// MOD Supply Chain

DCC
LEVEL 0

Defence Cyber Certification (DCC) Level 0 - the entry-level certification for UK defence supply chain organisations assessed at Very Low cyber risk. Assessed against Def Stan 05-138 (Issue 4) by Vincent Cyber Defence, an IASME Approved Certification Body.

3yr
Certificate Validity
05-138
Def Stan Assessed
i4
Def Stan Issue 4
IASME Approved Body
DCC Level 0 certification for MOD defence supply chain by Vincent Cyber Defence
// What Is DCC Level 0

DEFENCE CYBER CERTIFICATION EXPLAINED

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It strengthens the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.

DCC Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It is suitable for suppliers providing low-risk goods or services - requiring compliance with three basic controls.

As an IASME Approved Certification Body, Vincent Cyber Defence is authorised to deliver DCC Level 0 assessments and issue DCC certificates directly. Once certified, your organisation is published on the IASME public registry and receives a digital certificate and verifiable digital badge.

Who Is DCC Level 0 For?

  • Any organisation can apply - you do not need to be a current defence contractor
  • Suppliers whose MOD contract carries a Very Low Cyber Risk Profile (CRP)
  • Organisations certifying proactively ahead of future MOD opportunities
  • Businesses in the wider defence supply chain looking to strengthen their cyber posture

Is DCC Level 0 Currently Mandatory?

DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised. Read our full breakdown of the December 2026 deadline →

CERTIFY BEFORE YOU NEED IT

DCC certification is expected to become mandatory across all Defence procurement. Certifying now means you're ready when the requirement lands - not scrambling to catch up.

With the Cyber Security Model (CSM) in place, a DCC certificate also replaces the ad-hoc supplier questionnaires that MOD and prime contractors previously used - proving your cyber posture once, to a recognised standard, rather than answering bespoke requests for every contract.

Start Your Assessment →DCC Readiness Checklist →
  • 📐

    ASSESSED AGAINST DEF STAN 05-138

    The cornerstone of the DCC scheme. Issue 4 expands scope to enhancing overall organisational resilience, aligned to the CAF framework and NIST and ISO standards.

  • 🔑

    CYBER ESSENTIALS IS MANDATORY

    A valid Cyber Essentials certificate - with scope aligned to your DCC scope - is a prerequisite. Misalignment between scopes will result in certification failure. CE Plus is not required at Level 0.

  • 🔒

    3-YEAR CERTIFICATE VALIDITY

    Valid for three years with annual Cyber Essentials recertification and an annual attestation confirming controls are maintained and scope is unchanged.

  • 🌐

    LISTED ON THE IASME WEBSITE

    Once certified, your organisation is published on the IASME public registry and you receive a digital certificate and verifiable digital badge for use on your website or email footer.

// The Process

HOW DCC LEVEL 0 WORKS

1

CONFIRM CE SCOPE

Ensure you hold a valid Cyber Essentials certificate with a scope that aligns with your intended DCC assessment scope - misalignment will cause certification failure.

2

DEFINE DCC SCOPE

We review your scoping statement - covering what is included, excluded, and your rationale - and challenge it to ensure it is logical and clearly documented.

3

ASSESSMENT

We assess your organisation against the Def Stan 05-138 (Issue 4) controls, reviewing evidence and confirming compliance as an IASME Approved Body.

4

CERTIFIED ✓

Your DCC Level 0 certificate is issued. You receive a digital certificate and verifiable badge. Your organisation is published on the IASME public registry. Valid for 3 years.

// The Controls

WHAT YOU'RE ASSESSED AGAINST

Level 0 covers three controls drawn from Def Stan 05-138 (Issue 4). All three must be met - there is no partial pass.

Control 0001

CYBER ESSENTIALS

Two sub-controls: your CE certificate must cover all internet-connected devices in your DCC scope (0001.1), and your organisation must commit to maintaining CE for the full 3-year duration of your DCC certificate (0001.2). Scope misalignment fails the assessment immediately.

  • CE certificate covers full DCC scope
  • Commitment to maintain CE throughout DCC period
  • Renewal history or attestation available
Control 2314

UK GDPR COMPLIANCE

Two sub-controls: documented policies and procedures for UK GDPR compliance (2314.1 - evidence requirements vary by org size), and DPIAs conducted against data types your organisation stores or processes (2314.2). Supporting evidence such as ICO registration, privacy notice, and data mapping may also be reviewed.

  • GDPR policies/procedures (size-appropriate)
  • DPIAs conducted against data types held
  • Evidence scaled to organisation size
Control 2500

RESILIENT NETWORKS AND SYSTEMS

Two sub-controls: a documented assessment of how resilient your systems need to be against cyber-attack and failure (2500.1 - varies by org size), and concrete evidence that resilience is built in (2500.2). Policy documents alone are not accepted for 2500.2 - practical implementation evidence is required.

