Do I need Cyber Essentials to get DCC?
Do I need Cyber Essentials to get DCC?
Yes. If your organisation wants Defence Cyber Certification, commonly called DCC, Cyber Essentials forms part of the required foundation. Every DCC level starts with Cyber Essentials, while DCC Levels Two and Three require Cyber Essentials Plus. IASME, which delivers DCC for the Ministry of Defence, confirms these requirements in its current scheme guidance.
DCC provides organisation-wide cyber assurance for suppliers that work with, or want to work with, the UK defence sector. The Ministry of Defence and IASME developed the scheme to strengthen security and resilience across the defence supply chain. A successful certification demonstrates that the organisation meets the controls associated with its assessed DCC level.
Cyber Essentials therefore does not sit beside DCC as an unrelated certificate. It provides a required technical foundation. Organisations seeking the higher DCC levels need Cyber Essentials Plus because those levels require stronger independent technical assurance.
UK Cyber Security Group provides Cyber Essentials certification and support to businesses preparing for the assessment. The company can help organisations understand the five technical controls, review their current security arrangements and work towards certification before they move further along the DCC route.
What DCC actually means for defence suppliers
Defence Cyber Certification is an organisation-wide cyber security assurance framework for suppliers in the UK defence sector. The Ministry of Defence developed it with IASME as part of its wider work to strengthen cyber resilience throughout the supply chain. IASME acts as the MOD’s delivery partner and manages DCC through a network of assured Certification Bodies.
DCC also supports the MOD Cyber Security Model. Government guidance explains that DCC provides an independent way for suppliers to evidence compliance with that model. Suppliers should expect DCC requirements to appear increasingly within MOD tenders, although IASME currently states that DCC does not apply as a universal mandatory requirement to every organisation.
That distinction matters. A business should not assume that every organisation in the UK needs DCC. The scheme focuses on defence suppliers and organisations that need to demonstrate cyber assurance in support of UK Defence procurement.
However, a company that already supplies the MOD, plans to bid for defence work or operates within a relevant supply chain should understand DCC early. A future tender may specify a required certification level, and waiting until that point can create unnecessary pressure.
Cyber Essentials sits at the foundation
The National Cyber Security Centre describes Cyber Essentials as a scheme built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
These controls address common routes that criminals use to compromise systems. They help organisations reduce unnecessary internet exposure, remove unsafe configurations, restrict user permissions, manage malicious software and address known software weaknesses.
DCC then expands the assurance approach beyond this technical baseline. It looks at the wider security and resilience of the organisation according to the level that applies.
This creates a logical progression. Before a defence supplier demonstrates broader organisational resilience, it first shows that the essential technical controls operate across the relevant environment.
How the four DCC levels work
DCC currently offers four levels, from Level Zero through Level Three. Each level corresponds to increasing cyber risk within the defence supply chain. IASME currently lists three controls at Level Zero, 101 controls at Level One, 139 controls at Level Two and 144 controls at Level Three.
All four levels start with Cyber Essentials.
Levels Two and Three require Cyber Essentials Plus.
Cyber Essentials Plus assesses the same five Cyber Essentials control areas but adds more rigorous independent technical testing. The NCSC describes Plus as providing the same protections with stronger independent technical assurance.
The higher DCC levels therefore ask for stronger technical evidence before the organisation demonstrates the wider defence controls.
Level Zero
Level Zero represents the starting DCC level and contains three DCC controls. Cyber Essentials still forms the required technical foundation.
Level One
Level One contains 101 DCC controls and also requires Cyber Essentials.
Level Two
Level Two contains 139 DCC controls and requires Cyber Essentials Plus rather than the standard Cyber Essentials certificate.
Level Three
Level Three contains 144 DCC controls and also requires Cyber Essentials Plus. It represents the highest current DCC level.
The appropriate level reflects the degree of cyber risk associated with the supplier’s role. IASME also allows organisations to seek certification even when they do not currently hold an MOD contract.
Does my Cyber Essentials scope need to match my DCC scope?
The relationship between the two scopes needs careful handling.
