By EJN Labs · 27 Aug 2026 · 8 min read
The DCPP does not name penetration testing as a blanket requirement. Its Cyber Security Model is risk-based: your contract’s Cyber Risk Profile decides which controls apply, and technical testing becomes the practical way to evidence them at Moderate and High profiles. Defence suppliers commonly commission a scoped test from a CREST-accredited firm at £1,100 to £1,400 per tester day.
Where DCPP penetration testing actually fits
Search for DCPP penetration testing and you will find vendors implying that the Defence Cyber Protection Partnership hands every supplier a mandatory annual pen test. It does not. The DCPP is a joint Ministry of Defence and industry initiative, and what it produced is a risk-based assurance model, not a testing schedule. Whether you need a penetration test, and how deep it goes, depends on the Cyber Risk Profile attached to each defence contract you bid for or hold.
That distinction matters commercially. Assume no testing is needed and a Moderate or High profile contract will ask for technical evidence you cannot produce; over-buy and you pay for red-team depth a baseline contract never expected. This post sets out what DCPP membership actually expects, and where independent testing earns its keep.
Why this matters for defence contractors
Defence supply chains are long, and the MoD knows the weakest link is rarely the prime. The DCPP exists because the MoD and the large primes wanted supplier assurance that is proportionate and contract-driven rather than one-size-fits-all, reaching every tier that handles MOD Identifiable Information.
The exposure is concrete. A CAD file at a fourth-tier machining shop, a maintenance schedule at an MSP, or credentials at a small software vendor can all carry MOD Identifiable Information.
For a commercial officer or security controller, the practical consequence is that cyber requirements arrive through the contract, flow down to your subcontractors, and get checked before award and during delivery. If you cannot evidence your controls, you carry bid risk as well as security risk: a competitor who can show independent test results against the same control set is simply easier for a prime to select.
The contractual driver: risk profiles, not a testing mandate
The DCPP’s Cyber Security Model works in three broad steps. First, the contracting authority runs a risk assessment on the contract itself, producing a Cyber Risk Profile. Second, the supplier completes a Supplier Assurance Questionnaire declaring how it meets the control set for that profile. Third, where gaps exist, the supplier agrees a Cyber Implementation Plan to close them. These requirements reach suppliers through defence contract conditions, commonly via DEFCON 658 and the Def Stan 05-138 control standard, and they flow down the chain: if you subcontract work that touches protected information, your subcontractors inherit proportionate obligations.
Here is the honest part. The control sets at lower risk profiles centre on hygiene: Cyber Essentials style controls, patching, access control, boundary protection. At Moderate and High profiles, the expected controls include technical assurance that your defences actually work, and self-declaration becomes hard to defend when a prime’s supply chain team, or an MoD assurance reviewer, asks how you know your controls are effective. An independent test report is the answer that closes that conversation. We cover the same honest-evidence pattern in our guide to choosing the best UK penetration testing provider: frameworks rarely say “pen test annually”, but assessors consistently accept little else as proof.
What to test against each Cyber Risk Profile
Scope should follow where MOD Identifiable Information lives and how an attacker would reach it. In the defence supplier estates we test, that usually means four layers.
External perimeter and remote access
Internet-facing services, VPN concentrators and remote desktop gateways are the first thing a hostile actor probes. External infrastructure penetration testing is the minimum sensible evidence for any profile above Very Low, and it is the cheapest test to commission.
Engineering and collaboration platforms
PLM and CAD repositories, document management, and Microsoft 365 tenants holding contract deliverables. Misconfigured sharing links and stale guest accounts are the recurring findings here, and cloud penetration testing covers the tenant configuration layer that network scans miss.
Internal network and segregation
Higher risk profiles expect protected information to be segregated. An internal test proves whether the segregation holds once an attacker has a foothold, or whether a compromised office laptop can reach the project enclave in one hop.
Software you ship into the programme
Defence software vendors and MSPs should test the products and portals they deliver, not just their corporate estate, because that is the surface the contracting authority actually consumes.
How a defence supplier engagement runs
A defence supplier engagement starts with a scoping call that maps your contract’s risk profile and control set to concrete targets: IP ranges, tenants, applications and any segregated enclave boundary. Testing runs over an agreed window with daily contact, and critical findings are flagged the day we confirm them.
