For UK defence suppliers

Defence Cyber Certification Level 1.

Understand the gaps. Prepare the evidence. Plan your assessment.

DCC Level 1 covers 101 controls, with documented evidence and practical verification. We help UK defence suppliers establish their scope, close gaps and prepare for the assessment process.

Company credentials
ISO 27001 & 9001Certified by a UKAS-accredited certification body Cyber Essentials & PlusCertification body NCSC AssuredCyber Advisor scheme CISSPHeld by Daniel McClure Fisher

DCC Level 1 support.

We agree the work around your current controls and procurement deadline. You get a record of the gaps, the evidence needed and who is responsible for each action.

Preparing for Level 1

Scope the organisation, review gaps against the 101 controls and organise evidence for the Assessment Submission Record. Rehearse the practical demonstration and record the actions still needed.

Planning formal assessment

Discuss scope, evidence, readiness and the target date. The quote will distinguish assessment work from preparation, with the appointed body, impartiality requirements and responsibilities confirmed.

Your Cyber Essentials position

Cyber Essentials is required at every DCC level. Check the scope and expiry of your current certificate as part of the preparation.

Declared roles and prior work

Level 1 requires a conflict of interest statement. Preparation work and prior services are declared. A certification body cannot assess answers or evidence it prepared itself.

The 101 controls in DCC Level 1

Def Stan 05-138 Issue 4 holds 148 controls across four objectives. Level 1 uses 101 of them, and they are not spread evenly.

1Cyber EssentialsControl 0001, the same one Level 0 uses. Hold Cyber Essentials for the right scope and commit to maintaining it.
12Objective AManaging security risk. Governance, risk management, asset management, supplier management, physical security. The governance controls start here: Level 0 has none of them.
75Objective BProtecting against cyber attack. Planning for resilience, identity and access, data security, system security, network resilience, awareness and culture, staff and environment. Three quarters of Level 1 is here.
9Objective CDetecting cyber security events. Security monitoring and proactive detection. This is where suppliers without a detection and response capability find a hard floor.
4Objective DMinimising the impact of incidents. Incident response, recovery and lessons learned.

The objectives are the NCSC Cyber Assessment Framework's, which is why work you have already done on CAF alignment is not wasted here. If you have run a CAF self-assessment, you have a usable head start on Objectives C and D in particular.

Two things follow from the shape of that table. Objective C is the one that catches people: nine controls sounds small, but monitoring and detection cannot be written into existence the week before an assessment, and there is no partial credit route around a control scoring zero. And Objective A is where a small engineering firm usually has the least documentation, because governance artefacts are the ones nobody needed until a prime asked.

What changes when you leave Level 0 behind

The control count is the least of it. The process itself is different.

01The submissionLevel 0 is a portal form. Level 1 is an Assessment Submission Record: a document you own, holding every answer, its context and its evidence. The Level 0 portal route cannot be used to reach a higher level.
02Marked twiceTheoretical scoring reviews your answers and evidence. Practical scoring then tests whether it is true. Level 0 has only the first.
03Show me, do not tell mePractical scoring includes a remote demonstration of your controls over teleconference, and an in-person site visit where scoping identified one.
04Clarification roundsYou and your assessor agree in advance how many rounds of clarification the engagement includes. Run out and remaining controls can be marked not met.
05Conflict of interestMandatory from Level 1 up, signed by both parties early. Any previous work your certification body did for you, including Cyber Essentials, is declared. Failing to declare can fail the whole assessment.
06Hashing and retentionAnswers and evidence are compressed into one file and hashed, so the submission can be verified later. It stays reachable for up to three and a half years.
07RecordingsYour assessor can require video calls and screen shares to be recorded on your systems, and you have to comply.

How DCC Level 1 is scored

Every control is scored 0 if it is not met, 1 if it is partially met, and 2 if it is fully met. To pass Level 1 you must satisfy both of these, per objective:

  • At least 80% of the total points available in that objective, and
  • Every control in that objective at least partially met, so nothing scores zero.

Take an objective with 10 controls. The maximum is 20 points, so you need 16. Ten controls fully met gets you 20. Nine full and one partial gets 19. Six full and four partial gets exactly 16, and passes. Five full and five partial gets 15, and fails on the threshold.

Now the part that catches people. Seven full, two partial and one not met also reaches 16 points, and still fails, because a control scored zero fails the objective outright however good the arithmetic looks. One neglected control sinks an objective that was otherwise comfortably clear.

This is the difference between Level 1 and Level 0, where 100% of controls must be fully met and there is no partial credit at all. Level 1 gives you room to be imperfect, but no room to have a gap.