IASME states that Cyber Essentials concentrates on internet-connected networks and systems, while DCC considers the wider security and resilience of the organisation. The scopes therefore do not operate in exactly the same way.
However, any internet-connected devices or networks inside the DCC scope must receive coverage under Cyber Essentials or Cyber Essentials Plus in line with the Cyber Essentials rules. The DCC assessor reviews the scopes to confirm that they align appropriately.
DCC normally takes a broad organisational view. IASME states that the scope should include the organisation and the services or functions essential to its operation, rather than focusing only on networks linked directly to one MOD contract.
That means a supplier should work out its scope early. Waiting until the assessment begins may reveal systems, cloud platforms, business functions or supplier dependencies that need more work than expected.
Cloud services and external suppliers still matter
Using an external provider does not automatically remove responsibility from your organisation.
IASME states that DCC scope must include internal processes for managing and overseeing suppliers. When a third party fulfils a control, the applicant still needs to demonstrate that the requirement has been met and may need evidence from that supplier.
Cloud services can also sit inside DCC scope when the organisation relies on them to continue operating.
Cyber Essentials follows a similar principle for cloud services. Current NCSC requirements state that cloud services hosting organisational data or services need appropriate consideration within the Cyber Essentials scope, with responsibility shared according to what the organisation and cloud provider each control.
A defence supplier should therefore know which external services support its operation, which party controls each security measure and what evidence it can obtain.
What are the key requirements for achieving Cyber Essentials certification?
Cyber Essentials requires organisations to meet five technical control areas.
The first is firewalls. Organisations need suitable protection between devices and the internet and should control unnecessary access.
The second is secure configuration. Businesses should remove avoidable weaknesses, change unsafe defaults and restrict functions that users do not need.
The third is security update management. Organisations need supported software and must address relevant security weaknesses within the requirements set by the scheme.
The fourth is user access control. Businesses need to control who can access organisational information and services and limit the level of access each person receives.
The fifth is malware protection. Organisations need appropriate measures that help identify and stop malicious software before it causes harm.
Current Cyber Essentials requirements are set out in Requirements for IT Infrastructure v3.3, which the NCSC published for the April 2026 scheme update.
For a DCC applicant, meeting these controls is not only useful preparation. It forms part of the certification route itself.
Why the technical baseline matters to defence
Defence suppliers can hold sensitive operational, contractual, commercial or government-related information. Attackers may also target organisations because they connect to a larger supply chain.
A supplier does not need to be a major defence manufacturer to create risk. Smaller contractors can provide software, engineering services, consultancy, logistics, maintenance, communications or specialist support.
The MOD’s Cyber Security Model aims to increase assurance throughout that supply chain. Government guidance says DCC provides an independent route for demonstrating compliance with the model.
Cyber Essentials reduces common technical weaknesses before the DCC assessment considers broader organisational resilience.
This layered approach makes sense because strong policies cannot compensate for weak administrator accounts, unsupported software or badly controlled internet access.
Current UK cyber risk supports stronger supplier assurance
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. Phishing affected 38 per cent of businesses and remained the most commonly identified attack method.
The NCSC has also reported a rise in nationally significant incidents. Its 2025 annual review reported 204 nationally significant cyber attacks against the UK during the 12 months to August 2025, compared with 89 during the previous period.
These figures help explain why defence procurement places increasing attention on cyber resilience. A compromise at one supplier can potentially create operational, information or supply-chain consequences elsewhere.
Cyber Essentials gives suppliers a recognised technical starting point, while DCC provides broader assurance aligned with the needs of UK Defence.
How can I prepare my small business for Cyber Essentials assessment?
Start by working out what sits inside scope. Identify your laptops, desktops, servers, mobile devices, routers, firewalls, cloud services and relevant user accounts.
Next, check whether your operating systems and applications still receive security support. Unsupported technology can create serious certification problems.
Review administrator accounts. Staff should only receive elevated permissions when their work genuinely requires them.
Check multi-factor authentication across cloud services and administrator access where the current requirements apply.
Review security updates and confirm that your organisation manages relevant fixes consistently.
