Level 0 requires Cyber Essentials covering the right scope, documented UK GDPR compliance including Data Protection Impact Assessments, and evidence that you have assessed how resilient your systems need to be and then built that resilience. Three controls, two questions each.

Using the guide: the six question references below follow IASME’s Applicant Guide Levels 0–3 v2.1. Check the current applicant, process and scoping guides (opens in new tab) before submission for the authoritative wording, evidence and assessment terms. IASME’s public scheme overview confirms the three Level 0 controls; this article is an explanation, not the assessment form.

Ready to arrange your assessment? As a DCC Level 0 Certification Body, we can assess your application. Compare Level 0 assessment prices and the route that includes Cyber Essentials. If you need help preparing the evidence, we agree that work separately before you commit.

It is the smallest of the four DCC levels by a long way. Level 1 is 101 controls, Level 2 is 139 and Level 3 is 144. Level 0 is three, while the MOD’s May 2026 statement asks industry partners to achieve Level 0 by 31 December 2026. A buyer’s contract can specify a higher level.

All three Level 0 controls must be met. A current Cyber Essentials certificate does not establish the other two controls or the adequacy of your DCC scope. Start with the scope and evidence rather than treating a short questionnaire as a promise of an easy pass.

Control 0001 · The 000X family

Cyber Essentials, scoped to match

The requirement: hold Cyber Essentials covering the scope required for all aspects of the assessment, and commit to maintaining it for the duration of the Defence Cyber Certification.

0001.1 asks whether your organisation holds Cyber Essentials certification covering the required scope for this activity. 0001.2 asks whether you commit to maintaining it for the duration of any function related to the activity or the DCC certification.

The maintenance commitment matters throughout the DCC certificate’s life. Check both whether the certificate is current and whether it covers the applicable systems, then plan the annual renewal.

Why the two scopes never quite match

Cyber Essentials applies its technical controls to the required devices, software and cloud services in scope. DCC takes a wider organisational resilience view, which can include non-internet-connected assets such as operational technology, industrial control systems, air-gapped networks and isolated test rigs. Explain how the two scopes relate.

Some organisations can align the boundaries closely; others need to explain the additional assets in DCC scope. The relevant question is whether the Cyber Essentials certificate covers the applicable part of the documented DCC scope.

IASME asks every applicant, whatever its size, to supply a diagram showing which parts of the organisation and network fall within Cyber Essentials and how they relate to the DCC scope. Not "larger organisations". Every applicant. It looks like this:

DCC scope Everything supporting your business-critical functions
Cyber Essentials scope Internet connected only
  • Laptops, desktops and thin clients
  • Mobiles and tablets
  • Servers and virtual servers
  • Cloud services: IaaS, PaaS, SaaS
  • Firewalls and routers
In DCC, outside CE Not internet connected
  • OT, ICS and SCADA
  • Air gapped networks
  • Isolated test and build rigs
  • Standalone CAD workstations
Your Cyber Essentials certificate has to cover every applicable internet connected device inside the DCC scope. A small organisation may align the two exactly; most do not, because DCC includes assets Cyber Essentials rules exclude. That is expected, and you explain the difference in your answer. A Cyber Essentials scope that does not adequately align is an automatic failure, and IASME asks every applicant, whatever its size, to supply a diagram like this one.

The certification body must be able to verify the relationship between the two scopes. Resolve missing systems, unclear boundaries or an unsuitable Cyber Essentials certificate before submission. Do not assume the assessor can accept a scope mismatch because the certificate itself is current.

Evidence for control 0001

  • Your Cyber Essentials certificate number.
  • The Cyber Essentials self-assessment questionnaire or report.
  • The diagram showing Cyber Essentials scope in relation to DCC scope.
  • For 0001.2, an attestation or a renewal history demonstrating you recertify regularly.

One thing worth planning for: Cyber Essentials is a separate scheme that updates on its own schedule, and your commitment covers those updates too. If the scheme changes its requirements during your three-year DCC certificate, you are committed to meeting them. Our guide to the Cyber Essentials requirements covers the current five controls, and DCC and Cyber Essentials covers how the schemes relate.

Control 2314 · The 23XX data security family

UK GDPR compliance, documented

The requirement: personal data processing is conducted in compliance with the UK Data Protection Act 2018.

2314.1 asks whether you have documented policies and procedures ensuring compliance with your obligations under the UK GDPR. 2314.2 asks whether you conduct Data Protection Impact Assessments against the data types you store or process.

IASME is explicit that a DCC assessment is limited in scope and does not certify GDPR compliance. What this control tests is whether you have done the work and can show it, not whether a regulator would agree with every line of it. The scheme points you at the Information Commissioner's Office for the substance.

What the policy has to cover

Whatever your size, a data protection policy is expected to address the core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. A five-person engineering firm and a 400-person prime both need those principles addressed. What differs is length, not coverage.

