DCC Made Easy With URM

Achieve Defence Cyber Certification with our team of qualified experts

The Defence Cyber Certification (DCC) Consultancy Services

In 2025, the UK Ministry of Defence (MoD), in partnership with IASME, released the Defence Cyber Certification (DCC), a cyber security certification framework for UK defence suppliers.  The DCC is part of a broader initiative by the UK Government to strengthen the cyber resilience of the defence sector’s supply chain, and is aimed at providing independently assessed, verifiable assurance of a defence supplier’s cyber security compliance in support of UK Defence Procurements.  By successfully achieving and maintaining DCC compliance, your organisation will clearly demonstrate the effectiveness of its security programme, gain access to MoD tenders that require certification, and strengthen its competitiveness in securing and retaining defence contracts.

The scheme defines four different compliance levels, with the level your organisation falls into dictating the number of controls you will need to implement.  The compliance levels correspond to the level of risk associated with your organisation.  Your organisation’s level will also dictate whether you need to be certified to Cyber Essentials or Cyber Essentials Plus in order to obtain DCC; Level Zero and Level One (lower risk suppliers) will need only Cyber Essentials certification, whilst Levels Two and Three (higher risk suppliers) are required to achieve Cyber Essentials Plus.

Having implemented the appropriate controls and prepared for certification, your organisation will be assessed for compliance by an approved certification body.  The assessor will identify any compliance gaps, however will be unable to assist in your implementation of solutions to close these.  Following your assessment, you will either receive certification or a confidential report of failure.

Cyber Essentials and Cyber Essentials Plus Support

As an accredited certification body for Cyber Essentials and a National Cyber Security Centre (NCSC) Assured Cyber Advisor, URM can both provide practical support to help you prepare for Cyber Essentials and/or Cyber Essentials Plus assessment and facilitate the assessment itself, allowing your organisation to meet the necessary prerequisites for certification under the DCC scheme.

DCC-Specific Support

In addition to assisting your organisation achieve the appropriate Cyber Essentials certification, URM can provide DCC-specific consultancy to help you meet the scheme’s requirements.   Our experts can conduct a gap analysis of your current cyber security programme to identify where you are already aligned with the DCC, and where improvements are required.  Following the gap analysis, we can provide practical implementation support to help you close any gaps identified and achieve DCC compliance.

Get in touch

Please note, we can only process business email addresses.

Why URM?

Track record

URM has a 20-year track record of providing high-quality training and consultancy services, assisting organisations to improve their information security, cyber security and risk management programmes.  Whilst the DCC is a relatively new framework, URM’s can leverage its extensive experience supporting organisations’ implementation of other security frameworks that have considerable overlap with the scheme (such as the NIST Cybersecurity Framework (CSF), and ISO 27001) to support your DCC compliance.

Tailored solutions

We at URM appreciate that no two organisations are the same and, as such, neither will their cyber security and DCC compliance programmes.  The unique requirements of your organisation, size and structure, risk appetite, products and services provided, legal and obligatory requirements, etc., will always guide our approach to supporting your compliance with the DCC.  Meanwhile, we will ensure the advice we offer reflects your existing working practices, enabling you to integrate the required DCC controls into your organisation’s business-as-usual (BAU) operations as seamlessly as possible.

Knowledge transfer

With our ‘real world’ knowledge transfer philosophy, you will benefit from our large team of consultants’ extensive practical experience and knowledge of cyber security best practice, and be able to independently improve your security by virtue of what you have learned from them, without needing to rely on ongoing consultancy support.

Cyber Essentials FAQ

Understanding Defence Cyber Certification (DCC)

Published on
14/8/2025

URM’s blog explains what DCC is, how compliance with the scheme and the process to certification work, and the benefits to obtaining certification.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
5/8/2025
Critical Cyber Security Practices to Defend Against Ransomware Attacks

URM’s blog examines how ransomware occur, and highlights practical cyber security measures you can implement to reduce your exposure and mitigate security risk.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
11/7/2025
Supplementing Cyber Essentials

URM’s blog outlines the practical measures you can take following Cyber Essentials certification to further enhance your information & cyber security posture.

Read more
Thumbnail of the Blog Illustration
Cyber Security
Published on
16/6/2025
Lexcel: Deconstructing Your Information Management and Security Policy

URM explains each control law firms must include in an information management and security policy that complies with the Lexcel Practice Management Standard.

Read more
"
Having never gone through the Cyber Essentials Plus process on behalf of a client I was very impressed with how the process went on testing day and I cant wait to take other clients through the process with URM.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.