Already hold Cyber Essentials?
From £499 + VAT · 1–9 people
Discuss DCC assessmentAssessment by an appointed certification body, with the IASME certification fee included.
The Ministry of Defence has asked industry partners to achieve DCC Level 0 by 31 December 2026.
From £499 + VAT · 1–9 people
Discuss DCC assessmentFrom £799 + VAT · 1–9 people
Discuss CE and DCC
Preparation and formal assessment have separate responsibilities.
Choose the route that matches your current Cyber Essentials position. If you need both certifications, we are the certification body for both.
The DCC Level 0 assessment and the IASME certification fee. We check that your Cyber Essentials scope aligns with the DCC scope as part of the assessment, at no extra cost.
All prices + VAT. If your Cyber Essentials scope turns out not to cover what DCC needs, we will tell you before you order, not after.
Discuss DCC with existing Cyber EssentialsThe same assessment, plus Cyber Essentials certification. One company, one order, no separate Cyber Essentials invoice and no IASME fee added at the end.
All prices + VAT. This route includes Cyber Essentials certification and the applicable scheme fees. We confirm the scope and written price before you order.
Discuss DCC and Cyber EssentialsWhat is not in the price. Remediation, and preparation work beyond what a certification body is allowed to do inside an assessment, are quoted separately. You decide whether we do that or you do, or whether another provider does. You get the findings either way.
The three year picture. A DCC certificate lasts three years with an annual attestation, and Cyber Essentials recertifies annually, so the running cost is the annual Cyber Essentials recertification plus the attestation. We set that out in writing before you commit, and we confirm the current IASME fee at the time you order, because scheme fees change.
Large organisations are quoted in writing before we start, because at 250 people and above the number of sites and the complexity of the estate move the figure more than headcount does.
You prepare the answers and evidence. We review and mark the submission against the scheme requirements.
Preparation beyond the certification body's permitted role and technical remediation are quoted separately. Annual attestation and Cyber Essentials renewal costs are confirmed before you commit.
A few practical questions to help you prepare for a conversation with an assessor. Your answers stay on this page.
The MOD has asked industry partners to reach Level 0 by 31 December 2026. Your contract or prime determines the level your work requires.
Defence Cyber Certification is the MOD's assurance scheme for its supply chain, built with IASME as the scheme's Certification Authority. It evidences compliance with the Cyber Security Model, and the controls sit in Defence Standard 05-138 Issue 4. It comes at four levels, 0 to 3, matched to your contract's Cyber Risk Profile. The Cyber Risk Profile and the DCC level are the same number.
Three controls, six questions. Every one has to be fully met, and each answer needs evidence and an explanation, not just a yes.
Hold Cyber Essentials covering the scope the assessment needs, and keep it for as long as the DCC certificate lasts.
Evidence expectedYour certificate number, the Cyber Essentials self-assessment questionnaire or report, a diagram showing how the Cyber Essentials scope relates to the DCC scope, and a history or attestation of regular renewal.
Show how you comply with the UK Data Protection Act 2018, and that you assess the risk in the data you hold.
Evidence expectedThe policy or procedure showing how you comply, which can sit inside other documentation such as a risk register. For DPIAs: the procedure, the template or tool, or a completed assessment report.
Work out how resilient your systems need to be against attack and failure, then show what you actually did about it.
Evidence expectedFor the assessment: what you judged essential and the risks to it, scaled to your size. For the implementation: concrete things, such as automated backups or an uninterruptible power supply. IASME explicitly does not want policies here.
How it is scored. Each control is marked 0 for not met, 1 for partially met or 2 for fully met. Level 0 requires every control fully met, which is why the two questions inside a control matter as much as the control itself: answer one well and one poorly and you have a partial, and a partial is a fail at this level. Level 1 and Level 2 allow partials as long as you reach 80% of the points in each objective and nothing scores zero. Level 3 returns to 100%.
A short walkthrough of scope, evidence and the certification body's role.
28 seconds · Silent explainer.
You document the proposed scope and explain how your organisation meets each control, with evidence to support the answers.
The certification body verifies and marks the submission. Certification follows a successful result.
