Defence · Supplier Compliance

31 December 2026: the date every MOD supplier should have in the diary

In May 2026 the MOD asked all industry partners to reach Defence Cyber Certification Level 0 by the end of the year. For a capture business, that date is the smaller half of the problem.

OnXR 17 August 2026 7 min read
A secure data centre facility building photographed from outside at dusk

In a Defence Digital blog on 8 May 2026, the Ministry of Defence's Director of Cyber Defence and Risk, Eleanor Fairford, set a deadline in public: all industry partners are asked to achieve Defence Cyber Certification Level 0 by 31 December 2026.

For a technology supplier looking at the defence estate as a market, that date is the entry ticket. It is also the smaller half of the problem.

What Defence Cyber Certification is, and what it is not

DCC launched on 8 May 2025, delivered with IASME. It has four levels, 0 to 3, so an organisation certifies at a level matched to its risk and maturity. It builds on Cyber Essentials and adds governance, risk and resilience requirements. Level 0 covers three basic controls and includes obtaining Cyber Essentials for applicable business critical systems in scope. Level 1 runs to 101 controls, Level 2 to 139 and Level 3 to 144, with more evidence expected against each one as you climb. Levels 2 and 3 require Cyber Essentials Plus rather than Cyber Essentials, which is worth knowing before you agree a target level with a prime. Attestation is annual, with full recertification every three years.

Here is the part the trade press keeps getting wrong. DCC does not replace the Cyber Security Model. GOV.UK currently states that suppliers with a valid DCC certificate are not yet exempt from completing elements of the Supplier Assurance Questionnaire through the Supplier Cyber Protection Service. Read the "not yet". This is expected to change, but today the Cyber Security Model remains the contractual assurance route and DCC provides independent verification alongside it.

That model, now at version 4, works like this. The MOD delivery team completes a risk assessment producing a cyber risk profile and a risk assessment reference number. The reference passes to the supplier, who self assesses against it. Where the supplier falls short, it must submit a cyber improvement plan setting out when it will comply. DEFCON 658 is the contract condition that makes this binding, and primes must repeat the process for their own subcontractors, cascading down the tiers.

The underlying control set is Defence Standard 05-138, Issue 4, dated 14 May 2024. Suppliers must have a documented, implemented control with auditable evidence for each requirement, and flag at bid stage any control that is not appropriate. Cyber Essentials underpins all of it: NCSC calls it the minimum standard of cyber security recommended by government, and certification starts from £320 plus VAT.

The part that is specific to spatial data

For most suppliers, defence compliance is a cyber question. For anyone capturing three dimensional records of physical sites, it is also a criminal law question, and this is where the sector needs to be careful.

Under section 4 of the National Security Act 2023, it is an offence to inspect a prohibited place for a purpose the person knows, or ought reasonably to know, is prejudicial to the safety or interests of the United Kingdom. Section 4(2) expressly defines inspecting to include taking, or procuring the taking of, photographs, videos or other recordings, and inspecting such recordings. Section 4(3) confirms the offence can be committed by electronic or remote means. The maximum penalty is 14 years imprisonment, a fine, or both. Section 5 creates a lower threshold offence of unauthorised entry or inspection. Prohibited places under section 7 include Crown land, vehicles and buildings used for UK defence purposes, plus sites designated by regulations under section 8.

MOD guidance is clear that ongoing recreational use of the defence estate, including photography, is not affected by section 5 where a right of access or permission to enter already exists in other legislation, because entry in those circumstances is not unauthorised. Do not read that across to commissioned work. Guidance is not an exemption, photography can still be restricted by military bylaws even where a right of access exists, section 5 expressly covers taking photographs, video and other recordings, and it does not require a prejudicial purpose to be shown. Commissioned spatial capture of a defence site is authorised by contract, not by assumption, and nothing about a site in this category is authorised until someone with the authority to say so has said it in writing.

Classification, handling and the document that actually governs

The Government Security Classifications Policy, version 2.0 published 5 August 2024, sets three tiers: OFFICIAL, SECRET and TOP SECRET. OFFICIAL-SENSITIVE is a marking applied within OFFICIAL, not a fourth tier. Only the information creator in the originating organisation can classify or reclassify.

For electronic movement of OFFICIAL-SENSITIVE MOD identifiable information, Industry Security Notice 2023/04 sets the handling rules: data at rest encryption using approved products, passwords of at least nine characters sent through a different channel from the file, no transmission to personal devices, and a recommendation that the end to end email connection uses mandatory TLS 1.2 or higher. Where classified material must be held or classified work performed at a contractor's own premises, Facility Security Clearance is required, formerly known as List X, triggered at SECRET or foreign CONFIDENTIAL and above.

Two housekeeping points catch people out. JSP 604, the network rules publication, was withdrawn on 23 July 2024 with no named successor, so any supplier documentation still citing it as live is wrong. And JSP 440, the Defence Manual of Security, is not released outside Defence by default; if your contract requires you to meet it, your contracting authority should give you a specific statement of the security requirements.

The honest position: there is no published general rule for handling spatial data, point clouds or scans of the defence estate. The Security Aspects Letter on your specific contract is the operative document, and it should be read before a capture device leaves the office, not after.

Why the market is opening anyway

The Defence Investment Plan published on 30 June 2026 sets total planned MOD spending of £298 billion across the four years from 2026/27 to 2029/30, including around £7.3 billion for the digital targeting web and digital backbone over that period. On a longer horizon it commits £9 billion for defence housing and £26 billion across the naval bases at Devonport, Portsmouth and the Clyde, both over the next decade.

The estate needs it. MOD land holdings stood at 341,300 hectares as at 1 April 2026, 1.4 per cent of the UK land mass. The National Audit Office put the MOD property maintenance backlog at £15.3 billion as at October 2024, the largest single component of a backlog of at least £49 billion across government, and cautioned that incomplete and out of date condition data means the true figure is likely higher. The Public Accounts Committee reported in June 2026 that of roughly 50,000 service housing units, nine in ten need some remedial work and three in ten need substantial work or demolition.

Incomplete and out of date condition data is not a footnote. It is the problem statement.

Procurement is moving to match. The MOD SME Action Plan published on 21 July 2026 commits to £2.5 billion of additional SME spend by summer 2028 on top of a £5 billion baseline. An Office for Small Business Growth was stood up in January 2026. Commercial X, the procurement transformation programme, fields a commercial team delivering contracts up to £50 million and under two years at pace.

The sequence that works

Get Cyber Essentials. Register on the Supplier Cyber Protection Service and complete the questionnaire against the risk profile you are given. Certify to DCC Level 0 before 31 December 2026 and agree the eventual target level with your prime rather than guessing. Then, before you propose capturing anything, read the Security Aspects Letter and get the classification of the output agreed in writing.

Defence buys on evidence, not intention. Every supplier reading this, ourselves included, is working through the same sequence. The only question is whether you start it now or in December. Our piece on secure twins for defence and government estates covers the hosting side, and UK data residency covers where the data actually sits.

This article is general information about UK defence supplier requirements and is not legal or security advice. Suppliers should take their own advice and follow the requirements set by their contracting authority.

Talk to us under NDA

Defence conversations start with classification, hosting and handling rather than features. We are happy to have that one first.

See the Defence vertical