DCC Level 0 requirements: three controls, six questions.
Defence Standard 05-138 Issue 4 holds 148 controls. Defence Cyber Certification Level 0 uses three of them, and all three must be fully met. This is what each one asks, what counts as evidence, and the handful of things that fail an assessment before anyone reads your answers.
Level 0 requires Cyber Essentials covering the right scope, documented UK GDPR compliance including Data Protection Impact Assessments, and evidence that you have assessed how resilient your systems need to be and then built that resilience. Three controls, two questions each.
It is the smallest of the four DCC levels by a long way. Level 1 is 101 controls, Level 2 is 139 and Level 3 is 144. Level 0 is three, which is why the MOD could reasonably ask its whole supply chain to hold it by 31 December 2026.
Small does not mean lenient. Level 0 is scored at 100%: every control fully met, no partial compliance allowed. Levels 1 and 2 let you carry partials as long as you reach 80% of the points in each objective. Level 0 does not. And the two failure modes that end most first attempts are not about controls at all, they are about scope.
Cyber Essentials, scoped to match
The requirement: hold Cyber Essentials covering the scope required for all aspects of the assessment, and commit to maintaining it for the duration of the Defence Cyber Certification.
0001.1 asks whether your organisation holds Cyber Essentials certification covering the required scope for this activity. 0001.2 asks whether you commit to maintaining it for the duration of any function related to the activity or the DCC certification.
The second question is nearly free. The first one is where assessments are lost, because holding a current certificate is not the same as holding the right certificate.
Why the two scopes never quite match
Cyber Essentials covers internet-connected devices and networks. DCC scope covers internet-connected and non-internet-connected assets. So the Cyber Essentials scope sits inside the DCC scope rather than alongside it, and for most organisations there is a gap between them that is entirely legitimate: operational technology, industrial control systems, air-gapped networks, isolated test rigs.
A very small organisation might align the two exactly. Most cannot, and are not expected to. What you are expected to do is explain the difference in your answer, so the assessor understands what your Cyber Essentials certificate covers and why the DCC scope is wider.
IASME asks every applicant, whatever its size, to supply a diagram showing which parts of the organisation and network fall within Cyber Essentials and how they relate to the DCC scope. Not "larger organisations". Every applicant. It looks like this:
- Laptops, desktops and thin clients
- Mobiles and tablets
- Servers and virtual servers
- Cloud services: IaaS, PaaS, SaaS
- Firewalls and routers
- OT, ICS and SCADA
- Air gapped networks
- Isolated test and build rigs
- Standalone CAD workstations
The hard rule: if the Cyber Essentials scope does not adequately align with the DCC scope, it is an automatic failure. Not a clarification round, not a partial. Your assessor will check the alignment, and this is the single most valuable thing to get reviewed before you commit to an assessment date.
Evidence for control 0001
- Your Cyber Essentials certificate number.
- The Cyber Essentials self-assessment questionnaire or report.
- The diagram showing Cyber Essentials scope in relation to DCC scope.
- For 0001.2, an attestation or a renewal history demonstrating you recertify regularly.
One thing worth planning for: Cyber Essentials is a separate scheme that updates on its own schedule, and your commitment covers those updates too. If the scheme changes its requirements during your three-year DCC certificate, you are committed to meeting them. Our guide to the Cyber Essentials requirements covers the current five controls, and DCC and Cyber Essentials covers how the schemes relate.
UK GDPR compliance, documented
The requirement: personal data processing is conducted in compliance with the UK Data Protection Act 2018.
2314.1 asks whether you have documented policies and procedures ensuring compliance with your obligations under the UK GDPR. 2314.2 asks whether you conduct Data Protection Impact Assessments against the data types you store or process.
IASME is explicit that a DCC assessment is limited in scope and does not certify GDPR compliance. What this control tests is whether you have done the work and can show it, not whether a regulator would agree with every line of it. The scheme points you at the Information Commissioner's Office for the substance.
What the policy has to cover
Whatever your size, a data protection policy is expected to address the core principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. A five-person engineering firm and a 400-person prime both need those principles addressed. What differs is length, not coverage.
The policy does not have to be a standalone document. It can sit inside other company documentation, including a risk register that records the risks to the data subject. Assessors are told to expect simpler documentation from smaller organisations, so a short, genuine policy beats a long template you have not read.
