Assessment and certification
DSC is a Defence Cyber Certification body for Level 0. Confirm your organisation’s scope and the current scheme requirements before starting.
Level 0 routeDefence suppliers / Engineering businesses
Support your people, protect engineering data and prepare the evidence your customer requires.
Managed IT, cyber security and supplier assurance, with responsibilities agreed around your contract and existing internal team.

Contract requirements
Start with the Cyber Risk Profile, Risk Assessment Reference and security instructions supplied by your customer. These determine the controls and evidence to review.
Def Stan 05-138 sets out supplier cyber controls. DEFCON 658 covers the MOD Cyber Security Model, including subcontractor obligations; DEFCON 659 addresses security measures. Check the conditions and editions incorporated into your contract.
CSMv4 uses Levels 0 to 3. Older profile names do not map directly to those levels. If your requirement is unclear, confirm it with your customer before choosing an assessment.
DSC is a Defence Cyber Certification body for Level 0. Confirm your organisation’s scope and the current scheme requirements before starting.
Level 0 routeLevel 1 services are available, including review, remediation and evidence preparation. The engagement agrees the appointed body and formal assessment arrangements.
Level 1 servicesA DCC certificate does not currently replace the full Supplier Assurance Questionnaire. We help organise the controls and records relevant to your answers.
Compare DCC routesEngineering information
Design files, test results and customer material need named owners, controlled access and a recovery plan.
Match each answer to an implemented control, its owner and a dated record. JOSCAR registrations, renewals and prime-specific reviews can use an organised evidence index.
Identify who can change, share and recover each dataset. Include external partners, engineering workstations, shared storage and the interfaces to flight systems in the scope discussion.
Where AS9100 or the Cyber Assessment Framework (CAF) is relevant, agree how IT records support the review. Certification or conformance is not implied by a service engagement.
Services
Choose the work your organisation needs. Projects, managed services, preparation and formal assessments have their own scope.
Support for agreed devices, Microsoft 365, infrastructure and backups. Document recovery priorities, support hours and escalation paths alongside your internal team.
Review identity, endpoint protection and access to customer information. Managed Detection and Response (MDR) and incident response follow the agreed systems, actions and coverage.
Connect business systems and reduce repeated data entry, with permissions, change approval and logging considered during discovery. UK-hosted deployment options are available.
Review policies, technical evidence and outstanding actions. Agree who approves questionnaire answers and how evidence will be kept current after the initial review.
Our appointments and certification An appointed certification body for Cyber Essentials and Cyber Essentials Plus. Assured under the NCSC Cyber Advisor scheme. ISO 27001 certified by a UKAS-accredited certification body.
Handling and access
OFFICIAL and OFFICIAL-SENSITIVE information is handled against your contract and customer instructions. Scope can include encryption, need-to-know access, logging, secure disposal and hosting locations.
Our team is UK-based. SC and DV clearance are not held. Any work requiring clearance depends on the appropriate sponsorship, vetting and approval before that work starts.
UK-hosted options are available. ITAR, EAR and UK export control requirements are determined with your specialist advisers; we implement the agreed technical controls.
Questions
Check the Cyber Risk Profile and security requirements supplied by your customer. We help you identify the relevant Cyber Essentials, Cyber Essentials Plus and Defence Cyber Certification route. Preparation and formal assessment are scoped separately.
DEFCON 658 covers cyber obligations, including requirements passed to subcontractors. DEFCON 659 addresses security measures. Review the conditions and editions in your contract alongside any Security Aspects Letter. We identify the IT controls and evidence within our agreed scope.
We do not hold SC or DV clearance. Our team is UK-based. We confirm the permitted scope before accepting work; any task requiring clearance depends on appropriate sponsorship, vetting and approval.
We agree handling controls with you against the contract, information sensitivity and customer instructions. The scope can include access, encryption, logging, disposal and approved hosting locations. The marking alone does not impose a universal UK-only hosting requirement.
We can help organise the cyber security answers and supporting records for JOSCAR registration, renewal and related customer questionnaires. Your organisation approves the submission. We distinguish controls already in place from actions still outstanding.
We review the technical requirements with your export control advisers before accepting the work. Hosting, administrative access and audit records are agreed for the systems in scope. UK staffing or hosting alone does not establish ITAR or EAR compliance.
Next step
Tell us the required assessment, systems involved and target date. We can agree the review needed, the people involved and the basis for a quote.
0118 359 2220 · Reading, Berkshire
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.