Defence Cyber Certification Level 0

The Ministry of Defence has asked all industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026. Level 0 is three controls out of the 148 in Defence Standard 05-138: Cyber Essentials, UK GDPR, and the resilience of your systems. We are an appointed certification body for Level 0, and for the Cyber Essentials it requires.

Appointed
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher
DCC / 01 · The date that matters

Defence Cyber Certification and the 31 December 2026 date

If you supply the MOD, directly or through a prime, Level 0 by 31 December 2026 is the floor.

Defence Cyber Certification is the MOD's assurance scheme for its supply chain, built with IASME as the scheme's Certification Authority. It evidences compliance with the Cyber Security Model, and the controls sit in Defence Standard 05-138 Issue 4. It comes at four levels, 0 to 3, matched to your contract's Cyber Risk Profile. The Cyber Risk Profile and the DCC level are the same number.

01Three controls, not 148. Def Stan 05-138 Issue 4 holds 148 controls. Level 0 uses three of them, and no level uses all of them.
02Cyber Essentials is one of the three. You need it, covering the right scope, and you commit to keeping it for as long as the DCC certificate lasts.
03There is no partial credit. Level 0 passes only when 100% of the controls are fully met. The higher levels allow partial compliance; Level 0 does not.
04No site visit, no demonstration. Level 0 is a portal submission that your certification body marks. The practical scoring and site visits start at Level 1.
DCC / 02 · The requirements

What DCC Level 0 actually requires

Three controls, six questions. Every one has to be fully met, and each answer needs evidence and an explanation, not just a yes.

Control 0001

Cyber Essentials

Hold Cyber Essentials covering the scope the assessment needs, and keep it for as long as the DCC certificate lasts.

0001.1Does the organisation hold Cyber Essentials certification that covers the required scope for this activity?
0001.2Does the organisation commit to maintaining Cyber Essentials for the duration of the DCC certification?

Evidence expectedYour certificate number, the Cyber Essentials self-assessment questionnaire or report, a diagram showing how the Cyber Essentials scope relates to the DCC scope, and a history or attestation of regular renewal.

Control 2314

UK GDPR compliance

Show how you comply with the UK Data Protection Act 2018, and that you assess the risk in the data you hold.

2314.1Does the organisation have documented policies and procedures ensuring compliance with obligations under the UK GDPR?
2314.2Does the organisation conduct Data Protection Impact Assessments against the data types it stores or processes?

Evidence expectedThe policy or procedure showing how you comply, which can sit inside other documentation such as a risk register. For DPIAs: the procedure, the template or tool, or a completed assessment report.

Control 2500

Resilient networks and systems

Work out how resilient your systems need to be against attack and failure, then show what you actually did about it.

2500.1Has the organisation assessed the degree to which its systems must be resilient to cyber attack and system failure?
2500.2Has the organisation built resilience into its systems to meet its resilience needs?

Evidence expectedFor the assessment: what you judged essential and the risks to it, scaled to your size. For the implementation: concrete things, such as automated backups or an uninterruptible power supply. IASME explicitly does not want policies here.

How it is scored. Each control is marked 0 for not met, 1 for partially met or 2 for fully met. Level 0 requires every control fully met, which is why the two questions inside a control matter as much as the control itself: answer one well and one poorly and you have a partial, and a partial is a fail at this level. Level 1 and Level 2 allow partials as long as you reach 80% of the points in each objective and nothing scores zero. Level 3 returns to 100%.

DCC / 03 · Scope

Scope decides the outcome before anyone marks an answer

Scope is yours to set and document. If your assessor judges it inadequate, the whole assessment fails, whatever your controls look like.

DCC scope Everything supporting your business-critical functions
Cyber Essentials scope Internet connected only
  • Laptops, desktops and thin clients
  • Mobiles and tablets
  • Servers and virtual servers
  • Cloud services: IaaS, PaaS, SaaS
  • Firewalls and routers
In DCC, outside CE Not internet connected
  • OT, ICS and SCADA
  • Air gapped networks
  • Isolated test and build rigs
  • Standalone CAD workstations
Your Cyber Essentials certificate has to cover every applicable internet connected device inside the DCC scope. A small organisation may align the two exactly; most do not, because DCC includes assets Cyber Essentials rules exclude. That is expected, and you explain the difference in your answer. A Cyber Essentials scope that does not adequately align is an automatic failure, and IASME asks every applicant, whatever its size, to supply a diagram like this one.

You are responsible for determining the scope, documenting it accurately and being able to defend it. Your assessor can verify a scope and challenge it, but cannot set it for you. What you have to produce is a clear statement of what is in and what is out, supported by business organisation diagrams, network diagrams and lists of systems, explicitly marking which systems fall inside the Cyber Essentials scope.

The test is whether someone who has never seen your business can understand it from your documentation alone. That is where we spend most of the preparation time, because it is the cheapest place to fix a problem and the most expensive place to get one wrong.

DCC / 04 · The process

How to get DCC Level 0, step by step

Five steps, defined by the scheme. Level 0 runs entirely through the IASME portal.

