Labdesk - innovating the science sector with Microsoft Cloud Solutions

Ministry of Defence (MOD) Asking Every Supplier For Defence Cyber Certification By 31 December 2026. What You Need To Know.

Written by Labdesk Team | Sep 22, 2026, 10:26:04 AM

 

On 13 July 2026 the Ministry of Defence asked every company in its supply chain to reach Level 0 of the new Defence Cyber Certification by 31 December. Level 0 is the smallest of its four levels, and Cyber Essentials is one of the three things it asks for. 

 

"The DCC is a badge of excellence in cyber resilience for all Defence industry partners."

Eleanor Fairford, Director of Cyber Defence and Risk, Ministry of Defence

 

 What has happened 

Here is the sentence, from the MOD's own blog on 13 July 2026.

"The Ministry of Defence have asked all industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope."


Notice the word "asked". This is not a new law, and nobody is going to fine you on 1 January. It is the MOD telling its supply chain, in public and with a date, where things are heading.

 

 The four levels, in plain terms 

Level For contracts at Requirements Certificate you need
Level 0 Basic Very low cyber risk 3 Cyber Essentials
Level 1 Foundational Low to moderate risk 101 Cyber Essentials
Level 2 Advanced High risk 139 Cyber Essentials Plus
Level 3 Expert Substantial risk 144 Cyber Essentials Plus

The MOD sets the level for each contract, based on the risk it carries. Here is what each one is asking you to show.

  • Level 0, Basic. Basic cyber security practices, evidenced. Three requirements, and Cyber Essentials is one of them.
  • Level 1, Foundational. A cyber security programme covering the whole business, with good practices already running. The jump from 3 requirements to 101 happens here.
  • Level 2, Advanced. Advanced oversight and planning sitting behind those practices, and Cyber Essentials Plus rather than Cyber Essentials.
  • Level 3, Expert. Expert capability with layered defences, set up for new and evolving threats.

Most suppliers sit at the bottom of that ladder. Lockheed Martin's own security lead said as much this summer, when it became the first company to reach Level 3. "It is fair to say that not every supplier will require the Level 3 and indeed 2."

Ask your prime contractor which level your contracts sit at before you spend anything.

 

 A Word From Our Director 

 

 

 Is this change aimed at you? 

If you sell to the MOD, yes. If you sell to a company that sells to the MOD, also yes. In the MOD's words, the requirement passes "from the prime contractor to their sub-contractors and onwards down the sub-contracting tiers". Company size makes no difference.

A good deal of nuclear work sits inside defence programmes, so many nuclear suppliers are caught that way. If your work is purely civil nuclear, this deadline is not yours. The same question is reaching those supply chains anyway, through a separate government pledge that large employers have been signing since July.

 

 You may be closer than you think 

Across UK business, 24% of organisations already have the controls in all five areas. Only 5% hold the certificate.

Five times as many companies have done the work as have the proof of it. What is usually missing is the evidence and someone to own it, rather than the technology.

 

 Get Started 

  •  Defence Cyber Certification and Cyber Essentials done with time to spare  - labdesk can run your assessment and provide the guidance and technology to get you certified.
  • A clean renewal in 12 months - the Microsoft 365 Accelerator manages your security settings centrally, so your logins and updates stay in place.
  • An answer ready when your prime contractor asks - reporting shows where you stand and what is left.