DCC Level 0 › DEFCON 658
DEFCON 658 is the standard Ministry of Defence contract condition covering cyber security. If a contract contains it, cyber risk assessment and certification are contractual obligations rather than good practice, and they flow down the supply chain.
That last part is why most people encounter it. You are not contracting with the MOD. You supply somebody who does, and the obligation has arrived through them.
What the clause obliges
Four things, in substance.
- The contract carries a Cyber Risk Profile, assessed by the buying authority through the Cyber Security Model. That profile determines the level of control required.
- The supplier completes a Supplier Assurance Questionnaire demonstrating that it meets the controls for that profile.
- The supplier flows the same obligation down to its own sub-contractors where they handle the relevant information.
- The supplier notifies cyber incidents affecting the contract, within defined timescales.
The obligation is continuous rather than a one-off at award. Losing compliance mid-contract is a contractual issue, not simply a renewal problem.
Where Defence Cyber Certification comes in
DEFCON 658 and the Cyber Security Model establish what is required. Defence Cyber Certification is the scheme through which a supplier demonstrates it, with independent assessment rather than self-declaration.
DCC has four levels, 0 to 3, aligned to the Cyber Risk Profile of the contract. Level 0 covers the lowest profile and is where most of the supply chain sits.
One point worth stating plainly, because it is widely got wrong including on other suppliers' websites: Cyber Essentials is required at every DCC level, including Level 0, under Def Stan 05-138 Issue 4. Cyber Essentials Plus is required in addition at Levels 2 and 3. You will see it written elsewhere that Levels 0 and 1 need Cyber Essentials and Levels 2 and 3 need Plus instead. That is not what the standard says, and planning around it leaves you short at the worst moment.
How it reaches you
| Route | What it looks like |
|---|---|
| Direct MOD contract | The clause is in the contract. You will also have been told the Cyber Risk Profile. |
| Prime contractor flow-down | The commonest route. A prime passes the obligation to you, often as a schedule you sign without much explanation. |
| Second or third tier | Your customer supplies a prime. The obligation arrives with even less context, sometimes as a questionnaire out of the blue. |
| Framework or tender stage | It appears in the requirement before you have won anything, which is the best time to encounter it. |
If you have received a Supplier Assurance Questionnaire, or a customer has mentioned a Cyber Risk Profile, this is the conversation starting.
The question to put back to your customer
One question answers almost everything: what Cyber Risk Profile does the contract carry?
That determines your DCC level, which determines the controls, which determines the cost and the timeline. Everything else follows from it. Suppliers routinely start preparing before asking, and end up preparing for the wrong level.
If your customer does not know, they can find out from the buying authority. If nobody knows, that is itself worth flagging, because the profile is supposed to be assessed rather than assumed.
Flow-down: your own obligation
Easy to miss, and increasingly checked. If your sub-contractors handle the information covered by the contract, the same obligations pass to them and you are responsible for making sure they do.
In practice that means identifying which of your suppliers touch the relevant information, adding the requirement to your own contracts with them, and being able to show you have done both. Doing it after the fact, once your customer asks, is considerably more awkward than doing it as part of preparing your own submission.
Incident notification
The part nobody reads until it matters. The clause requires notification of cyber incidents affecting the contract, within defined timescales, through a specified route.
Two practical steps. Know the route and the timescale before you need them, and make sure whoever answers the phone at two in the morning knows this obligation exists. An incident response plan that does not mention the contractual notification requirement will not produce a notification inside the window.
What to do if this has just landed
- Ask your customer for the Cyber Risk Profile.
- Establish whether you already hold Cyber Essentials, and whether it is current. You will need it at every level.
- Scope properly: which systems handle the defence information, which is rarely the same as which contract they relate to.
- Work out which of your own suppliers the obligation flows down to.
- Start early. Certification takes time you will not have once a tender is live, and the prerequisite work takes longer still if there is remediation in it.
What this realistically takes
Suppliers consistently underestimate the timeline, usually because they price the certification and not the work that has to happen first.
| Stage | Typical duration | What drives it |
|---|---|---|
| Establishing the profile and level | Days to two weeks | How quickly your customer answers. Ask in writing. |
| Scoping | One week | Deciding which systems handle the covered information, which is rarely obvious. |
| Cyber Essentials, if not already held | Two to six weeks | Entirely remediation. The assessment itself is quick. |
| Assembling the evidence pack | Two weeks | Exporting what exists and fixing what the exports reveal. |
| Supplier flow-down | Two to six weeks | Other people's timelines, which you do not control. |
| DCC Level 0 assessment | One to two weeks | Scheduling and the assessment itself. |
Run sequentially that is three to four months. Run sensibly in parallel, with Cyber Essentials and the supplier conversations started on day one, it is six to ten weeks. Either way it is not a fortnight, and a tender that closes in three weeks is not a timeline this fits into.
Start these two on day one
Cyber Essentials, because it is required at every level and because the remediation inside it is the longest pole. If you already hold it, check it is current and that its scope covers the systems in your DCC scope, which is a mismatch that catches people out late.
The supplier conversations, because they depend on other organisations moving at their own pace. A supplier who needs to certify will take weeks, and you cannot compress that by asking more urgently in week six.
If the deadline is already too close
Tell your customer early, with a plan and dates rather than an apology. Some contracts permit a cyber implementation plan with agreed milestones instead of immediate full compliance, and that route is open to suppliers who engage before the deadline and closed to those who engage after it.
The worst version is silence followed by a discovery at contract award, which is a commercial problem rather than a compliance one.
Does DEFCON 658 apply to us if we do not contract with the MOD directly?
If the obligation has been flowed down to you through a customer, yes. The clause is designed to pass down the supply chain, which is how most suppliers encounter it.
Is Cyber Essentials really required at Level 0?
Yes. Def Stan 05-138 Issue 4 applies Cyber Essentials at every level, including Level 0. Cyber Essentials Plus is required in addition at Levels 2 and 3. The commonly repeated claim that Levels 0 and 1 need Cyber Essentials while 2 and 3 need Plus instead is wrong.
Who decides our Cyber Risk Profile?
The buying authority, through the Cyber Security Model, based on the contract rather than on your size. Ask your customer what the profile is, because everything else follows from it.
What if we cannot meet the required level in time?
Tell your customer early rather than late. Some contracts permit a cyber implementation plan with agreed milestones instead of immediate full compliance. That route closes once the deadline has passed.
Not sure which level applies to you?
Send us what your customer has asked for and we will tell you which level it points to and what it actually takes to get there.