InsightsCyber Security

Is DCC Level 0 mandatory by 31 December 2026?

The MOD has asked its suppliers to hold Defence Cyber Certification Level 0 by the end of 2026. Its guidance also says every invitation to tender should set Level 0 as the minimum.

5-minute read

No law requires DCC Level 0 by 31 December 2026. The Ministry of Defence (MOD) has asked its industry partners to hold it by then, and IASME, the scheme's certification authority, says "DCC is currently not mandatory".

It matters if you supply the MOD or a defence prime. This post covers the MOD's exact wording and what happens at tender if you don't hold DCC Level 0 certification.

What the MOD said

The date comes from the MOD's Digital and Data blog on GOV.UK. A post on 13 July 2026 says the MOD has "asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026".

The same sentence adds that this "includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope". An earlier post, on 8 May 2026, quotes Eleanor Fairford, the MOD's Director of Cyber Defence & Risk, saying she'd made the same request.

Both posts use the word "asked". IASME's FAQ adds that the MOD will decide which contracts require DCC.

IASME also says you can tender for MOD contracts through the normal MOD process without DCC at this stage. Where a tender asks for a DCC level you don't hold, you'd bid with a Cyber Improvement Plan (covered below).

What "asked" means for a bid

The MOD's Cyber Security Model guidance on GOV.UK tells suppliers to "expect to see increasing requirement to hold valid DCC certification" for the length of their MOD contracts. It says this will be written in as a condition of tenders.

The request also reaches you through the supply chain. IASME's FAQ says the level you need for a contract "will be decided by the MOD or your Prime".

The 31 December date applies to Level 0. Where higher levels of certification are required further down the supply chain, Eleanor Fairford says in the MOD's 8 May post that these "should be scheduled for delivery after 31 December 2026".

On 30 March 2026 the MOD issued Industry Security Notice (ISN) 2026/02. It instructs buyers to accept a current, valid DCC certificate at the contract's level or higher as meeting the Def Stan 05-138 control requirement under DEFCON 658.

The ISN's table maps each certificate to the contract levels it covers. A Level 0 certificate covers Level 0 requirements only.

If you don't have Level 0 by 31 December

The MOD's Cyber Improvement Plan (CIP) template, updated on 17 July 2026, says all invitations to tender "should specify at least a minimum Level 0 certification requirement". The MOD's published guidance doesn't set a consequence for missing 31 December itself.

If you don't hold DCC at the level a contract asks for, MOD guidance says you must submit a CIP, and it should go in with your tender. The buyer takes your compliance, or your CIP, into account when choosing a supplier.

An agreed CIP becomes part of the contract and sets a grace period for each stage of compliance.

During a grace period the buyer agrees not to claim losses or end the contract over the gap, except in cases like negligence, fraud or not putting agreed interim measures in place. Once the period ends, the buyer's full contractual rights apply again.

If you're a subcontractor, you agree any CIP with the contractor above you in the supply chain, and the MOD delivery team must be given sight of it. That contractor's own CIP gives you no relief or grace period, and any arrangement with you is at its discretion.

You still complete the SAQ

DCC doesn't replace the Supplier Assurance Questionnaire (SAQ). The GOV.UK Cyber Security Model guidance says suppliers with a valid DCC certificate "are not yet exempt" from completing elements of the SAQ in the Supplier Cyber Protection Service.

It adds that "completion of the full SAQ to the required level remains mandatory" in contract risk assessment and procurement. IASME's FAQ says DCC uses the same questions as the MOD's SAQ, though there may be small differences between versions, so the two pieces of work overlap.

The SAQ itself is a self-assessment against the contract's Cyber Risk Profile, completed in the Supplier Cyber Protection Service when you bid. On a live contract, you complete a new one each year on the anniversary of the award.

What Level 0 involves

Level 0 has three controls, each taken from Def Stan 05-138 Issue 4. They're Cyber Essentials, UK GDPR compliance, and resilient networks and systems.

Across those controls you answer six yes-or-no questions and back each answer with evidence, which a certification body then marks. IASME's Applicant Guide says you must meet 100% of the controls to pass Level 0, with no partial compliance allowed.

No level of DCC is a self-assessment, Level 0 included. The scope is your whole organisation and the services it needs to operate, whether those serve MOD or non-MOD contracts.

A DCC certificate is valid for three years. Each year, you re-certify Cyber Essentials and complete an attestation that you're still meeting the controls and your scope hasn't changed significantly.

Any organisation can apply, whether or not it holds a defence contract today. One certificate covers all your contracts at the certified level, so you don't need a separate assessment for each.

If you don't hold Cyber Essentials yet, that comes first. As an IASME-accredited Cyber Essentials Certification Body, we certify Cyber Essentials directly.

Where Osiris fits

IASME licenses Osiris IT as a Defence Cyber Certification Body at Level 0. We assess other organisations' Level 0 submissions and issue their certificates, and our licence covers Level 0 only.

IASME's FAQ sets a limit on that role. A certification body acting as your DCC assessor "cannot be involved in implementing or managing your security defences".

That's why we run preparation and assessment as separate engagements, for different clients. If we're your assessor, we can point out gaps, but we won't implement or manage the fixes.

If a buyer or prime has asked you for Level 0

Check the wording of the request first, including the level and whether it's a condition of the tender. Then talk to a certification body about your scope before you submit, which IASME recommends to avoid under-scoping.

IASME publishes an Applicant Guide and Scoping Guidance, and its FAQ suggests downloading both to prepare.

IASME doesn't set a timescale for certification. Its FAQ says it depends on how prepared you are, including any gaps you need to fix first, and on when the certification body can assess you.

Sources

Get a DCC Level 0 assessment quote

Osiris IT is licensed by IASME to assess and certify organisations at DCC Level 0. Book a call and we'll confirm your scope and quote for the assessment.