1

Assessment preparation

You

Define the scope using the IASME Scoping Guide, then choose a certification body. You give them your organisation size, the critical environment being certified, the number of sites, how complex the organisation is, any security clearance requirements, and how prepared you are. They review the scope you propose and confirm it is appropriate.

If you are not ready, this is the moment to stop and say so. You can engage a provider for implementation support and come back for certification later. Discovering it at step four costs far more.

2

Onboarding

Us

We enter your organisation's details into the IASME portal and select the assessment level. Alongside that, you set up file sharing so we can reach your submission files, which stay on your systems throughout, and arrange any clearances needed to review sensitive material.

Level 0 only: no conflict of interest declaration is required. That becomes mandatory from Level 1 upwards.

3

Submission preparation

You

We run a readiness check first: that you hold the current guidance, have read it, and understand what the scheme expects, including the requirements that cause an automatic failure if missed. Then you answer the six questions in the portal, each with an explanation and evidence, and submit for marking. At Level 0 it is a portal submission rather than the Assessment Submission Record used at Levels 1 to 3.

Worth knowing: the Level 0 route cannot be used to aim at a higher level. If you may need Level 1 or above, take the Levels 1 to 3 process instead.

4

Assessment

Us

We review the submission and mark every question compliant, non-compliant, or more information needed. Where we ask for more, you update your answer and resubmit. Once every question is either compliant or non-compliant, we submit the result.

This is where the boundary sits. We can explain the scheme, clarify a control, describe the evidence a question needs, verify your scope and give you blank templates. We cannot implement controls for you, answer a question for you, or write documentation we will later mark. That is the scheme's rule, and it is what keeps the certificate worth holding.

5

Certification

Us

On a pass, the certificate is issued automatically through the scheme's digital certification system. On a fail, no certificate is issued and the process ends; you can remediate and return, and at Level 0 there is no conflict of interest check to redo.

Where we do the preparation, that is a separate piece of work agreed separately, and it stays inside what the scheme permits a certification body to do. If what you need is someone to build the controls and write the evidence, that is implementation work: any provider can do it, and using a different one for that than for your assessment keeps the line clean.

DCC / 05 · The four levels

Which levels we certify, and which we do not.

Certifying at a level removes the need for contract-by-contract assessment at that level and below.

Current scope: We provide Defence Cyber Certification Level 0 assessments. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Contact us if you would like to be notified when Level 1 becomes available, or see DCC Level 1 readiness for the preparation work we do today.

03 controlsWe assess and certify Level 0. The supply chain floor, for a very low assessed cyber risk. Requires Cyber Essentials, which we also certify. Pass mark 100%.
1101 controlsLow to moderate risk: a comprehensive programme with good practices. We do not assess Level 1 today. We prepare you and refer the assessment. Pass mark 80% per objective, nothing at zero.
2139 controlsHigh risk: advanced oversight and planning. We do not assess Level 2. It requires Cyber Essentials Plus, which we can certify; we refer the DCC assessment.
3144 controlsSubstantial risk: expert capability, defence in depth. Assessed as a Level 2 and 3 hybrid of 145 controls, the only route to Level 3, at 100%. Same position as Level 2.

Your level is not a choice you make in isolation. The MOD awarding body assigns a Cyber Risk Profile to a procurement or contract, and that profile is the DCC level you need. It is identified by a Risk Assessment Reference number in the invitation to tender. You can certify higher than you are asked to, and under the current scheme you may apply at any level.

DCC / 06 · A common misunderstanding

DCC does not replace your Supplier Assurance Questionnaire.

You will hear that Defence Cyber Certification removes the need to complete a Supplier Assurance Questionnaire. It does not.

The MOD's own guidance is explicit: suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and completion of the full SAQ to the required level remains mandatory. The MOD intends the two to converge, and hopes to bring DCC into the online tooling. That has not happened yet.

DCC / 07 · What it costs

DCC Level 0 prices

Most suppliers arriving here already hold Cyber Essentials, so that route is priced on its own. If you need both, we are the certification body for both.

Most suppliers

You already hold Cyber Essentials

The DCC Level 0 assessment and the IASME certification fee. We check that your Cyber Essentials scope aligns with the DCC scope as part of the assessment, at no extra cost.

1–9Micro£499
10–49Small£799
50–249Medium£1,499
250+LargeFrom £2,399

All prices + VAT. If your Cyber Essentials scope turns out not to cover what DCC needs, we will tell you before you order, not after.

Or

You need Cyber Essentials as well

The same assessment, plus Cyber Essentials certification. One company, one order, no separate Cyber Essentials invoice and no IASME fee added at the end.

1–9Micro£799
10–49Small£1,199
50–249Medium£1,999
250+LargeFrom £2,999

All prices + VAT. The difference between the two columns is the IASME Cyber Essentials fee for your band, from £320 to £600, plus our work on the certification.

What is not in the price. Remediation, and preparation work beyond what a certification body is allowed to do inside an assessment, are quoted separately. You decide whether we do that or you do, or whether another provider does. You get the findings either way.

