Cyber Essentials, the defence baseline
Certified directly by us as an IASME Certification Body. The minimum the Cyber Security Model expects, renewed every 12 months.
If your contract carries DEFCON 658, the Cyber Security Model applies to you, and it flows down to every supplier beneath you. We get defence suppliers ready and certify them directly: Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification, with the technical evidence the MOD expects. From an IASME Certification Body that has certified UK organisations since the scheme launched in 2014, and an accredited DCC Certification Body.
Prefer email? hello@layer7.uk
A defence contract carrying DEFCON 658 triggers the MOD's Cyber Security Model. The MOD runs a Risk Assessment that assigns your contract a Cyber Risk Profile. You then have to meet the controls in Def Stan 05-138 for that level, and evidence it through a Supplier Assurance Questionnaire on the Supplier Cyber Protection Service.
The requirement does not stop at the prime. DEFCON 658 flows down through every tier of the supply chain. If you sit beneath a prime on a defence programme, it reaches you.
The model moved to CSMv4 for new contracts from December 2025, with Def Stan 05-138 Issue 4. Cyber Essentials is the baseline at the lower levels. Cyber Essentials Plus is required at the higher risk levels.
Defence Cyber Certification (DCC), developed by the MOD with IASME, adds independent certification against Def Stan 05-138 Issue 4, rather than self-assessment. One certificate covers your organisation across defence procurements at or below its level, and every level starts with Cyber Essentials. The MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026. We are an accredited DCC Certification Body, and our guide to what DCC Level 0 actually requires sets out the three controls and where applicants fail.
Above you, the department itself is assessed against the NCSC Cyber Assessment Framework through GovAssure, and CAF principle A4 makes your security its problem. That is why supplier assurance questions keep arriving from two directions at once: our walkthrough of what GovAssure actually asks for sets out what the department has to evidence, and what it will therefore need from you.
Certified directly by us as an IASME Certification Body. The minimum the Cyber Security Model expects, renewed every 12 months.
The hands-on, independently audited tier required at higher Cyber Risk Profiles. We test your live systems, not just your answers.
We help you read your Risk Assessment, scope the controls in Def Stan 05-138, and complete the Supplier Assurance Questionnaire with evidence behind it.
CREST and Cyber Scheme qualified testing to prove the technical controls a defence buyer will scrutinise.
Flow the same bar down to your own subcontractors, the way DEFCON 658 expects.
As an accredited DCC Certification Body, we assess you against Def Stan 05-138 and issue the certificate ourselves, and certify the Cyber Essentials every level is built on. Get to Level 0 before the MOD's 31 December 2026 deadline.
Defence Cyber Certification →We have certified UK organisations to Cyber Essentials since the scheme launched in 2014, one of the longest-standing certification bodies in the country. We deliver to public sector and defence-grade clients, with in-house CREST and Cyber Scheme qualified testers, so the controls are tested, not just claimed. We cut through the acronyms, DEFCON 658, CSMv4, Def Stan 05-138, SAQ, so you know exactly what your contract requires and what it does not.
The North East has a real defence base, from manufacturing on Tyneside to engineering across the region, and a growing cluster of SMEs winning defence work. We help suppliers across the region get and stay compliant. Local when you want us on site, remote when that is faster.
DEFCON 658 is the contract condition that applies the MOD's Cyber Security Model to a defence contract. It sets the cyber security terms and flows down through every tier of the supply chain, so it can reach you even as a subcontractor.
It depends on the Cyber Risk Profile the MOD assigns to your contract. Cyber Essentials is the baseline at the lower levels. Cyber Essentials Plus, the independently audited tier, is required at the higher levels. We help you work out which applies and get you there.
The Cyber Security Model is how the MOD protects information across its supply chain. The MOD assesses each contract's risk, assigns a profile, and expects suppliers to meet the matching controls in Def Stan 05-138. The model moved to CSMv4, with Def Stan 05-138 Issue 4, for new contracts from December 2025.
The Supplier Assurance Questionnaire is how you evidence your compliance against the controls for your assigned risk profile. It is completed and submitted through the MOD's Supplier Cyber Protection Service. We help you complete it with real evidence behind every answer.
Defence Cyber Certification (DCC) is the MOD's cyber certification scheme for its supply chain, developed with IASME and assessed against Def Stan 05-138 Issue 4. It gives independent, evidence-based certification rather than self-assessment, and every level starts with Cyber Essentials. IASME says DCC is currently not mandatory, but the MOD has asked all industry partners to achieve Level 0 by 31 December 2026, and the level a contract needs is set by the MOD or your prime. We are an accredited DCC Certification Body.
Yes. We are North East based and certify organisations across the region and the wider UK, on site or fully remotely.
Prefer email? hello@layer7.uk