Skip to content
All posts

Periculo Newsletter

This months newsletter looks at a hard deadline now facing defence sector suppliers, and at why more organisations than ever are working towards Cyber Essentials Plus.

Read on for company news, work from the field, a security tip of the month, and this issue's jargon buster.

Periculo named a founding company for CREST's new AI Charter

CREST has launched a new AI Charter, backed by more than seventy cybersecurity firms and underpinned by nine principles covering areas including accountability and governance, transparency of use, data sovereignty and client control, and the secure development of AI tooling.

Sitting alongside it is a new AI-Enabled Penetration Testing accreditation, added as a module to CREST's existing Penetration Testing Accreditation Standard, giving independent assurance that a provider is using AI responsibly both internally and in client-facing work.

Periculo has been confirmed as a founding company for the Charter.

CREST's own research found over three-quarters of cybersecurity providers have increased their AI use in the past year, with most already folding it into daily service delivery.

Periculo will be working towards the new accreditation in the coming months and will share more as that progresses.

Defence suppliers face a hard deadline for DCC Level 0

The Ministry of Defence has asked that every industry partners in its supply chain achieve DCC Level 0 by 31 December 2026, moving DCC from a contract-by-contract requirement to a blanket gating control for anyone doing business with the MOD, assessed against DEF STAN 05-138.

Suppliers cannot apply for Level 0 without first holding a valid Cyber Essentials certificate whose scope aligns with their DCC scope, and the assessment itself looks for evidence across three areas: UK GDPR compliance, data security fundamentals, and system resilience. Once achieved, certification runs for three years, with an annual attestation required in between to keep it valid.

With five months left on the clock and Cyber Essentials as a prerequisite rather than something that can run in parallel, Periculo is urging any supplier yet to start the process to get Cyber Essentials in place now, so there's no last-minute scramble as the deadline approaches. Periculo has published a guide, Preparing for DCC Level 0, for suppliers working through the requirements.

Periculo achieved DCC Levels 0 and 1 accreditation itself late last year and is an IASME-accredited certification body for both — full details are on the Defence Cyber Certification page. The team will continue to update readers as more detail emerges from the MOD and IASME, and any supplier unsure of its obligations is welcome to get in touch.

Cyber Essentials Plus: the new baseline for NHS suppliers

Cyber Essentials Plus continues to move from competitive advantage to contractual baseline, particularly for NHS suppliers. Procurement Policy Note 014, in force for new central government contracts since 24 February 2025 and replacing PPN 09/23 and PPN 09/14, has been adopted by NHS Supply Chain, which now accepts its own Information Security Third Party Questionnaire (ISTPQ) as an alternative route for suppliers who don't hold CE+.

Separately, the Cyber Essentials v3.3 ("Danzell") update makes multi-factor authentication mandatory for all in-scope cloud services from 28 April 2026, tightening the technical bar for both Cyber Essentials and Cyber Essentials Plus. Periculo has covered what this means for the sector in Why Cyber Essentials Plus Is Now Essential for NHS Suppliers — and How to Get Certified.

Periculo's Cyber Essentials Plus service guides organisations through the full CE and CE+ process, from initial gap assessment to audit day. Any supplier wanting to talk through what the new MFA requirement means in practice is welcome to get in touch.

In the Field

In July our GRC team took a digital health client through ENS Alto, the highest of three security categories under Spain's Esquema Nacional de Seguridad framework.

The category isn't chosen; it's calculated based on the potential impact of a security failure across five dimensions, and for a platform processing special category health data.

The work was real: cryptographic configurations below the required standard, an asset inventory that had gaps, a threat model that needed building from scratch for the actual data in scope, and retention processes that existed on paper but wouldn't have survived the audit. None of it was cosmetic.

Once certified, the job isn't done either. At Alto, organisations carry an ongoing obligation to report their security status to CCN-CERT via INES, Spain's national reporting platform.

Getting the cert is one thing; having a properly embedded process for who owns the submission, what triggers a formal incident report to a national authority, and how that interfaces with existing incident response is another.

Both are now in place.

Security Tip of the Month

Firmware patching has become a live topic in client conversations following updates to the Cyber Essentials Plus technical baseline, which now places greater scrutiny on firmware alongside operating system and application updates.

Many organisations have mature processes for patching software, but overlook router, firewall, and device firmware, often because it requires manual checks rather than automatic updates.

Periculo is advising clients to bring firmware into the same patching cadence as everything else, and to keep a clear record of when it was last checked, not just when it was last updated.

Jargon Buster

IASME, the organisation appointed by the National Cyber Security Centre to manage the Cyber Essentials scheme, and the accreditation body behind the Defence Cyber Certification framework.

IASME doesn't carry out assessments directly but accredits and oversees the certification bodies like us, Periculo, that do, setting the standards that those assessments must meet.