  • Resilience needs assessment (size-appropriate)
  • Concrete implementation evidence (backups, restore)
  • Policies alone do not satisfy 2500.2

Automatic Failure Conditions

A missing or expired Cyber Essentials certificate, or a CE scope that does not adequately cover your DCC scope, results in immediate failure - no further controls are assessed.

// Evidence Requirements

WHAT YOU'LL NEED TO PROVIDE

A breakdown of the specific documents and evidence required under each of the six DCC Level 0 sub-controls. Evidence requirements for 2314.1 and 2500.1 vary by organisation size. Prepare everything below before your assessment begins.

Control 0001

SCOPING & BOUNDARY

Two sub-controls covering CE scope alignment and the commitment to maintain CE throughout the DCC certification period.

  • 0001.1 - CE Certificate & Scope AlignmentYour CE certificate number, CE self-assessment questionnaire or report, and a diagram showing your CE scope in relation to your DCC scope. All internet-connected devices in your DCC scope must be covered by CE. Misalignment is an immediate failure - no further controls assessed.
  • 0001.2 - CE Maintenance CommitmentAn attestation confirming your organisation will maintain CE for the full duration of the DCC certificate, or a renewal history demonstrating regular annual recertification. DCC is valid for 3 years - CE must be renewed every year throughout.
Control 2314

UK GDPR & DATA PROTECTION

Two sub-controls covering GDPR policies (with size-dependent evidence requirements) and DPIAs conducted against data types your organisation holds.

  • 2314.1 - GDPR Policies & ProceduresDocumented policies and procedures ensuring UK GDPR compliance. Evidence varies by size: micro/small organisations may provide a simpler document or an incorporated section within existing company documentation. Medium/large organisations require a dedicated GDPR or Data Protection policy supported by a risk register. Supporting evidence that may also be reviewed includes ICO registration, a public privacy notice, data mapping records, and a named Data Protection Lead.
  • 2314.2 - Data Protection Impact AssessmentsEvidence that your organisation conducts DPIAs against the categories of personal data it stores or processes. Accepted evidence: your DPIA procedure outlining how assessments are conducted, the template or tool used, or an output report from a completed DPIA. If no high-risk processing has been identified, document the rationale.
Control 2500

BUSINESS RESILIENCE

Two sub-controls: first, assessing how resilient your systems need to be; second, demonstrating you have acted on that assessment with concrete implementation. Policy documents alone do not satisfy 2500.2.

  • 2500.1 - Resilience Needs AssessmentA document showing your organisation has assessed which systems must be resilient and to what degree. Evidence varies by size: micro organisations may provide a brief risk document. Small/medium organisations require a risk assessment covering essential systems and specific threats. Large organisations require a risk register and multiple supporting documents. The evidence must identify which systems are in scope and the threats assessed against them.
  • 2500.2 - Resilience Implementation EvidenceConcrete evidence that resilience has been built into your systems - not policy documents or plans. Accepted evidence: automated backup configuration records, offsite or cloud backup logs, tested restore reports with success logs, redundant infrastructure documentation, or UPS records. Assessors specifically require evidence of what has been done - plans or policies alone are not accepted for this sub-control.

Automatic Failure Condition

If your Cyber Essentials scope does not align with your DCC scope (0001.1), or if 2500.2 evidence consists only of policy documents with no concrete implementation proof, the assessment will trigger an automatic failure condition. We review your documentation before the formal assessment begins to identify and resolve any gaps before they become failures.

