Defence Cyber Certification Level 1
Level 1 is 101 controls. Level 0 is three. It is not the same exercise made longer: you write an Assessment Submission Record instead of filling in a portal, you are marked twice, and you demonstrate your controls live. We do the readiness work that gets you through it, and we are straight about which part we cannot do ourselves yet.
What we do at Level 1, and what we do not
Said up front, because it decides whether the rest of this page is useful to you.
Current scope: our certification-body appointment covers DCC Level 0 and Cyber Essentials. We do not assess or certify Level 1 today. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Until that authorisation exists, we do the readiness work and refer the assessment to a certification body appointed for Level 1.
This split is not a limitation we are working around. The scheme separates preparation from assessment on purpose: a certification body cannot mark documentation it wrote itself. So for most suppliers, using one organisation to get ready and another to assess is the cleaner arrangement anyway, and at Level 1 it is the one we can offer honestly.
101 controls, and where they actually sit
Def Stan 05-138 Issue 4 holds 148 controls across four objectives. Level 1 uses 101 of them, and they are not spread evenly.
The objectives are the NCSC Cyber Assessment Framework's, which is why work you have already done on CAF alignment is not wasted here. If you have run a CAF self-assessment, you have a usable head start on Objectives C and D in particular.
Two things follow from the shape of that table. Objective C is the one that catches people: nine controls sounds small, but monitoring and detection cannot be written into existence the week before an assessment, and there is no partial credit route around a control scoring zero. And Objective A is where a small engineering firm usually has the least documentation, because governance artefacts are the ones nobody needed until a prime asked.
What changes when you leave Level 0 behind
The control count is the least of it. The process itself is different.
Two conditions, and the second one is the trap
Every control is scored 0 if it is not met, 1 if it is partially met, and 2 if it is fully met. To pass Level 1 you must satisfy both of these, per objective:
- At least 80% of the total points available in that objective, and
- Every control in that objective at least partially met, so nothing scores zero.
Take an objective with 10 controls. The maximum is 20 points, so you need 16. Ten controls fully met gets you 20. Nine full and one partial gets 19. Six full and four partial gets exactly 16, and passes. Five full and five partial gets 15, and fails on the threshold.
Now the part that catches people. Seven full, two partial and one not met also reaches 16 points, and still fails, because a control scored zero fails the objective outright however good the arithmetic looks. One neglected control sinks an objective that was otherwise comfortably clear.
This is the difference between Level 1 and Level 0, where 100% of controls must be fully met and there is no partial credit at all. Level 1 gives you room to be imperfect, but no room to have a gap.
The readiness work, in the order we do it
Scoped from where you actually are. Most suppliers arriving here hold Cyber Essentials and Level 0 already.
Scope, and the diagrams that prove it
The boundary, the business organisation and network diagrams, the system lists, and which systems sit inside Cyber Essentials. An inadequate scope fails an assessment on its own, before a single control is marked.
Gap analysis across all 101
Control by control, scored the way an assessor would: not met, partial, or full. You get the register, and it is yours whatever you do next. The zeros get triaged first, because those are the ones that fail an objective.
Close the gaps
Governance artefacts written, monitoring and detection stood up, response and recovery tested rather than documented. We can do this work, or your own team can, or another provider can. You get the list either way.
Build the submission, then rehearse it
The Assessment Submission Record assembled with evidence referenced to the exact section that supports each answer, then a dry run of the practical demonstration, so the first time you are asked to show a control is not in front of your assessor.
Readiness work is quoted after a scoping conversation, not from a price list, because the distance between a supplier who holds Level 0 with good documentation and one starting from a spreadsheet is measured in months rather than percentages. What we will do on that first call is tell you roughly where you sit and whether Level 1 is realistic for the deadline you have in mind. That call is free and we do not need you to prepare anything for it.
If it turns out you need Level 0 rather than Level 1, we will say so. Certifying at a level removes the need for contract-by-contract assessment at that level and below, so there is an argument for going higher than your current contract demands, but it is an argument, not a default.
Common questions
Can you certify DCC Level 1?
No, not today. Our certification-body appointment covers DCC Level 0 and Cyber Essentials. We plan to add Level 1 assessment capability in Q4 2026, subject to completing the required training and receiving formal authorisation. Until then we do the readiness and preparation work and refer the assessment to a certification body appointed for Level 1.
How many controls are in DCC Level 1?
101. One is Cyber Essentials, 12 are in Objective A (managing security risk), 75 in Objective B (protecting against cyber attack), nine in Objective C (detecting cyber security events) and four in Objective D (minimising the impact of incidents). Def Stan 05-138 Issue 4 holds 148 controls in total, and no single level uses all of them.
What is the pass mark for DCC Level 1?
Two conditions, both required, assessed per objective: at least 80% of the points available in that objective, and no control scoring zero. Controls are marked 0 for not met, 1 for partially met and 2 for fully met. Reaching 80% does not save you if a single control is not met at all, which is the rule most people miss.
How is Level 1 different from Level 0?
Level 0 is three controls, marked once, through a portal, at 100% with no partial credit. Level 1 is 101 controls in an Assessment Submission Record, marked twice through theoretical then practical scoring, including a live demonstration of your controls and possibly a site visit, at 80% per objective with nothing at zero. Level 1 also requires a conflict of interest declaration and the hashing of your submission. The Level 0 portal route cannot be used to reach Level 1.
Do we need Level 0 before Level 1?
No. You can apply at any level under the current scheme, and Level 1 contains Level 0's controls anyway. But the Level 0 portal route specifically cannot be used to aim at a higher level, so if you know you need Level 1, start on the Levels 1 to 3 process rather than certifying Level 0 and expecting to upgrade it.
Does Level 1 need Cyber Essentials Plus?
No. Control 0002, Cyber Essentials Plus, applies at Levels 2 and 3. Level 1 needs basic Cyber Essentials under control 0001, covering the right scope and maintained for the life of the certificate. We are an appointed certification body for both, so if you are heading to Level 2 later it is worth scoping that now.
Will there be a site visit?
Possibly. Practical scoring always includes a remote demonstration of your controls over teleconference. An in-person site visit happens where one was identified during scoping. Either way you should raise site inductions, staff availability and clearance requirements early, because an assessor who runs out of time marks the remaining controls as not met.
If you help us prepare, can you still assess us later?
Not for work we would then be marking. The scheme is explicit: a certification body cannot complete documentation or prepare answers or evidence that it will later assess. Helping you achieve Cyber Essentials is permitted and is declared in the conflict of interest statement. Since we refer Level 1 assessments today, the question does not currently arise, and if our own Level 1 authorisation arrives we will keep preparation and assessment on separate engagements.
Find out where you actually stand.
A readiness review scores you against all 101 controls the way an assessor would, and tells you which ones are at zero. You get the register whatever you do next, and if Level 1 is not realistic for your deadline we will tell you that on the first call.