The readiness work, in the order we do it

Scoped from where you actually are. Most suppliers arriving here hold Cyber Essentials and Level 0 already.

Scope, and the diagrams that prove it

The boundary, the business organisation and network diagrams, the system lists, and which systems sit inside Cyber Essentials. An inadequate scope fails an assessment on its own, before a single control is marked.

Gap analysis across all 101

Control by control, scored the way an assessor would: not met, partial, or full. You get the register, and it is yours whatever you do next. The zeros get triaged first, because those are the ones that fail an objective.

Close the gaps

Governance artefacts written, monitoring and detection stood up, response and recovery tested rather than documented. We can do this work, or your own team can, or another provider can. You get the list either way.

Build the submission, then rehearse it

The Assessment Submission Record assembled with evidence referenced to the exact section that supports each answer, then a dry run of the practical demonstration, so the first time you are asked to show a control is not in front of your assessor.

Readiness work is quoted after a scoping conversation, not from a price list, because the distance between a supplier who holds Level 0 with good documentation and one starting from a spreadsheet is measured in months rather than percentages. What we will do on that first call is tell you roughly where you sit and whether Level 1 is realistic for the deadline you have in mind. That call is free and we do not need you to prepare anything for it.

If it turns out you need Level 0 rather than Level 1, we will say so. DCC provides organisation-level evidence, but the full Supplier Assurance Questionnaire remains required under current MOD guidance. The level should follow your procurement requirement and scope.

Common questions

Can you help us with DCC Level 1?

Yes. We provide Level 1 scope reviews, gap analysis across the 101 controls, remediation and evidence preparation. The engagement confirms the formal assessment route, the appointed certification body and responsibilities before work starts. Preparation and assessment have separate roles, including the required conflict of interest declaration.

How many controls are in DCC Level 1?

101. One is Cyber Essentials, 12 are in Objective A (managing security risk), 75 in Objective B (protecting against cyber attack), nine in Objective C (detecting cyber security events) and four in Objective D (minimising the impact of incidents). Def Stan 05-138 Issue 4 holds 148 controls in total, and no single level uses all of them.

What is the pass mark for DCC Level 1?

Two conditions, both required, assessed per objective: at least 80% of the points available in that objective, and no control scoring zero. Controls are marked 0 for not met, 1 for partially met and 2 for fully met. Reaching 80% does not save you if a single control is not met at all, which is the rule most people miss.

How is Level 1 different from Level 0?

Level 0 is three controls, marked once, through a portal, at 100% with no partial credit. Level 1 is 101 controls in an Assessment Submission Record, marked twice through theoretical then practical scoring, including a live demonstration of your controls and possibly a site visit, at 80% per objective with nothing at zero. Level 1 also requires a conflict of interest declaration and the hashing of your submission. The Level 0 portal route cannot be used to reach Level 1.

Do we need Level 0 before Level 1?

No. You can apply at any level under the current scheme, and Level 1 contains Level 0's controls anyway. But the Level 0 portal route specifically cannot be used to aim at a higher level, so if you know you need Level 1, start on the Levels 1 to 3 process rather than certifying Level 0 and expecting to upgrade it.

Does Level 1 need Cyber Essentials Plus?

No. Control 0002, Cyber Essentials Plus, applies at Levels 2 and 3. Level 1 needs basic Cyber Essentials under control 0001, covering the right scope and maintained for the life of the certificate. We are an appointed certification body for both, so if you are heading to Level 2 later it is worth scoping that now.

Will there be a site visit?

Possibly. Practical scoring always includes a remote demonstration of your controls over teleconference. An in-person site visit happens where one was identified during scoping. Either way you should raise site inductions, staff availability and clearance requirements early, because an assessor who runs out of time marks the remaining controls as not met.

If you help us prepare, can you still assess us later?

Not for work we would then be marking. The scheme is explicit: a certification body cannot complete documentation or prepare answers or evidence that it will later assess. Helping you achieve Cyber Essentials is permitted and is declared in the conflict of interest statement. The assessment route is agreed before preparation starts, so work that DSC prepares can be assessed by another appropriately appointed certification body.

Discuss your DCC Level 1 requirement.

A readiness review records your position against the 101 controls and the evidence still needed. Start by sharing your contract requirement and target date. We will discuss the scope, likely dependencies and next step, then agree the work needed to establish readiness.

Reading, Berkshire  /  Scope, evidence and assessment preparation for UK defence suppliers.  /  reply within one working day