"The DCC is a badge of excellence in cyber resilience for all Defence industry partners."
Eleanor Fairford, Director of Cyber Defence and Risk, Ministry of Defence
Here is the sentence, from the MOD's own blog on 13 July 2026.
"The Ministry of Defence have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope."
Notice the word "asked". This is not a new law, and nobody is going to fine you on 1 January. It is the MOD telling its supply chain, in public and with a date, where things are heading.
| Level | For contracts at | Requirements | Certificate you need |
|---|---|---|---|
| Level 0 Basic | Very low cyber risk | 3 | Cyber Essentials |
| Level 1 Foundational | Low to moderate risk | 101 | Cyber Essentials |
| Level 2 Advanced | High risk | 139 | Cyber Essentials Plus |
| Level 3 Expert | Substantial risk | 144 | Cyber Essentials Plus |
The MOD sets the level for each contract, based on the risk it carries. Here is what each one is asking you to show.
Most suppliers sit at the bottom of that ladder. Lockheed Martin's own security lead said as much this summer, when it became the first company to reach Level 3. "It is fair to say that not every supplier will require the Level 3 and indeed 2."
Ask your prime contractor which level your contracts sit at before you spend anything.
If you sell to the MOD, yes. If you sell to a company that sells to the MOD, also yes. In the MOD's words, the requirement passes "from the prime contractor to their sub-contractors and onwards down the sub-contracting tiers". Company size makes no difference.
A good deal of nuclear work sits inside defence programmes, so many nuclear suppliers are caught that way. If your work is purely civil nuclear, this deadline is not yours. The same question is reaching those supply chains anyway, through a separate government pledge that large employers have been signing since July.
Across UK business, 24% of organisations already have the controls in all five areas. Only 5% hold the certificate.
Five times as many companies have done the work as have the proof of it. What is usually missing is the evidence and someone to own it, rather than the technology.