Blog: Sep 2026 What UK Defence suppliers need to know about the DCC 31 December deadline

News & Insights > Blog >

The Ministry of Defence (MOD) has asked all defence industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026.

Existing MOD suppliers and any organisation planning to enter the defence market need to be getting to grips with DCC now rather than waiting until it becomes an immediate contractual requirement.

While cyber resilience is not a new priority for defence, DCC is an important development in how cyber security maturity is demonstrated across the supply chain.

What is DCC?

DCC is a cyber security framework developed by the MOD and IASME for organisations supplying the UK defence sector. The required level is set by the MOD to reflect the cyber risk associated with each contract.

There are four levels. Level 0 applies where there’s very low cyber risk, Level 1 covers low to moderate risk, Level 2 is for high cyber risk and Level 3 for substantial risk. There is a big difference between the levels, with Level 0 having three controls and Level 3 having 144. All levels begin with Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus.

Organisations can achieve certification proactively rather than waiting for a relevant contract. And for companies who want to grow in the defence market, DCC will help them prepare for future opportunities.

Why does it matter now?

The defence industry is growing. According to ADS, the defence sector generated £36.5 billion in turnover in 2025 and its contribution to the UK economy was £15.8 billion.

Increased government investment in defence is also creating opportunities across traditional defence capabilities and emerging areas including artificial intelligence, autonomous systems, software and advanced manufacturing. A technology company or specialist SME that may not previously have seen itself as a defence supplier may well find its products or services supporting a defence programme.

Importantly, threat actors targeting defence are not necessarily going to attack the most obvious target. Smaller contractors can be an attractive route into the wider ecosystem.

Not just another compliance exercise

Cyber Essentials may provide the foundation for DCC but it goes considerably further depending on the level required. Its controls address four broad areas - managing security risk, protecting against cyber attack, detecting cyber security events and minimising the impact of cyber security incidents.

Assessment goes beyond whether an organisation has particular security technologies in place. Governance, risk management, processes, incident response and the practical operation of security controls all matter. Having a policy that says an organisation manages vulnerabilities is very different from being able to demonstrate that vulnerabilities are effectively identified, prioritised and addressed.

DCC has additional significance following the MOD Industry Security Notice 2026/02, issued in March. It confirmed that suppliers holding DCC certification at the appropriate level can submit details of it as evidence of satisfying the relevant controls under Defence Standard 05-138 where required by DEFCON 658.

For organisations working across multiple defence contracts, DCC provides a more consistent, risk-based way of demonstrating cyber security assurance than addressing equivalent requirements on a contract-by-contract basis.

What should suppliers do now?

It is important to establish what DCC level is likely to apply and what systems, services and business activities will be within scope. Organisations should then assess current security maturity against relevant controls and identify any gaps.

That assessment has to go beyond technology. Weaknesses may be in governance, policies, risk management, third-party relationships, incident response or even the evidence needed to demonstrate controls are actually operating.

Organisations can then prioritise remediation and prepare for the certification process, which includes both theoretical and practical assessment. The time needed will vary depending on organisational maturity, scope, preparedness and the level being pursued.

There is no advantage in leaving it until the deadline is approaching. For organisations that identify significant gaps, starting early gives the opportunity to address gaps properly instead of treating DCC as a last-minute compliance exercise.

The opportunity behind the deadline

DCC is a structured, risk-based way of assessing and demonstrating resilience across the supply chain. For established suppliers, it is a framework for strengthening security. For SMEs, it helps build the foundations needed to scale. And for companies entering the market, it provides evidence that cyber security has been taken seriously from the start.

The MOD's December 2026 deadline is an opportunity for defence suppliers to understand their current position, identify any gaps and consider what level of cyber security maturity they will need as their role in the defence ecosystem develops.

Need help preparing for DCC?

31 December 2026 may be the deadline but the opportunity to understand your position and address any gaps needs to start now.

AMR CyberSecurity, part of Infinum, is a DCC Level 0–3 certified assessor organisation with extensive experience across the MOD and defence supply chain. If you are unsure which level your organisation may need, want to understand your current position or want support preparing for certification, get in touch with us now to discuss.

Get in touch about DCC

Related Resources

Defence Cyber Certification (DCC)

AMR CyberSecurity is an accredited DCC Level 0–3 Certification Body, authorised by IASME and the Ministry of Defence to independently assess and certify suppliers in the Defence Supply Chain.

Find out more
Registered address
AMR CyberSecurity, 3000a Parkway
Whiteley, Fareham
Hampshire, PO15 7FX
UK
© 2026 AMR CyberSecurity · Registered Company Number: 11551941