Defence Cyber Certification Level 0
The Ministry of Defence has asked all industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026. Level 0 is three controls out of the 148 in Defence Standard 05-138: Cyber Essentials, UK GDPR, and the resilience of your systems. We are an appointed certification body for Level 0, and for the Cyber Essentials it requires.
Defence Cyber Certification and the 31 December 2026 date
If you supply the MOD, directly or through a prime, Level 0 by 31 December 2026 is the floor.
Defence Cyber Certification is the MOD's assurance scheme for its supply chain, built with IASME as the scheme's Certification Authority. It evidences compliance with the Cyber Security Model, and the controls sit in Defence Standard 05-138 Issue 4. It comes at four levels, 0 to 3, matched to your contract's Cyber Risk Profile. The Cyber Risk Profile and the DCC level are the same number.
What DCC Level 0 actually requires
Three controls, six questions. Every one has to be fully met, and each answer needs evidence and an explanation, not just a yes.
Cyber Essentials
Hold Cyber Essentials covering the scope the assessment needs, and keep it for as long as the DCC certificate lasts.
Evidence expectedYour certificate number, the Cyber Essentials self-assessment questionnaire or report, a diagram showing how the Cyber Essentials scope relates to the DCC scope, and a history or attestation of regular renewal.
UK GDPR compliance
Show how you comply with the UK Data Protection Act 2018, and that you assess the risk in the data you hold.
Evidence expectedThe policy or procedure showing how you comply, which can sit inside other documentation such as a risk register. For DPIAs: the procedure, the template or tool, or a completed assessment report.
Resilient networks and systems
Work out how resilient your systems need to be against attack and failure, then show what you actually did about it.
Evidence expectedFor the assessment: what you judged essential and the risks to it, scaled to your size. For the implementation: concrete things, such as automated backups or an uninterruptible power supply. IASME explicitly does not want policies here.
How it is scored. Each control is marked 0 for not met, 1 for partially met or 2 for fully met. Level 0 requires every control fully met, which is why the two questions inside a control matter as much as the control itself: answer one well and one poorly and you have a partial, and a partial is a fail at this level. Level 1 and Level 2 allow partials as long as you reach 80% of the points in each objective and nothing scores zero. Level 3 returns to 100%.
Scope decides the outcome before anyone marks an answer
Scope is yours to set and document. If your assessor judges it inadequate, the whole assessment fails, whatever your controls look like.
- Laptops, desktops and thin clients
- Mobiles and tablets
- Servers and virtual servers
- Cloud services: IaaS, PaaS, SaaS
- Firewalls and routers
- OT, ICS and SCADA
- Air gapped networks
- Isolated test and build rigs
- Standalone CAD workstations
You are responsible for determining the scope, documenting it accurately and being able to defend it. Your assessor can verify a scope and challenge it, but cannot set it for you. What you have to produce is a clear statement of what is in and what is out, supported by business organisation diagrams, network diagrams and lists of systems, explicitly marking which systems fall inside the Cyber Essentials scope.
The test is whether someone who has never seen your business can understand it from your documentation alone. That is where we spend most of the preparation time, because it is the cheapest place to fix a problem and the most expensive place to get one wrong.
How to get DCC Level 0, step by step
Five steps, defined by the scheme. Level 0 runs entirely through the IASME portal.
Assessment preparation
YouDefine the scope using the IASME Scoping Guide, then choose a certification body. You give them your organisation size, the critical environment being certified, the number of sites, how complex the organisation is, any security clearance requirements, and how prepared you are. They review the scope you propose and confirm it is appropriate.
If you are not ready, this is the moment to stop and say so. You can engage a provider for implementation support and come back for certification later. Discovering it at step four costs far more.
Onboarding
UsWe enter your organisation's details into the IASME portal and select the assessment level. Alongside that, you set up file sharing so we can reach your submission files, which stay on your systems throughout, and arrange any clearances needed to review sensitive material.
Level 0 only: no conflict of interest declaration is required. That becomes mandatory from Level 1 upwards.
