Key Takeaways
- The Ministry of Defence (MOD) has asked every member of the industry supply chain to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026 as a minimum.
- MOD Commercial have stated having DCC in place may well prove to be a deal breaker, when selecting future suppliers.
- Level 0 is the entry point of a four-level scheme. It covers three control areas and is the most achievable.
- Cyber Essentials sits at the heart of DCC Level 0. Get that in place and you are most of the way there.
- You do not need a live defence contract to certify. Any organisation can apply, at any level, at any time.
- Starting now avoids the year end rush, when certification body diaries fill up and evidence takes time to gather.
The Ministry of Defence (MOD) has asked all of its industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, which includes Cyber Essentials for the business-critical systems in scope. If you supply to the defence sector, or if you want to, that deadline now sits in your calendar. DCC Level 0 is the most straightforward step in the scheme, and it is well within reach for organisations of any size.
What the MOD Has Actually Asked For
The request is specific. The MOD has asked all industry partners to reach DCC Level 0 by 31 December 2026, with Cyber Essentials required for all applicable business critical systems within scope. It is part of a wider push that includes the Cyber Resilience Pledge and the forthcoming Cyber Security and Resilience Bill, all aimed at strengthening the UK’s supply chains.
DCC Level 0 is the first and simplest step, not the whole scheme. It is the entry level requirement for doing business with Defence and provides MOD and larger buyers with independent proof that your organisation meets a recognised baseline, without you answering the same security questions for every new enquiry. Some suppliers will need a higher DCC Level for more complex work. So what does Level 0 involve in practice?
Why DCC Level 0 Is Achievable, and What It Involves
DCC has four levels, 0 to 3, delivered through IASME, the MOD’s official certification partner. Level 0 covers 3 baseline controls. Level 1 covers 101 controls in total, Level 2 covers 139, and Level 3 covers 144. That gap is why Level 0 is the shared starting line for everyone. Every level of DCC is built on Cyber Essentials, the UK’s foundational security standard. Level 0 asks for Cyber Essentials to be in place for your business critical systems. Levels 2 and 3 also require Cyber Essentials Plus, the independently tested version. Because Level 0 leans on a standard that thousands of UK organisations already hold, it is realistic to achieve it in a matter of weeks rather than months.
Pera Prometheus has been supporting organisations across the defence supply chain to achieve Cyber Essentials, Cyber Essentials Plus and DCC Level 0, so we know where businesses get stuck and how quickly the right guidance clears the path. We cover the background to the scheme in more detail in our guide on Defence Cyber Certification.
The single biggest factor in achieving Level 0 is getting Cyber Essentials right and that starts with defining an accurate business scope.
Cyber Essentials: The Piece to Get Right First
Most of the Level 0 effort sits in Cyber Essentials, so it makes sense to tackle it first. The standard covers a core set of technical controls, things like keeping software updated, controlling who has access to what and setting up devices securely. Most of it is good practice you may already have in place.
The part that catches organisations out is scope, which means deciding exactly which systems, devices and services the assessment will cover. Draw the boundary in the wrong place and you can fail on something that was never a real risk form a scoping perspective or expend nugatory effort on perceived risks which have no bearing or impact on the defined scope. Our post on Cyber Essentials scoping explains why this one decision matters more than people expect. If you plan to move on to Cyber Essentials Plus later, it helps to know what the assessment feels like, which we walk through in Inside a Cyber Essentials Plus Audit. With the groundwork clear, the last question is timing.
Don’t Leave It to the Last Quarter
There is no need to panic, but a good reason not to wait. Cyber Essentials and the Level 0 assessment both take time. Evidence has to be gathered, small fixes may be needed, and Certification Bodies work through applications in turn. As December approaches, your application may just sit in a queue.
There is a supply chain dimension too. Primes are responsible for passing security requirements down to their subcontractors, so if you supply a larger contractor, they may ask you to certify well before their own deadline. The MOD’s own advice, drawn from the first organisations through the scheme, is to start with scope and begin gathering evidence early. For more on how these obligations pass down the chain, see our post on supply chain assurance for PRIMEs.
Pera Prometheus can help
Working out where to begin, and which certification you need, is often the hardest part. Pera Prometheus is an approved certifying body for Cyber Essentials, Cyber Essentials Plus and DCC Level 0, and we are helping organisations across the Defence supply chain reach the December deadline, with room to spare. Get in touch and let’s work out where you stand.
Frequently Asked Questions
Q: Is the 31 December 2026 deadline mandatory for achieving DDC Level 0?
A: The MOD has asked all industry partners to reach DCC Level 0 by that date. If you work with defence or want to, treat it as a firm expectation.
Q: Do we need a defence contract before we can certify?
A: No. Any organisation can apply for DCC at any level and at any time, whether or not you are currently bidding for defence work.
Q: What does DCC Level 0 actually require?
A: Three baseline controls – Cyber Essentials for your business critical systems, being GDPR compliant and operating a resilient business. DCC Level 0 is the entry level of the scheme.
Q: How long does it take to achieve DCC level 0?
A: For many organisations it is a matter of weeks, most of it spent on Cyber Essentials. Starting early leaves time for any fixes.
Q: We are a small supplier low down the chain. Does this still apply to us?
A: Very likely, yes. If you supply a larger defence contractor, they may ask you to certify so they can meet their own obligations.


