Defence Cyber
Certification Level 0

Assessment by an appointed certification body, with the IASME certification fee included.

The Ministry of Defence has asked industry partners to achieve DCC Level 0 by 31 December 2026.

See all price bands and inclusions
Defence Cyber Certification body, Level 0
Appointed to assess DCC Level 0.

Preparation and formal assessment have separate responsibilities.

Our assessment scope
Appointed
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body NCSC AssuredCyber Advisor scheme CISSPHeld by Daniel McClure Fisher

DCC Level 0 prices

Choose the route that matches your current Cyber Essentials position. If you need both certifications, we are the certification body for both.

You already hold Cyber Essentials

The DCC Level 0 assessment and the IASME certification fee. We check that your Cyber Essentials scope aligns with the DCC scope as part of the assessment, at no extra cost.

1–9Micro£499
10–49Small£799
50–249Medium£1,499
250+LargeFrom £2,399

All prices + VAT. If your Cyber Essentials scope turns out not to cover what DCC needs, we will tell you before you order, not after.

Discuss DCC with existing Cyber Essentials

You need Cyber Essentials as well

The same assessment, plus Cyber Essentials certification. One company, one order, no separate Cyber Essentials invoice and no IASME fee added at the end.

1–9Micro£799
10–49Small£1,199
50–249Medium£1,999
250+LargeFrom £2,999

All prices + VAT. This route includes Cyber Essentials certification and the applicable scheme fees. We confirm the scope and written price before you order.

Discuss DCC and Cyber Essentials

What is not in the price. Remediation, and preparation work beyond what a certification body is allowed to do inside an assessment, are quoted separately. You decide whether we do that or you do, or whether another provider does. You get the findings either way.

The three year picture. A DCC certificate lasts three years with an annual attestation, and Cyber Essentials recertifies annually, so the running cost is the annual Cyber Essentials recertification plus the attestation. We set that out in writing before you commit, and we confirm the current IASME fee at the time you order, because scheme fees change.

Large organisations are quoted in writing before we start, because at 250 people and above the number of sites and the complexity of the estate move the figure more than headcount does.

What your assessment includes

You prepare the answers and evidence. We review and mark the submission against the scheme requirements.

  • Review of the proposed DCC scope and its alignment with Cyber Essentials.
  • Organisation setup in the IASME assessment portal.
  • Review of your answers and evidence, with clarification requests where needed.
  • The marked result and scheme certification on a successful assessment.

Preparation beyond the certification body's permitted role and technical remediation are quoted separately. Annual attestation and Cyber Essentials renewal costs are confirmed before you commit.

What happens next

  1. Tell us the basics. Your organisation's size, whether you hold Cyber Essentials and your target date, if known.
  2. Confirm scope and price. We discuss the proposed environment, readiness and applicable assessment route before you order.
  3. Prepare your submission. Once the assessment is agreed, we arrange portal onboarding and explain the evidence and process.
Discuss your Level 0 assessment

Reply within one working day. Your first enquiry can be brief.

Where should you start?

A few practical questions to help you prepare for a conversation with an assessor. Your answers stay on this page.

Defence Cyber Certification and the 31 December 2026 date

The MOD has asked industry partners to reach Level 0 by 31 December 2026. Your contract or prime determines the level your work requires.

Defence Cyber Certification is the MOD's assurance scheme for its supply chain, built with IASME as the scheme's Certification Authority. It evidences compliance with the Cyber Security Model, and the controls sit in Defence Standard 05-138 Issue 4. It comes at four levels, 0 to 3, matched to your contract's Cyber Risk Profile. The Cyber Risk Profile and the DCC level are the same number.

Three controls, not 148. Def Stan 05-138 Issue 4 holds 148 controls. Level 0 uses three of them, and no level uses all of them.
Cyber Essentials is one of the three. You need it, covering the right scope, and you commit to keeping it for as long as the DCC certificate lasts.
There is no partial credit. Level 0 passes only when 100% of the controls are fully met. The higher levels allow partial compliance; Level 0 does not.
No site visit, no demonstration. Level 0 is a portal submission that your certification body marks. The practical scoring and site visits start at Level 1.

What DCC Level 0 actually requires

Three controls, six questions. Every one has to be fully met, and each answer needs evidence and an explanation, not just a yes.

