Yes, if they sit inside the certification scope. Def Stan 05-138 Issue 4 scopes your whole corporate environment, not just contract data, so AI tools count as software or cloud services under Cyber Essentials. The MOD has asked industry partners to hold DCC Level 0 by 31 December 2026. Mickai installs on hardware you already hold in scope.
What is Defence Cyber Certification and who needs it?
Defence Cyber Certification is an independent audit of a supplier's cyber security against Def Stan 05-138. The MOD created it with IASME, who act as the scheme's certification authority, and it sits alongside two things that were already in place: DEFCON 658, which carries the contractual terms, and the Cyber Security Model itself.
The mechanism runs in a fixed order. An MOD delivery team completes an initial risk assessment on a contract, and that assessment determines a Cyber Risk Profile numbered Level 0 to Level 3. You are given a Risk Assessment Reference number and the required level at early market engagement. You then self-assess against the Cyber Security Model requirements using a Supplier Assurance Questionnaire on the Supplier Cyber Protection Service.
DCC is the independently audited version of that self-assessment. Rather than telling the MOD you meet the controls, a licensed certification body examines you and says so.
One point catches people out. A DCC certificate does not currently release you from the questionnaire. The gov.uk Cyber Security Model guidance states that suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ through the Supplier Cyber Protection Service. Budget for both.
As for who needs it: anyone in the defence supply chain, prime or lower tier. Suppliers are responsible for flow-down, and DEFCON 658 contains the obligations a supplier must place on its own subcontractors.
What does Level 0 actually require?
Three controls from Def Stan 05-138 Issue 4. Not thirty. Three.
Control 0001, Cyber Essentials. The standard requires the supplier to hold Cyber Essentials certification that covers the scope required for all aspects of the contract, and to commit to maintaining it for the duration of the contract.
Control 2314, ensuring personal data is processed in compliance with UK GDPR.
Control 2500, resilient networks and systems. The supplier must build resilience against cyber attack and system failure into the design, implementation, operation and management of the systems supporting its business functions and protecting its data.
For scale: Level 1 is 101 controls, Level 2 is 139, Level 3 is 144. Cyber Essentials Plus, control 0002, only enters at Level 2. Level 0 is genuinely a floor, and most of the work at that floor is the Cyber Essentials scope question.
Which is where AI arrives.
When does an AI tool fall inside your certification scope?
Nearly always, because the standard scopes your organisation rather than your contract.
Clause 1.1 of Issue 4 sets the scope as the supplier's overarching corporate or enterprise environment, covering all supplier organisations, systems, processes, procedures and data necessary for the effective protection of data and functions, going beyond the protection of just the information handed to the supplier for the contracted output. Clause 1.2 says the standard is intentionally broad.
People misread this consistently. They assume the test is whether the AI tool touches MOD data. Under Issue 4 that is not the test. The test is whether the tool forms part of the enterprise environment that keeps business functions running and data protected. A summarisation assistant that half your engineering team pastes into is part of that environment whether or not a single MOD document has ever passed through it.
So the useful question is not whether your AI is in scope. It is whether you can describe your AI honestly inside a boundary you can defend to an assessor.
How does Cyber Essentials treat AI software and cloud services?
As software, and as cloud services. There is no AI control.
Worth stating plainly: the current Cyber Essentials requirements for IT infrastructure, version 3.3, April 2026, does not mention artificial intelligence anywhere. That is not a gap to exploit. It means your AI tooling gets classified under definitions that already exist.
The scheme defines software to include operating systems, commercial off-the-shelf applications, extensions, interpreters, scripts and libraries. A model running on a server you own is software on an in-scope device. Scope itself is defined as the networks, hardware and software assets, and cloud services included in the assessment.
A hosted AI service meets the scheme's cloud definition: an on-demand, scalable service on shared infrastructure, reached over the internet through an account, storing or processing data for your organisation. Then comes the line that settles the argument. Cloud services cannot be excluded from scope.
For cloud, the applicant organisation is always responsible for ensuring all controls are implemented, even where the provider implements some of them. Table 1 of the requirements sets out who typically implements each control. For SaaS, user access control is yours and secure configuration is shared. Where the provider implements a control on your behalf, you must show the provider has committed to it through contractual clauses or documents referenced by the contract.
That last requirement is what quietly costs money. Every AI service in your estate needs a named account owner, MFA, a defensible configuration position and contract evidence for whatever the provider does on your behalf. Multiply that by the number of AI subscriptions that arrived without procurement seeing them.
What does the 31 December 2026 date mean for suppliers?
It is a request from the MOD, not a statute. In a Defence Digital blog post dated 8 May 2026, the MOD said it has asked all industry partners to achieve Level 0 DCC certification by 31 December 2026, including obtaining Cyber Essentials for all applicable business-critical systems in scope.
Treat it as a commercial date rather than a legal one. Requirements of this kind arrive through tender conditions and contract terms, so the consequence of missing it is not a fine. It is losing a bid, or becoming the lower-tier supplier a prime cannot use because its own flow-down obligation under DEFCON 658 requires it to place the requirement on you.