DCC does not replace the MOD Supplier Assurance Questionnaire. DCC and the SAQ
Defence Cyber Certification Level Zero covers three controls: Cyber Essentials, UK GDPR, and resilient networks and systems.
Start with your scope: the organisation, systems, processes and people. Discuss it with your assessor.
Explain how you meet each control, with evidence for your answers. DCC does not replace the MOD Supplier Assurance Questionnaire.
The certification body reviews and marks your submission. Certification follows a successful assessment.
Dead Simple Computing. Talk to our Level Zero assessment team.
Scope is yours to set and document. If your assessor judges it inadequate, the whole assessment fails, whatever your controls look like.
You are responsible for determining the scope, documenting it accurately and being able to defend it. Your assessor can verify a scope and challenge it, but cannot set it for you. What you have to produce is a clear statement of what is in and what is out, supported by business organisation diagrams, network diagrams and lists of systems, explicitly marking which systems fall inside the Cyber Essentials scope.
The test is whether someone who has never seen your business can understand it from your documentation alone. That is where we spend most of the preparation time, because it is the cheapest place to fix a problem and the most expensive place to get one wrong.
Five steps, defined by the scheme. Level 0 runs entirely through the IASME portal.
Define the scope using the IASME Scoping Guide, then choose a certification body. You give them your organisation size, the critical environment being certified, the number of sites, how complex the organisation is, any security clearance requirements, and how prepared you are. They review the scope you propose and confirm it is appropriate.
If you are not ready, this is the moment to stop and say so. You can engage a provider for implementation support and come back for certification later. Discovering it at step four costs far more.
We enter your organisation's details into the IASME portal and select the assessment level. Alongside that, you set up file sharing so we can reach your submission files, which stay on your systems throughout, and arrange any clearances needed to review sensitive material.
Level 0 only: no conflict of interest declaration is required. That becomes mandatory from Level 1 upwards.
We run a readiness check first: that you hold the current guidance, have read it, and understand what the scheme expects, including the requirements that cause an automatic failure if missed. Then you answer the six questions in the portal, each with an explanation and evidence, and submit for marking. At Level 0 it is a portal submission rather than the Assessment Submission Record used at Levels 1 to 3.
Worth knowing: the Level 0 route cannot be used to aim at a higher level. If you may need Level 1 or above, take the Levels 1 to 3 process instead.
We review the submission and mark every question compliant, non-compliant, or more information needed. Where we ask for more, you update your answer and resubmit. Once every question is either compliant or non-compliant, we submit the result.
This is where the boundary sits. We can explain the scheme, clarify a control, describe the evidence a question needs, verify your scope and give you blank templates. We cannot implement controls for you, answer a question for you, or write documentation we will later mark. That is the scheme's rule, and it is what keeps the certificate worth holding.
On a pass, the certificate is issued automatically through the scheme's digital certification system. On a fail, no certificate is issued and the process ends; you can remediate and return, and at Level 0 there is no conflict of interest check to redo.
Where we do the preparation, that is a separate piece of work agreed separately, and it stays inside what the scheme permits a certification body to do. If what you need is someone to build the controls and write the evidence, that is implementation work: any provider can do it, and using a different one for that than for your assessment keeps the line clean.
DCC provides organisation-level evidence. The full Supplier Assurance Questionnaire remains required under current MOD guidance.
We provide Defence Cyber Certification Level 0 assessments and DCC Level 1 support, including scope reviews, gap analysis and evidence preparation. Tell us your requirement and we will agree the work and assessment route.
Your level is not a choice you make in isolation. The MOD awarding body assigns a Cyber Risk Profile to a procurement or contract, and that profile is the DCC level you need. It is identified by a Risk Assessment Reference number in the invitation to tender. You can certify higher than you are asked to, and under the current scheme you may apply at any level.
You will hear that Defence Cyber Certification removes the need to complete a Supplier Assurance Questionnaire. It does not.
The MOD's own guidance is explicit: suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and completion of the full SAQ to the required level remains mandatory. The MOD intends the two to converge, and hopes to bring DCC into the online tooling. That has not happened yet.