The DPIA question is the one people fail
2314.2 is where organisations that have a policy still lose the control. A DPIA is a process: identify your data processing activities, assess the data types involved, identify the risks and impacts, mitigate them, and write it down. If you have never done one, having a good policy does not cover you, and this control needs both questions answered to be fully met.
Acceptable evidence is any of: the procedure describing how you conduct DPIAs, the template or tool you use to complete one, or a report showing the output of an assessment you have actually run. The third is the strongest.
Resilient networks and systems
The requirement: build resilience against cyber attack and system failure into the design, implementation, operation and management of the systems supporting your business functions and protecting your data.
2500.1 asks whether you have assessed the degree to which your systems must be resilient to cyber attack and system failure. 2500.2 asks whether you have built that resilience in.
IASME's own guidance warns against underestimating this one because it is only two yes-or-no questions. The word doing the work is resilience: the ability to return quickly to a previous good condition after a problem. Not prevention. Recovery.
Assess first, then implement, and do not mix the evidence up
These two questions want different kinds of proof, and answering both with the same document is the most common way to turn a full mark into a partial.
For 2500.1, the assessment: what you judged essential, and the risks to it. A micro business might have a single brief document showing the risks. A large organisation will have several, including a risk register. The evidence is expected to be tailored to your size, the service you provide and the risks you actually face, and it must show which systems are essential, which may well be the same as your scope.
For 2500.2, the implementation: tangible, practical actions that address the needs your assessment identified. The guidance is unusually direct here, and says to avoid referencing policy documents or high-level plans. It wants the concrete things. Automated backups. An uninterruptible power supply. Redundant network paths and endpoints. Something that would still be true if every policy document vanished.
So the shape of a strong answer is: here is what we decided we needed, and here is the specific thing we bought, built or configured to meet it. If your answer to 2500.2 cites a business continuity policy, expect a clarification round.
The 25XX family is drawn from the NCSC Cyber Assessment Framework's principle on resilient networks and systems, so CAF alignment work maps across, and backup and disaster recovery is usually where the evidence for 2500.2 comes from.
Scope is yours, and it can fail the whole assessment on its own
Determining the scope is solely the applicant's responsibility. Your certification body can review a proposed scope and challenge it, and can verify it, but cannot set it for you. You consult the IASME DCC Scoping Guide, decide the boundary, and document it.
What you produce has to define clearly what is included and what is excluded, supported by:
- Business organisation diagrams.
- Network diagrams.
- Lists of systems.
- An explicit indication of which systems fall inside the Cyber Essentials scope.
The test is stated plainly in the guide: the assessor, and other relevant parties, must be able to fully understand the scope from your documentation and scoping attestation alone. Not from a conversation. Not from a follow-up call. From the documents.
And then: if the assessor determines the scope or its documentation is inadequate, the entire assessment is failed. Ahead of every control, before any answer is marked. Combined with the Cyber Essentials alignment rule, that means the two things most likely to end your assessment are both settled before you write a single answer.
The ways a DCC assessment fails outright
Not "scores badly". Fails, sometimes with no route back except starting again.
Read that list again and notice how little of it is technical. Two of the eight are about scope, three are about how you write and reference evidence, one is about scheduling. Only item three is about whether your security is any good. For most defence suppliers, Level 0 is a documentation and scoping exercise with a Cyber Essentials certificate attached, which is good news if you plan for the right work and bad news if you budget for firewalls.
How your answers get scored
At Level 0 the whole assessment runs through the IASME portal. Your certification body reviews the submission and marks each question one of three ways: compliant, non-compliant, or more information needed. Where more information is needed you update your answer, add evidence and resubmit. Once every question is either compliant or non-compliant, the result is submitted and, on a pass, the certificate is issued automatically through the scheme's digital certification system.
Underneath that, controls are scored on a three-point scale: 0 if not met, 1 if partially met, meaning some of the control's questions meet the baseline and others do not, and 2 if fully met. This is where the two-questions-per-control structure matters at Level 0. A control with one strong answer and one weak one scores 1, and a 1 is not a pass at this level.
Two more practical points. Your evidence stays on your systems throughout: you host the files and grant your certification body access, rather than uploading everything to a portal. And the Level 0 route cannot be used to aim at a higher level, so if there is a chance you need Level 1, take the Levels 1 to 3 process from the start.
What a certification body can and cannot do for you
You are allowed third-party help. The scheme is specific about which help, from whom.
