UK Defence Supply Chain

is your technology environment ready for DCC?

The Ministry of Defence has asked industry partners to achieve Level 0 Defence Cyber Certification by 31 December 2026.

Symposium helps Defence suppliers understand where their technology stands today, identify the gaps and build a practical route towards stronger cyber resilience.

20-minute introductory conversation. No obligation.

  • ISO 27001 certified
  • ISO 9001 certified
  • Cyber Essentials certified
  • Armed Forces Covenant signatory
  • Employer Recognition Scheme Gold Award
The Deadline

what the deadline actually asks of you.

For many organisations supplying Defence, cyber security is not the core business.

  • You manufacture.
  • You engineer.
  • You design.
  • You consult.
  • You develop specialist technology.

But increasingly, demonstrating that the organisation behind that expertise is secure is becoming part of being ready to do business with Defence.

DCC isn't simply another IT project. it is part of demonstrating cyber resilience across the Defence supply chain.

MoD target date

31 December 2026

Level 0 includes Cyber Essentials requirements for applicable business-critical systems within scope.

  1. today
  2. readiness review
  3. remediation
  4. 31 December 2026

Indicative only. Organisations should confirm their own obligations and timescales through official MoD, Defence Digital and IASME guidance.

What is DCC?

Defence Cyber Certification, without the jargon.

Defence Cyber Certification provides an organisation-level approach to demonstrating cyber resilience across the UK Defence supply chain.

Level 0 provides the foundation and includes Cyber Essentials requirements for applicable business-critical systems within scope.

The challenge for many SMEs isn't understanding that cyber matters. It's working out:

  • 01what needs to change
  • 02which systems are actually in scope
  • 03whether existing controls are sufficient
  • 04where Microsoft 365 fits
  • 05whether devices are properly managed
  • 06how identities and privileged access are controlled
  • 07whether evidence exists to demonstrate good practice
  • 08what happens after certification

Symposium provides technical readiness, remediation and managed security services. Formal DCC certification is delivered through the authorised certification framework. For authoritative requirements, refer to official MoD, Defence Digital and IASME guidance.

Scope

DCC Level 0 is the foundation. our review looks beyond the minimum.

Achieving a point-in-time certification and operating a genuinely resilient technology environment are not the same thing.

The Symposium Defence Cyber Readiness Review considers both immediate readiness and the wider Microsoft, identity, device, data and security controls that help an organisation remain resilient afterwards.

The areas we review are the scope of the Symposium review — they are not all formal DCC Level 0 requirements. Your specific certification requirements should be confirmed through official DCC guidance.

The Defence Cyber Readiness Review

understand where you stand before you start fixing things.

The Symposium Defence Cyber Readiness Review gives leadership and IT teams a practical view of their current cyber posture, priority gaps and the actions required to strengthen the environment.

The areas below set out the scope of the Symposium review — broader than DCC Level 0 alone.

  • 01

    identity & access

    Review Entra ID, MFA, Conditional Access, privileged accounts, access controls and authentication.

  • 02

    Microsoft 365 security

    Review tenant configuration, security controls, email protection, Microsoft Defender capabilities and administrative exposure.

  • 03

    endpoints

    Review device management, configuration, patching, encryption, compliance and endpoint protection.

  • 04

    Cyber Essentials readiness

    Identify technical gaps that may prevent or complicate Cyber Essentials readiness.

  • 05

    data & information protection

    Review permissions, data access, sensitive information exposure, sharing and relevant Microsoft security controls.

  • 06

    backup & recovery

    Review resilience, backup arrangements, recovery assumptions and key dependencies.

  • 07

    monitoring & response

    Review security monitoring, alerts, escalation, incident response and ongoing visibility.

  • 08

    operational resilience

    Review practical IT and cyber dependencies that could affect the organisation's ability to continue operating securely.

Example output

what the review actually produces.

Findings are summarised using a clear Red / Amber / Green view of each area reviewed, followed by a short list of prioritised actions and an overall position.

Illustrative example only. It is not based on a real assessment and does not represent any client's results.

Example Readiness Output

Illustrative
  • Identity & AccessGREEN
  • Microsoft 365 SecurityAMBER
  • EndpointsAMBER
  • Cyber Essentials ReadinessAMBER
  • Backup & RecoveryGREEN
  • Monitoring & ResponseRED

Priority actions

  1. 01Strengthen privileged access controls.
  2. 02Remediate unmanaged or non-compliant endpoints.
  3. 03Establish consistent security monitoring and response.
Overall positionAMBER
What you receive

a clear answer to three questions.

  1. 01

    where are we now?

  2. 02

    where are the gaps?

  3. 03

    what do we do next?

The output gives leadership and technical teams a concise view of the current position, priority risks and recommended next actions.

  1. 01

    discover

    We understand your organisation, technology environment, Defence exposure and current cyber position.

  2. 02

    assess

    We review the agreed technical areas and identify material gaps.

  3. 03

    prioritise

    Findings are classified using a clear Red / Amber / Green methodology.

  4. 04

    roadmap

    You receive a prioritised remediation roadmap covering immediate actions, medium-term improvements, strategic recommendations, dependencies and areas requiring further specialist assessment.

  5. 05

    executive review

    Symposium presents the findings to leadership and technical stakeholders in plain English.

you'll know what needs attention, why it matters and what to do next.

Book a DCC Readiness Triage
From readiness to resilience

getting ready is only the beginning.

A point-in-time assessment can identify weaknesses.

Long-term resilience comes from continuously managing the environment behind them.

readiness reviewtechnical remediationMicrosoft securityCyber Defenceongoing managed IT
  • Symposium One

    Managed Microsoft workplace, devices, support and cloud.

  • Cyber Defence

    Ongoing security monitoring, Microsoft Defender, threat detection and response.

  • Microsoft cloud

    Azure, Microsoft 365, Entra, Intune, Defender and associated cloud technologies.

  • advisory

    Technology roadmap, cyber maturity, cloud strategy and ongoing improvement.

Why Symposium

why Symposium?

  • Founded by a former Royal Corps of Signals serviceman.
  • Armed Forces Covenant signatory.
  • Employer Recognition Scheme Gold Award holder.
  • ISO 27001 certified.
  • ISO 9001 certified.
  • Cyber Essentials certified.

Symposium combines Microsoft cloud, modern workplace, cyber security and managed IT expertise with a long-standing connection to the Armed Forces community.

we understand the technology — and why getting it right matters.

  • ISO 27001
  • ISO 9001
  • Cyber Essentials
  • Microsoft technology expertise
  • Armed Forces Covenant
  • Employer Recognition Scheme Gold Award
Who this is for

is this relevant to your organisation?

this is likely relevant if:

  • You currently supply UK Defence
  • You expect to bid for Defence work
  • Your customers are asking more cyber questions
  • You rely heavily on Microsoft 365
  • You have a small internal IT team
  • Cyber Essentials is becoming commercially important
  • You aren't certain what your current cyber posture looks like
  • You want to improve security without building an enterprise-sized security team

it may not be suitable if:

  • You require formal DCC certification directly from Symposium
  • You require specialist classified-network accreditation outside Symposium's scope
Next step

find out where you stand.

A short conversation is enough to establish whether a Defence Cyber Readiness Review is appropriate for your organisation.

Prefer to talk first? Use the form and note that you'd simply like to talk to Symposium — we'll arrange a conversation without any assessment commitment.

Request a conversation

book a 20-minute dcc readiness triage

By submitting this form, you agree that Symposium IT may use the information provided to respond to your enquiry. See our Privacy Policy for information about how we process personal data.

FAQs

common questions about DCC readiness