Cyber Essentials is a prerequisite for Defence Cyber Certification, not an alternative to it. If you supply the MOD and you are working toward DCC, Cyber Essentials is part of the work rather than a different route to the same place.
The MOD's own request makes this concrete. In May 2026 its Director of Cyber Defence and Risk asked all industry partners to achieve DCC Level 0 by 31 December 2026, a request that explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope.
Sources: IASME’s DCC scheme overview (opens in new tab) and the MOD statement of 8 May 2026 (opens in new tab). The MOD’s CSM guidance (opens in new tab) also confirms that a DCC certificate does not currently remove the SAQ requirement.
So if you hold Cyber Essentials already, you are not starting from zero on DCC. If you hold neither, coordinated planning can avoid duplicating scope work, while each scheme retains its own assessment and certification decision.
Same controls underneath. Different jobs.
Both schemes involve IASME, and the technical ground at the lower levels overlaps heavily: firewalls, secure configuration, access control, malware protection, patching. Where they differ is who is asking, and what the certificate is for.
Four steps, and the first one is not technical.
Establish scope from the contract, not the office
DCC covers the organisation’s security and resilience, including the processes, systems and business parts needed to function and deliver. The applicant documents the proposed scope and the certification body verifies it. Use the buyer’s Cyber Risk Profile to establish the required level, but do not reduce organisational scope to the files for one contract.
Certify Cyber Essentials over that scope
Check that the Cyber Essentials certificate covers the applicable systems within the DCC scope and remains current. A valid existing certificate may be usable; an unsuitable scope or certificate date can require a revised assessment or renewal.
Review against Def Stan 05-138 for your risk profile
Review every required DCC control. Cyber Essentials supplies one prerequisite; data protection, resilience and the other controls at higher levels require their own evidence.
Assess and certify DCC at your level
Certification follows a successful assessment. Maintain the controls and complete annual attestation during the three-year DCC term, alongside annual Cyber Essentials renewal.
Holding Cyber Essentials is not the same as holding it over the right systems.
An existing Cyber Essentials certificate needs a scope check before the DCC assessment. Check the entity, systems and services covered, and any changes since it was issued.
The applicant defines the proposed scope of each assessment, with the certification body checking it against the relevant scheme. DCC takes an organisation-wide resilience view and may include assets outside Cyber Essentials. The buyer’s contractual requirements also need to be met. Document how these boundaries relate.
Common ways it happens: the certificate covers the corporate laptops but not the engineering network where the contract data lives. Or it was scoped before a cloud migration and the new tenancy was never brought in. Or a subsidiary does the defence work and the certificate belongs to the parent.
None of that is negligence. It is what happens when two scopes are set for two purposes. But it does mean the first question to ask about an existing Cyber Essentials certificate is not "is it current". It is "what does it cover". If you are heading for Cyber Essentials Plus as well, what fails a CE Plus assessment is worth reading alongside this.
We are appointed for both.
Dead Simple Computing is an appointed Cyber Essentials certification body and an appointed certification body for DCC Level 0. Holding both appointments means one body can assess the Cyber Essentials that Level 0 requires and the Level 0 certification itself. Both are listed on the IASME register.
We can coordinate the Cyber Essentials prerequisite and DCC Level 0 assessment. Scope, evidence and the certification decision remain separately recorded for each scheme. Any preparation or implementation work is agreed within the applicable impartiality rules.
For DCC Level 0 certification, DSC is an appointed certification body. For higher-level work, including Level 1 support, the readiness scope and formal assessment route are agreed up front. We also assess Cyber Essentials Plus. See what Cyber Essentials costs for the prerequisite.
Common questions
Do I need Cyber Essentials for DCC?
Yes. Every DCC level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. The MOD's request for Level 0 by 31 December 2026 explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope.
Is Cyber Essentials enough on its own for MOD work?
It depends on your contract. Cyber Essentials is not the same as compliance with the Cyber Security Model, which is what DEFCON 658 brings into your contract and what Def Stan 05-138 specifies. Cyber Essentials is a substantial part of the lower risk profiles, and it is required for DCC, but it is not a substitute for the model.
Which should I do first?
First establish the required DCC level and organisational scope, then confirm Cyber Essentials covers the applicable systems. Cyber Essentials must be in place for DCC certification. Preparation for the wider DCC controls can proceed alongside it.
Do I need Cyber Essentials Plus?
For DCC Levels 2 and 3, yes. At Levels 0 and 1, Cyber Essentials is what is required. Your contract may ask for Cyber Essentials Plus independently of DCC, so check the terms rather than assuming.
Can you certify both?
Yes for Cyber Essentials, Cyber Essentials Plus and DCC Level 0, for which we hold the relevant appointments. Higher-level readiness work and the formal assessment route are agreed separately before engagement.
My Cyber Essentials certificate is current. Am I covered for DCC?
Check its scope, named entity, validity and relationship to the proposed organisational DCC scope. Holding Cyber Essentials does not automatically meet DCC’s remaining controls. A scope or renewal change may be needed before assessment.