Check malware protection and secure configuration across your devices.
Look at firewall rules and remove unnecessary external access.
The NCSC provides the current assessment questions and a free readiness tool that can help organisations identify areas requiring work before certification.
UK Cyber Security Group also provides Cyber Essentials assessment and support for organisations that need guidance through the process.
For a company planning to progress towards DCC, keep the evidence produced during this work. Asset information, access records, update reports, cloud details and security policies may support later assurance activity.
Preparing for DCC while you work on Cyber Essentials
A business can reduce repeated effort by thinking about DCC at the same time as it prepares for Cyber Essentials.
Start with clear ownership. Decide who coordinates the DCC programme, who owns cyber risk and which managers own important services.
Document key systems and suppliers.
Review policies and operational processes.
Identify services that the organisation cannot operate without.
Gather evidence rather than relying on verbal explanations.
Speak with suppliers that deliver controls on your behalf.
Make sure senior management understands the security responsibilities attached to defence work.
DCC applicants need to demonstrate compliance with the controls for their selected level and provide supporting evidence.
A business that builds evidence gradually will usually find this easier than trying to recreate records shortly before assessment.
What software solutions support compliance with Cyber Essentials standards?
Several software solutions can help organisations maintain Cyber Essentials controls.
Endpoint management platforms can provide visibility of devices and update status.
Identity and access management platforms can help control user accounts and administrator permissions.
Multi-factor authentication services provide additional protection for accounts.
Password managers help staff maintain unique credentials.
Endpoint protection tools can help detect malicious software.
Vulnerability management tools can identify known weaknesses that need attention.
Asset management platforms can help the business track devices and applications.
Cloud administration dashboards provide useful information about identities, authentication and configuration.
Compliance management platforms can help organisations organise evidence and responsibilities.
Software does not create Cyber Essentials compliance automatically. The business still needs to configure systems correctly, maintain them and answer the assessment accurately.
For DCC, the organisation also needs broader evidence around governance, risk and resilience, so technical tools should form part of a managed security programme rather than work in isolation.
DCC certification lasts longer, but annual work still matters
IASME states that DCC certification requires re-certification every three years. Organisations must also complete an annual attestation confirming that they continue to meet the controls and that their scope has not changed significantly.
Cyber Essentials or Cyber Essentials Plus needs annual re-certification while the organisation maintains DCC.
This means a business cannot achieve DCC and then ignore its Cyber Essentials status.
The technical baseline needs continued attention. Devices change. Staff leave. Cloud services appear. Suppliers change. Software reaches end of support. New vulnerabilities emerge.
Regular reviews make annual Cyber Essentials renewal easier and help the organisation maintain its DCC assurance.
Can I renew my Cyber Essentials certification through an online service?
Yes. Cyber Essentials uses an online verified self-assessment process. The NCSC explains that organisations can choose a self-led route or use an IASME-licensed Certification Body for supported certification.
Annual renewal should reflect your current environment rather than simply copying the answers from the previous year.
Check your devices, cloud services, user accounts, administrator access, supported software, updates and internet-facing systems before submitting again.
For a DCC holder, maintaining Cyber Essentials or Cyber Essentials Plus each year is particularly important because IASME requires annual re-certification of the technical prerequisite.
UK Cyber Security Group provides online Cyber Essentials assessment and support and can help businesses prepare their current environment before renewal.
Is DCC mandatory for every MOD supplier?
Not automatically at present.
IASME’s current FAQ states that DCC is not universally mandatory. However, MOD guidance says suppliers should expect an increasing requirement to hold valid DCC certification for the duration of relevant contracts, with the requirement specified through tender conditions.
This creates an important commercial point for defence suppliers.
A business may not need DCC for every existing arrangement today, but procurement requirements can change. Preparing early can put the organisation in a stronger position when a tender specifies certification.
Government guidance also confirms that suppliers currently still need to complete the required Supplier Assurance Questionnaire activity through the Supplier Cyber Protection Service where applicable, even if they hold DCC.
A supplier should therefore read the specific tender and contract requirements rather than assuming that one certificate automatically removes every other assurance obligation.