The policy does not have to be a standalone document. It can sit inside other company documentation, including a risk register that records the risks to the data subject. Assessors are told to expect simpler documentation from smaller organisations, so a short, genuine policy beats a long template you have not read.

The DPIA question is the one people fail

Control 2314.2 asks about the DPIA process and the data types you process. Record your processing activities, how you identify risks to individuals and when you carry out a full assessment. Under UK GDPR, a DPIA is required for processing likely to result in high risk; that does not mean every small business must write a full DPIA for every activity. The ICO’s DPIA guidance (opens in new tab) explains screening and the legal threshold.

Acceptable evidence is any of: the procedure describing how you conduct DPIAs, the template or tool you use to complete one, or a report showing the output of an assessment you have actually run. Use evidence that reflects the work actually performed, including the recorded screening decision where relevant.

Control 2500 · The 25XX resilience family

Resilient networks and systems

The requirement: build resilience against cyber attack and system failure into the design, implementation, operation and management of the systems supporting your business functions and protecting your data.

2500.1 asks whether you have assessed the degree to which your systems must be resilient to cyber attack and system failure. 2500.2 asks whether you have built that resilience in.

IASME's own guidance warns against underestimating this one because it is only two yes-or-no questions. The word doing the work is resilience: the ability to return quickly to a previous good condition after a problem. Not prevention. Recovery.

Assess first, then implement, and do not mix the evidence up

Keep the assessed need and the implemented control distinct. A single document can reference both, but the assessor needs to see what you decided and what is operating as a result.

For 2500.1, the assessment: what you judged essential, and the risks to it. A micro business might have a single brief document showing the risks. A large organisation will have several, including a risk register. The evidence is expected to be tailored to your size, the service you provide and the risks you actually face, and it must show which systems are essential, which may well be the same as your scope.

For 2500.2, the implementation: tangible, practical actions that address the needs your assessment identified. The guidance is unusually direct here, and says to avoid referencing policy documents or high-level plans. It wants the concrete things. Automated backups. An uninterruptible power supply. Redundant network paths and endpoints. Something that would still be true if every policy document vanished.

So the shape of a strong answer is: here is what we decided we needed, and here is the specific thing we bought, built or configured to meet it. If your answer to 2500.2 cites a business continuity policy, expect a clarification round.

The 25XX family is drawn from the NCSC Cyber Assessment Framework's principle on resilient networks and systems, so CAF alignment work maps across, and backup and disaster recovery is usually where the evidence for 2500.2 comes from.

Before the controls · Scope

Scope is yours, and it can fail the whole assessment on its own

Determining the scope is solely the applicant's responsibility. Your certification body can review a proposed scope and challenge it, and can verify it, but cannot set it for you. You consult the IASME DCC Scoping Guide, decide the boundary, and document it.

What you produce has to define clearly what is included and what is excluded, supported by:

  • Business organisation diagrams.
  • Network diagrams.
  • Lists of systems.
  • An explicit indication of which systems fall inside the Cyber Essentials scope.

Make the scope documentation understandable without relying on undocumented knowledge. Diagrams, system lists and the scoping attestation should agree. Discuss uncertainties with the certification body before submission and update the documents to reflect the agreed boundary.

An inadequate scope or unclear records can prevent successful assessment. Clarify the scope, Cyber Essentials relationship and required evidence early. The current process guide and assessment terms determine how clarifications, unsuccessful submissions and any further assessment are handled.

Failure modes

The ways a DCC assessment fails outright

The following are practical risks to resolve before submission. Confirm the formal marking, clarification and retest arrangements in the current process guide.

01Inadequate scopeAn unclear or inadequate scope prevents the assessor establishing what is covered. Document the boundary and dependencies before submission.
02Misaligned Cyber EssentialsAn otherwise valid Cyber Essentials certificate may not cover the systems required by the DCC scope. Resolve the relationship before assessment.
03One control not fully metAll three controls need to be met. Each answer and its supporting evidence must demonstrate the applicable requirement.
04Evidence nobody can findYou must point at the exact section of a document that supports each answer. If the assessor cannot easily identify it, they can request clarification or mark the question failed.
05Answers without contextRestating the answer options is not sufficient. "Yes" needs the explanation of how the control is met. That added context can be the deciding factor on a control.
06Failing a later quality reviewKeep the submission and evidence accessible for the scheme’s quality assurance. Resolve any findings under the process and certification terms.
07Running out of timeAgree access, availability and any site or clearance arrangements in advance. Missing access can delay assessment or leave a control unevidenced.
08Undeclared conflict of interestDiscuss previous consultancy, implementation and other relationships before assessment so the certification body can apply the scheme’s impartiality rules.

