Confirm the requirement
We review the tender, contract, Risk Assessment Reference and Cyber Risk Profile supplied by the authority or customer.
UK defence supply chain
Defence Cyber Certification gives UK defence suppliers a route to independently evidence compliance with the Ministry of Defence Cyber Security Model. We help suppliers understand the level attached to their work, translate Defence Standard 05-138 controls into action and prepare credible evidence before certification.
How we can help
Prepare for Defence Cyber Certification and Cyber Security Model v4 requirements with scope, control, SAQ, improvement-plan and evidence support.
CSMv4 in practice
Under CSMv4, the authority's risk assessment produces a Cyber Risk Profile from Level 0 to Level 3. That level determines the applicable Defence Standard 05-138 controls and should normally be supplied with a Risk Assessment Reference during procurement.
The level is not something a supplier should guess or choose for marketing. We help interpret the stated requirement, map it to the organisation and identify what must change before the relevant assurance activity.
Tender and contract readiness
Suppliers currently still complete the relevant Supplier Assurance Questionnaire through the Supplier Cyber Protection Service. Where a requirement is not met, the Cyber Improvement Plan needs to describe a credible route and timescale rather than hiding the gap.
We help technical teams, bid owners and leadership keep those statements aligned with deployed controls, existing certifications and contractual responsibilities.
Supply-chain assurance
Defence cyber obligations may flow from a prime contractor through several tiers of suppliers. That makes ownership, supplier due diligence, contractual wording and visibility of improvement activity as important as the organisation's own endpoint and cloud controls.
Readiness support can cover both your direct requirement and the process used to assess and manage relevant subcontractors.
Simple process
We review the tender, contract, Risk Assessment Reference and Cyber Risk Profile supplied by the authority or customer.
Current controls are mapped to the applicable level, with gaps assigned through a practical remediation or Cyber Improvement Plan.
We organise technical and governance evidence for the SAQ and for assessment by an authorised DCC certification body.
Independent decisions stay independent
The MOD or contracting authority determines contractual requirements, and certification is performed through the authorised DCC scheme. Wrexham Tech Support provides independent readiness, remediation and evidence support only.
Check the current MOD Cyber Security Model guidanceConnected assurance
Use the framework that fits the requirement, then reuse compatible controls and evidence without confusing one standard for another.
Practical readiness support for Cyber Essentials, ISO 27001, Defence Cyber Certification, DSPT, PCI DSS and the NCSC Cyber Assessment Framework.
View readiness support Certification supportPrepare confidently for Cyber Essentials and Cyber Essentials Plus with practical gap analysis, remediation and evidence support.
View readiness support Information security managementBuild and prepare an ISO/IEC 27001 information security management system with practical gap analysis, risk treatment, documentation and audit readiness support.
View readiness support Essential services & resilienceAssess and improve cyber resilience against the NCSC Cyber Assessment Framework with outcome mapping, evidence review and prioritised remediation support.
View readiness supportCommon questions
Still unsure? A quick message is enough—we will point you in the right direction.
CSMv4 uses Cyber Risk Profiles from Level 0 to Level 3. The applicable level should be determined by the authority's risk assessment for the specific defence activity, not selected by the supplier.
Current MOD guidance says suppliers with a valid DCC certificate are not yet exempt from completing all required SAQ elements through the Supplier Cyber Protection Service. Always check the current tender and official guidance.
No. We prepare the organisation, remediate controls and organise evidence. Certification must be completed through an authorised DCC certification body under the scheme.
Yes. We can help document responsibilities, review supplier evidence, map required controls and build a repeatable flow-down process alongside your commercial and legal owners.
Ready when you are