What happens if I do not already have Cyber Essentials?
If you want DCC and do not currently hold the required Cyber Essentials certificate, start with Cyber Essentials.
For DCC Levels Zero and One, achieve Cyber Essentials.
For DCC Levels Two and Three, you will need Cyber Essentials Plus.
It often makes sense to review DCC requirements before completing the Cyber Essentials work so that the scopes align correctly and you do not create unnecessary repeat work.
A DCC Certification Body can advise on the required level and scope. IASME maintains a network of specially trained Certification Bodies licensed to provide DCC assessment.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification comes through IASME and its licensed network of Certification Bodies. The NCSC states that IASME manages a network of more than 400 cyber security organisations across the UK that can provide advice and certification support.
UK Cyber Security Group provides Cyber Essentials certification and support to UK businesses. Its service includes assessment options and assistance for organisations that need help understanding or meeting the controls.
When DCC sits behind your Cyber Essentials requirement, consider choosing a provider that understands defence assurance as well as the basic certificate.
Ask whether the provider can help with scoping, evidence, cloud services, access control, supplier dependencies and preparation for Cyber Essentials Plus where required.
Which UK-based firms offer Cyber Essentials consultancy services?
UK businesses can obtain Cyber Essentials consultancy from IASME-licensed Certification Bodies, NCSC-assured Cyber Advisors and cyber security consultancies.
The NCSC says Cyber Advisors provide assured advice and practical support to small and medium organisations implementing the five Cyber Essentials controls.
UK Cyber Security Group provides Cyber Essentials support and certification and can guide businesses through assessment preparation.
For defence suppliers, consultancy should focus on sustainable security rather than simply completing questionnaire answers. The organisation needs controls that remain effective after certification because DCC requires ongoing assurance.
A good adviser should help the company understand why each control matters, what evidence exists and how changes in systems or working practices affect continued compliance.
A practical route from Cyber Essentials to DCC
A defence supplier can approach the process in a clear sequence.
Confirm why you need DCC
Review your current and planned MOD work. Check tender conditions and discuss the expected DCC level with the relevant procurement contact or Certification Body.
Determine your DCC scope
Identify the organisation, services and functions essential to continued operation. Include relevant external services and supplier dependencies.
Align Cyber Essentials
Make sure internet-connected devices and networks inside the DCC environment receive appropriate Cyber Essentials coverage.
Achieve the correct technical certificate
Levels Zero and One require Cyber Essentials. Levels Two and Three require Cyber Essentials Plus.
Assess DCC controls
Review the controls for your required level and identify gaps.
Gather evidence
Record how your organisation meets each requirement and retain appropriate supporting evidence.
Complete the independent assessment
Work through an assured DCC Certification Body.
Maintain the certification
Renew Cyber Essentials or Plus annually, complete the DCC annual attestation and undertake DCC re-certification every three years.
Where UK Cyber Security Group fits
UK Cyber Security Group can provide the Cyber Essentials foundation needed before progressing through DCC. Its Cyber Essentials service supports certification and helps businesses understand the technical controls that underpin the scheme.
For an organisation entering the defence supply chain, getting those basics right early provides wider value. It strengthens everyday security, helps establish a clearer technology baseline and prepares the business for higher assurance requirements.
Cyber Essentials also gives senior leaders a useful view of common technical weaknesses before the business tackles the wider DCC controls.
The clear answer for defence suppliers
If you want Defence Cyber Certification, you need Cyber Essentials.
Every DCC level starts with Cyber Essentials, and Levels Two and Three require Cyber Essentials Plus.
DCC then builds on that technical baseline by assessing wider organisational cyber security and resilience for UK defence suppliers.
The certifications also need ongoing maintenance. DCC requires annual attestation and re-certification every three years, while the underlying Cyber Essentials or Cyber Essentials Plus certificate needs renewal each year.
UK Cyber Security Group provides Cyber Essentials certification and support for businesses that want to establish that required technical foundation. Starting early can help defence suppliers strengthen security, prepare evidence and approach future DCC requirements with much greater confidence.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










