Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Before you certify

Your level is decided by the contract, not by you

Suppliers routinely prepare for the wrong level because they assumed it followed from their size. It follows from the contract, and somebody else assesses it.

DCC Level 0 › Cyber Risk Profile

The most common wasted effort in defence supply chain compliance is a supplier preparing for a level nobody asked them to reach. It happens because people assume the level follows from the size of their business. It does not. It follows from the contract, and the buying authority assesses it.

What the profile is

The Cyber Security Model requires the buying authority to assess each contract and assign it a Cyber Risk Profile, from Very Low up to High. The assessment is about the information involved and the consequence of it being compromised, not about the supplier.

A two-person consultancy on a contract handling sensitive design data can carry a higher profile than a large manufacturer supplying fasteners. Size is not a factor.

What drives it

The factors that push a profile up
FactorEffect
Sensitivity of the information handledThe main driver. Design data, operational detail and anything aggregated pushes the profile up.
Whether information is aggregatedIndividually innocuous data can become sensitive in volume, and profiles reflect that.
Connection to MOD systemsDirect connectivity raises the profile considerably.
Criticality of what you supplyA component whose failure or compromise affects capability.
Whether you hold information at restStoring it is treated differently from passing it through.

How profiles map to DCC levels

Broadly: a Very Low profile points to Level 0, Low to Level 1, Moderate to Level 2 and High to Level 3. The mapping is set by the standard rather than negotiated, and your customer should be able to tell you both the profile and the level it implies.

At every level, Cyber Essentials is required. At Levels 2 and 3, Cyber Essentials Plus is required in addition. Levels 2 and 3 also bring substantially more in the way of governance, risk management and supply chain assurance, which is why the jump from Level 1 to Level 2 is the expensive one.

The Supplier Assurance Questionnaire

Alongside the profile you may be asked to complete a Supplier Assurance Questionnaire, which produces a risk score against the profile's control requirements.

Two things worth knowing. It is a self-assessment, so answering optimistically creates a gap that surfaces later rather than a problem that goes away. And where it identifies shortfalls, the usual route is a cyber implementation plan with agreed milestones rather than immediate exclusion, provided you engage early.

DCC differs in being independently assessed, which is why an increasing number of buyers prefer it to a questionnaire.

If the profile looks wrong

It happens, in both directions. A profile set too high imposes cost you cannot recover in the contract price. A profile set too low leaves a genuine risk unaddressed and, occasionally, gets revised mid-contract at your expense.

You can query it. Ask the buying authority, through your customer if you are not the prime, what the assessment was based on. The productive question is factual rather than commercial: "the profile assumes we hold design data at rest, and in fact we only view it through your portal" is a conversation that can change an assessment. "This is too expensive for us" is not.

Get any change in writing, and make sure it reaches whoever is managing the certification timeline.

Where suppliers most often go wrong

Assuming the level from the size of the business. It is set by the contract.

Preparing before asking. One email establishes the profile. Preparing for Level 2 when the contract carries Level 0 wastes months.

Scoping to the contract rather than the systems. The scope is the systems that handle the defence information, which rarely maps neatly to one contract or one team.

Treating it as a one-off. The obligation is continuous. A new contract may carry a different profile, and a higher one means more work with its own lead time.

The single most useful email you can send

To your customer, today: "Can you confirm the Cyber Risk Profile for this contract, and the DCC level it requires?"

Everything else follows from the answer, and the answer costs you nothing to obtain.

What each level actually asks of you

Useful for judging whether the level you have been given is proportionate, and for understanding why the step from Level 1 to Level 2 is the expensive one.

Broadly what each level involves
LevelProfileIn substance
Level 0Very LowCyber Essentials, plus evidence of three core control areas. Assessed on documentary evidence. Achievable for a small supplier in weeks.
Level 1LowCyber Essentials, plus a wider control set and more governance evidence. Still document-led, noticeably more of it.
Level 2ModerateCyber Essentials and Cyber Essentials Plus, plus risk management, incident response, supply chain assurance and evidence that they operate rather than exist.
Level 3HighEverything at Level 2 with greater depth and assurance, appropriate to the most sensitive contracts.

The jump from Level 1 to Level 2 is where the cost and the elapsed time change materially, because Cyber Essentials Plus is a hands-on audit with its own preparation and its own scheduling, and because the governance evidence at Level 2 has to show a functioning process rather than a written one.

If you have been assigned Level 2 and the contract seems modest, that is a reasonable thing to query, factually, through your customer.

Certifying above your requirement, deliberately

Some suppliers certify one level above what any current contract demands. It is worth considering if two things are true: you expect to bid for work carrying a higher profile within the next year, and the gap between your current level and the next one is mostly evidence rather than infrastructure.

The argument for it is timing. Certification takes weeks you will not have once a tender is live, and being able to answer "yes, already" rather than "we could start" is occasionally the difference in an evaluation.

The argument against is simply cost and effort for a requirement nobody has made. If your work is settled and the profiles are stable, certify to what is asked and revisit when something changes.

Can we choose which DCC level to certify at?

Not for a specific contract: the profile decides it. You can certify at a higher level voluntarily if you expect future contracts to require it, which some suppliers do deliberately to avoid repeating the exercise.

Does a bigger company need a higher level?

No. The profile is assessed against the contract and the information involved, not against the supplier. A small firm on a sensitive contract can sit above a large firm on a routine one.

What if different contracts carry different profiles?

You certify at the highest level you need, and that certification covers the lower ones. What matters is that your certified scope actually covers the systems used for each contract.

Is the Supplier Assurance Questionnaire the same as DCC?

No. The questionnaire is a self-assessment producing a risk score. DCC is independent certification. Some contracts accept the questionnaire, some require DCC, and an increasing number of buyers prefer DCC precisely because it is independently assessed.

Know your profile but not what it takes?

Tell us the level your customer has asked for and we will tell you what the evidence actually has to show, and how long it realistically takes.