A certification body may: explain the scheme and its levels, clarify the controls and how to meet them, help you understand a question and what a complete answer needs, describe the evidence a control requires, verify your scope, provide blank template documents, help you achieve Cyber Essentials or Cyber Essentials Plus, and facilitate clarification rounds.
A certification body may not: implement policies, controls or technical changes on your behalf, answer questions for you or dictate your responses, or complete documentation, answers or evidence that it will later assess.
That last clause is the one that shapes how a sensible engagement is structured. If you need someone to write the policy and build the resilience, that is implementation work, and the scheme explicitly encourages you to engage a separate technology provider for it. It does not have to be a DCC certification body at all, though one familiar with the scheme will be faster.
Certification bodies are also required to promote your resilience without creating dependency or exploiting the process, and to act impartially. If a conversation feels like it is heading toward "we will handle all of it and then certify it", that is the boundary the scheme exists to police.
What holding the certificate commits you to
A DCC certificate is valid for three years. Annual attestation is required at the end of years one and two, confirming nothing significant has changed. At the end of year three it expires and you reapply; it does not roll forward.
Running alongside that, Cyber Essentials recertifies annually, because control 0001 commits you to maintaining it for as long as the DCC certification lasts, including any changes the Cyber Essentials scheme makes in the meantime.
And your paperwork has a retention obligation. Access to your submission, its evidence and any recordings of assessment calls must be available to your certification body and to IASME for up to three and a half years after the assessment completes. That is longer than the certificate's first attestation cycle, so it needs a real home, not a folder on the laptop of whoever ran the project.
Common questions
How many controls are in DCC Level 0?
Three: control 0001 (Cyber Essentials), control 2314 (UK GDPR compliance) and control 2500 (resilient networks and systems). Each has two questions, so six questions in total. Def Stan 05-138 Issue 4 contains 148 controls, and no level uses all of them.
What is the pass mark for DCC Level 0?
100%. Every control must be fully met, with no partial compliance allowed. Controls score 0 for not met, 1 for partially met and 2 for fully met, and at Level 0 only a 2 on every control passes. Levels 1 and 2 pass at 80% of the points per objective with nothing scoring zero; Level 3 returns to 100%.
Does DCC Level 0 require a site visit?
No. Level 0 is a portal submission that your certification body marks. Practical scoring, remote demonstrations of your controls and site visits all start at Level 1.
Do I need a network diagram for DCC Level 0?
Yes. Your scope documentation must include business organisation diagrams, network diagrams and lists of systems, explicitly indicating which systems fall within the Cyber Essentials scope. Separately, a diagram showing how the Cyber Essentials scope relates to the DCC scope is required for every applicant regardless of size.
Will my existing Cyber Essentials certificate be enough?
Only if its scope covers every applicable internet-connected device inside the DCC scope. The two scopes are set separately and a misalignment is an automatic failure, so this is worth checking before you book an assessment rather than during one. It is also the most common reason a straightforward-looking Level 0 turns into a re-scope.
Does a DPIA really apply to a small business?
Control 2314.2 asks whether you conduct Data Protection Impact Assessments against the data types you store or process, and it applies at Level 0 regardless of size. Smaller organisations are expected to have simpler documentation, not none. Evidence can be the procedure you follow, the template you use, or a completed assessment report.
Can I use a policy document as evidence for the resilience control?
Not for 2500.2. The guidance says to avoid referencing policy documents or high-level plans there, and to show concrete actions and tools instead, such as automated backups or uninterruptible power supplies. Documentation is appropriate for 2500.1, the assessment of what resilience you need.
Can my certification body write my answers?
No. A certification body cannot answer questions for you, dictate your responses, implement controls on your behalf, or complete documentation or evidence that it will later assess. It can explain controls, describe what evidence is needed, verify your scope and provide blank templates. Anything beyond that is implementation work and can be done by any provider.
How much does DCC Level 0 cost?
Our prices start at £499 + VAT for a micro business that already holds Cyber Essentials, and at £799 + VAT if you need Cyber Essentials as well. Full bands are on the DCC Level 0 page. Remediation, where it is needed, is quoted separately.
Find the gaps before you book.
Send us your Cyber Essentials scope and a rough picture of your systems. We will tell you whether the two scopes align, which of the three controls you already meet, and what is missing. If you are not ready, we will say so before you order rather than after.