Defence suppliers
Level 0 by 31 December 2026.
MOD has asked all industry partners to achieve Defence Cyber Certification Level 0 by the end of 2026. It applies whether you supply MOD directly or sit three tiers down under a prime — the obligation flows down the chain with the contract.
If a contract assigns you a higher Cyber Risk Profile, the level that comes with it is required from award, not by the deadline.
What is actually required
Three names, three different jobs.
Most of the confusion here comes from treating Def Stan 05-138, DCC and DEFCON 658 as three words for the same thing. They are not.
- Def Stan 05-138 — the method
- Defence Standard 05-138 defines the cyber risk profiles and the control sets expected at each one. Issue 4 is dated 14 May 2024, and from 3 November 2025 contracts carrying DEFCON 658 are held against it.
- Defence Cyber Certification — the assessment
- DCC is the organisation-wide certification that assesses you against those control sets, delivered through IASME's network of assured Certification Bodies. It has four levels, 0 to 3. Certificates are issued by the Certification Body — never by a firm that prepared you.
- DEFCON 658 — the mechanism
- The contract condition that carries the cyber obligation and flows it down the supply chain. It is why a subcontractor who has never spoken to MOD still ends up with the requirement in their inbox.
Two things suppliers get wrong
Your level is assigned, not chosen. The MOD delivery team or the prime performs the risk assessment and assigns a Cyber Risk Profile for the contract. That sets your minimum. It does not bend to what feels proportionate for a company your size.
Cyber Essentials is still in scope. DCC requires the appropriate level of Cyber Essentials — or Cyber Essentials Plus — for the business-critical systems in scope, and the Level 0 requirement specifically includes obtaining Cyber Essentials across all applicable business-critical systems.
Sources: Def Stan 05-138 Issue 4 and the Cyber Security Model on GOV.UK, and MOD Defence Digital, One Year of Defence Cyber Certification (May 2026). MOD guidance in this area is actively changing — check the current position before relying on it in a bid.
Where suppliers get stuck
Most SMEs can do the technical half.
The controls span governance, risk management, asset management, supply-chain management, access control, secure configuration, vulnerability management, security monitoring, incident response, recovery, testing and organisational learning. A capable engineering team has usually done the second half of that list without being asked. The first half is the one with nothing written down.
- Governance
Who owns security, and where is that recorded?
- Risk management
A register that is maintained, not one written for the bid.
- Asset management
What you run, who owns it, what it holds.
- Supply-chain management
Your own suppliers, and the obligations you must flow down.
- Security monitoring
Evidence that something is watching, not that logs exist.
- Recovery and learning
Plans that have been exercised, and lessons that changed something.
How we cover it
Three services against one control set.
- Atlas
- Governance, risk management, asset management and supply-chain management — held current, with the evidence pack an assessor asks for already assembled. Explore Atlas →
- Crucible
- Vulnerability management and security testing, independent of the people who wrote the code, on a stated cadence rather than once a year. Explore Crucible →
- Vigil
- Security monitoring, incident response and recovery — evidenced monthly, so the control is demonstrably operating rather than merely purchased. Explore Vigil →
If you are already mid-bid
A gap you cannot close in time is not automatically the end.
Where the gap cannot be closed before award, a Cyber Implementation Plan agreed with the buyer can let you compete while committing to remediation on an agreed timeline. It sets out what is missing, what you will do about it, and by when — and it is a commitment with dates attached, not a way of deferring the work.
We can help you write one, and then do the remediation it commits you to. Those are the same piece of work, and it is worth having the same people on both ends of it.
Honest scope
We prepare you. We do not certify you.
DCC certificates are issued under the IASME-administered scheme, by an assured Certification Body. Lybica is not one, and cannot be one for a client it has prepared. What we do is get you ready, produce the evidence the assessment asks for, and keep it current afterwards — because the certificate is the beginning of the obligation, not the end of it.
Questions defence suppliers ask.
What is Defence Cyber Certification Level 0 and do I need it?
DCC is the organisation-wide scheme that assesses suppliers against the control sets in Def Stan 05-138, delivered through IASME's network of assured Certification Bodies. MOD has asked all industry partners to achieve Level 0 by 31 December 2026. Higher levels come from the Cyber Risk Profile assigned to an individual contract and are required from award.
How do Def Stan 05-138, DCC and DEFCON 658 fit together?
Def Stan 05-138 defines the cyber risk profiles and the control sets expected at each one. DCC is the scheme that assesses an organisation against them and issues the certificate. DEFCON 658 is the contract condition that carries the obligation and flows it down. In short: 05-138 is the method, DCC is the assessment, DEFCON 658 is the mechanism.
Who decides which level we need?
Not you. The MOD delivery team or the prime performs a risk assessment for the contract and assigns a Cyber Risk Profile. That profile sets the minimum you must meet, and it comes from the contract rather than from your own judgement of what feels proportionate for a company your size.
Do we still need Cyber Essentials?
Yes. DCC requires the appropriate level of Cyber Essentials — or Cyber Essentials Plus — to be in place for the business-critical systems in scope. The Level 0 requirement specifically includes obtaining Cyber Essentials for all applicable business-critical systems within scope.
We're mid-bid and can't meet the controls in time. Are we out?
Not necessarily. Where a gap cannot be closed before award, a Cyber Implementation Plan agreed with the buyer can let you compete while committing to remediation on an agreed timeline. It is a commitment with dates attached, not a way of deferring the work.
We're a 30-person company. Is any of this proportionate for us?
Requirements scale with the risk of the contract, not the size of the supplier. The starting point is what your contract actually says, not what feels reasonable. The saving grace is that most frameworks scope to the contract boundary, so a small team working on one defence contract scopes to those people and the systems behind them.
Can Lybica certify us?
No. DCC certificates are issued under the IASME-administered scheme by an assured Certification Body. We get you ready, produce the evidence, and keep it current so the assessment is a formality.
The deadline does not move. Your readiness can.
One scoping call. We map what your contract assigns you, what you can evidence today, and what is left between here and the assessment.