// FAQ

DCC LEVEL 0 QUESTIONS

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It aims to strengthen the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.
Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It requires compliance with three controls: an active Cyber Essentials certificate (the mandatory baseline), GDPR compliance demonstrating secure processing of personal data in line with ICO standards, and resilient network operation showing internal systems are configured to minimise basic cyber threats. It is suitable for suppliers providing low-risk goods or services - for example, non-technical goods, facilities management, or similar.
DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, compliance with the UK Defence standard is expected to become a requirement in all Defence procurement and contract activities - so early certification is strongly encouraged.
Yes. Cyber Essentials is a mandatory baseline requirement for DCC Level 0. Your Cyber Essentials certification scope must align with or overlap the scope of your intended DCC assessment - misalignment will result in certification failure. Note: Level 0 requires standard Cyber Essentials only - Cyber Essentials Plus is not required at this level.
DCC Level 0 is assessed against the Cyber Security Defence Standard - Def Stan 05-138. Its latest iteration, Issue 4, expands scope beyond protecting MOD-identifiable information to enhancing the overall resilience of an organisation against threats. It aligns to national and international standards, including the CAF framework and NIST and ISO standards.
Your DCC scope should include all essential functions and services necessary for your organisation to operate securely and resiliently. Non-essential parts of your organisation do not need to be included. You must provide a clear scoping statement outlining what is included and excluded, how it aligns with your Cyber Essentials scope, and the rationale behind your decisions. We will review and challenge your scope to ensure it is logical and clearly documented.
Yes - the DCC Level 0 certificate covers all of your contracts at or below the certified level. This streamlines the process by requiring only one assessment rather than separate assessments for each individual contract.
Your DCC certificate is valid for three years. You must re-certify annually to Cyber Essentials and complete an annual attestation confirming you are meeting and maintaining the controls and that your scope has not significantly changed. Normal organisational changes are considered routine and do not typically require recertification - however, significant changes should be reviewed with us to determine whether the scope has been substantially impacted.
The MOD determines the required certification level based on the nature and sensitivity of the contracted work - its Cyber Risk Profile (CRP). This will be decided by the MOD or your Prime contractor. If you are unsure of your required level, speak to us and we can help clarify this before you start the process.
Control 2314 covers two sub-questions. Sub-control 2314.1 asks whether your organisation has documented policies and procedures ensuring UK GDPR compliance - evidence requirements vary by size (smaller organisations can provide a simpler or incorporated document; larger organisations need a dedicated policy and risk register). Sub-control 2314.2 asks whether your organisation conducts DPIAs against the data types it holds, evidenced by your DPIA procedure, the template or tool used, or an output report. Supporting evidence such as ICO registration, a public privacy notice, and a named Data Protection Lead may also be reviewed. If you already have a solid data protection framework in place, this control is unlikely to present a significant challenge.
Control 2500 covers two sub-questions. Sub-control 2500.1 asks whether you have assessed how resilient your systems need to be against cyber-attack and failure - evidence requirements vary by size (micro organisations can provide a brief risk document; large organisations need a risk register and multiple supporting documents). Sub-control 2500.2 asks whether you have actually built that resilience into your systems. Critically, policy documents are not accepted for 2500.2 - assessors require concrete implementation evidence such as backup configuration records, offsite backup logs, tested restore reports with success logs, or redundant infrastructure documentation. If you can describe what you have done rather than what you plan to do, and can show the evidence, this control should be straightforward.
We specialise in DCC Level 0 assessments. If your MOD contract requires Level 1, 2, or 3, you will need to work with a Certification Body accredited for those higher levels. We are happy to advise you on this and help point you in the right direction.
// Transparent Pricing

HOW MUCH DOES DCC LEVEL 0 COST?

Fixed prices based on organisation size. IASME certification fee included. No hidden charges.

Organisation SizeEmployeesPrice + VAT
Micro1–9 employees£729
Small10–49 employees£910
Medium50–249 employees£1,500
Large250+ employees£1,900

📋 CYBER ESSENTIALS PREREQUISITE

DCC Level 0 requires a valid Cyber Essentials certificate. If you do not yet hold one, we can manage both certifications together as a single engagement - Cyber Essentials first, then DCC Level 0. Learn about Cyber Essentials →

// Client Reviews

WHAT OUR CLIENTS SAY

★★★★★
"VCD managed our Cyber Essentials and DCC Level 0 together as one engagement. The scoping guidance was invaluable - we passed first time with no issues."

- CONTRACTS DIRECTOR / MOD Supplier, South East

★★★★★
"The team understood the Def Stan 05-138 requirements in detail and guided us through every control clearly. We had our DCC certificate well before our contract deadline."

- HEAD OF COMPLIANCE / Defence Supply Chain

★★★★★
"We were unsure whether our Cyber Essentials scope aligned with DCC requirements. VCD identified the gap before we started and we avoided a costly restart. Excellent service."

- MANAGING DIRECTOR / Engineering Services

Client names are withheld in line with confidentiality requirements; character references are available upon request.

🛡️

GOVERNMENT CYBER RESILIENCE PLEDGE SIGNATORY

Vincent Cyber Defence has signed the Government Cyber Resilience Pledge - including the commitment to require Cyber Essentials across our supply chain. Action 3 of the pledge directly mirrors the supply chain cyber security requirements being rolled out across MOD procurement. View our signed declaration →

START YOUR DCC LEVEL 0 ASSESSMENT

Before reaching out, confirm you hold a valid Cyber Essentials certificate with a scope that covers your intended DCC scope. Then contact our UK team - no jargon, no hard sell.

// Blog & Guides

LATEST INSIGHTS

View All Articles →
// Get In Touch

GET CERTIFIED TODAY

Fill in the form and we'll be in touch shortly. No jargon, no hard sell.