Defence Cyber Certification Level 1

Level 1 is 101 controls. Level 0 is three. It is not the same exercise made longer: you write an Assessment Submission Record instead of filling in a portal, you are marked twice, and you demonstrate your controls live. We do the readiness work that gets you through it, and we are straight about which part we cannot do ourselves yet.

Appointed
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber EssentialsCertification body NCSC AssuredCyber Advisor CISSPHeld by Daniel McClure Fisher
Level 1 / 01 · Where we stand

What we do at Level 1, and what we do not

Said up front, because it decides whether the rest of this page is useful to you.

Current scope: our certification-body appointment covers DCC Level 0 and Cyber Essentials. We do not assess or certify Level 1 today. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Until that authorisation exists, we do the readiness work and refer the assessment to a certification body appointed for Level 1.

This split is not a limitation we are working around. The scheme separates preparation from assessment on purpose: a certification body cannot mark documentation it wrote itself. So for most suppliers, using one organisation to get ready and another to assess is the cleaner arrangement anyway, and at Level 1 it is the one we can offer honestly.

01Readiness and preparation: yes. Gap analysis against all 101 controls, evidence built and documented, the Assessment Submission Record drafted with you, a dry run before you submit.
02Cyber Essentials: yes. Control 0001 applies at every level. We are an appointed certification body for it, and for Cyber Essentials Plus if you are heading for Level 2.
03The Level 1 assessment: not yet. We refer it. We will tell you who to, and we hand over a submission that is ready rather than a pile of documents.
04Declare us either way. From Level 1 upwards a conflict of interest statement is mandatory. Work we did for you goes in it. That is normal, and expected.
Level 1 / 02 · The controls

101 controls, and where they actually sit

Def Stan 05-138 Issue 4 holds 148 controls across four objectives. Level 1 uses 101 of them, and they are not spread evenly.

1Cyber EssentialsControl 0001, the same one Level 0 uses. Hold Cyber Essentials for the right scope and commit to maintaining it.
12Objective AManaging security risk. Governance, risk management, asset management, supplier management, physical security. The governance controls start here: Level 0 has none of them.
75Objective BProtecting against cyber attack. Planning for resilience, identity and access, data security, system security, network resilience, awareness and culture, staff and environment. Three quarters of Level 1 is here.
9Objective CDetecting cyber security events. Security monitoring and proactive detection. This is where suppliers without a detection and response capability find a hard floor.
4Objective DMinimising the impact of incidents. Incident response, recovery and lessons learned.

The objectives are the NCSC Cyber Assessment Framework's, which is why work you have already done on CAF alignment is not wasted here. If you have run a CAF self-assessment, you have a usable head start on Objectives C and D in particular.

Two things follow from the shape of that table. Objective C is the one that catches people: nine controls sounds small, but monitoring and detection cannot be written into existence the week before an assessment, and there is no partial credit route around a control scoring zero. And Objective A is where a small engineering firm usually has the least documentation, because governance artefacts are the ones nobody needed until a prime asked.

Level 1 / 03 · The step up

What changes when you leave Level 0 behind

The control count is the least of it. The process itself is different.

01The submissionLevel 0 is a portal form. Level 1 is an Assessment Submission Record: a document you own, holding every answer, its context and its evidence. The Level 0 portal route cannot be used to reach a higher level.
02Marked twiceTheoretical scoring reviews your answers and evidence. Practical scoring then tests whether it is true. Level 0 has only the first.
03Show me, do not tell mePractical scoring includes a remote demonstration of your controls over teleconference, and an in-person site visit where scoping identified one.
04Clarification roundsYou and your assessor agree in advance how many rounds of clarification the engagement includes. Run out and remaining controls can be marked not met.
05Conflict of interestMandatory from Level 1 up, signed by both parties early. Any previous work your certification body did for you, including Cyber Essentials, is declared. Failing to declare can fail the whole assessment.
06Hashing and retentionAnswers and evidence are compressed into one file and hashed, so the submission can be verified later. It stays reachable for up to three and a half years.
07RecordingsYour assessor can require video calls and screen shares to be recorded on your systems, and you have to comply.
Level 1 / 04 · Scoring

Two conditions, and the second one is the trap

Every control is scored 0 if it is not met, 1 if it is partially met, and 2 if it is fully met. To pass Level 1 you must satisfy both of these, per objective:

  • At least 80% of the total points available in that objective, and
  • Every control in that objective at least partially met, so nothing scores zero.

Take an objective with 10 controls. The maximum is 20 points, so you need 16. Ten controls fully met gets you 20. Nine full and one partial gets 19. Six full and four partial gets exactly 16, and passes. Five full and five partial gets 15, and fails on the threshold.