Defence estates add two wrinkles we plan for explicitly. Facility and policy constraints sometimes mean testing on site or over an agreed secure channel rather than the open internet, and we agree up front how findings referencing protected systems are classified, stored and transmitted, so the report does not become a handling problem. The final report maps each finding to the control it undermines, directly supporting your Supplier Assurance Questionnaire answers and any Cyber Implementation Plan actions. Our penetration testing checklist walks through the preparation steps in detail.
What it costs and how scope drives the price
Penetration testing for defence suppliers is priced by effort, not by headcount or turnover. UK day rates for a CREST-accredited firm typically run £1,100 to £1,400 per tester day, and the risk profile of your contract is the biggest driver of how many days you need.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| External infrastructure only | 2 to 4 days | £2,200 to £5,600 |
| Cloud tenant and collaboration platform | 3 to 6 days | £3,300 to £8,400 |
| Internal network and segregation review | 4 to 7 days | £4,400 to £9,800 |
| Combined estate for Moderate or High profiles | 6 to 10 days | £6,600 to £14,000 |
These are typical UK ranges rather than a quotation; the exact figure depends on target counts and constraints. For a fuller breakdown of what moves the number, see our guide to penetration testing cost in the UK, or get an exact figure through the quote form.
How EJN Labs approaches DCPP-aligned testing
EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, and all testing is delivered by UK-based testers. That matters in defence work: many primes will not accept evidence from unaccredited suppliers, and offshore testing of systems holding MOD Identifiable Information is usually a non-starter.
- We scope against your contract’s Cyber Risk Profile, so you buy the depth the control set expects and no more.
- Findings are mapped to controls, giving you direct evidence for assurance questionnaires and implementation plans.
- We agree report classification and handling before testing starts, and can test on site where connectivity or policy requires it.
- Retest of remediated findings is included, so closed actions come with proof of closure.
All engagements run under our CREST penetration testing methodology, which is the assurance wrapper supply chain reviewers recognise.
Frequently Asked Questions
Does the DCPP require penetration testing?
Not as a blanket rule. The DCPP’s Cyber Security Model is risk-based: each defence contract carries a Cyber Risk Profile, and that profile determines the control set you must evidence. Penetration testing is not named as a universal requirement anywhere in the scheme.
At Moderate and High profiles, though, independent testing is the accepted way to demonstrate that technical controls actually work. Self-declaration alone rarely convinces a prime’s assurance review at those levels.
What is a Cyber Risk Profile and who sets it?
A Cyber Risk Profile is an assessment of the cyber risk carried by a specific defence contract, and it is set by the contracting authority rather than the supplier. It determines which controls from the applicable standard apply to that contract.
Suppliers then declare their position through a Supplier Assurance Questionnaire and, where gaps exist, agree a Cyber Implementation Plan to close them within an agreed timescale.
How much does penetration testing cost for a defence contractor?
Expect £1,100 to £1,400 per tester day at a CREST-accredited UK firm. An external infrastructure test usually takes 2 to 4 days, so £2,200 to £5,600, while a combined estate test for a Moderate or High profile contract runs 6 to 10 days, so £6,600 to £14,000.
Scope drives the price, so exact figures come from a scoping call.
Do DCPP requirements flow down to subcontractors?
Yes. Where a subcontract involves MOD Identifiable Information, the cyber conditions flow down the supply chain in a form proportionate to the risk carried by that subcontract. Primes and upper-tier suppliers are responsible for flowing requirements down and for gaining assurance over their subcontractors.
That assurance duty is why many primes ask lower tiers for independent test evidence.
Is Cyber Essentials enough for defence contracts?
Cyber Essentials is often enough at the lowest risk profiles, and it is the baseline for most MoD contracts. As the Cyber Risk Profile rises, the expected control set grows well beyond Cyber Essentials, and a certificate alone does not evidence those controls.
The growth covers areas such as segregation, monitoring and technical assurance. At those levels independent penetration testing becomes the practical proof point.
Turn your risk profile into evidence before the next bid
The cheapest time to close the evidence gap is before the assurance questions arrive. Tell us your contract’s risk profile and estate shape through our CREST pentesting quote form and we will return a fixed scope and price within one working day.




Leave a Reply