UK defence supply chain

Defence Cyber Certification readiness support

Defence Cyber Certification gives UK defence suppliers a route to independently evidence compliance with the Ministry of Defence Cyber Security Model. We help suppliers understand the level attached to their work, translate Defence Standard 05-138 controls into action and prepare credible evidence before certification.

How we can help

Practical support, properly explained

Prepare for Defence Cyber Certification and Cyber Security Model v4 requirements with scope, control, SAQ, improvement-plan and evidence support.

01

CSMv4 and DCC applicability review

02

Level 0 to Level 3 readiness assessment

03

Defence Standard 05-138 control mapping

04

Supplier Assurance Questionnaire support

05

Cyber Improvement Plan development

06

Cyber Essentials and Plus coordination

07

Supply-chain flow-down readiness

08

Technical remediation and evidence preparation

CSMv4 in practice

Start with the level attached to the defence activity

Under CSMv4, the authority's risk assessment produces a Cyber Risk Profile from Level 0 to Level 3. That level determines the applicable Defence Standard 05-138 controls and should normally be supplied with a Risk Assessment Reference during procurement.

The level is not something a supplier should guess or choose for marketing. We help interpret the stated requirement, map it to the organisation and identify what must change before the relevant assurance activity.

  • Review the supplied Risk Assessment Reference and Cyber Risk Profile
  • Define the organisation, systems and evidence in scope
  • Map current controls to the applicable requirements
  • Record gaps, owners, dependencies and realistic completion dates

Tender and contract readiness

Make the SAQ, improvement plan and real environment agree

Suppliers currently still complete the relevant Supplier Assurance Questionnaire through the Supplier Cyber Protection Service. Where a requirement is not met, the Cyber Improvement Plan needs to describe a credible route and timescale rather than hiding the gap.

We help technical teams, bid owners and leadership keep those statements aligned with deployed controls, existing certifications and contractual responsibilities.

Supply-chain assurance

Prepare for requirements that flow through subcontractors

Defence cyber obligations may flow from a prime contractor through several tiers of suppliers. That makes ownership, supplier due diligence, contractual wording and visibility of improvement activity as important as the organisation's own endpoint and cloud controls.

Readiness support can cover both your direct requirement and the process used to assess and manage relevant subcontractors.

Simple process

From problem to practical plan

01

Confirm the requirement

We review the tender, contract, Risk Assessment Reference and Cyber Risk Profile supplied by the authority or customer.

02

Assess and improve

Current controls are mapped to the applicable level, with gaps assigned through a practical remediation or Cyber Improvement Plan.

03

Prepare to evidence

We organise technical and governance evidence for the SAQ and for assessment by an authorised DCC certification body.

Independent decisions stay independent

Preparation you can stand behind.

The MOD or contracting authority determines contractual requirements, and certification is performed through the authorised DCC scheme. Wrexham Tech Support provides independent readiness, remediation and evidence support only.

Check the current MOD Cyber Security Model guidance

Common questions

Before you get in touch

Still unsure? A quick message is enough—we will point you in the right direction.

What are the DCC levels?

CSMv4 uses Cyber Risk Profiles from Level 0 to Level 3. The applicable level should be determined by the authority's risk assessment for the specific defence activity, not selected by the supplier.

Does a DCC certificate replace the Supplier Assurance Questionnaire?

Current MOD guidance says suppliers with a valid DCC certificate are not yet exempt from completing all required SAQ elements through the Supplier Cyber Protection Service. Always check the current tender and official guidance.

Can you issue our DCC certificate?

No. We prepare the organisation, remediate controls and organise evidence. Certification must be completed through an authorised DCC certification body under the scheme.

Can you help with subcontractor flow-down?

Yes. We can help document responsibilities, review supplier evidence, map required controls and build a repeatable flow-down process alongside your commercial and legal owners.

Ready when you are

Let’s prepare your defence supply-chain assurance properly.