The three year picture. A DCC certificate lasts three years with an annual attestation, and Cyber Essentials recertifies annually, so the running cost is the annual Cyber Essentials recertification plus the attestation. We set that out in writing before you commit, and we confirm the current IASME fee at the time you order, because scheme fees change.

Large organisations are quoted in writing before we start, because at 250 people and above the number of sites and the complexity of the estate move the figure more than headcount does.

DCC / 08 · Keeping it

Three years, with two attestations in between

A DCC certificate is not a one off. Cyber Essentials sits on its own annual cycle underneath it.

Year 0

Certified

The certificate is issued through the scheme's digital certification system and is valid for three years.

End of year 1

Attestation

You confirm nothing significant has changed. Cyber Essentials recertifies on its own annual cycle.

End of year 2

Attestation

The second annual attestation. Cyber Essentials recertifies again.

End of year 3

Reapply

The certificate expires and you apply again. It does not roll forward automatically.

Two obligations catch people out. You commit to holding Cyber Essentials for the whole life of the DCC certificate, including any scheme updates Cyber Essentials makes in that time. And your answers, evidence and any assessment recordings stay available to your certification body and to IASME for up to three and a half years after the assessment, so they need somewhere sensible to live rather than a folder on one person's laptop.

FAQ

Common questions

How do I get DCC certified?

Five steps. Define your scope using the IASME Scoping Guide and choose a certification body; the certification body onboards you to the IASME portal; you answer the questions with explanations and evidence and submit them; the certification body marks each question and submits the result; the certificate is issued automatically on a pass. At Level 0 the whole thing runs through the portal, with no site visit. Our guide to the Level 0 requirements covers each step in detail.

What does DCC Level 0 require?

Three controls, six questions. Control 0001, Cyber Essentials: hold it for the right scope and commit to maintaining it. Control 2314, UK GDPR: documented policies and procedures for compliance with the UK Data Protection Act 2018, and Data Protection Impact Assessments against the data you hold. Control 2500, resilient networks and systems: assess how resilient your systems need to be, and show what you built to meet that. All three must be fully met.

Do we need Cyber Essentials before DCC Level 0?

Yes. Cyber Essentials is one of the three Level 0 controls, so it is part of the certification rather than a prerequisite you can defer. It must cover every applicable internet-connected device inside the DCC scope, and a Cyber Essentials scope that does not adequately align is an automatic failure. We are an appointed Cyber Essentials certification body, so we can certify that part too, and if you already hold it we check the scope as part of the assessment.

How long does DCC Level 0 take?

It depends almost entirely on how ready you are, not on the assessment. The marking itself is quick, but every question that comes back as "more information needed" adds a round trip. Organisations that already hold Cyber Essentials with a clean, documented scope and have a data protection policy and real backups tend to move through quickly. The ones that take months are usually fixing scope documentation or building evidence that did not exist. That is why the readiness conversation happens before you order.

What is the deadline for DCC Level 0?

In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026. It is a request rather than a contractual mandate, but DCC requirements are specified at tender, so check your contract conditions.

Can our certification body help us pass?

Within limits the scheme sets out. A certification body can explain the scheme, clarify what a control means, describe the evidence a question needs, verify your scope, hand you blank templates and run clarification rounds. It cannot implement controls on your behalf, answer questions for you, or write documentation it will later assess. If you need more than that, it is implementation work and you can use any provider for it. We keep preparation and assessment as separate pieces of work for exactly this reason.

Can you assess Level 1?

Not yet. Our current certification-body scope is Level 0. We are working towards Level 1 capability in Q4 2026, subject to completing the required training and formal authorisation. We do not assess Levels 2 or 3 at all: for those we will prepare you, certify the Cyber Essentials Plus they require, and point you to a certification body that does the assessment. Level 1 is 101 controls against Level 0's three, so the readiness work starts well before the assessment does.

Does DCC replace the Supplier Assurance Questionnaire?

No, not currently. MOD guidance states that suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.

How long does DCC certification last?

Three years, with an annual attestation at the end of years one and two confirming nothing significant has changed. At the end of year three the certificate expires and you apply again. Cyber Essentials, which Level 0 requires, recertifies annually throughout.

What is Def Stan 05-138?

Defence Standard 05-138 is where the controls sit, and Issue 4 is the current version. It holds 148 controls applied across four progressively stricter levels, so what applies depends on your contract's Cyber Risk Profile. Issue 4 widened the standard's purpose from protecting MOD-identifiable information to improving a supplier's overall resilience. More in Def Stan 05-138 explained.

We are a subcontractor, not a prime. Does this apply to us?

Usually yes. DEFCON 658 contains the obligations suppliers must place upon their subcontractors, so requirements flow down through contract conditions. If a prime sends you a questionnaire mentioning DEFCON 658, a Cyber Risk Profile or Def Stan 05-138, it applies.

Start your DCC Level 0

Tell us who you supply, whether you hold Cyber Essentials, and what your scope looks like. We will tell you which of the three controls you already meet, what is missing, and what it costs. You speak to an engineer and an assessor, and if you are not ready we will say so before you order.

Reading, Berkshire  /  Defence Cyber Certification body for Level 0  /  reply within one working day