DCPP is a joint Ministry of Defence (MOD) / industry initiative to improve the protection of the defence supply chain from the cyber threat.
The Defence Cyber Protection Partnership (DCPP), a government industry initiative was formed to create a joint response to the cyber threat.
The DCPP aims to protect our military capability by improving cyber defence through the MOD’s supply chain while preserving existing investment in cyber security measures.
As part of the partnership the Ministry of Defence has created a number of cyber security standards that have to be met to contract with MOD, these are outlined in the Cyber Security Model (CSM).
In order for a supplier to demonstrate their compliance MOD has created the Supplier Cyber Protection Service. This is an online tool that enables you to complete a risk assessment (RA) and/or a supplier assurance questionnaire (SAQ).
What is DCPP ?
The DCPP is the partnership between the MOD and industry to decide upon new cyber security standards for industry. These are outlined in our Cyber Security Model which is built upon the Cyber Essentials Scheme.
How to comply with CSM
The Cyber Security Model (CSM) outlines the minimum required cyber security standards depending on the cyber risk level of each contract. The contractual requirement to meet the CSM is outlined in Defence Standard (DEFSTAN) 05-138 and Defence Condition (DEFCON) 658.
The DEFCON is one of a suite of conditions which make up a contract and you can view all MOD contract conditions on the Commercial Toolkit, which can be accessed by registering on the Acquisition System Guidance.
Communicate DCPP to others
These links and documents are here to assist you in understanding the requirements of the Cyber Security Model and communicating them to your staff and sub-contractors.
DCPP, Cyber Security Model: podcast. Please note: this podcast is hosted by a third party and the MOD is not responsible for the content of that site.
DCPP, Supply Chain Cyber Resilience: podcast. This 30 minute podcast is suitable for senior business leaders and CEOs of small and medium sized enterprises. Please note: this podcast is hosted by a third party and the MOD is not responsible for the content of that site.
Published: 2 June 2016
Updated: 17 October 2017
- Added Cyber security for defence suppliers (Defence Standard 05-138, Issue 2) and DEFCON 658
- Added Supplier cyber protection service development updates.
- Updated link to Cyber Protection Service.
- Added information on the Supplier Cyber Protection Service online tool.
- Added links to updated documents related to DCPP.
- DCPP: Cyber risk profile control guidance added
- Added link to: Defence Cyber Protection Partnership: your questions answered
- First published.
From: Ministry of Defence