Control 0001

Cyber Essentials

Hold Cyber Essentials covering the scope the assessment needs, and keep it for as long as the DCC certificate lasts.

0001.1Does the organisation hold Cyber Essentials certification that covers the required scope for this activity?
0001.2Does the organisation commit to maintaining Cyber Essentials for the duration of the DCC certification?

Evidence expectedYour certificate number, the Cyber Essentials self-assessment questionnaire or report, a diagram showing how the Cyber Essentials scope relates to the DCC scope, and a history or attestation of regular renewal.

Control 2314

UK GDPR compliance

Show how you comply with the UK Data Protection Act 2018, and that you assess the risk in the data you hold.

2314.1Does the organisation have documented policies and procedures ensuring compliance with obligations under the UK GDPR?
2314.2Does the organisation conduct Data Protection Impact Assessments against the data types it stores or processes?

Evidence expectedThe policy or procedure showing how you comply, which can sit inside other documentation such as a risk register. For DPIAs: the procedure, the template or tool, or a completed assessment report.

Control 2500

Resilient networks and systems

Work out how resilient your systems need to be against attack and failure, then show what you actually did about it.

2500.1Has the organisation assessed the degree to which its systems must be resilient to cyber attack and system failure?
2500.2Has the organisation built resilience into its systems to meet its resilience needs?

Evidence expectedFor the assessment: what you judged essential and the risks to it, scaled to your size. For the implementation: concrete things, such as automated backups or an uninterruptible power supply. IASME explicitly does not want policies here.

How it is scored. Each control is marked 0 for not met, 1 for partially met or 2 for fully met. Level 0 requires every control fully met, which is why the two questions inside a control matter as much as the control itself: answer one well and one poorly and you have a partial, and a partial is a fail at this level. Level 1 and Level 2 allow partials as long as you reach 80% of the points in each objective and nothing scores zero. Level 3 returns to 100%.

From three controls to an assessed submission.

A short walkthrough of scope, evidence and the certification body's role.

28 seconds · Silent explainer.

Your submission.
A separate assessment.

You document the proposed scope and explain how your organisation meets each control, with evidence to support the answers.

The certification body verifies and marks the submission. Certification follows a successful result.

DCC does not replace the MOD Supplier Assurance Questionnaire. DCC and the SAQ

Read the service explanation

Defence Cyber Certification Level Zero covers three controls: Cyber Essentials, UK GDPR, and resilient networks and systems.

Start with your scope: the organisation, systems, processes and people. Discuss it with your assessor.

Explain how you meet each control, with evidence for your answers. DCC does not replace the MOD Supplier Assurance Questionnaire.

The certification body reviews and marks your submission. Certification follows a successful assessment.

Dead Simple Computing. Talk to our Level Zero assessment team.

Scope decides the outcome before anyone marks an answer

Scope is yours to set and document. If your assessor judges it inadequate, the whole assessment fails, whatever your controls look like.

DCC scope Everything supporting your business-critical functions
Cyber Essentials scope Internet connected only
  • Laptops, desktops and thin clients
  • Mobiles and tablets
  • Servers and virtual servers
  • Cloud services: IaaS, PaaS, SaaS
  • Firewalls and routers
In DCC, outside CE Not internet connected
  • OT, ICS and SCADA
  • Air gapped networks
  • Isolated test and build rigs
  • Standalone CAD workstations
Your Cyber Essentials certificate has to cover every applicable internet connected device inside the DCC scope. A small organisation may align the two exactly; most do not, because DCC includes assets Cyber Essentials rules exclude. That is expected, and you explain the difference in your answer. A Cyber Essentials scope that does not adequately align is an automatic failure, and IASME asks every applicant, whatever its size, to supply a diagram like this one.

You are responsible for determining the scope, documenting it accurately and being able to defend it. Your assessor can verify a scope and challenge it, but cannot set it for you. What you have to produce is a clear statement of what is in and what is out, supported by business organisation diagrams, network diagrams and lists of systems, explicitly marking which systems fall inside the Cyber Essentials scope.

The test is whether someone who has never seen your business can understand it from your documentation alone. That is where we spend most of the preparation time, because it is the cheapest place to fix a problem and the most expensive place to get one wrong.

How to get DCC Level 0, step by step

Five steps, defined by the scheme. Level 0 runs entirely through the IASME portal.

