How to align your DCC Level with MOD contract expectations

Key Takeaways

  • DCC Level 0 is a baseline that MOD expects every supplier to achieve by 31 December 2026.
  • For any specific contract, the MOD sets a Cyber Security Model (CSM) Cyber Risk Profile Level. You do not choose it yourself.
  • MOD flows down CSM Cyber Risk Profile Levels, normally through industry Primes, to the Supply Chain. 
  • As a commercial certification aligned to MOD CSM, DCC Cyber Risk Profile Levels align to the MOD CSM.
  • Commercial organisations can choose which DCC Level they wish to achieve, but there may be a minimum Level flowed down to you by MOD or a Prime Industry.
  • Higher DCC levels mean more controls need to be implemented and Levels 2 and 3 require Cyber Essentials Plus.
  • If you sub-contract to other suppliers, you are required to assess the risk of doing so and flow down the Cyber risk to them, ensuring they either hold an appropriate level of Defence Cyber Certificate or conform to the required CSM Cyber Risk Profile level.

Defence suppliers must be aware that although the DCC (beyond Level 0 after 31 December 2026) is currently optional, this is very likely to change in the near future, with every indication being that MOD will expect increasing numbers of organisations to achieve DCC.  As much as organisations can choose any DCC level they wish to achieve, they may find the level dictated to them as risk profiles are flowed down the supply chain from MOD and Primes.

The baseline everyone shares: DCC Level 0

Before any contract specific level comes into play, there is a base level that applies to the whole defence supply chain. The MOD has asked all of its industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026.  DCC Level 0 is built on Cyber Essentials, for those business critical systems in scope. Think of it as a licence to operate, insofar as it is a pre-requisite to working in Defence.

DCC Level 0 applies to every organisation who wants to work with defence, regardless of any other certifications you may have e.g. ISO 27001. Cyber Essentials is a mandatory prerequisite of DCC, therefore, it is crucial you understand what the scope of your Cyber Essentials needs to cover.  

As an approved certifying body for Cyber Essentials, Cyber Essentials Plus and DCC Level 0, Pera Prometheus supports organisations with defining scope on a regular basis. 

How does the MOD set the CSM Cyber Risk Profile Level?

When the MOD has a requirement, its own delivery team completes a Risk Assessment for that activity and assigns a Risk Assessment Reference (RAR). The assessment looks at the sensitivity of the information involved within the contract. When the Risk Assessment is complete a Cyber Risk Profile Level, rated from Level 0 to Level 3 is assigned. We explain how these profiles work in CSM Version 4 Explained. In other words, the MOD does this work as the buyer, it is not something you can decide for yourself.

You then receive that decision. The official Cyber Security Model guidance states that a Risk Assessment Reference number and the required Cyber Risk Profile Level will be provided by the authority at the earliest market engagement and will usually be found in the invitation to tender. In plain English, you open the tender pack, you find a reference number and a profile level which tells you the Cyber Risk Profile Level the contract expects.  The task for your organisation is to prove you meet the requirements at that Level.  This will either be by completing the CSM Supplier Assurance Questionnaire (SAQ), if provided to you by MOD, or more increasingly, by achieving the appropriate DCC compliance.  Only MOD can enable you to complete the SAQ but you can choose to attain DCC whenever you wish.

So, as a Defence Industry supplier you can choose to position yourself to be ready to achieve the MOD CSM standard, ahead of time by achieving DCC, provided you choose the appropriate level.

What is the requirement of each DCC level?

DCC has four levels and the higher the level, the more controls you have to satisfy to provide MOD with the appropriate degree of confidence its’ supply chain is Cyber secure. The controls come from Defence Standard (DefStan) 05-138 issue 4, the control standard that underlies both the CSM and DCC schemes. This is clearly explained by IASME, Defence Cyber Certification.

DCC LevelNumber of controlsAlso requires
Level 03Cyber Essentials
Level 1101Cyber Essentials
Level 2139Cyber Essentials Plus
Level 3144Cyber Essentials Plus

The jump from Level 0 to Level 1 is large and Levels 2 and 3 raise the bar again with the Cyber Essentials Plus requirement, which is an audited check rather than a self-assessment. The important point is that you match the level in your contract or, more likely, your Security Aspects Letter (SAL). 

Does the DCC level apply to your subcontractors?

If you win the work and then place part of it with subcontractors, the roles flip. You become the buyer for that onward work and you have to run your own Risk Assessment to decide what Cyber Risk Profile your suppliers need, your SAL should provide further direction on this. This is how protection is meant to flow down the chain, so that risk is managed effectively and suitably ‘owned’.

For PRIMEs and larger contractors, this is not optional housekeeping. If your flow-down is wrong, you carry the risk. A weak link below you can place the whole contract at risk . How can Pera Prometheus help?

Reading a Cyber Risk Profile off a tender and knowing what it means for your business is not always obvious, especially the first time. At Pera Prometheus we work with defence contractors and supply chain organisations at exactly this stage, from Level 0 through to the higher tiers. As the certifying body for Level 0 and having assisted companies with implementation at higher DCC levels, we are very much aware of the challenges businesses face. Pera Prometheus uses its in-depth knowledge of DefStan 05-138 issue 4, the CSM, and DCC to provide clarity and alleviate doubts when pursuing the required certification. Our website has plenty of information and blogs on this subject should you wish to research further. Alternatively, Get in touch and let’s work out where you stand.

Frequently Asked Questions

Q: Does the MOD tell me which DCC level I need? 

A: No. For a given contract the MOD completes a Risk Assessment and will assign a CSM Cyber Risk Profile Level. You do not choose the CSM level but you can choose your DCC level, although it will be expected to at least match the MOD assigned CSM Cyber Risk Profile Level.

Q: How do I identify my required DCC level? 

A: In the invitation to tender, shown as a Cyber Risk Profile Level, your contract, or your SAL.

Q: Is DCC Level 0 mandatory for everyone working with MOD? 

A: Yes, Level 0 is the baseline the MOD expects all defence suppliers to hold by 31 December 2026.

Q: What is the difference between a CSM v4 Cyber Risk Profile Level and a DCC Level? 

A: The Cyber Risk Profile is the risk rating the MOD assigns to the work. The DCC level is a certification that enables your organisation to prove that it meets the controls for that Level.

Q: Do subcontractors need the same DCC level as the PRIMEs? 

A: Not always. PRIMEs run their own Risk Assessment to set the right level for each subcontractor, based on the information they handle.

Stay Safe, Stay Secure