If you are starting now, the scope conversation is the critical path, not the audit booking. Getting a certification body to agree your boundary takes longer than most people budget, and each shadow AI subscription you discover late moves that boundary again.
Does on-premise AI make scoping simpler?
Structurally, yes, for one reason: there is no cloud service to scope.
I build the Mickai Sovereign Intelligence Operating System, so let me be straight about what it does and does not do here. It does not certify you. Mickai holds no DCC or Cyber Essentials certificate, and no product can hand you a certification. What changes is the shape of the problem.
SIOS installs on hardware you already own and already hold inside your boundary. It is offline capable, with no data egress. The AI capability stops being a cloud service you must scope, evidence with contractual clauses and re-evidence when a provider changes its terms. It becomes software on servers already in your asset register and already covered by your five technical controls.
Two things then help on the evidence side rather than the scope side. Every consequential action is sealed in the Open Audit Record under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024. That record is tamper-evident, not tamper-proof. Nothing physically stops someone altering the bytes. Altering them makes verification fail, and an auditor can verify an exported record offline with a public key, using tools that are not ours. Control 2500 asks for resilience you can demonstrate, and clause 2.4 asks for a documented, implemented control with auditable evidence. A record an assessor can check without trusting me is the kind of evidence that survives an audit.
Consequential actions also wait for a named person to approve them, which produces the human accountability trail that scoping documents keep asserting and estates rarely deliver.
None of this is an argument against cloud. Cloud remains the right answer for a great deal of non-regulated work, and the organisations building the compute and cloud layer are doing necessary work. The narrower argument is this: for work sitting inside a Def Stan 05-138 boundary, renting your intelligence means importing a third party into that boundary and taking their word for what happened to your data. That is an assumption, not a law.
SIOS is in closed beta. Fourteen of sixty-three studios are production-ready, forty-nine are in development, and one regulated company is onboarding as a design partner. The partner and its sector stay confidential. If document reading matters to you, a local OCR runtime has read scanned PDFs in controlled tests, and the SIOS extraction and ingestion integration is still being completed. More on the wider position at sovereign AI.
Frequently asked questions
Is Defence Cyber Certification mandatory?
Not by law. DCC is a contractual and policy expectation rather than a legal mandate. The MOD has asked industry partners to reach Level 0 by 31 December 2026, and DEFCON 658 carries the contractual terms of the Cyber Security Model. In practice it arrives through tender conditions and prime contractor flow-down, so treat it as commercially compulsory.
Does a cloud AI service have to sit inside our Cyber Essentials scope?
Yes. The Cyber Essentials requirements for IT infrastructure state that cloud services cannot be excluded from scope where your organisation's data or services are hosted on them. A hosted AI assistant, reached through an account and processing your data, meets the scheme's definition of a cloud service. You remain responsible for ensuring all five controls are implemented.
What is the difference between Defence Cyber Certification and Def Stan 05-138?
Def Stan 05-138 is the standard. It defines the four Cyber Risk Profiles and the controls required at each level. DCC is the certification scheme that independently audits you against those controls, run with IASME as certification authority. The standard tells you what to do. The certificate is third-party evidence that you did it.
Do subcontractors need Defence Cyber Certification too?
Often, yes. Suppliers are responsible for flow-down, and DEFCON 658 contains the contractual obligations a supplier must place on its subcontractors. The level required depends on the Cyber Risk Profile assessed for the work that subcontractor actually does, so it is not automatically the level the prime holds. Ask your prime what they intend to flow down.
Which Defence Cyber Certification level does our contract need?
The MOD delivery team decides. An initial risk assessment produces a Cyber Risk Profile from Level 0 to Level 3, and you receive a Risk Assessment Reference number with the required level at early market engagement. Level 0 needs three Def Stan 05-138 controls. Levels 2 and 3 add Cyber Essentials Plus and substantially more.
Related briefings
Procurement and defence
- Buy AI Through G-Cloud and Government Frameworks: Guide
- AI Disclosure in Public Sector Tenders: What's Required?
- AI Bid Evaluation in Public Procurement: Is It Lawful?
- AI for Procurement Contract Review: Is It Allowed?
- AI Supplier Contract Clauses: A UK Buyer's Checklist
UK AI regulation
- Is There a UK AI Act? How the UK Regulates AI Today
- AI Cyber Security Code of Practice: Who It Applies To
Part of a series of 60 briefings on deploying and governing AI in UK regulated organisations, archived with a DOI at 10.5281/zenodo.22975756.
Evaluating AI for a regulated organisation? Mickai runs on hardware you own, offline. Consequential actions wait for a named person to approve them, and what the AI did is sealed into a signed record an auditor can check without us. Applications for the invitation-only closed beta are open. Apply for the closed beta.
Written by Micky Irons, founder and chief executive of Mickai LTD.
Top comments (0)