1

Assessment preparation

You

Define the scope using the IASME Scoping Guide, then choose a certification body. You give them your organisation size, the critical environment being certified, the number of sites, how complex the organisation is, any security clearance requirements, and how prepared you are. They review the scope you propose and confirm it is appropriate.

If you are not ready, this is the moment to stop and say so. You can engage a provider for implementation support and come back for certification later. Discovering it at step four costs far more.

2

Onboarding

Us

We enter your organisation's details into the IASME portal and select the assessment level. Alongside that, you set up file sharing so we can reach your submission files, which stay on your systems throughout, and arrange any clearances needed to review sensitive material.

Level 0 only: no conflict of interest declaration is required. That becomes mandatory from Level 1 upwards.

3

Submission preparation

You

We run a readiness check first: that you hold the current guidance, have read it, and understand what the scheme expects, including the requirements that cause an automatic failure if missed. Then you answer the six questions in the portal, each with an explanation and evidence, and submit for marking. At Level 0 it is a portal submission rather than the Assessment Submission Record used at Levels 1 to 3.

Worth knowing: the Level 0 route cannot be used to aim at a higher level. If you may need Level 1 or above, take the Levels 1 to 3 process instead.

4

Assessment

Us

We review the submission and mark every question compliant, non-compliant, or more information needed. Where we ask for more, you update your answer and resubmit. Once every question is either compliant or non-compliant, we submit the result.

This is where the boundary sits. We can explain the scheme, clarify a control, describe the evidence a question needs, verify your scope and give you blank templates. We cannot implement controls for you, answer a question for you, or write documentation we will later mark. That is the scheme's rule, and it is what keeps the certificate worth holding.

5

Certification

Us

On a pass, the certificate is issued automatically through the scheme's digital certification system. On a fail, no certificate is issued and the process ends; you can remediate and return, and at Level 0 there is no conflict of interest check to redo.

Where we do the preparation, that is a separate piece of work agreed separately, and it stays inside what the scheme permits a certification body to do. If what you need is someone to build the controls and write the evidence, that is implementation work: any provider can do it, and using a different one for that than for your assessment keeps the line clean.

DCC levels and assessment routes.

DCC provides organisation-level evidence. The full Supplier Assurance Questionnaire remains required under current MOD guidance.

We provide Defence Cyber Certification Level 0 assessments and DCC Level 1 support, including scope reviews, gap analysis and evidence preparation. Tell us your requirement and we will agree the work and assessment route.

03 controlsWe assess and certify Level 0. The supply chain floor, for a very low assessed cyber risk. Requires Cyber Essentials, which we also certify. Pass mark 100%.
1101 controlsLow to moderate risk: a comprehensive programme with good practices. Scope reviews, gap analysis and evidence preparation are available. The formal assessment route is agreed in the engagement. Pass mark 80% per objective, nothing at zero.
2139 controlsHigh risk: advanced oversight and planning. We do not assess Level 2. It requires Cyber Essentials Plus, which we can certify; we refer the DCC assessment.
3144 controlsSubstantial risk: expert capability, defence in depth. Assessed as a Level 2 and 3 hybrid of 145 controls, the only route to Level 3, at 100%. Same position as Level 2.

Your level is not a choice you make in isolation. The MOD awarding body assigns a Cyber Risk Profile to a procurement or contract, and that profile is the DCC level you need. It is identified by a Risk Assessment Reference number in the invitation to tender. You can certify higher than you are asked to, and under the current scheme you may apply at any level.

DCC does not replace your Supplier Assurance Questionnaire.

You will hear that Defence Cyber Certification removes the need to complete a Supplier Assurance Questionnaire. It does not.

The MOD's own guidance is explicit: suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and completion of the full SAQ to the required level remains mandatory. The MOD intends the two to converge, and hopes to bring DCC into the online tooling. That has not happened yet.

Three years, with two attestations in between

A DCC certificate is not a one off. Cyber Essentials sits on its own annual cycle underneath it.

Year 0

Certified

The certificate is issued through the scheme's digital certification system and is valid for three years.

End of year 1

Attestation

You confirm nothing significant has changed. Cyber Essentials recertifies on its own annual cycle.

End of year 2

Attestation

The second annual attestation. Cyber Essentials recertifies again.

End of year 3

Reapply

The certificate expires and you apply again. It does not roll forward automatically.

