NOVA BLUE

BB headshot

Why the Compliance Gate Nobody Warns North East Defence SMEs About Keeps Me Up at Night

July 29, 20264 min read

I've lost count of the number of times I've watched a technically excellent SME lose a MOD supply chain bid for a reason that had nothing to do with their engineering. The team was right, the price was right, the delivery plan was solid. A due diligence check flagged a gap in their Cyber Essentials or DCC evidence, and by the time anyone noticed, there was no time left to fix it. That's the pattern I see most often in my day-to-day work, and it's a big part of why I care personally about Nova Blue becoming a Strategic Member of NERDSC, the North East Regional Defence & Security Cluster.

I lead our managed services team at Nova Blue, and most of my working week is spent inside Cyber Essentials Plus and DCC engagements with SMEs across the defence supply chain. I'm also partway through my Cyber Advisor certification, which means I spend as much time in the fine print of frameworks like DefStan 05-138 as I do running my own team. NERDSC puts me in the same room as the primes, MoD regional bodies and academic partners who are actually setting the direction here, rather than leaving me to read about DefStan or CSM v4 changes after they've already landed on a client's desk.

The North East's defence and security sector has pulled in over £0.5bn in Innovate UK grants since 2002, and MOD spending supports around 900 jobs across the region. That's real growth, and it's dragging serious money into the local supply chain. It's also dragging in serious scrutiny. Procurement routes like JOSCAR and DSP increasingly build compliance checks into the qualification stage itself, not the delivery stage. Primes and government buyers aren't asking whether a supplier can eventually get compliant. They're asking whether the supplier already is, right now, on paper, with evidence.

What frustrates me is that the businesses who get caught out are rarely incompetent. They're just late. A gap that would have taken a few weeks to close six months earlier becomes disqualifying the moment it surfaces mid-bid. I've seen this cost SMEs contracts, and often the relationship that came with them, not because they didn't take security seriously, but because nobody flagged it early enough for it to be a quick fix instead of a crisis.

This is the exact problem my team spends its time closing, and I'll admit I lean hard on the fact that our leadership includes Steve Mason, a former GCHQ Technical Director, and a wider team with over fifty years of collective defence and national security experience. It changes how we approach the work. We built the systems and requirements MOD suppliers are now expected to meet, before we ever advised on them commercially, and I treat compliance as an ongoing operational discipline rather than a certificate to file away.

In practice, that's three things I oversee running together. Security Leadership gives a business without a CISO a strategic roadmap and someone accountable for it. Compliance Support, delivered through our AEGIS programme, is where my team gets a business through Cyber Essentials, DefStan and DCC properly the first time, mapped to what their actual contracts require rather than a generic checklist. Managed Services, through MIDAS and ATLAS, is how we keep that posture live day to day, so the certification a client earned in March is still true in November when a prime's due diligence team comes asking.

If there's one thing I'd tell a North East defence SME to do this week rather than next quarter, it's find out which DCC level your current or target contracts actually require, and check that honestly against where your business sits today. Most gaps are fixable in weeks if caught early. Almost none are fixable in the middle of a live bid.

Being part of NERDSC gives my team and our clients earlier sight of exactly these shifts, procurement changes, framework updates, funding routes, before they reach the wider market. I'd genuinely encourage any North East defence supply chain business to get in that room themselves. NERDSC's introductory session in Durham on 15 September covers procurement routes, bid writing and the cyber compliance requirements that catch most SMEs out first. I'll be there. Come and say hello.

If you're not certain where your business stands against Cyber Essentials, DCC or DefStan requirements, get in touch with my team.

Ben Brown

Ben Brown

Managed Services Team Lead, ensuring everything we do adds value to our customers

LinkedIn logo icon
Back to Blog

© 2026 Nova Blue Technologies Ltd · Registered in England & Wales · Company #12840005 · All rights reserved