Submission preparation
YouWe run a readiness check first: that you hold the current guidance, have read it, and understand what the scheme expects, including the requirements that cause an automatic failure if missed. Then you answer the six questions in the portal, each with an explanation and evidence, and submit for marking. At Level 0 it is a portal submission rather than the Assessment Submission Record used at Levels 1 to 3.
Worth knowing: the Level 0 route cannot be used to aim at a higher level. If you may need Level 1 or above, take the Levels 1 to 3 process instead.
Assessment
UsWe review the submission and mark every question compliant, non-compliant, or more information needed. Where we ask for more, you update your answer and resubmit. Once every question is either compliant or non-compliant, we submit the result.
This is where the boundary sits. We can explain the scheme, clarify a control, describe the evidence a question needs, verify your scope and give you blank templates. We cannot implement controls for you, answer a question for you, or write documentation we will later mark. That is the scheme's rule, and it is what keeps the certificate worth holding.
Certification
UsOn a pass, the certificate is issued automatically through the scheme's digital certification system. On a fail, no certificate is issued and the process ends; you can remediate and return, and at Level 0 there is no conflict of interest check to redo.
Where we do the preparation, that is a separate piece of work agreed separately, and it stays inside what the scheme permits a certification body to do. If what you need is someone to build the controls and write the evidence, that is implementation work: any provider can do it, and using a different one for that than for your assessment keeps the line clean.
Which levels we certify, and which we do not.
Certifying at a level removes the need for contract-by-contract assessment at that level and below.
Current scope: We provide Defence Cyber Certification Level 0 assessments. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Contact us if you would like to be notified when Level 1 becomes available, or see DCC Level 1 readiness for the preparation work we do today.
Your level is not a choice you make in isolation. The MOD awarding body assigns a Cyber Risk Profile to a procurement or contract, and that profile is the DCC level you need. It is identified by a Risk Assessment Reference number in the invitation to tender. You can certify higher than you are asked to, and under the current scheme you may apply at any level.
DCC does not replace your Supplier Assurance Questionnaire.
You will hear that Defence Cyber Certification removes the need to complete a Supplier Assurance Questionnaire. It does not.
The MOD's own guidance is explicit: suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and completion of the full SAQ to the required level remains mandatory. The MOD intends the two to converge, and hopes to bring DCC into the online tooling. That has not happened yet.
DCC Level 0 prices
Most suppliers arriving here already hold Cyber Essentials, so that route is priced on its own. If you need both, we are the certification body for both.
You already hold Cyber Essentials
The DCC Level 0 assessment and the IASME certification fee. We check that your Cyber Essentials scope aligns with the DCC scope as part of the assessment, at no extra cost.
All prices + VAT. If your Cyber Essentials scope turns out not to cover what DCC needs, we will tell you before you order, not after.
You need Cyber Essentials as well
The same assessment, plus Cyber Essentials certification. One company, one order, no separate Cyber Essentials invoice and no IASME fee added at the end.
All prices + VAT. The difference between the two columns is the IASME Cyber Essentials fee for your band, from £320 to £600, plus our work on the certification.
What is not in the price. Remediation, and preparation work beyond what a certification body is allowed to do inside an assessment, are quoted separately. You decide whether we do that or you do, or whether another provider does. You get the findings either way.
The three year picture. A DCC certificate lasts three years with an annual attestation, and Cyber Essentials recertifies annually, so the running cost is the annual Cyber Essentials recertification plus the attestation. We set that out in writing before you commit, and we confirm the current IASME fee at the time you order, because scheme fees change.
Large organisations are quoted in writing before we start, because at 250 people and above the number of sites and the complexity of the estate move the figure more than headcount does.
Three years, with two attestations in between
A DCC certificate is not a one off. Cyber Essentials sits on its own annual cycle underneath it.
Certified
The certificate is issued through the scheme's digital certification system and is valid for three years.
Attestation
You confirm nothing significant has changed. Cyber Essentials recertifies on its own annual cycle.
Attestation
The second annual attestation. Cyber Essentials recertifies again.
Reapply
The certificate expires and you apply again. It does not roll forward automatically.
