Manage UK Defence Cyber Certification requirements with confidence
Complyance helps defence suppliers map controls to DCC levels, automate evidence collection, and maintain certification year-round. From Level 0 through Level 3, compliance that scales with your contract portfolio.

































Configure controls aligned to DefStan 05-138 requirements at Level 0 through Level 3, and track evidence for each.
Integrations pull evidence directly from your existing toolstack, so your team isn't chasing screenshots before each assessment.
AI agents continuously review incoming evidence and flag gaps before your annual check-in or re-certification window.
DCC Level 2 and 3 require subcontractor assurance. Complyance's TPRM module manages vendor cyber requirements alongside your own.
DCC compliance automation
Automate evidence collection across all DCC levels
DCC certification is evidence-based. Assessors need to see that your controls are implemented and working, not just documented on paper. Complyance integrations connect directly to the systems your team already uses, automatically collecting the logs, access records, and policy documentation your assessor will ask for.
When new evidence comes in, Complyance's Evidence Review Agent validates it against your control requirements and flags anything that doesn't meet the mark, before anyone needs to look.


DCC compliance
Controls configured to your certification level
Not every defence supplier needs to certify to Level 3. Complyance lets you configure your control set to match the Cyber Risk Profile assigned to your contracts, whether that's the 3 controls required for Level 0 or the full 144 for Level 3. As your contract portfolio grows and risk profiles change, your program scales with it.
Workflows can be tailored to your internal governance structure, including who owns each control, what evidence is required, and how findings are escalated and remediated.
Multi-framework coverage
DCC, ISO 27001, and Cyber Essentials in one place
Related resources
Read more on this topic
Frequently asked questions
The Defence Cyber Certification (DCC) is a UK Ministry of Defence certification scheme for defence suppliers. Launched in May 2025 and managed by IASME on behalf of the MOD, it provides independent, evidence-based verification that a supplier's cyber security controls meet the requirements of their contract's Cyber Risk Profile. It builds on DefStan 05-138, the MOD's foundational cyber security standard.
DCC applies to organisations in the UK defence supply chain, including prime contractors and subcontractors bidding for or delivering MOD contracts. Certification is organisation-wide, not per contract, and maps to one of four levels (0 to 3) depending on the cyber risk profile of the work involved.
Level 0 (3 controls) covers very low cyber risk contracts. Level 1 (101 controls) covers low to moderate risk. Level 2 (139 controls) and Level 3 (144 controls) cover high and very high-risk environments respectively. Levels 2 and 3 also require Cyber Essentials Plus in addition to the DCC controls.
Complyance maps your controls to your required DCC level, automates evidence collection via integrations, and uses AI agents to continuously review evidence and flag gaps. The platform also supports third-party assurance requirements at Level 2 and 3, and cross-maps evidence across DCC, Cyber Essentials, and ISO 27001 to reduce duplication.
Cyber Essentials is a prerequisite for all DCC levels (Cyber Essentials Plus for Levels 2 and 3). At higher levels, DCC control requirements overlap significantly with ISO 27001. Complyance maps evidence across all three, so effort isn't duplicated.
