Skip to main content

Written question asked by Ben Obese-Jecty (Conservative) on Friday, 29 May 2026, in the House of Commons. It was due for an answer on Tuesday, 2 June 2026. It was answered by Luke Pollard (Labour) on Friday, 5 June 2026 on behalf of the Ministry of Defence.


Defence: Cybersecurity

Question

To ask the Secretary of State for Defence, what assessment he has made of the potential impact of the requirement to attain IASME certification on separate entities within the same business.

Answer

The Department applies a proportionate, risk‑based framework, with Defence Cyber Certification using Cyber Essentials as a baseline. The Department requires higher levels of assurance only where appropriate in order to minimise unnecessary administrative burden.

The Department keeps the impact of its cyber resilience requirements on suppliers under review, including how these apply to different entities within the same corporate group. In doing so, it seeks to recognise existing assurance activity where valid, and to address any gaps in a proportionate manner, without unnecessary duplication.

The approach we have taken ensures our Armed Forces are supported by a supply chain that is verifiably resilient against evolving cyber threats.


Secondary information

Type
Written question
Reference
5086
Session
2026-27
Subjects
Defence Certification Cybersecurity
Link
View this Written question on www.parliament.uk