Do subcontractors need DCC certification? How flow-down works under CSM v4
Yes. Under Cyber Security Model v4, cyber security requirements flow down through the entire defence supply chain, so subcontractors at any tier need to meet the Cyber Risk Profile assigned to their part of the work, and increasingly to evidence it with Defence Cyber Certification. Being two or three tiers below the MOD does not put you out of scope. It just means your requirement arrives via your prime rather than directly from the MOD.
How flow-down actually works
On a direct MOD contract, the MOD conducts the risk assessment, produces a Risk Assessment Reference (RAR), and specifies the required Cyber Risk Profile in the invitation to tender.
When you are subcontracting, that responsibility moves up one tier. The contractor engaging you conducts the risk assessment for your portion of the work and generates your RAR and CRP. You then complete a Supplier Assurance Questionnaire against that profile through the Supplier Cyber Protection Service, exactly as a direct supplier would.
Where DEFCON 658 appears in the contract chain, these obligations are contractual, not advisory.
Will my level be the same as my prime's?
Usually not, and this matters commercially. The profile is assessed per contract and per role, based on the risk your work carries. A prime delivering a critical platform might hold Level 2 or 3 while a subcontractor supplying a low-risk component is assessed at Level 0 or 1. You need to meet your assessed profile, not mirror your prime's.
That cuts both ways. Do not assume you can coast at Level 0 because you are small. If your work involves sensitive design data, your profile may be higher than your headcount suggests.
Why primes are already asking for DCC
Primes carry accountability for their supply chain's compliance under CSM v4, and the practical way to discharge it is to prefer subcontractors who hold DCC certification at the appropriate level. A certificate is independently assessed and valid for three years, which is far easier for a prime's assurance function to accept than reviewing your self-assessment answers contract by contract.
The commercial reality: as the end of 2026 approaches, uncertified subcontractors become the friction in a prime's supplier onboarding. Certified competitors get the easier path onto the bid team.
What if I have gaps?
Non-compliance is not automatic disqualification. You can complete a Cyber Improvement Plan documenting your gaps, remediation steps, and timeline, which becomes part of the contract. It keeps you in the game, but you are then remediating against contractual deadlines.
Certifying before you need to is considerably less stressful than certifying because a contract says you must.
Three questions to ask your prime this week
- What Cyber Risk Profile has been, or will be, assigned to our scope of work?
- Will you require DCC certification as a condition of onboarding or contract renewal, and by when?
- Are there flow-down obligations we need to pass to our own suppliers?
Suppliers who certify ahead of the ask tend to find the conversation with their prime is short. Suppliers who wait tend to find it is expensive.
If your prime has gone quiet
Silence is not exemption. If nobody up the chain has told you your Cyber Risk Profile, the requirement has not disappeared; it is going to arrive later, with less notice, attached to a bid deadline. We will give you a view on where yours is likely to land.