DEFENCE ASSURANCE

Defence Cyber
Certification (L0-L3).

Secure your position in the Ministry of Defence (MOD) supply chain. We guide defence contractors through the Defence Cyber Protection Partnership (DCPP) Cyber Security Model (CSM) from Level 0 to Level 3.

MOD MandatoryDefence Supply Chain Requirement
L0 - L3 TiersRisk-Based Cyber Standard
SAQ ValidationSupplier Assurance Compliance
Defcon 658Adherence & Contract Readiness
DCPP AlignedDefence Cyber Protection
THE CYBER SECURITY MODEL (CSM)

Understanding the DCC Levels.

The Ministry of Defence assigns a cyber risk profile to every contract. Depending on the sensitivity of the information you handle, your organization must comply with one of four specific risk levels (L0 to L3).

Level 0: Very Low Risk

Baseline Defence

Required for contracts with minimal risk exposure. At this level, organizations must prove foundational hygiene to protect against basic, untargeted cyber attacks.

Minimum Requirements
  • Cyber Essentials (CE) Certification
  • Completion of the L0 SAQ
Level 1: Low Risk

Verified Baseline

For contracts handling moderately sensitive information. The MOD requires independent technical verification that your foundational controls are actively working.

Minimum Requirements
  • Cyber Essentials Plus (CE+) Certification
  • Completion of the L1 SAQ
Level 2: Moderate Risk

Advanced Governance

Required when handling highly sensitive or secret information. In addition to technical controls, organizations must demonstrate robust security governance, often mapping to ISO 27001 or NIST frameworks.

Minimum Requirements
  • Cyber Essentials Plus (CE+)
  • Advanced SAQ (Governance & Policy Checks)
  • Formal Incident Management Processes
Level 3: High Risk

Continuous Defence

Reserved for the most critical defence contracts. Suppliers must prove they can detect, resist, and respond to sophisticated, highly targeted nation-state threats on a continuous basis.

Minimum Requirements
  • All Level 2 Requirements
  • Active Threat Hunting & Monitoring (SOC/SIEM)
  • Penetration Testing & Vulnerability Management
  • Complex SAQ with Evidential Audits
THE DCPP PROCESS

How we help you achieve compliance.

1

Risk Assessment (RA) Review

The MOD buyer will complete a Risk Assessment to define the required level (L0-L3). We help you interpret this requirement and scope your technical environment accordingly.

2

Gap Analysis & Remediation

We review your current security posture against the required Level. If gaps are found—whether in technical controls (like CE+) or governance policies—our engineers help you remediate them.

3

SAQ Completion & Evidence

We guide you through the Supplier Assurance Questionnaire (SAQ), ensuring responses are accurate and backed by solid evidence, guaranteeing smooth acceptance by the MOD.

START A CONVERSATION

Ready to secure your Defence Cyber Certification?

Talk to our defence compliance experts about scoping your environment, preparing your SAQ, or achieving the required Cyber Essentials prerequisites.

Speak to an Expert info@worldcomputing.co.uk
This frontend launcher is ready for the real Tawk.to integration.