Gap Assessment
We map your current posture against the applicable framework (CMMC, DCC, or both) and produce a scored, prioritised remediation roadmap.
Documentation & Evidence
We author every required artefact: SSPs, POA&Ms, risk registers, JSP applicability reviews, and Def Stan compliance packs, ready for assessment.
Assessment & Certification
We coordinate with C3PAOs and DCC assessors, manage the assessment process end-to-end, and support you through to certification.
Ongoing Assurance
Post-certification, we keep your compliance posture current as frameworks evolve, so you're never caught out at contract renewal.
What RPO status means for you.
RPO status is awarded to consultancies that meet rigorous standards of competence, ethics and methodology. When you work with BK17, you're working with an organisation that has been independently vetted, not just a consultancy that read the standard.
CMMC RPO
Registered Provider Organisation for the Cybersecurity Maturity Model Certification programme. Authorised to provide CMMC consulting services to defence contractors seeking DoD contract eligibility.
DCC RPO
Registered Provider Organisation for the UK Ministry of Defence's Defence Cyber Certification standard. Authorised to support UK defence suppliers through DCC assessment and compliance.
Supplying the MoD? Compliance is the contract.
The UK Ministry of Defence has its own cyber security framework, and it goes deeper than most suppliers realise. From DCC assessments to JSP compliance and Def Stan obligations, BK17 navigates the full landscape so you don't have to.
Why it matters
The MoD's Cyber Security Model (CSM) requires all suppliers to achieve a minimum Cyber Risk Profile. DCC, JSP 440, JSP 604 and relevant Def Stans are not optional guidance. They are contractual obligations embedded in DEFCON clauses.
77
DCC Controls
10+
JSPs covering cyber
50+
Def Stans with security requirements
DCC, JSPs and Def Stans.
Defence Cyber Certification
The DCC is the MoD's primary cyber security standard for defence suppliers. It maps to the NCSC Cyber Assessment Framework (CAF) and is assessed against four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents.
CAF-aligned
Baseline
Minimum requirement for most MoD supply chain contracts. Demonstrates foundational cyber hygiene and risk management.
Enhanced
Full CAFRequired for higher-risk contracts and programmes. Full CAF alignment with independent assessment.
Joint Service Publications
JSPs are the MoD's internal policy and procedural standards. Several carry direct cyber security obligations for suppliers, particularly JSP 440 (Defence Manual of Security), JSP 604 (Information Assurance) and JSP 490 (MOD Cryptographic Policy). Understanding which JSPs apply to your contract is the first step.
Defence Standards
Defence Standards (Def Stans) define technical and quality requirements for defence equipment and services. Many carry embedded information security and cyber requirements, including DEF STAN 05-138 (Cyber Security for Defence Suppliers), which sets the baseline for supply chain cyber obligations.
The full MoD landscape, handled.
DCC Gap Assessment & Roadmap
We assess your current posture against the DCC's four CAF objectives and produce a clear, prioritised remediation roadmap aligned to your contract risk profile.
JSP Applicability Review
We identify which Joint Service Publications apply to your specific contract and programme, and map your obligations clearly so nothing is missed.
Def Stan Compliance
We assess your compliance with relevant Defence Standards, including DEF STAN 05-138, and produce the documentation required to satisfy MoD supply chain requirements.
DEFCON Clause Navigation
We interpret the cyber security DEFCON clauses in your contract and translate them into actionable compliance obligations with clear ownership and timelines.
Ongoing Assurance & Monitoring
Continuous compliance support. We keep your posture current as MoD requirements evolve, so you're never caught out at contract renewal.
From first call to certified.
Step 1
Discovery Call
We understand your contract scope, CUI handling, and current security posture in a focused 60-minute session.
Step 2
Gap Assessment
We assess your environment against the applicable framework (CMMC, DCC, or both) and produce a scored gap report.
Step 3
Remediation
We work alongside your team to close gaps (technical controls, policies, procedures and evidence) in priority order.
Step 4
Documentation
We produce all required artefacts: SSP, POA&M, risk register, and evidence packages, ready for assessment.
Step 5
Assessment Support
We coordinate with C3PAOs or DCC assessors, manage the assessment process, and support you through to certification.
Keep defence controls live in the Compliance and Supply modules.
Track DCC and CMMC controls alongside ISO, and manage flow-down requirements across your own supply chain.
Ready to get defence-ready?
Whether you're entering the US DoD supply chain or strengthening your MoD supplier status, BK17 has the RPO credentials and the experience to get you there.