Two obligations catch people out. You commit to holding Cyber Essentials for the whole life of the DCC certificate, including any scheme updates Cyber Essentials makes in that time. And your answers, evidence and any assessment recordings stay available to your certification body and to IASME for up to three and a half years after the assessment, so they need somewhere sensible to live rather than a folder on one person's laptop.

Scheme references: IASME Defence Cyber Certification, MOD Cyber Security Model guidance and the MOD's 2026 Level 0 request. Deadline and SAQ guidance checked 12 September 2026.

Common questions

How do I get DCC certified?

Five steps. Define your scope using the IASME Scoping Guide and choose a certification body; the certification body onboards you to the IASME portal; you answer the questions with explanations and evidence and submit them; the certification body marks each question and submits the result; the certificate is issued automatically on a pass. At Level 0 the whole thing runs through the portal, with no site visit. Our guide to the Level 0 requirements covers each step in detail.

What does DCC Level 0 require?

Three controls, six questions. Control 0001, Cyber Essentials: hold it for the right scope and commit to maintaining it. Control 2314, UK GDPR: documented policies and procedures for compliance with the UK Data Protection Act 2018, and Data Protection Impact Assessments against the data you hold. Control 2500, resilient networks and systems: assess how resilient your systems need to be, and show what you built to meet that. All three must be fully met.

Do we need Cyber Essentials before DCC Level 0?

Yes. Cyber Essentials is one of the three Level 0 controls, so it is part of the certification rather than a prerequisite you can defer. It must cover every applicable internet-connected device inside the DCC scope, and a Cyber Essentials scope that does not adequately align is an automatic failure. We are an appointed Cyber Essentials certification body, so we can certify that part too, and if you already hold it we check the scope as part of the assessment.

How long does DCC Level 0 take?

It depends almost entirely on how ready you are, not on the assessment. The marking itself is quick, but every question that comes back as "more information needed" adds a round trip. Organisations that already hold Cyber Essentials with a clean, documented scope and have a data protection policy and real backups tend to move through quickly. The ones that take months are usually fixing scope documentation or building evidence that did not exist. That is why the readiness conversation happens before you order.

What is the deadline for DCC Level 0?

In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026. It is a request rather than a contractual mandate, but DCC requirements are specified at tender, so check your contract conditions.

Can our certification body help us pass?

Within limits the scheme sets out. A certification body can explain the scheme, clarify what a control means, describe the evidence a question needs, verify your scope, hand you blank templates and run clarification rounds. It cannot implement controls on your behalf, answer questions for you, or write documentation it will later assess. If you need more than that, it is implementation work and you can use any provider for it. We keep preparation and assessment as separate pieces of work for exactly this reason.

Can you help with DCC Level 1?

Yes. We provide Level 1 support: scope reviews, gap analysis across the 101 controls and evidence preparation. The engagement confirms the formal assessment route, the appointed certification body and responsibilities before work starts. We refer Level 2 and 3 assessments to a body appointed for those levels.

Does DCC replace the Supplier Assurance Questionnaire?

No, not currently. MOD guidance states that suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.

How long does DCC certification last?

Three years, with an annual attestation at the end of years one and two confirming nothing significant has changed. At the end of year three the certificate expires and you apply again. Cyber Essentials, which Level 0 requires, recertifies annually throughout.

What is Def Stan 05-138?

Defence Standard 05-138 is where the controls sit, and Issue 4 is the current version. It holds 148 controls applied across four progressively stricter levels, so what applies depends on your contract's Cyber Risk Profile. Issue 4 widened the standard's purpose from protecting MOD-identifiable information to improving a supplier's overall resilience. More in Def Stan 05-138 explained.

We are a subcontractor, not a prime. Does this apply to us?

Usually yes. DEFCON 658 contains the obligations suppliers must place upon their subcontractors, so requirements flow down through contract conditions. If a prime sends you a questionnaire mentioning DEFCON 658, a Cyber Risk Profile or Def Stan 05-138, it applies.

Start your DCC Level 0

Start with your organisation's size, Cyber Essentials position and target date. We will discuss the proposed scope and confirm the assessment route and written price. Preparation or remediation, where needed, is scoped separately.

Reading, Berkshire  /  Defence Cyber Certification body for Level 0  /  reply within one working day