


SMEs in the UK Defence supply chain nowface a mandatory baseline: Cyber Essentials (with Cyber Essentials Plus for higher levels) as part ofthe four-tier Defence Cyber Certification scheme overseen by IASME. DCC includes annual checkins and full recertification everythree years.
Are you ready?
This guide walks you through practical steps for howto prepare yourself.
Securing DCC accreditation isn’t just red tapeit’s a strategic advantage.
Unlock lucrative Defence and public sector contracts.
Build customertrust through cyber resilience.
Mitigate cyber attacks with the rightfuture-proofed security measures and systems.
Align with upcoming UK cyber resilience legislation.
Before tackling DCC, you must...
Level3:144controls 1 2 3
Five core controls:firewalls, secure configuration, access control, malware protection, patch management.
Achieve Cyber Essentials Plus ForLevelsTwo &Three.This adds independentaudits/vulnerabilitytests.
Build on this foundation with the broader DCC control sets
Level0: 3 controls
Level1:101 controls
Level2:139controls
This four-stage mission roadmap breaks down the journeyyou need to embark on.
1. Reconnaissance
Map existing security controls against Cyber Essentials and DCC requirements.
2. Augmentation
Deploytraining, patching, MFA, network segmentation. Orworkwith Enhancedto supportyou onthis.
3. Certification
Use an IASME-approved bodyto certify Essentials/Plus, then proceed to the DCC assessment.
4. Sustain & Improve
Use quarterly check-ins to stay aligned with DCC; recertify every 3years.
Ifyou’re already certified under Cyber Essentials, this mapping documentfrom the Ministry of Defence clearly shows which Defence
Standardisation controls are already coveredsaving you from “reinventing the wheel” and doing them again.
Use the mapperto systematically pinpoint additional controls required:
Level 0 (“Basic”): 3 core controls - all tied to Cyber Essentials certification.
Level 1 (“Foundational”): 101 controls - adding governance, risk, MFA, policies.
Levels 2 & 3: 139–144 controls - covering detection, incident response, encryption, threat monitoring, & deep defence‑in‑depth practices.
Click here to download the mapping document
As a Microsoft-certified and JOSCAR-accredited IT partner, Enhanced is equipped to help you.
We workwith you to reviewyour systems against DCC, uncovering any gaps that could put compliance or security at risk. Together, we create a clear, prioritised plan and supportyou through each step of remediation - helping you meetthe standard while building stronger, long-term cyber resilience.
We offer Security Managed Services that provide continuous protection through proactive remediation. Combined with Managed Detection and Response (MDR) we help you identify and neutralise threats early, strengthen defences, and build a security-aware culture across your business.
30 years Experience Award Winning IT Support
CSAT rating of95%
See howwe helped Dorset-based manufacturing company NORCO get Cyber Essentials Plus accredited. We also implemented an automated Data Compliance solution forthem enforcing policies and reducing manual processes. The Cyber Essentials Plus accreditation means NORCO are now eligible to bid for UK Government and MOD contracts.
Click here to read the story
Achieving DCC isn’tthe end ofyour journeyit’s a launchpad.
Use certification to win bigger contracts and public trust.
Prepare for evolving UK regulations like the Cyber Security & Resilience Bill. Position your business as a Defender-grade partner, not just a supplier.
Nowyou’re armed with the knowledge and tools to master DCC - through robustfoundations, strategic certifications, and true resilience.
For step‑by‑step support, Enhanced is readyto be your co‑pilot on this journey.
We’re trusted by many UK-based manufacturers and can help you every step ofthe way.
Find out more at enhanced.co.uk/it-solutions/cyber-security/