Purpose and Scope
Designed to enhance the cyber resilience and security of the UK defence sector’s supply chain, it focuses on overall organisational security, rather than just the systems and data used to deliver a contract, and demonstrates ongoing commitment to improvement. It aligns with international standards and best practices, involving a point-in-time assessment against the UK Defence standard DEFSTAN 05-138i4.
Achieving and maintaining DCC certification signals an organisation’s dedication to cyber resilience, providing verifiable assurance for defence-related bids and contracts.
See SCC Scoping Guide - V1.3 for more details.
Certification Levels
Each level aligns with a Cyber Risk Profile (CRP) level that is assigned to a project by the MOD
Process and Requirements
- All levels require Cyber Essentials certification; Levels 2 and 3 also need Cyber Essentials Plus.
- Applicants must show compliance with controls, explain how they meet them, and provide evidence.
- Supporting documents are available to guide understanding of controls and assessment questions.
- Re-certification every 3 years; annual check-ins required.
- Companies can still apply if they are not currently participating in an MOD contract but would need to estimate the level that they may need in the future.
- No documentation is ever sent to a Certification Body, it is either presented over a screen share session (for the lower levels) and is presented to assessors whilst on site for the higher levels.
- The company must maintain an evidence record that never needs to leave their systems. See for more details.
Engaging with us
- When you wish to certify, contact us and we will need to know:
- The company Size
- Scope
- Number of Sites
- Complexity of the Organisation
- Any clearances required.