A DCC certificate is not a one off. Cyber Essentials sits on its own annual cycle underneath it.
The certificate is issued through the scheme's digital certification system and is valid for three years.
You confirm nothing significant has changed. Cyber Essentials recertifies on its own annual cycle.
The second annual attestation. Cyber Essentials recertifies again.
The certificate expires and you apply again. It does not roll forward automatically.
Two obligations catch people out. You commit to holding Cyber Essentials for the whole life of the DCC certificate, including any scheme updates Cyber Essentials makes in that time. And your answers, evidence and any assessment recordings stay available to your certification body and to IASME for up to three and a half years after the assessment, so they need somewhere sensible to live rather than a folder on one person's laptop.
Scheme references: IASME Defence Cyber Certification, MOD Cyber Security Model guidance and the MOD's 2026 Level 0 request. Deadline and SAQ guidance checked 12 September 2026.
Five steps. Define your scope using the IASME Scoping Guide and choose a certification body; the certification body onboards you to the IASME portal; you answer the questions with explanations and evidence and submit them; the certification body marks each question and submits the result; the certificate is issued automatically on a pass. At Level 0 the whole thing runs through the portal, with no site visit. Our guide to the Level 0 requirements covers each step in detail.
Three controls, six questions. Control 0001, Cyber Essentials: hold it for the right scope and commit to maintaining it. Control 2314, UK GDPR: documented policies and procedures for compliance with the UK Data Protection Act 2018, and Data Protection Impact Assessments against the data you hold. Control 2500, resilient networks and systems: assess how resilient your systems need to be, and show what you built to meet that. All three must be fully met.
Yes. Cyber Essentials is one of the three Level 0 controls, so it is part of the certification rather than a prerequisite you can defer. It must cover every applicable internet-connected device inside the DCC scope, and a Cyber Essentials scope that does not adequately align is an automatic failure. We are an appointed Cyber Essentials certification body, so we can certify that part too, and if you already hold it we check the scope as part of the assessment.
It depends almost entirely on how ready you are, not on the assessment. The marking itself is quick, but every question that comes back as "more information needed" adds a round trip. Organisations that already hold Cyber Essentials with a clean, documented scope and have a data protection policy and real backups tend to move through quickly. The ones that take months are usually fixing scope documentation or building evidence that did not exist. That is why the readiness conversation happens before you order.
In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026. It is a request rather than a contractual mandate, but DCC requirements are specified at tender, so check your contract conditions.
Within limits the scheme sets out. A certification body can explain the scheme, clarify what a control means, describe the evidence a question needs, verify your scope, hand you blank templates and run clarification rounds. It cannot implement controls on your behalf, answer questions for you, or write documentation it will later assess. If you need more than that, it is implementation work and you can use any provider for it. We keep preparation and assessment as separate pieces of work for exactly this reason.
Yes. We provide Level 1 support: scope reviews, gap analysis across the 101 controls and evidence preparation. The engagement confirms the formal assessment route, the appointed certification body and responsibilities before work starts. We refer Level 2 and 3 assessments to a body appointed for those levels.
No, not currently. MOD guidance states that suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
Three years, with an annual attestation at the end of years one and two confirming nothing significant has changed. At the end of year three the certificate expires and you apply again. Cyber Essentials, which Level 0 requires, recertifies annually throughout.
Defence Standard 05-138 is where the controls sit, and Issue 4 is the current version. It holds 148 controls applied across four progressively stricter levels, so what applies depends on your contract's Cyber Risk Profile. Issue 4 widened the standard's purpose from protecting MOD-identifiable information to improving a supplier's overall resilience. More in Def Stan 05-138 explained.
Usually yes. DEFCON 658 contains the obligations suppliers must place upon their subcontractors, so requirements flow down through contract conditions. If a prime sends you a questionnaire mentioning DEFCON 658, a Cyber Risk Profile or Def Stan 05-138, it applies.
Start with your organisation's size, Cyber Essentials position and target date. We will discuss the proposed scope and confirm the assessment route and written price. Preparation or remediation, where needed, is scoped separately.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.