Defence Cyber
Certification.

Level 0 assessment and Level 1 support for UK defence suppliers.

Start with the level your customer or contract requires. Choose a route below to see the work involved, assessment responsibilities and next steps.

An engineer examining an electronic component at a workshop bench.
Illustrative engineering photograph. © This is Engineering / Pexels.

Level 0 assessment

For suppliers preparing an evidence-based submission against the three Level 0 controls.

Controls
Cyber Essentials, UK GDPR and system resilience.
Assessment
A portal submission reviewed by an appointed certification body.
Our role
DSC is appointed to assess and certify Level 0. Separate prices cover suppliers with or without Cyber Essentials.
Level 0 assessment and prices

Level 1 support

For suppliers preparing for the wider Level 1 requirements across 101 controls.

Preparation
Scope review, gap analysis and organised evidence.
Assessment
Documented evidence and practical verification. Responsibilities and the appointed assessment body are confirmed in the engagement.
Our role
We help you prepare and plan the assessment route around your requirement.
Level 1 support and process
Defence Cyber Certification body, Level 0

Appointed certification body for DCC Level 0. We are also appointed for Cyber Essentials and Cyber Essentials Plus. Preparation and formal assessment have separate responsibilities.

Start with your
procurement requirement.

Your customer or MOD awarding authority provides the required Cyber Risk Profile and Risk Assessment Reference. Ask them to confirm these if the requirement is unclear.

Cyber Essentials is required at every DCC level. Levels 2 and 3 require Plus; we refer those DCC assessments to an appointed body.

DCC is organisation-level assurance. It does not currently replace the full Supplier Assurance Questionnaire required by the MOD.

Tell us what you know

Start with your organisation's size, requested level, current Cyber Essentials position and target date. If the level is still being confirmed, say so.

We will discuss scope, preparation and the assessment route before setting out the work and price.

Discuss your DCC requirement

Reply within one working day.
Or call 0118 359 2220.

Choosing a DCC route

Who decides which DCC level we need?

Your customer or MOD awarding authority provides the Cyber Risk Profile for the work, normally with a Risk Assessment Reference. Confirm the required level and scope with them before selecting an assessment route.

Does Cyber Essentials replace DCC?

No. Cyber Essentials is required at every DCC level, with Cyber Essentials Plus required at Levels 2 and 3. DCC adds the controls and evidence required by the defence scheme.

Does DCC replace the Supplier Assurance Questionnaire?

No, not currently. The MOD still requires the full Supplier Assurance Questionnaire for the relevant Cyber Risk Profile, even where a supplier holds a valid DCC certificate.

Scheme information checked 12 September 2026: IASME Defence Cyber Certification and MOD Cyber Security Model guidance. For the underlying standard, see our Defence Standard 05-138 guide.