DCC vs Cyber Essentials: you need both.

This is not a choice between two schemes. Every level of Defence Cyber Certification requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. So the real question is not which one. It is what order, and over which systems.

Cyber Essentials is a prerequisite for Defence Cyber Certification, not an alternative to it. If you supply the MOD and you are working toward DCC, Cyber Essentials is part of the work rather than a different route to the same place.

The MOD's own request makes this concrete. In May 2026 its Director of Cyber Defence and Risk asked all industry partners to achieve DCC Level 0 by 31 December 2026, a request that explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope.

So if you hold Cyber Essentials already, you are not starting from zero on DCC. And if you hold neither, doing them as one piece of work is cheaper and faster than doing them as two.

Compare / 01 · What each one is

Same controls underneath. Different jobs.

Both schemes involve IASME, and the technical ground at the lower levels overlaps heavily: firewalls, secure configuration, access control, malware protection, patching. Where they differ is who is asking, and what the certificate is for.

01Who runs itCyber Essentials: an NCSC scheme delivered by IASME. DCC: created by the MOD with IASME as Certification Authority.
02Who asks for itCyber Essentials: public sector buyers, insurers, primes, and increasingly private customers. DCC: the MOD supply chain, through contract conditions.
03What it provesCyber Essentials: the five technical controls are in place. DCC: compliance with the Cyber Security Model at your contract's risk level.
04LevelsCyber Essentials: Cyber Essentials and Cyber Essentials Plus. DCC: four, Levels 0 to 3, matched to your Cyber Risk Profile.
05Where the controls are writtenCyber Essentials: the NCSC requirements document. DCC: Defence Standard 05-138, Issue 4.
06How long it lastsCyber Essentials: annual. DCC: three years, with an annual check in.
07The relationshipCyber Essentials is required at every DCC level. Cyber Essentials Plus is required at Levels 2 and 3.
Compare / 02 · Sequence

Four steps, and the first one is not technical.

01

Establish scope from the contract, not the office

Find which systems are business-critical for the contract in question. This determines everything downstream, and doing it from your contract rather than from a mental map of your IT is what stops you certifying the wrong boundary.

02

Certify Cyber Essentials over that scope

Not over whatever was convenient last year, over the systems DCC will care about. If you already hold it, this is a scope check rather than a fresh certification.

03

Review against Def Stan 05-138 for your risk profile

Cyber Essentials covers a good deal of the lower profiles, but not all of it, and the gap is usually evidence rather than technology.

04

Assess and certify DCC at your level

Then the annual check in keeps it live across the three year term, alongside your annual Cyber Essentials recertification.

Compare / 03 · The mistake worth avoiding

Holding Cyber Essentials is not the same as holding it over the right systems.

This is the single most common problem when a Cyber Essentials holder starts on DCC, and it is almost always discovered late.

Cyber Essentials scope is set by you when you certify. Contract scope is set by the contract. The two are decided independently, by different people, at different times, and there is no mechanism that keeps them aligned. So a company can hold a perfectly valid Cyber Essentials certificate that does not cover the systems its MOD work actually runs on.

Common ways it happens: the certificate covers the corporate laptops but not the engineering network where the contract data lives. Or it was scoped before a cloud migration and the new tenancy was never brought in. Or a subsidiary does the defence work and the certificate belongs to the parent.

None of that is negligence. It is what happens when two scopes are set for two purposes. But it does mean the first question to ask about an existing Cyber Essentials certificate is not "is it current". It is "what does it cover". If you are heading for Cyber Essentials Plus as well, what actually fails a CE Plus assessment is worth reading alongside this.

Compare / 04 · Why this is one job, not two

We are appointed for both.

Dead Simple Computing is an appointed Cyber Essentials certification body and an appointed certification body for DCC Level 0. That is unusual: most firms competing on DCC are not Cyber Essentials certification bodies, and most Cyber Essentials certification bodies do not assess DCC.

Practically, it means the prerequisite and the certification are assessed by the same team, so the scope question above gets asked once, at the start, by the people who will be assessing both. Nothing gets handed to a third party halfway through, and there is no gap between two assessors' interpretations of what "in scope" meant.

Our ceiling, plainly. We assess DCC Level 0 today. Our Level 1 assessor training is booked for October 2026, so we expect to assess Level 1 from late 2026. We do not assess Levels 2 or 3. We will prepare you, certify the Cyber Essentials Plus those levels require, and point you to a certification body for the DCC assessment itself. For what Level 0 involves and what it costs, see DCC Level 0 certification, and what Cyber Essentials costs covers the prerequisite.

FAQ

Common questions

Do I need Cyber Essentials for DCC?

Yes. Every DCC level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. The MOD's request for Level 0 by 31 December 2026 explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope.

Is Cyber Essentials enough on its own for MOD work?

It depends on your contract. Cyber Essentials is not the same as compliance with the Cyber Security Model, which is what DEFCON 658 brings into your contract and what Def Stan 05-138 specifies. Cyber Essentials is a substantial part of the lower risk profiles, and it is required for DCC, but it is not a substitute for the model.

Which should I do first?

Cyber Essentials, scoped to the systems your contract cares about. It is a prerequisite for DCC, so there is no version of this where DCC comes first.

Do I need Cyber Essentials Plus?

For DCC Levels 2 and 3, yes. At Levels 0 and 1, Cyber Essentials is what is required. Your contract may ask for Cyber Essentials Plus independently of DCC, so check the terms rather than assuming.

Can you certify both?

Yes for Cyber Essentials, Cyber Essentials Plus, and DCC Level 0. We are an appointed certification body for each. We expect to assess DCC Level 1 from late 2026 after assessor training in October. We do not assess DCC Levels 2 or 3.

My Cyber Essentials certificate is current. Am I covered for DCC?

Only if its scope covers the systems the contract runs on, which is not automatic, the two scopes are set separately. It is the first thing worth checking, and the most common reason a straightforward-looking DCC assessment turns into a re-scope.

One team for both.

Tell us what you already hold and who you supply. We will check whether your Cyber Essentials scope covers the right systems, and tell you what Level 0 needs from you. Appointed certification body for both.

Reading, Berkshire  /  reply within one working day