Good preparation combines scope, working controls and clear evidence. A policy alone does not demonstrate an operating backup or recovery arrangement, and a technical control alone may not explain why it meets the business’s resilience needs. Plan both parts.

Marking

How your answers get scored

At Level 0 the whole assessment runs through the IASME portal. Your certification body reviews the submission and marks each question one of three ways: compliant, non-compliant, or more information needed. Where more information is needed you update your answer, add evidence and resubmit. Once every question is either compliant or non-compliant, the result is submitted and, on a pass, the certificate is issued automatically through the scheme's digital certification system.

The Level 0 requirement is that each control is met. Use the current applicant and process guides for scoring and evidence rules. Do not apply another DCC level’s thresholds to a Level 0 submission.

Agree how the assessor will securely access evidence, which records are submitted and how long they must remain available. Choose the process for the level your buyer requires at the start; if Level 1 is required, discuss that route rather than assuming a Level 0 application can simply be upgraded.

Getting help

What a certification body can and cannot do for you

You are allowed third-party help. The scheme is specific about which help, from whom.

A certification body may: explain the scheme and its levels, clarify the controls and how to meet them, help you understand a question and what a complete answer needs, describe the evidence a control requires, verify your scope, provide blank template documents, help you achieve Cyber Essentials or Cyber Essentials Plus, and facilitate clarification rounds.

The applicant retains ownership: your certification body must not supply answers or manufacture evidence for the assessment. Discuss any previous or proposed implementation work before engagement so the assessment can comply with the scheme’s impartiality rules.

If you need policies written or controls implemented, agree that preparation separately and establish an appropriate assessment route before work begins. A technology provider can help implement the controls; who may then assess that work is governed by the scheme rules, not just by having two lines on a quotation.

Certification bodies are also required to promote your resilience without creating dependency or exploiting the process, and to act impartially. If a conversation feels like it is heading toward "we will handle all of it and then certify it", that is the boundary the scheme exists to police.

Afterwards

What holding the certificate commits you to

A DCC certificate is valid for three years. Annual attestation is required at the end of years one and two, confirming nothing significant has changed. At the end of year three it expires and you reapply; it does not roll forward.

Running alongside that, Cyber Essentials recertifies annually, because control 0001 commits you to maintaining it for as long as the DCC certification lasts, including any changes the Cyber Essentials scheme makes in the meantime.

Agree the evidence retention and access requirements in writing with the certification body, including any assessment recordings and access for IASME quality assurance. Keep the submission in an organisation-controlled location with a named owner, rather than only on the project contact’s laptop.

FAQ

Common questions

How many controls are in DCC Level 0?

Three: control 0001 (Cyber Essentials), control 2314 (UK GDPR compliance) and control 2500 (resilient networks and systems). The v2.1 applicant guide references two questions for each control. Use the current IASME pack when preparing the actual submission.

What is the pass mark for DCC Level 0?

All three Level 0 controls must be met; partial implementation is not sufficient. Use the current scheme guides for the formal scoring and evidence rules, and agree clarification or retest arrangements with the certification body.

Does DCC Level 0 require a site visit?

No. Level 0 is a portal submission that your certification body marks. Practical scoring, remote demonstrations of your controls and site visits all start at Level 1.

Do I need a network diagram for DCC Level 0?

Yes. Your scope documentation must include business organisation diagrams, network diagrams and lists of systems, explicitly indicating which systems fall within the Cyber Essentials scope. Separately, a diagram showing how the Cyber Essentials scope relates to the DCC scope is required for every applicant regardless of size.

Will my existing Cyber Essentials certificate be enough?

Check the certificate’s entity, scope and validity against the applicable part of the DCC scope. The assessor must be able to establish the relationship. Review any changes to your systems and resolve omissions before assessment.

Does a DPIA really apply to a small business?

Control 2314.2 asks about DPIAs and the data you process, regardless of organisation size. Show your screening method and evidence appropriate to the activity. The UK GDPR requirement for a full DPIA applies to processing likely to result in high risk; a small organisation is not automatically exempt, nor does every activity automatically require one.

Can I use a policy document as evidence for the resilience control?

Not for 2500.2. The guidance says to avoid referencing policy documents or high-level plans there, and to show concrete actions and tools instead, such as automated backups or uninterruptible power supplies. Documentation is appropriate for 2500.1, the assessment of what resilience you need.

Can my certification body write my answers?

No. You own the answers and supporting evidence. The certification body can explain the scheme and question requirements, review the proposed scope and discuss evidence expectations. Any preparation or implementation relationship must comply with the scheme’s impartiality rules before assessment is agreed.

How much does DCC Level 0 cost?

Our prices start at £499 + VAT for a micro business that already holds Cyber Essentials, and at £799 + VAT if you need Cyber Essentials as well. Full bands are on the DCC Level 0 page. Remediation, where it is needed, is quoted separately.