Reference library
DCC and CSM v4: what UK defence suppliers need to know
Straight answers to the questions we get asked most about Defence Cyber Certification, the MOD Cyber Security Model, and what the defence supply chain now expects. Written by people who helped build the requirements.
10 guides, reviewed 10 August 2026.
- 01 How does a UK defence SME achieve DCC Level 0? Cyber Essentials, UK GDPR evidence and resilient networks, assessed through an IASME certification body. What each step actually requires and how long it takes.
- 02 When is the DCC Level 0 deadline and what happens if I miss it? 31 December 2026, and the exact status of that date matters. What the MOD has actually asked for, and what missing it costs you commercially.
- 03 What is the MOD Cyber Security Model v4 and does it apply to my company? The MOD's framework for assessing supplier cyber risk. What changed from v3, the four Cyber Risk Profiles, the SAQ process, and who is in scope.
- 04 Do I need Cyber Essentials or Cyber Essentials Plus for MOD contracts? Standard CE for DCC Levels 0 and 1, CE Plus for Levels 2 and 3. The real difference between them, what each costs, and how long each takes.
- 05 What is the difference between CSM v4, DefStan 05-138 and DCC? One decides, one defines, one proves. The clearest way to hold the three apart, and where Secure by Design sits alongside them.
- 06 What is Defence Standard 05-138 and which controls does it require? The MOD's control set behind CSM v4. What each of the four levels demands, what kind of controls they are, and where suppliers most often get stuck.
- 07 Do subcontractors need DCC certification? How flow-down works under CSM v4 Yes, at any tier. How flow-down assigns your Cyber Risk Profile, why it may differ from your prime's, and what to ask them this week.
- 08 How much does DCC Level 0 certification cost? Budget £1,500 to £2,500 all in for a prepared small business. The four cost components, what pushes the price up, and when consultancy is not worth paying for.
- 09 Do I need DCC if I already have ISO 27001? Yes, you still need DCC. Why ISO 27001 is not a substitute, the parts of it that genuinely transfer, and which order to certify in.
- 10 How does an overseas company enter the UK defence supply chain? Same requirements as a domestic supplier, but your CMMC or NIST work maps across rather than transferring. The five-step sequence, and the items that are genuinely new.
Not sure which of these applies to you?
The instant CSM v4 readiness check skips the vocabulary and tells you what your position actually is. Free, a few minutes, and you get a downloadable report.