Two obligations catch people out. You commit to holding Cyber Essentials for the whole life of the DCC certificate, including any scheme updates Cyber Essentials makes in that time. And your answers, evidence and any assessment recordings stay available to your certification body and to IASME for up to three and a half years after the assessment, so they need somewhere sensible to live rather than a folder on one person's laptop.
Common questions
How do I get DCC certified?
Five steps. Define your scope using the IASME Scoping Guide and choose a certification body; the certification body onboards you to the IASME portal; you answer the questions with explanations and evidence and submit them; the certification body marks each question and submits the result; the certificate is issued automatically on a pass. At Level 0 the whole thing runs through the portal, with no site visit. Our guide to the Level 0 requirements covers each step in detail.
What does DCC Level 0 require?
Three controls, six questions. Control 0001, Cyber Essentials: hold it for the right scope and commit to maintaining it. Control 2314, UK GDPR: documented policies and procedures for compliance with the UK Data Protection Act 2018, and Data Protection Impact Assessments against the data you hold. Control 2500, resilient networks and systems: assess how resilient your systems need to be, and show what you built to meet that. All three must be fully met.
Do we need Cyber Essentials before DCC Level 0?
Yes. Cyber Essentials is one of the three Level 0 controls, so it is part of the certification rather than a prerequisite you can defer. It must cover every applicable internet-connected device inside the DCC scope, and a Cyber Essentials scope that does not adequately align is an automatic failure. We are an appointed Cyber Essentials certification body, so we can certify that part too, and if you already hold it we check the scope as part of the assessment.
How long does DCC Level 0 take?
It depends almost entirely on how ready you are, not on the assessment. The marking itself is quick, but every question that comes back as "more information needed" adds a round trip. Organisations that already hold Cyber Essentials with a clean, documented scope and have a data protection policy and real backups tend to move through quickly. The ones that take months are usually fixing scope documentation or building evidence that did not exist. That is why the readiness conversation happens before you order.
What is the deadline for DCC Level 0?
In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026. It is a request rather than a contractual mandate, but DCC requirements are specified at tender, so check your contract conditions.
Can our certification body help us pass?
Within limits the scheme sets out. A certification body can explain the scheme, clarify what a control means, describe the evidence a question needs, verify your scope, hand you blank templates and run clarification rounds. It cannot implement controls on your behalf, answer questions for you, or write documentation it will later assess. If you need more than that, it is implementation work and you can use any provider for it. We keep preparation and assessment as separate pieces of work for exactly this reason.
Can you assess Level 1?
Not yet. Our current certification-body scope is Level 0. We are working towards Level 1 capability in Q4 2026, subject to completing the required training and formal authorisation. We do not assess Levels 2 or 3 at all: for those we will prepare you, certify the Cyber Essentials Plus they require, and point you to a certification body that does the assessment. Level 1 is 101 controls against Level 0's three, so the readiness work starts well before the assessment does.
Does DCC replace the Supplier Assurance Questionnaire?
No, not currently. MOD guidance states that suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
How long does DCC certification last?
Three years, with an annual attestation at the end of years one and two confirming nothing significant has changed. At the end of year three the certificate expires and you apply again. Cyber Essentials, which Level 0 requires, recertifies annually throughout.
What is Def Stan 05-138?
Defence Standard 05-138 is where the controls sit, and Issue 4 is the current version. It holds 148 controls applied across four progressively stricter levels, so what applies depends on your contract's Cyber Risk Profile. Issue 4 widened the standard's purpose from protecting MOD-identifiable information to improving a supplier's overall resilience. More in Def Stan 05-138 explained.
We are a subcontractor, not a prime. Does this apply to us?
Usually yes. DEFCON 658 contains the obligations suppliers must place upon their subcontractors, so requirements flow down through contract conditions. If a prime sends you a questionnaire mentioning DEFCON 658, a Cyber Risk Profile or Def Stan 05-138, it applies.
Start your DCC Level 0
Tell us who you supply, whether you hold Cyber Essentials, and what your scope looks like. We will tell you which of the three controls you already meet, what is missing, and what it costs. You speak to an engineer and an assessor, and if you are not ready we will say so before you order.



