WHAT IS DCC LEVEL 0?
Defence Cyber Certification (DCC) is the Ministry of Defence's framework for managing cyber security across its supply chain. DCC Level 0 is the entry-level certification within the scheme, designed for organisations with a Very Low assessed cyber risk profile. It is assessed against Def Stan 05-138 (Issue 4). DCC is currently not mandatory - applicants may still tender for MOD contracts via the normal process. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026. Early certification is strongly advised.
Cyber Essentials is a mandatory prerequisite for DCC Level 0 - you must hold a valid CE certificate with a scope that aligns to your DCC scope before applying. DCC Level 0 is then assessed against Def Stan 05-138 (Issue 4), with MOD-specific requirements and context for the defence supply chain. It is delivered and certified by IASME Approved Certification Bodies - including Vincent Cyber Defence.
WHY WAS DCC INTRODUCED?
The MOD recognised that its supply chain represented a significant cyber risk. Many cyber attacks on defence organisations target smaller suppliers with weaker security rather than attacking the MOD directly. DCC was introduced to raise the baseline of cyber security across all organisations that work with the MOD, regardless of size.
WHAT IS DEFCON 658?
DEFCON 658 is a MOD standard contractual condition that references the Cyber Security Model. When DEFCON 658 appears in a contract, it means you are required to hold and maintain an appropriate DCC certification. For organisations with a "Very Low" risk profile, that means DCC Level 0.
DEFCON 658 references the DCC certification requirement in MOD contracts. DCC is currently not mandatory - applicants may still tender for MOD contracts via the normal process. Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026. Early certification is strongly advised.
WHAT IS THE CYBER SECURITY MODEL (CSM) V4?
The Cyber Security Model is the MOD's framework for assessing and managing cyber risk in its supply chain. Version 4 updated the requirements and introduced the DCC certification scheme. Under CSM v4, all MOD suppliers are assessed for cyber risk and assigned a profile - Very Low, Low, Medium, High, or Very High. The required DCC certification level corresponds to this risk profile.
- Very Low risk: DCC Level 0 (Cyber Essentials-based)
- Low risk: DCC Level 1 (additional controls)
- Medium and above: Higher DCC levels with more rigorous requirements
HOW IS DCC LEVEL 0 DIFFERENT FROM CYBER ESSENTIALS?
As noted above, Cyber Essentials is a mandatory prerequisite - not incorporated within the DCC process itself. Key differences between CE and DCC Level 0:
- MOD supply chain-specific context and requirements
- Additional questions relevant to the defence environment
- A 3-year certificate validity (versus 1 year for standard CE)
- Formal recognition within the DEFCON 658 / CSM framework
In practice, many of the technical controls are the same - but the certification is specifically recognised by the MOD for defence supply chain purposes.
WHO NEEDS DCC LEVEL 0?
- SMEs and new entrants to the MOD supply chain
- Organisations bidding for MOD contracts that reference DEFCON 658
- Suppliers assessed as "Very Low" cyber risk under CSM v4
- Businesses working toward prime contractor requirements in defence
Is DCC Level 0 Currently Mandatory? DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised. Read our full breakdown of the December 2026 deadline →
THE THREE DCC LEVEL 0 CONTROLS
DCC Level 0 is assessed against three controls drawn from Def Stan 05-138 (Issue 4). All three must be met - there is no partial pass.
Control 0001 - Cyber Essentials
Your CE certificate must be current and must cover all internet-connected devices and networks within your DCC assessment scope. There are two sub-controls: scope alignment (0001.1) and a commitment to maintain CE for the full 3-year DCC certificate period (0001.2).
Critical: A misaligned CE scope triggers automatic failure before any other control is assessed. Your CE certificate and DCC scoping statement must align - any gap here ends the assessment immediately.
