Defence Cyber Certification
Secure your position in the UK Defence supply chain. Periculo guides you through Levels 0-3 DCC, ensuring compliance with DEF STAN 05-138.
DCC is more than just a requirement,
it’s a strategic advantage for your business.
STREAMLINED COMPLIANCE
This service helps prime contractors and SME suppliers rapidly achieve Defence Cyber Certification. We remove the complexity from framework onboarding, guiding you seamlessly through the required technical controls.
3-YEAR VALIDITY
The cost is dependent on the level of support you require. We tailor our services to meet your specific needs, ensuring you get the right balance of guidance and management.
COMPETITIVE EDGE
Holding DCC certification signals to the MOD and prime contractors that your security posture meets defence-grade standards — opening doors to contracts and frameworks that require supplier assurance.
The Defence Cyber Certification (DCC) is the Ministry of Defence's new framework for supplier cyber assurance. Developed in partnership with IASME, it replaces the previous "per-contract" self-assessments with a robust, whole-organisation standard.
It assesses your entire organisation's ability to withstand cyber threats, covering not just IT systems but also Operational Technology (OT), physical security, and personnel.
Based on DEF STAN 05-138
Aligned with the latest UK defence standards for cybersecurity.
Requires Cyber Essentials
Builds upon the solid foundation of Cyber Essentials certification.
Periculo supports organisations across all four DCC levels, from Level 0 through Level 3. We're currently authorised to certify Levels 0 - 3.
Choose Your Path to Compliance
Periculo supports you whether you are ready for an audit or need help getting there.
(Note: As an accredited Certification Body, we maintain strict separation of duties. We cannot audit work we have implemented.)
Periculo as Your Auditor
For organisations ready for certification
As an official IASME Certification Body, we conduct the formal assessment to certify your organisation against DEF STAN 05-138.
- OFFICIAL LEVEL 0 -3 ASSESSMENTS
- INDEPENDENT VERIFICATION
- FAST AUDIT PROCESS
Periculo as Your Implementer
For organisations needing guidance & support
Our expert consultants work alongside your team to build the governance, policies, and controls required for compliance. We support every DCC level, from Level 0 through Level 3.
- GAP ANALYSIS & READINESS ASSESSMENT
- POLICY WRITING & CONTROL IMPLEMENTATION
- DCC MANAGED SERVICE (ONGOING SUPPORT)
DCC Managed Service
We provide comprehensive cybersecurity solutions to the defence sector, helping organizations meet the stringent requirements of the Defence Cyber Scheme and other government standards. Our services include supplier assurance, securing sensitive data, and ensuring the resilience of critical defence infrastructure. We help you navigate the complexities of defence procurement and maintain a robust security posture in an ever-evolving threat landscape.
Why choose Managed Service?
EXPERTISE ON DEMAND
Access to senior cyber security consultants without the headcount cost.
RISK REDUCTION
Proactively identify and close security gaps before they become compliance failures or costly breaches.
SIMPLIFIED AUDIT
We manage the evidence, documentation, and liaison with your certification body, so audit day is straightforward.
Your Path To Certification
We don’t just do audits; we can manage your certification. Our team guides you through every step of the journey.
Readiness Assessment
WE ASSESS YOUR CURRENT SECURITY POSTURE AGAINST DCC REQUIREMENTS AND IDENTIFY WHAT'S NEEDED TO GET AUDIT-READY.
Gap Analysis
WE PINPOINT SPECIFIC GAPS BETWEEN YOUR EXISTING CONTROLS AND THE DCC LEVEL YOU'RE TARGETING, THEN PRIORITISE REMEDIATION.
Implementation
Our experts help you prepare the necessary evidence and documentation to demonstrate compliance.
Certification
We conduct the final assessment and, upon success, issue your official DCC certificate.
Testimonials
We had a great experience working with Periculo for our Cyber Essentials Plus certification. From the very beginning, their team was incredibly responsive, supportive, and approachable, which made the preparation phase smooth and efficient.
