Navigating Defence Procurement Cyber Security Compliance

Navigating Defence Procurement Cyber Security Compliance

Quick Summary:

The UK’s Defence Cyber Certification (DCC) and the US’s Cybersecurity Maturity Model Certification (CMMC) set the cyber security standards for defence procurement. Both aim to protect sensitive defence data, but differ in scope, assessment, and cost.


 

Arcanum Chief Consultant, Lawrie Abercrombie explores how in the ever-evolving landscape of defence procurement cyber security, compliance has become a cornerstone of both UK and US supply chains.

Why Cyber Security Is Now Central to Defence Procurement

As a Principal Security Consultant, I’ve had the privilege of witnessing firsthand the transformative impact of robust cybersecurity frameworks.  Today, I want to delve into the comparative analysis of two pivotal frameworks: the Defence Cyber Certification (DCC) mandated by the UK Ministry of Defence (MOD) and the Cybersecurity Maturity Model Certification (CMMC) enforced by the US Department of Defense (DoD).

Understanding the Frameworks

The DCC framework, governed by the MOD via IASME and the CMMC framework, governed by the DoD via DFARS, are both designed to enhance cybersecurity measures within defence contracts.  While both frameworks share a common goal of securing sensitive information, their structural, procedural and strategic differences are noteworthy.

Applicability

Whilst DCC is still voluntary, but in the US the Pentagon has just announced that from November 9 CMMC compliance is now MANDATORY for all DoD contractors.  That’s circa 220,000 companies in the DoD supply chain.  And, according to the Pentagon announcement, they only have 60 days to achieve certification.

Certification Levels and Scope

DCC certification levels range from 0 (Basic) to 3 (Expert) while CMMC has three levels, 1- Foundational up to 3 – Expert.  CMMC Levels 2 and 3 are broadly comparable in the number of controls to DCC levels 2 and 3.  However, the scope of DCC is organisation-wide, whereas CMMC is environment/network-specific.  This distinction is crucial for organisations operating across multiple environments. Find out more about DCC here.

Validity and Entry Requirements

DCC certification is valid for three years with annual check-ins, while CMMC certification ranges from one to three years with annual affirmations.  Entry into the DCC framework requires Cyber Essentials / Plus, whereas CMMC necessitates registration on the DoD Supplier Performance Risk System database. Read our 5 step supplier guide here.

Key Differences

The control basis for DCC is Defence Standard 05-138, while CMMC relies on NIST SP 800-171 / 800-172.  DCC assessments are conducted by independent third parties, whereas CMMC assessments vary by level, with Level 1 being self-assessed, Level 2 assessed by Certified Third-Party Assessor Organisations and Level 3 by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

And Some Similarities

DCC was originally conceived as being interchangeable with CMMC so that UK companies certified to DCC could supply to the DoD and vice versa.  However, reality overcame the aspiration and that mutual recognition hasn’t happened.  But, the similarities remain such that for any companies thinking of entering the US defence, or should that be defense, market, following the recent UK US ‘tech prosperity deal’, achieving DCC level 2 would be a massive step in the right direction.

 

Aspect

DCC (UK)

CMMC (US)

Governing body

MOD via IASME

DoD via DFARS

Mandatory?

Not yet

Yes (from Nov 2024)

Certification levels

0–3

1–3

Scope

Organisation-wide

Network-specific

Base standard

DEF STAN 05-138

NIST 800-171/172

Entry requirement

Cyber Essentials Plus

SPRS registration

Validity

3 years

1–3 years

Cost Implications

DCC certification is generally more cost-effective, with costs ranging from £2,000 for Level 0 to circa £30,000 for Level 3 for a large organisation.  In contrast, CMMC can be significantly more expensive, with costs ranging from $30,000 to $150,000 for SMEs and up to $500,000+ for large enterprises.

Strategic Recommendations

For organisations aiming to engage in cross-border defence contracting, early preparation is key.  Initiating certification planning well ahead of contract deadlines, conducting gap analyses, maintaining auditable evidence and budgeting realistically for certification and ongoing compliance are essential steps.  Monitoring regulatory updates to track phased rollouts and evolving requirements in both jurisdictions is also crucial.

Conclusion

Both DCC and CMMC are becoming indispensable for defence sector engagement.  While structurally different, they share the common goal of securing sensitive information across global supply chains.  Organisations must treat compliance as a strategic priority and align internal processes accordingly.

By understanding and navigating these frameworks, organisations can not only ensure compliance but also enhance their cybersecurity posture, ultimately contributing to a more secure and resilient defence ecosystem.

If your company is interested in DCC certification, get in touch or rewatch our DCC webinar.