Control 2314 - UK GDPR & Data Protection
The assessor reviews evidence that your organisation processes personal data lawfully under UK GDPR. Two sub-controls:
- 2314.1 - GDPR Policies & Procedures. Documented policies ensuring UK GDPR compliance. Evidence scales by size - micro and small organisations can use a simpler incorporated document; medium and large require a dedicated Data Protection policy supported by a risk register.
- 2314.2 - Data Protection Impact Assessments (DPIAs). Evidence that DPIAs are conducted against the personal data your organisation holds. Accepted evidence includes your DPIA procedure, template, or a completed report. Supporting evidence such as ICO registration, a public privacy notice, and a named Data Protection Lead may also be reviewed.
If you already have a solid data protection framework in place, this control is unlikely to present a significant challenge.
Control 2500 - Business Resilience
The assessor reviews whether your systems can withstand and recover from a cyber incident. Two sub-controls:
- 2500.1 - Resilience Needs Assessment. A documented assessment of how resilient your systems must be against cyber-attack and failure. Evidence scales by size - micro organisations need a brief document identifying risks to essential systems; large organisations require a full risk register.
- 2500.2 - Resilience Implementation Evidence. Concrete evidence that resilience has been built into your systems. Policy documents are not accepted for this sub-control. Assessors require practical evidence: backup configuration records, offsite or cloud backup logs, tested restore reports with success logs, or redundant infrastructure documentation.
DCC LEVEL 0 PREPARATION CHECKLIST
Use this checklist before engaging a certification body. All items should be in place before your assessment begins.
- Confirm your required level with your MOD contracting authority or prime contractor - the Supplier Assurance Questionnaire (SAQ) determines this.
- Hold a valid Cyber Essentials certificate issued by an IASME-approved body, covering all internet-connected devices in your intended DCC scope.
- Prepare a DCC scoping statement - a written document defining what is in and out of scope, with a clear rationale aligned to your CE certificate scope.
- Confirm ICO registration is current for your organisation.
- Have a GDPR policy appropriate to your size - micro/small: an incorporated document is acceptable; medium/large: a dedicated Data Protection policy and risk register.
- Have DPIA evidence in place - a procedure, template, or completed report showing assessments are conducted against your data types.
- Document your resilience needs assessment identifying which systems are essential and the risks they face.
- Gather concrete backup and recovery evidence - backup configuration records and tested restore reports. Untested policies will not satisfy Control 2500.2.
For the full sub-control evidence requirements, use our free DCC Level 0 readiness checklist.
HOW LONG IS THE CERTIFICATE VALID?
DCC Level 0 certificates are valid for three years - significantly longer than the 12-month validity of standard Cyber Essentials. This means less frequent renewal overhead for defence suppliers, while still maintaining a meaningful assurance standard.
There is an important annual obligation, however. You must re-certify to Cyber Essentials every year and complete an annual attestation confirming that your controls are still in place and your scope has not significantly changed. The three-year DCC certificate does not remove the need for annual CE renewal - it runs alongside it. If your CE certificate lapses, your DCC certification is at risk.
HOW DO I GET DCC LEVEL 0 CERTIFIED?
DCC Level 0 assessments can only be delivered by IASME Approved Certification Bodies. Vincent Cyber Defence is approved to deliver DCC assessments and issue DCC Level 0 certificates directly. Our process covers scoping, gap analysis, guided assessment, and certification - with a focus on first-time pass and minimal disruption to your team. All DCC Level 0 assessments include a document template bundle to support your compliance documentation. DCC Level 0 is fixed-priced from £799 + VAT including the IASME certification fee - view DCC Level 0 pricing →
✓ Confirm your evidence is ready. Use our free DCC Level 0 readiness checklist to work through all six sub-controls across the three Def Stan 05-138 controls before your assessment begins.
Need DCC Level 0 certification? Fixed-priced from £799 + VAT — IASME certification fee included, 3-year certificate, December 2026 deadline approaching. We guide UK defence suppliers through DCC Level 0 with a first-time pass focus.