Does Defence Cyber Certification replace the MOD supplier cyber questionnaire?
Certification, the contract risk profile and the supplier questionnaire perform different jobs in MOD cyber assurance.
A software supplier should treat Defence Cyber Certification as evidence within a wider assurance process. It should not assume that holding a certificate removes the need to respond to the requirements of a particular Ministry of Defence contract. The practical starting point is the opportunity's risk profile and the obligations attached to it.
The MOD's current guidance says Cyber Security Model version 4 is live. The model uses contract risk assessment, a Supplier Assurance Questionnaire and requirements under Defence Standard 05-138. Defence Cyber Certification provides independent evidence of compliance. The guidance identifies four risk profiles, Levels 0 to 3, and warns that the older model's profiles are not directly consistent with these. MOD Cyber Security Model The MOD Cyber Improvement Plan review addresses how identified assurance gaps affect the proposed delivery plan.
For a commercial software business, this changes how qualification should be recorded in the sales pipeline. “Cyber compliant” is too broad to be a useful field. Record which organisational scope was assessed, what evidence exists, which contract profile applies and when the evidence needs renewal. A certificate held by one legal entity or covering one environment should not silently become a claim about every subsidiary and service. The French Diag Cybersécurité Défense provides a separate example of a management assessment rather than a customer-specific approval.
Separate product functionality from supplier assurance. A company can sell cybersecurity software while still needing to demonstrate how it protects its own organisation and delivery arrangements. The fact that its product detects threats does not, by itself, establish that its development, support and administrative processes satisfy the buyer's requirements. The Fraunhofer Q-net-Q article illustrates why an integration demonstration must also retain its own evidence boundaries when wider security claims are considered.
The commercial team should involve the person responsible for assurance before pricing is final. Additional evidence collection, process changes, external assessment and ongoing administration can affect cost and timing. Discovering them after the bid has been approved creates avoidable disagreement between the salesperson's margin assumptions and the delivery team's workload.
Subcontracting adds another ownership question. When delivery depends on a cloud service provider, specialist developer or support partner, establish which requirements apply to that relationship and which party will provide the necessary evidence. An assurance plan that stops at the prime contractor's company boundary may not describe how the contracted service is actually delivered.
During procurement, ask the authorised buyer to resolve ambiguity in the stated profile or required certification. Keep the answer with the tender record. Do not translate a requirement from an earlier contract into a new one merely because the customer organisation is familiar. Equally, do not assume that a higher sounding certificate cures a mismatch in scope or contractual wording.
After award, assign responsibility for maintaining evidence and monitoring changes in the service. Moving support to a different subcontractor or changing the organisational structure can have consequences that a static certificate register will miss. The relevant question is whether the delivered arrangement continues to meet the agreed requirements.
Certification and the contract questionnaire have separate maintenance cycles
IASME, the scheme's delivery authority, describes DCC as an organisation-level assurance supported by annual attestation and recertification every three years. Its current explanation says all levels begin with Cyber Essentials, while levels two and three require Cyber Essentials Plus. The assessment concerns the organisation's evidence of compliance. These details make certification a continuing business capability, with a preparation and maintenance cost, rather than a document purchased once for an individual bid. IASME's DCC scheme description
The MOD's CSM guidance nevertheless says that a valid DCC certificate does not currently remove the requirement to complete the full SAQ at the required level. The questionnaire connects the supplier to the risk assessment for the relevant activity. Certification and the procurement record therefore answer related questions at different levels: what assurance the organisation holds, and what the supplier has declared for this contract. CSM certification and SAQ guidance
A supplier with several business units can see the consequence immediately. The commercial team may receive a certificate from a group security function, while the bid concerns a particular contracting entity and delivery arrangement. Someone must establish that the evidence being supplied is the evidence the buyer requested. Treating the group name, legal entity and delivery scope as interchangeable can leave the bid team unable to explain an otherwise credible certification record.
July guidance adds a specific certification trigger
The separate MOD publication for the Cyber Improvement Plan was updated on 17 July 2026. It now states that defence suppliers without DCC at the required level must submit a CIP, and it links the current CSMv4 template. That publication is newer than the March update date on the main CSM page. Read together, the pages make it unwise to conclude that a favourable questionnaire result alone resolves every requirement concerning certification. Current Cyber Improvement Plan publication
For a prospective bidder, the practical distinction is between technical readiness and the evidence route by which the authority receives assurance. A company may believe it has implemented the relevant controls but still be preparing for an independent assessment. Its commercial plan needs to account for both states. The appropriate explanation to the buyer is a precise account of the evidence already held and the remaining certification work, using the tender's required process.
This also changes how a prime contractor evaluates a specialist supplier. Asking whether the specialist is cyber secure produces an answer too broad to place into a procurement record. Asking which legal entity holds which certification, what activity it covers and how the subcontract's requirements will be addressed produces information that can be used. The specialist benefits because it can distinguish a missing document, a pending assessment and a substantive implementation gap instead of having all three labelled as the same problem.
Budget for the assurance work the business will actually maintain
Consider a hypothetical twelve-person software company entering defence research for the first time. Its developers already use controlled access and documented release practices for civil customers. The extra commercial task is to map its organisation to the required evidence, resolve identified gaps and arrange the appropriate independent assessment. The time spent by engineering, management and the assessor must be considered alongside the external certification fee. A low fee does not make internal preparation free.
The benefit can extend across several relevant opportunities, but it should be assessed against the company's likely work. Preparing for a level that no realistic customer requires can consume resources before there is a commercial reason to do so. Conversely, waiting until a preferred bidder discussion begins can leave too little time to complete a requirement that was visible in the tender. The buyer's stated risk profile and certification conditions provide the reference point for that investment decision.
Ongoing maintenance belongs with normal business ownership. Changes in the delivery organisation, suppliers or systems should reach the person maintaining the assurance record, as well as the person running the project. Otherwise, the sales team may continue presenting an accurate historical certificate alongside an outdated description of how the company now works. A maintained record makes subsequent bids easier because staff can identify what remains applicable and what needs a fresh explanation.
For customers of security software, this distinction is equally useful. DCC concerns the supplier organisation's resilience; evidence that a product performs a particular security function is a different commercial claim. A company can explain both convincingly, provided it does not substitute the strength of one for the evidence required for the other.
This article explains the commercial division of responsibilities rather than certifying any supplier or prescribing a technical security configuration. Qualification is assessed against the live procurement and contract. A clear internal record of scope, evidence, ownership and renewal makes that assessment more manageable and prevents sales claims from outrunning what the company can demonstrate.
Sources & evidence
- Cyber Security ModelUK Ministry of Defence · 6 March 2026
- Defence Cyber Certification: scheme and assessmentIASME
- Cyber Improvement Plan: template and July 2026 guidanceUK Ministry of Defence
CSM version 4 guidance was read on 6 September 2026. Contract requirements and buyer instructions determine a supplier's obligations.
Suggest a correction