Implementer (PECB)ISO 27001 Lead Auditor (PECB)CISSP
Download the DCC readiness service sheet (PDF)Service sheet, PDF, August 2026. No email required.

INDEPENDENCE

Advice and assessment cannot come from the same place.

Goldline advises on DCC readiness. Assessment is referred to a DCC certification body.

That split is deliberate and it works in your favour. A DCC certification body cannot advise the clients it assesses, because the independence rules that make its certificate worth anything also prevent it from telling you how to pass. Goldline can. You get the preparation from a party free to give it, and the certificate from a party whose independence is intact.

On mandate: the Ministry of Defence asked industry to reach Level 0 by 31 December 2026, stated on the Defence Digital blog on 8 May 2026 and repeated on 13 July 2026. IASME's own FAQ still states that DCC is not mandatory. Contractual force arrives through DEFCON 658 and the Cyber Risk Profile attached to a specific contract, not through a general legal requirement.

THE REQUIREMENT

Which level applies to you.

DCC is assessed against DEFSTAN 05-138. The level required follows the Cyber Risk Profile assigned to the contract, not the size of the supplier. That profile is set by the buying organisation and flows down through DEFCON 658.

Very Low

Level 0

Prerequisite
Cyber Essentials
Controls
3
Goldline
Supported

Low

Level 1

Prerequisite
Cyber Essentials
Controls
101
Goldline
Supported

Moderate

Level 2

Prerequisite
Cyber Essentials Plus
Controls
139
Goldline
Not offered

High

Level 3

Prerequisite
Cyber Essentials Plus
Controls
144
Goldline
Not offered

Control counts are approximate and scope-dependent. Your applicable profile is established at the scope review. Goldline supports Levels 0 and 1. Levels 2 and 3 are not offered, because they must be led by a UK Cyber Security Council Principal or by a Chartered professional at an NCSC Assured Consultancy.

THE ENGAGEMENTS

Four routes, depending on where you are.

Published starting prices. Final scope and price confirmed at the scope review.

DCC Requirement and Scope Review

Review of contract requirements, DEFCON 658 wording, Cyber Risk Profile, existing certifications and the likely DCC route. Written route map, effort estimate and recommended next step.

Set at the free diagnostic

From £1,950 + VAT

Book a scoping call

DCC Level 0 Readiness Diagnostic

Gap assessment against the applicable DEFSTAN 05-138 expectations at Level 0, evidence review, prioritised remediation plan and assessment roadmap.

2 to 4 days

From £2,500 + VAT

Book a scoping call

DCC Level 1 Readiness Diagnostic

Gap assessment across the Level 1 control set, scoped stakeholder interviews, evidence maturity findings, prioritised remediation roadmap and assessment readiness plan.

4 to 8 days, longer for multi-site or complex estates

From £4,500 + VAT

Book a scoping call

DCC Level 1 mobilisation

Governance setup and sponsor cadence, control owner mobilisation, evidence architecture and tracker, RAID and milestone management, coordinated remediation tracking, and handover to an independent assessor.

Set at the free diagnostic

From £14,000 + VAT

Book a scoping call

Fractional DCC programme lead

One to three days per week for complex remediation, stakeholder coordination and assessment preparation. Minimum three month initial term.

From £4,250 per month + VAT

Book a scoping call

Technical remediation remains client-owned unless separately contracted. Scope is agreed in writing before commencement.

The DCC assessment fee is paid directly to an independent IASME-authorised Certification Body and is not included in these prices.

SCOPING

What moves the price.

Scope is not driven by headcount. It is driven by the following, which the scope review establishes.

  • The number of MOD or prime contracts in scope, and their Cyber Risk Profiles
  • The clarity of the DEFCON 658 wording and whether a Risk Assessment Reference has been issued
  • The number of legal entities and sites
  • Existing Cyber Essentials or Cyber Essentials Plus status
  • Whether the environment includes engineering, operational technology or restricted data
  • Whether the requirement is driven by a live tender or by operational compliance
Alfred Obeng, Founder and Principal Consultant at Goldline Consultancy

WHO DELIVERS THIS

Alfred Obeng

Founder and Principal Consultant, Goldline Consultancy

Senior practitioner credentialed as ISO 42001 Lead Implementer and Lead Auditor (PECB), ISO 27001 Senior Lead Implementer and Lead Auditor (PECB), CISSP and PMP, with delivery experience across UK defence, national security and central government programmes. Engagements are delivered by the founder, not delegated to junior staff.

Defence eligibility is a commercial question before it is a technical one. A supplier that misreads its Cyber Risk Profile either over-invests in controls it does not need or discovers the gap when a contract is already at risk.

QUESTIONS

Common questions.

Five months to the deadline.

A 45 minute scoping call establishes which level applies, what your current position is, and whether the deadline is achievable. No sales pitch.

Or email info@goldlineconsultancy.co.uk

Goldline prepares organisations for DCC assessment. Certification is issued by an independent IASME-authorised DCC assessor.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.