Lockheed Martin UK has become the first defence company to achieve Level 3 of the Ministry of Defence’s Defence Cyber Certification (DCC), the highest tier of a scheme designed to strengthen cyber resilience across the UK’s defence supply chain, ahead of a December 2026 deadline facing all MOD suppliers.
The company confirmed the achievement on 13 July, positioning itself ahead of the wider industry timeline: the MOD has asked all industry partners, from major primes to small suppliers, to reach at least the baseline Level 0 of the DCC by 31 December 2026. Lockheed Martin UK’s move to Level 3, the scheme’s top tier, puts it well beyond that minimum threshold.
The certification comes as the MOD continues to tighten cyber resilience requirements across its supply base, reflecting mounting concern over the exposure of defence programmes to cyber threats from state and criminal actors targeting contractors and subcontractors as a route into sensitive programmes and data.
Eleanor Fairford, Director of Cyber Defence & Risk at the Ministry of Defence, welcomed the milestone: “I am delighted that Lockheed Martin has successfully achieved Level 3 of the new Defence Cyber Certification demonstrating excellent cyber resilience in their business supporting UK Defence.”
Paul Livingston, Chief Executive of Lockheed Martin UK & NATO, said the early certification reflected the company’s broader approach to security across its operations and supply chain. “By achieving DCC Level 3 ahead of deadline, Lockheed Martin UK has demonstrated its leadership in defence cyber security and its commitment to maintaining the trusted, secure and dependable operations and supply chain that its MOD customers expect,” he said.
For the UK Defence Supply Chain
Lockheed Martin’s early move to DCC Level 3 signals the direction of travel for the MOD’s supply chain: cyber resilience is fast becoming a baseline commercial requirement rather than a differentiator, with certification set to cascade down from primes to the SMEs and subcontractors that support them. Suppliers across IT services, managed security, systems integration and any business handling MOD data or connecting into defence networks should expect certification requirements to reach further down their contracts over the coming months. To compete for this work, suppliers will need to evidence DCC certification at the level appropriate to their role, alongside demonstrable incident response processes and secure handling of controlled information, assessed by MOD-approved routes; smaller firms should prioritise reaching Level 0 well before the December 2026 deadline rather than treating it as a late scramble. The push reflects the MOD’s wider strategic drive to harden the resilience of its supply chain against sustained and escalating cyber threats.