Introduction Chimera Energy, a cutting-edge-chemistry battery technology business recently got...
Ministry of Defence (MOD) Asking Every Supplier For Defence Cyber Certification By 31 December 2026. What You Need To Know.
On 13 July 2026 the Ministry of Defence asked every company in its supply chain to reach Level 0 of the new Defence Cyber Certification by 31 December. Level 0 is the smallest of its four levels, and Cyber Essentials is one of the three things it asks for.
"The DCC is a badge of excellence in cyber resilience for all Defence industry partners."
Eleanor Fairford, Director of Cyber Defence and Risk, Ministry of Defence
What has happened
Here is the sentence, from the MOD's own blog on 13 July 2026.
"The Ministry of Defence have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope."
Notice the word "asked". This is not a new law, and nobody is going to fine you on 1 January. It is the MOD telling its supply chain, in public and with a date, where things are heading.
The four levels, in plain terms
| Level | For contracts at | Requirements | Certificate you need |
|---|---|---|---|
| Level 0 Basic | Very low cyber risk | 3 | Cyber Essentials |
| Level 1 Foundational | Low to moderate risk | 101 | Cyber Essentials |
| Level 2 Advanced | High risk | 139 | Cyber Essentials Plus |
| Level 3 Expert | Substantial risk | 144 | Cyber Essentials Plus |
The MOD sets the level for each contract, based on the risk it carries. Here is what each one is asking you to show.
- Level 0, Basic. Basic cyber security practices, evidenced. Three requirements, and Cyber Essentials is one of them.
- Level 1, Foundational. A cyber security programme covering the whole business, with good practices already running. The jump from 3 requirements to 101 happens here.
- Level 2, Advanced. Advanced oversight and planning sitting behind those practices, and Cyber Essentials Plus rather than Cyber Essentials.
- Level 3, Expert. Expert capability with layered defences, set up for new and evolving threats.
Most suppliers sit at the bottom of that ladder. Lockheed Martin's own security lead said as much this summer, when it became the first company to reach Level 3. "It is fair to say that not every supplier will require the Level 3 and indeed 2."
Ask your prime contractor which level your contracts sit at before you spend anything.
A Word From Our Director
"Over the last few years, we have seen the positive impact Cyber Essentials has had on supply chains across the UK in improving the cyber awareness and standards in sectors such as Nuclear, energy and finance.
With the launch of DCC (Defence Cyber Certification), and the recent announcement from the MoD, requesting that all members of their supply chain to gain DCC level zero, we are now seeing activity and scrambling getting ready for the certification process.
Alot of SME's have the written policies in place, but where we see the gaps is aligning Microsoft 365 environments and security polices with the controls required from the standard.
It's important teams spend time reviewing the requirements and ensuring their cloud and IT requirements align - Not only will the DCC soon become mandatory, it will add real commercial value, allowing you access to opportunities across the defence sector.'
Is this change aimed at you?
If you sell to the MOD, yes. If you sell to a company that sells to the MOD, also yes. In the MOD's words, the requirement passes "from the prime contractor to their sub-contractors and onwards down the sub-contracting tiers". Company size makes no difference.
A good deal of nuclear work sits inside defence programmes, so many nuclear suppliers are caught that way. If your work is purely civil nuclear, this deadline is not yours. The same question is reaching those supply chains anyway, through a separate government pledge that large employers have been signing since July.
You may be closer than you think
Across UK business, 24% of organisations already have the controls in all five areas. Only 5% hold the certificate.
Five times as many companies have done the work as have the proof of it. What is usually missing is the evidence and someone to own it, rather than the technology.
"Could you do it yourself?
Yes, but the thing that's going to take labdesk 20 minutes is going to take you two days. And at the end of it you're not going to have that certification."
Get Started
- Defence Cyber Certification and Cyber Essentials done with time to spare - labdesk can run your assessment and provide the guidance and technology to get you certified.
- A clean renewal in 12 months - the Microsoft 365 Accelerator manages your security settings centrally, so your logins and updates stay in place.
- An answer ready when your prime contractor asks - reporting shows where you stand and what is left.