They were always available to answer our questions, clarify requirements, and help us feel fully prepared before the audit.
NASSOS KATSAMANIS // AUXILIS.AISomething powerful
Tell the reader more
The headline and subheader tell us what you're offering and the form header closes the deal. Over here you can explain why your offer is so great that it's worth filling out a form for.
Remember:
- Bullets are great
- For spelling out benefits and
- Turning visitors into leads.
FAQ’s
Cyber Essentials focuses specifically on internet-connected IT infrastructure. DCC is broader, covering the "whole organization," including air-gapped systems, physical security, OT, and HVAC systems that are essential for operations.
No, Level 0 and Level 1 require a valid Cyber Essentials (Basic) certificate. Level 2 and Level 3 require Cyber Essentials Plus.
If you don't meet the requirements, Periculo will provide feedback on the areas that need improvement. You can address these gaps and resubmit your application.
DCC certification is valid for 3 years, subject to an annual check-in to ensure continued compliance.
No. To maintain impartiality and accreditation standards, the same individual or team cannot both implement the controls and perform the certification audit. However, Periculo can provide separate teams for these services, or you can choose us for one specific role.
If gaps are identified during the assessment, you will be provided with a report detailing the non-compliances. You will typically have a remediation period to address these issues before a re-assessment is conducted.
Yes. The requirements of DEF STAN 05-138 must be "flowed down" through the supply chain. If you subcontract work that involves MOD identifiable information, you are responsible for ensuring your suppliers also hold the appropriate level of DCC certification.
While ISO 27001 is a broad international standard for information security management, DCC is a specific UK Ministry of Defence framework. DCC is prescriptive about certain controls (like Cyber Essentials) and is mandatory for defence contracts, whereas ISO 27001 is often voluntary or industry-specific.
Costs vary depending on the size of your organization and the certification level (Level 0 vs Level 1). Level 0 is generally lower cost due to the smaller control set. Contact Periculo for a tailored quote based on your specific organisational scope.
Unlike previous standards that could be limited to a specific contract, DCC typically applies to the "Whole Organisation" or at least the entire specific business unit handling MOD data. This ensures a baseline of security across your entire corporate environment.
For Level 1, once you have submitted your self-assessment and evidence, the review process by Periculo typically takes 1-3 days, depending on the complexity and quality of the submission. We aim for a fast turnaround to keep your contract bids on track.
The Ministry of Defence has set a strict DCC Level 0 deadline of 31 December 2026. MoD suppliers must act before this date to ensure ongoing contract compliance.
Latest Insights
DSPT 2026-27 Is Live: What's Confirmed, and W...
The Data Security and Protection Toolkit for 2026-27 went live on 4 September 2026. Version 9 is now aligned to the Cybe...
Tailored for Defence: Why Generic AI-Generate...
Ask an AI assistant to write an Acceptable Use Policy, and it will produce something plausible-looking in seconds: don't...
The Rules of Engagement: What Your Certificat...
Somewhere in every DCC preparation project, a compliance officer asks a reasonable question: "Can our Certification Body...
DCC Level 2/3 Hybrid: The Assessment Process,...
If your contract requires Defence Cyber Certification (DCC) Level 3, there's one thing worth knowing before you go any f...
DCC Level 1: The Assessment Process, Step by ...
For suppliers in the UK Ministry of Defence (MOD) supply chain, Defence Cyber Certification (DCC) Level 1 is typically t...
How to Manage Operational Technology (OT) Und...
Industrial control systems have traditionally sat outside IT's compliance conversations, too specialised, too fragile, t...
Why Cyber Essentials and DCC Scope Rarely Mat...
CE scope and DCC scope are not the same thing, and treating them as interchangeable is the single most common reason Def...
DCC Penetration Testing Requirements: A Compl...
UK defence procurement no longer assesses cybersecurity contract by contract. The Ministry of Defence (MOD) and IASME ha...



