Defence Digital has asked industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026. A lot of suppliers are reading that as a security programme. It is not one.
Def Stan 05-138 Issue 4, which the certification maps to, sets four Cyber Risk Profiles.
- Level 0, Basic: 3 controls.
- Level 1, Foundational: 101 controls.
- Level 2, Advanced: 139 controls.
- Level 3, Expert: 144 controls.
Level 0 is Cyber Essentials covering the contract scope, GDPR-compliant processing, and resilience built into how you design and operate. Vulnerability management (control 2402), penetration testing (2403) and patch management (2405) start at Level 1.
So the first question is not what to buy. It is which profile your contracts actually require. That is set by the MOD project team under DEFCON 658 and written into the contract. It is worth checking before anything else, because the answer decides whether your next step is a certification body or a vulnerability programme.
If it is Level 0, the honest route is Cyber Essentials and a certification body. If it is Level 1 or above, the 31 December date is the least of it.




