top of page
SHIELD button

News & Updates

Sign up to be the first to be informed of our news & updates

 

Join our mailing list

Never miss an update

Search
  • natasha5042
  • Aug 3
  • 2 min read

Updated: Aug 4

DCC Level 0 is intended for every organisation that supplies the UK Ministry of Defence (MoD), either directly or indirectly through the defence supply chain. The MoD has asked all industry partners to achieve DCC Level 0 by 31 December 2026 as the minimum baseline for cyber resilience.


This includes organisations such as:

  • Prime contractors delivering directly to the MoD

  • SMEs working as subcontractors within the defence supply chain

  • Manufacturers and engineering companies

  • IT, cyber security and software providers

  • Facilities management and maintenance providers

  • Professional services, consultancy and support organisations

  • Logistics, transport and warehousing providers

  • Any business that provides goods or services in support of defence contracts


What if I'm not currently an MoD supplier?


Even if you're not currently working with the MoD, achieving DCC Level 0 can be beneficial if you:


  • Plan to bid for future defence contracts

  • Supply organisations that work with the MoD

  • Want to demonstrate your cyber resilience to defence customers

  • Wish to avoid delays when DCC becomes a contractual requirement


Starting your preparation early will help ensure you meet contractual requirements, protect your business from evolving cyber threats and remain a trusted defence supplier.


What are the Benefits of DCC Level 0?




How can Fortis Cyber® Support Us to Achieve DCC Level 0?


Fortis Cyber® provides a range of consultancy services to support you on your journey to Defence Cyber Certification Level 0 and we can arrange certification:


Readiness Assessment and Gap Analysis:

  • Assessing current security posture

  • Identifying gaps against the framework and providing prioritised recommendations to meet compliance requirements

  • This is the theoretical scoring element


Technical Security Implementation:

  • Hardening systems and networks to meet secure configuration requirements

  • Cyber Essentials


Training and Awareness:

  • Workshops in preparation for evidence collection and audits

  • Staff cyber awareness training


Policy, Process and Documentation:

  • Developing or refining cyber policies and processes to ensure clear and auditable documentation

  • This is part of the assist/consult and implement stage to prepare the applicant for DCC


Security Testing and Assurance:

  • Secure configuration reviews and CREST-accredited Vulnerability Assessments

  • Automated Pen Testing as a Service

  • Penetration Testing


Information Security Officer as a Service:

  • Ongoing support with governance, security strategy and continuous improvement

  • Maintaining DCC compliance and managing annual attestations


You must achieve Cyber Essentials before applying for DCC Level 0, and for higher levels Cyber Essentials Plus is mandatory. Fortis Cyber® has guided organisations to certification and we currently have capacity to support your organisation in readiness for the end of the year deadline. Get in touch for more information and let our experts support you with clear, actionable guidance on DCC compliance.

 
 
 

As of April 27th 2026, there are important changes to Cyber Essentials which all organisations holding, or looking to achieve Cyber Essentials or Cyber Essentials Plus, must be aware of. These changes have come about to reflect what is being seen by IASME and the National Cyber Security Centre across real-world incidents, evolving cyber threats and feedback from assessments.


The current question set is being updated to tighten certain criteria and to help organisations become more robust in their cyber security, benefiting all parties. Updates include the following, as well as other changes:




To support customers with the new Cyber Essentials Plus requirements, Fortis Cyber® are aligning services to deliver ongoing compliance and assessment readiness designed to significantly reduce the risk of failure under the new, more rigorous standards.


We are enhancing our Cyber Essentials Plus capability with a structured readiness workflow in the months leading up to assessment, alongside improved visibility into your organisation’s compliance posture. This ensures you have a clear understanding of your readiness at every stage, enabling proactive remediation and a smoother, more effective certification process. This support is already included for customers who have signed up to the Fortis Cyber® Attack Mitigation Service. https://www.fortiscyber.co.uk/attack-mitigation-service


Get ahead of the new changes to reduce the risk of CE+ assessment failure and increase your cyber resilience. Contact us to review your current compliance position and put the right controls in place to achieve successful certification. For further information on the new requirements please check out the IASME article: https://iasme.co.uk/articles/important-update-changes-to-cyber-essentials-for-april-2026/







 
 
 

Artificial Intelligence (AI) is now being weaponised as threat actors leverage AI at every stage of the attack lifecycle to launch faster, more widespread and more damaging attacks on businesses. 


This fundamental shift in the threat landscape means cyber criminals can now automate their reconnaissance of businesses, scaling to the scanning thousands of systems, enumerating software versions, analysing configurations, and pinpointing vulnerabilities in Internet-facing business systems and devices faster than ever before. 


Industry threat intelligence reports confirm that external vulnerability exploitation is one of the most prevalent initial access vectors used by attackers to breach the business perimeter.  


According to Mandiant’s M-Trends Report 2025, vulnerability exploitation was the leading initial access method, generating 33% of attacks, including those targeting Internet-facing systems such as web servers, APIs, and edge devices such as firewalls and VPN services. 


Verizon’s 2025 Data Breach Investigations Report also found exploitation of vulnerabilities to be behind 20% of breaches, with attacks on externally facing Internet edge devices and VPNs increasing dramatically from 3% to 22%. 


How Does the Fortis Attack Mitigation Service Work?

To counter AI-driven attacks, reduce the workload on internal security teams, and cut cyber risk, organisations need to adopt a proactive and layered approach to protecting internet-facing infrastructure. This is where the Fortis Cyber® Attack Mitigation Service (AMS) comes in, simplifying vulnerability management, providing comprehensive detection and validation, and delivering assurance against external cyber threats using: 


  • Regular Assessments: scheduled evaluations detecting and identifying risks across internet-facing assets and discovering vulnerabilities before threat actors do. 

  • Simulated Attacks: replicating real-world threat scenarios at scale to reveal how resilient your defences are under realistic attack conditions. 

  • Expert-Led Evaluation: experienced cyber security specialists perform in-depth analysis, validating findings and providing actionable recommendations. 

  • Security Workshops for Zero-Day Resilience: helping organisations understand and mitigate emerging threats and build resilience against zero-day vulnerabilities. 


What This Means for Your Business 

AI has transformed the balance of power in cyber security, giving criminals the tools to rapidly launch scalable attacks. Organisations need to act pre-emptively to anticipate and counter these threats. 

By regularly assessing external attack surfaces, simulating real-world threats, and building resilience through expert-led guidance, organisations can be the first to find the gaps and vulnerabilities, rather than the last to know about them. 


Ready to Simplify Security and Reduce Risk?  

Our experts will work with you to understand your security requirements and recommend tailored solutions aligned to your business that will reduce risk and lighten your team’s workload. Start the conversation today at enquiries@fortiscyber.co.uk.

 
 
 
bottom of page