TheMS

TheMS / Our Solutions / Defence

RPO-certified. Defence-ready.

BK17 is a Registered Provider Organisation for both CMMC and DCC, the two frameworks that define cyber security compliance for US and UK defence supply chains. We guide contractors through assessment, certification and ongoing compliance with precision.

Gap Assessment

We map your current posture against the applicable framework (CMMC, DCC, or both) and produce a scored, prioritised remediation roadmap.

Documentation & Evidence

We author every required artefact: SSPs, POA&Ms, risk registers, JSP applicability reviews, and Def Stan compliance packs, ready for assessment.

Assessment & Certification

We coordinate with C3PAOs and DCC assessors, manage the assessment process end-to-end, and support you through to certification.

Ongoing Assurance

Post-certification, we keep your compliance posture current as frameworks evolve, so you're never caught out at contract renewal.

What RPO status means for you.

RPO status is awarded to consultancies that meet rigorous standards of competence, ethics and methodology. When you work with BK17, you're working with an organisation that has been independently vetted, not just a consultancy that read the standard.

I supply to:

CMMC RPO

Registered Provider Organisation for the Cybersecurity Maturity Model Certification programme. Authorised to provide CMMC consulting services to defence contractors seeking DoD contract eligibility.

DCC RPO

Registered Provider Organisation for the UK Ministry of Defence's Defence Cyber Certification standard. Authorised to support UK defence suppliers through DCC assessment and compliance.

Supplying the MoD? Compliance is the contract.

The UK Ministry of Defence has its own cyber security framework, and it goes deeper than most suppliers realise. From DCC assessments to JSP compliance and Def Stan obligations, BK17 navigates the full landscape so you don't have to.

Why it matters

The MoD's Cyber Security Model (CSM) requires all suppliers to achieve a minimum Cyber Risk Profile. DCC, JSP 440, JSP 604 and relevant Def Stans are not optional guidance. They are contractual obligations embedded in DEFCON clauses.

77

DCC Controls

10+

JSPs covering cyber

50+

Def Stans with security requirements

DCC, JSPs and Def Stans.

Defence Cyber Certification

The DCC is the MoD's primary cyber security standard for defence suppliers. It maps to the NCSC Cyber Assessment Framework (CAF) and is assessed against four objectives: managing security risk, protecting against cyber attack, detecting cyber security events, and minimising the impact of incidents.

CAF-aligned

Baseline

Minimum requirement for most MoD supply chain contracts. Demonstrates foundational cyber hygiene and risk management.

Enhanced

Full CAF

Required for higher-risk contracts and programmes. Full CAF alignment with independent assessment.

Joint Service Publications

JSPs are the MoD's internal policy and procedural standards. Several carry direct cyber security obligations for suppliers, particularly JSP 440 (Defence Manual of Security), JSP 604 (Information Assurance) and JSP 490 (MOD Cryptographic Policy). Understanding which JSPs apply to your contract is the first step.

JSP 440JSP 604JSP 490

Defence Standards

Defence Standards (Def Stans) define technical and quality requirements for defence equipment and services. Many carry embedded information security and cyber requirements, including DEF STAN 05-138 (Cyber Security for Defence Suppliers), which sets the baseline for supply chain cyber obligations.

DEF STAN 05-138

The full MoD landscape, handled.

DCC Gap Assessment & Roadmap

We assess your current posture against the DCC's four CAF objectives and produce a clear, prioritised remediation roadmap aligned to your contract risk profile.

JSP Applicability Review

We identify which Joint Service Publications apply to your specific contract and programme, and map your obligations clearly so nothing is missed.

Def Stan Compliance

We assess your compliance with relevant Defence Standards, including DEF STAN 05-138, and produce the documentation required to satisfy MoD supply chain requirements.

DEFCON Clause Navigation

We interpret the cyber security DEFCON clauses in your contract and translate them into actionable compliance obligations with clear ownership and timelines.

Ongoing Assurance & Monitoring

Continuous compliance support. We keep your posture current as MoD requirements evolve, so you're never caught out at contract renewal.

From first call to certified.

Step 1

Discovery Call

We understand your contract scope, CUI handling, and current security posture in a focused 60-minute session.

Step 2

Gap Assessment

We assess your environment against the applicable framework (CMMC, DCC, or both) and produce a scored gap report.

Step 3

Remediation

We work alongside your team to close gaps (technical controls, policies, procedures and evidence) in priority order.

Step 4

Documentation

We produce all required artefacts: SSP, POA&M, risk register, and evidence packages, ready for assessment.

Step 5

Assessment Support

We coordinate with C3PAOs or DCC assessors, manage the assessment process, and support you through to certification.

Keep defence controls live in the Compliance and Supply modules.

Track DCC and CMMC controls alongside ISO, and manage flow-down requirements across your own supply chain.

Ready to get defence-ready?

Whether you're entering the US DoD supply chain or strengthening your MoD supplier status, BK17 has the RPO credentials and the experience to get you there.

Defence and compliance affiliations

Armed Forces Covenant – Employer Recognition Scheme Bronze Award

Armed Forces Covenant

BK17 is a proud signatory to the Armed Forces Covenant and holds the Employer Recognition Scheme Bronze Award — committed to supporting serving personnel, veterans, reservists, and their families.

NERDSC Associate Member – Norfolk & East of England Regional Defence & Security Cluster

NERDSC Associate Member

BK17 is an Associate Member of NERDSC — the Norfolk & East of England Regional Defence & Security Cluster — an MoD-backed industry network strengthening the UK defence supply chain.

© 2026 BK17 Limited. TheMS is a BK17 platform.