Elastic achieves Defence Cyber Certification Level 0 in the UK

Organisations working with the UK Ministry of Defence (MOD) face a clear requirement: Demonstrate baseline cyber resilience through independent assessment, or risk exclusion from the defence supply chain. As of 31 December 2026, the MOD expects all industry partners to hold at least DCC Level 0. Elastic has met that requirement ahead of schedule.

The Defence Cyber Certification (DCC) scheme is the UK Ministry of Defence's cyber assurance framework for industry partners. It replaces earlier self-attestation approaches with independent verification, giving the MOD confidence that the organisations it works with are meeting consistent, auditable security standards. Level 0 is the entry tier of a structured framework that is independently assessed, providing verified demonstration of cyber resilience rather than relying on self attestation.

What is the DCC scheme?

The DCC scheme was launched in May 2025 by the UK Ministry of Defence and is administered by IASME, the organisation that also administers Cyber Essentials on behalf of the National Cyber Security Centre. It is assessed against Def Stan 05-138 (Issue 4) — the MOD's own defence standard for cyber security in the supply chain.

The scheme is structured as a four-level hierarchy with each level mapped to the degree of cyber risk associated with a supplier's role in the defence supply chain. Cyber Essentials certification is a prerequisite at all levels, providing a consistent baseline across the framework. Elastic already holds Cyber Essentials Plus certification — the higher of the two Cyber Essentials tiers, which requires technical verification rather than self-assessment. 

DCC Level 0 builds directly on that foundation, so this achievement extends an existing, independently verified security baseline rather than starting from scratch.

The MOD Defence Digital blog post marking the scheme's first year sets out the broader strategic context: DCC is part of a sustained effort to raise the cyber resilience floor across the entire UK defence industrial base, extending beyond prime contractors.

What does this mean for the UK public sector?

The MOD's mandate that all industry partners achieve DCC Level 0 by 31 December 2026 reflects a broader shift in how the UK defence sector manages supply chain risk. Vendors operating in this space without DCC certification will face growing barriers to new and renewal contracts.

For Elastic customers in UK public sector and defence contexts, this certification provides an independently verified signal of security maturity. It confirms that Elastic meets the MOD's independently verified cyber assurance standard for defence supply chain partners, assessed against the MOD's own framework rather than a standard developed by the vendor.

Accessing the certificate

The DCC Level 0 certificate is available for download from assurance.elastic.co. Customers and partners requiring evidence of this certification for procurement, due diligence, or contract purposes can retrieve it directly from that page.

Elastic's full set of security certifications and compliance documentation is maintained at assurance.elastic.co. If you have questions about a specific compliance requirement or need to discuss our security posture for a procurement process, contact your Elastic account team.

A practical milestone in a longer programme

Certification is a point-in-time assessment, not a steady state. The DCC scheme like other frameworks Elastic operates under requires ongoing maintenance of the controls that earned certification. Our InfoSec team treats compliance work as part of standard operations, which is what makes achieving assessments like DCC Level 0 achievable without disrupting the rest of our security programme.

Elastic will continue to engage with the DCC scheme as the MOD evolves its requirements and will assess progression through higher certification tiers as appropriate to our role in the UK defence supply chain.

If you're evaluating Elastic for UK public sector or defence use cases, start with a free trial of Elastic Security or contact us to discuss your specific requirements.

The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.