惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
IT之家
IT之家
B
Blog RSS Feed
罗磊的独立博客
GbyAI
GbyAI
博客园 - Franky
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News
博客园 - 聂微东
N
Netflix TechBlog - Medium
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
U
Unit 42
博客园 - 叶小钗
Jina AI
Jina AI
MyScale Blog
MyScale Blog
雷峰网
雷峰网
B
Blog
Hugging Face - Blog
Hugging Face - Blog
Blog — PlanetScale
Blog — PlanetScale
Recent Announcements
Recent Announcements
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell

Elastic Blog - Elasticsearch, Kibana, and ELK Stack

The search multiplier: Driving revenue, productivity, and AI at scale Elastic Stack 9.5.2 released ECK 3.5: Dynamic namespaces, pause orchestration, and mTLS everywhere 7 lessons for IT leaders on using observability to monitor AI applications How state and local agencies can get ahead of fraud starting with the data they already have Why agentic treasury needs search and observability From retrieval to agents: 5 takeaways on production architecture for AI agents Elastic community newsletter — August 2026 Elastic Stack 8.19.20 released Elastic Stack 9.5.1 released Elastic Stack 9.4.5 released Building trusted agentic AI in financial services: From data to autonomous action Azure Private Link for Elastic Cloud Serverless is now generally available Elastic 9.5: Columnar, VectorDB index mode & auto-calibration, and AI-driven alert triage AI consolidation: Why platforms will win and portfolios will break Closing the AI gap in government: Next-gen knowledge access | Elastic Elastic and OpenAI collaborate to bring frontier intelligence to unstructured enterprise data Elastic Cloud Serverless continues global expansion to 4 more regions Elastic joins NVIDIA and industry leaders as inaugural member in the Open Secure AI Alliance Rethinking the SOC: From tool procurement to platform architecture Elastic’s new metrics capabilities will dramatically improve uptime for public sector IT Elastic and Deductive AI join forces to accelerate agentic incident investigation for engineering teams Higher education analytics for the ultra-intelligent university Elastic Stack 8.19.19 released Elastic Stack 9.4.4 released Elastic Stack 9.3.8 released Elastic Stack 9.4.3 released Elastic achieves the AWS AI Security Distinction, securing AI-specific risks Elastic and Axonius integrate to deliver unified asset intelligence for security teams Elastic’s guide to AI in the interview process
Elastic achieves Defence Cyber Certification Level 0 in t...
ByChristine BocciRyan KamAugust 13, 2026 · 2026-08-13 · via Elastic Blog - Elasticsearch, Kibana, and ELK Stack

Organisations working with the UK Ministry of Defence (MOD) face a clear requirement: Demonstrate baseline cyber resilience through independent assessment, or risk exclusion from the defence supply chain. As of 31 December 2026, the MOD expects all industry partners to hold at least DCC Level 0. Elastic has met that requirement ahead of schedule.

The Defence Cyber Certification (DCC) scheme is the UK Ministry of Defence's cyber assurance framework for industry partners. It replaces earlier self-attestation approaches with independent verification, giving the MOD confidence that the organisations it works with are meeting consistent, auditable security standards. Level 0 is the entry tier of a structured framework that is independently assessed, providing verified demonstration of cyber resilience rather than relying on self attestation.

What is the DCC scheme?

The DCC scheme was launched in May 2025 by the UK Ministry of Defence and is administered by IASME, the organisation that also administers Cyber Essentials on behalf of the National Cyber Security Centre. It is assessed against Def Stan 05-138 (Issue 4) — the MOD's own defence standard for cyber security in the supply chain.

The scheme is structured as a four-level hierarchy with each level mapped to the degree of cyber risk associated with a supplier's role in the defence supply chain. Cyber Essentials certification is a prerequisite at all levels, providing a consistent baseline across the framework. Elastic already holds Cyber Essentials Plus certification — the higher of the two Cyber Essentials tiers, which requires technical verification rather than self-assessment. 

DCC Level 0 builds directly on that foundation, so this achievement extends an existing, independently verified security baseline rather than starting from scratch.

The MOD Defence Digital blog post marking the scheme's first year sets out the broader strategic context: DCC is part of a sustained effort to raise the cyber resilience floor across the entire UK defence industrial base, extending beyond prime contractors.

What does this mean for the UK public sector?

The MOD's mandate that all industry partners achieve DCC Level 0 by 31 December 2026 reflects a broader shift in how the UK defence sector manages supply chain risk. Vendors operating in this space without DCC certification will face growing barriers to new and renewal contracts.

For Elastic customers in UK public sector and defence contexts, this certification provides an independently verified signal of security maturity. It confirms that Elastic meets the MOD's independently verified cyber assurance standard for defence supply chain partners, assessed against the MOD's own framework rather than a standard developed by the vendor.

Accessing the certificate

The DCC Level 0 certificate is available for download from assurance.elastic.co. Customers and partners requiring evidence of this certification for procurement, due diligence, or contract purposes can retrieve it directly from that page.

Elastic's full set of security certifications and compliance documentation is maintained at assurance.elastic.co. If you have questions about a specific compliance requirement or need to discuss our security posture for a procurement process, contact your Elastic account team.

A practical milestone in a longer programme

Certification is a point-in-time assessment, not a steady state. The DCC scheme like other frameworks Elastic operates under requires ongoing maintenance of the controls that earned certification. Our InfoSec team treats compliance work as part of standard operations, which is what makes achieving assessments like DCC Level 0 achievable without disrupting the rest of our security programme.

Elastic will continue to engage with the DCC scheme as the MOD evolves its requirements and will assess progression through higher certification tiers as appropriate to our role in the UK defence supply chain.

If you're evaluating Elastic for UK public sector or defence use cases, start with a free trial of Elastic Security or contact us to discuss your specific requirements.

The release and timing of any features or functionality described in this post remain at Elastic's sole discretion. Any features or functionality not currently available may not be delivered on time or at all.