Now the part that catches people. Seven full, two partial and one not met also reaches 16 points, and still fails, because a control scored zero fails the objective outright however good the arithmetic looks. One neglected control sinks an objective that was otherwise comfortably clear.

This is the difference between Level 1 and Level 0, where 100% of controls must be fully met and there is no partial credit at all. Level 1 gives you room to be imperfect, but no room to have a gap.

Level 1 / 05 · What we do

The readiness work, in the order we do it

Scoped from where you actually are. Most suppliers arriving here hold Cyber Essentials and Level 0 already.

01

Scope, and the diagrams that prove it

The boundary, the business organisation and network diagrams, the system lists, and which systems sit inside Cyber Essentials. An inadequate scope fails an assessment on its own, before a single control is marked.

02

Gap analysis across all 101

Control by control, scored the way an assessor would: not met, partial, or full. You get the register, and it is yours whatever you do next. The zeros get triaged first, because those are the ones that fail an objective.

03

Close the gaps

Governance artefacts written, monitoring and detection stood up, response and recovery tested rather than documented. We can do this work, or your own team can, or another provider can. You get the list either way.

04

Build the submission, then rehearse it

The Assessment Submission Record assembled with evidence referenced to the exact section that supports each answer, then a dry run of the practical demonstration, so the first time you are asked to show a control is not in front of your assessor.

Readiness work is quoted after a scoping conversation, not from a price list, because the distance between a supplier who holds Level 0 with good documentation and one starting from a spreadsheet is measured in months rather than percentages. What we will do on that first call is tell you roughly where you sit and whether Level 1 is realistic for the deadline you have in mind. That call is free and we do not need you to prepare anything for it.

If it turns out you need Level 0 rather than Level 1, we will say so. Certifying at a level removes the need for contract-by-contract assessment at that level and below, so there is an argument for going higher than your current contract demands, but it is an argument, not a default.

FAQ

Common questions

Can you certify DCC Level 1?

No, not today. Our certification-body appointment covers DCC Level 0 and Cyber Essentials. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Until then we do the readiness and preparation work and refer the assessment to a certification body appointed for Level 1.

How many controls are in DCC Level 1?

101. One is Cyber Essentials, 12 are in Objective A (managing security risk), 75 in Objective B (protecting against cyber attack), nine in Objective C (detecting cyber security events) and four in Objective D (minimising the impact of incidents). Def Stan 05-138 Issue 4 holds 148 controls in total, and no single level uses all of them.

What is the pass mark for DCC Level 1?

Two conditions, both required, assessed per objective: at least 80% of the points available in that objective, and no control scoring zero. Controls are marked 0 for not met, 1 for partially met and 2 for fully met. Reaching 80% does not save you if a single control is not met at all, which is the rule most people miss.

How is Level 1 different from Level 0?

Level 0 is three controls, marked once, through a portal, at 100% with no partial credit. Level 1 is 101 controls in an Assessment Submission Record, marked twice through theoretical then practical scoring, including a live demonstration of your controls and possibly a site visit, at 80% per objective with nothing at zero. Level 1 also requires a conflict of interest declaration and the hashing of your submission. The Level 0 portal route cannot be used to reach Level 1.

Do we need Level 0 before Level 1?

No. You can apply at any level under the current scheme, and Level 1 contains Level 0's controls anyway. But the Level 0 portal route specifically cannot be used to aim at a higher level, so if you know you need Level 1, start on the Levels 1 to 3 process rather than certifying Level 0 and expecting to upgrade it.

Does Level 1 need Cyber Essentials Plus?

No. Control 0002, Cyber Essentials Plus, applies at Levels 2 and 3. Level 1 needs basic Cyber Essentials under control 0001, covering the right scope and maintained for the life of the certificate. We are an appointed certification body for both, so if you are heading to Level 2 later it is worth scoping that now.

Will there be a site visit?

Possibly. Practical scoring always includes a remote demonstration of your controls over teleconference. An in-person site visit happens where one was identified during scoping. Either way you should raise site inductions, staff availability and clearance requirements early, because an assessor who runs out of time marks the remaining controls as not met.

If you help us prepare, can you still assess us later?

Not for work we would then be marking. The scheme is explicit: a certification body cannot complete documentation or prepare answers or evidence that it will later assess. Helping you achieve Cyber Essentials is permitted and is declared in the conflict of interest statement. Since we refer Level 1 assessments today, the question does not currently arise, and if our own Level 1 authorisation arrives we will keep preparation and assessment on separate engagements.

Find out where you actually stand.

A readiness review scores you against all 101 controls the way an assessor would, and tells you which ones are at zero. You get the register whatever you do next, and if Level 1 is not realistic for your deadline we will tell you that on the first call.

Reading, Berkshire  /  Readiness and preparation. Level 1 assessment referred.  /  reply within one working day