Quick Summary:
The UK’s Defence Cyber Certification (DCC) and the US’s Cybersecurity Maturity Model Certification (CMMC) set the cyber security standards for defence procurement. Both aim to protect sensitive defence data, but differ in scope, assessment, and cost.
Arcanum Chief Consultant, Lawrie Abercrombie explores how in the ever-evolving landscape of defence procurement cyber security, compliance has become a cornerstone of both UK and US supply chains.
Why Cyber Security Is Now Central to Defence Procurement
As a Principal Security Consultant, I’ve had the privilege of witnessing firsthand the transformative impact of robust cybersecurity frameworks. Today, I want to delve into the comparative analysis of two pivotal frameworks: the Defence Cyber Certification (DCC) mandated by the UK Ministry of Defence (MOD) and the Cybersecurity Maturity Model Certification (CMMC) enforced by the US Department of Defense (DoD).
Understanding the Frameworks
The DCC framework, governed by the MOD via IASME and the CMMC framework, governed by the DoD via DFARS, are both designed to enhance cybersecurity measures within defence contracts. While both frameworks share a common goal of securing sensitive information, their structural, procedural and strategic differences are noteworthy.
Applicability
Whilst DCC is still voluntary, but in the US the Pentagon has just announced that from November 9 CMMC compliance is now MANDATORY for all DoD contractors. That’s circa 220,000 companies in the DoD supply chain. And, according to the Pentagon announcement, they only have 60 days to achieve certification.
Certification Levels and Scope
DCC certification levels range from 0 (Basic) to 3 (Expert) while CMMC has three levels, 1- Foundational up to 3 – Expert. CMMC Levels 2 and 3 are broadly comparable in the number of controls to DCC levels 2 and 3. However, the scope of DCC is organisation-wide, whereas CMMC is environment/network-specific. This distinction is crucial for organisations operating across multiple environments. Find out more about DCC here.
Validity and Entry Requirements
DCC certification is valid for three years with annual check-ins, while CMMC certification ranges from one to three years with annual affirmations. Entry into the DCC framework requires Cyber Essentials / Plus, whereas CMMC necessitates registration on the DoD Supplier Performance Risk System database. Read our 5 step supplier guide here.
Key Differences
The control basis for DCC is Defence Standard 05-138, while CMMC relies on NIST SP 800-171 / 800-172. DCC assessments are conducted by independent third parties, whereas CMMC assessments vary by level, with Level 1 being self-assessed, Level 2 assessed by Certified Third-Party Assessor Organisations and Level 3 by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
And Some Similarities
DCC was originally conceived as being interchangeable with CMMC so that UK companies certified to DCC could supply to the DoD and vice versa. However, reality overcame the aspiration and that mutual recognition hasn’t happened. But, the similarities remain such that for any companies thinking of entering the US defence, or should that be defense, market, following the recent UK US ‘tech prosperity deal’, achieving DCC level 2 would be a massive step in the right direction.
Aspect |
DCC (UK) |
CMMC (US) |
|---|---|---|
|
Governing body |
MOD via IASME |
DoD via DFARS |
|
Mandatory? |
Not yet |
Yes (from Nov 2024) |
|
Certification levels |
0–3 |
1–3 |
|
Scope |
Organisation-wide |
Network-specific |
|
Base standard |
DEF STAN 05-138 |
NIST 800-171/172 |
|
Entry requirement |
SPRS registration |
|
|
Validity |
3 years |
1–3 years |
Cost Implications
DCC certification is generally more cost-effective, with costs ranging from £2,000 for Level 0 to circa £30,000 for Level 3 for a large organisation. In contrast, CMMC can be significantly more expensive, with costs ranging from $30,000 to $150,000 for SMEs and up to $500,000+ for large enterprises.
Strategic Recommendations
For organisations aiming to engage in cross-border defence contracting, early preparation is key. Initiating certification planning well ahead of contract deadlines, conducting gap analyses, maintaining auditable evidence and budgeting realistically for certification and ongoing compliance are essential steps. Monitoring regulatory updates to track phased rollouts and evolving requirements in both jurisdictions is also crucial.
Conclusion
Both DCC and CMMC are becoming indispensable for defence sector engagement. While structurally different, they share the common goal of securing sensitive information across global supply chains. Organisations must treat compliance as a strategic priority and align internal processes accordingly.
By understanding and navigating these frameworks, organisations can not only ensure compliance but also enhance their cybersecurity posture, ultimately contributing to a more secure and resilient defence ecosystem.
If your company is interested in DCC certification, get in touch or rewatch our DCC webinar.