The MOD supply chain deadline is 31 December 2026. We review your evidence before the formal assessment begins - most applicants already have the foundations, they just need correctly documenting. Direct lead assessor with defence sector background throughout. IASME fee included in the quoted price.
The scheme requirements are fixed. The preparation and support you receive from your certification body is not.
Most certification bodies assess what you submit. We review your evidence before the formal assessment begins, identifying and resolving gaps before they affect your result. It is the difference between a preparation service and a tick-box process.
You deal with your Lead Assessor from first contact through to certification. No helpdesk, no account managers, no rotating contacts. The person who knows your case is the person who certifies it.
Your DCC certificate requires attestation in Year 1 and Year 2 only, confirming controls are maintained. We include ongoing support for this as standard. Most certification bodies do not.

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It strengthens the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.
DCC Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It is suitable for suppliers providing low-risk goods or services - requiring compliance with three basic controls.
As an IASME Approved Certification Body, Vincent Cyber Defence is authorised to deliver DCC Level 0 assessments and issue DCC certificates directly. Once certified, your organisation is published on the IASME public registry and receives a digital certificate and verifiable digital badge.
DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised. Read our full breakdown of the December 2026 deadline →
Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026. Certifying now means you're ready ahead of the deadline - not scrambling to catch up.
Start Your Assessment →DCC Readiness Checklist →The cornerstone of the DCC scheme. Issue 4 expands scope to enhancing overall organisational resilience, aligned to the CAF framework and NIST and ISO standards.
A valid Cyber Essentials certificate - with scope aligned to your DCC scope - is a prerequisite. Misalignment between scopes will result in certification failure. CE Plus is not required at Level 0.
Valid for three years with annual Cyber Essentials recertification and attestation in Year 1 and Year 2 only, confirming controls are maintained and scope is unchanged.
Once certified, your organisation is published on the IASME public registry and you receive a digital certificate and verifiable digital badge for use on your website or email footer.
Ensure you hold a valid Cyber Essentials certificate with a scope that aligns with your intended DCC assessment scope. Your DCC scope cannot extend beyond the boundary of your CE certificate.
We review your scoping statement - covering what is included, excluded, and your rationale - and challenge it to ensure it is logical and clearly documented.
We assess your organisation against the Def Stan 05-138 (Issue 4) controls, reviewing evidence and confirming compliance as an IASME Approved Body.
Your DCC Level 0 certificate is issued. You receive a digital certificate and verifiable badge. Your organisation is published on the IASME public registry. Valid for 3 years.
Level 0 covers three controls drawn from Def Stan 05-138 (Issue 4). All three must be met - there is no partial pass.
Two sub-controls: your CE certificate must cover all internet-connected devices in your DCC scope (0001.1), and your organisation must commit to maintaining CE for the full 3-year duration of your DCC certificate (0001.2). Scope misalignment fails the assessment immediately.
Two sub-controls: documented policies and procedures for UK GDPR compliance (2314.1 - evidence requirements vary by org size), and DPIAs conducted against data types your organisation stores or processes (2314.2). Supporting evidence such as ICO registration, privacy notice, and data mapping may also be reviewed.
Two sub-controls: a documented assessment of how resilient your systems need to be against cyber-attack and failure (2500.1 - varies by org size), and concrete evidence that resilience is built in (2500.2). Policy documents alone are not accepted for 2500.2 - practical implementation evidence is required.
Automatic Failure Conditions
A missing or expired Cyber Essentials certificate, or a CE scope that does not adequately cover your DCC scope, results in immediate failure - no further controls are assessed.
A breakdown of the specific documents and evidence required under each of the six DCC Level 0 sub-controls. Evidence requirements for 2314.1 and 2500.1 vary by organisation size. Prepare everything below before your assessment begins.
Two sub-controls covering CE scope alignment and the commitment to maintain CE throughout the DCC certification period.
Two sub-controls covering GDPR policies (with size-dependent evidence requirements) and DPIAs conducted against data types your organisation holds.
Two sub-controls: first, assessing how resilient your systems need to be; second, demonstrating you have acted on that assessment with concrete implementation. Policy documents alone do not satisfy 2500.2.
Automatic Failure Condition
If your Cyber Essentials scope does not align with your DCC scope (0001.1), or if 2500.2 evidence consists only of policy documents with no concrete implementation proof, the assessment will trigger an automatic failure condition. We review your documentation before the formal assessment begins to identify and resolve any gaps before they become failures.
Most organisations are closer than they think
If you trade commercially, you almost certainly already hold the foundations. A privacy policy on your website and ICO registration satisfy much of Control 2314. A scheduled cloud backup - even OneDrive or Google Drive - can satisfy Control 2500 if it is configured, runs automatically, and you can show it has been tested. The gap for most small suppliers is not having nothing - it is having things undocumented or untested. We help you identify what you already have and map it to what the assessment requires.
Before the formal assessment begins, we'll ask you to share read-only access to your evidence documents - SharePoint, Google Drive, or equivalent works fine.
We review what you already have, identify any gaps, and tell you exactly what needs completing before the assessment begins - so nothing catches you out on the day.
You don't need everything to be perfect before sharing. Incomplete evidence is fine at this stage - that's what the pre-assessment review is for.
Fixed prices based on organisation size. IASME certification fee included. No hidden charges. Read our plain-English DCC Level 0 guide →
DCC Level 0 requires a valid Cyber Essentials certificate. If you do not yet hold one, we can manage both certifications together as a single engagement - Cyber Essentials first, then DCC Level 0. Learn about Cyber Essentials →
Cyber Essentials is a mandatory prerequisite for DCC Level 0. If you need both, we manage them together as a single engagement - CE first, then straight into DCC Level 0 once certified.
View Pricing →Vincent Cyber Defence has signed the Government Cyber Resilience Pledge - including the commitment to require Cyber Essentials across our supply chain. Action 3 of the pledge directly mirrors the supply chain cyber security requirements being rolled out across MOD procurement. View our signed declaration →
Every client works directly with a qualified lead assessor from first contact through to certification. No helpdesk, no handoffs, no rotating contacts - consistent, senior-level support throughout. This is a deliberate part of how Vincent Cyber Defence operates, not an afterthought.
All of our staff come from military and defence backgrounds. We understand the obligations and pressures of the MOD supply chain from direct experience - not just the certification standard.
"Vincent Cyber Defence managed our Cyber Essentials and DCC Level 0 together as one engagement. The scoping guidance was invaluable - we passed first time with no issues."
- CONTRACTS DIRECTOR / MOD Supplier, South East
"The team understood the Def Stan 05-138 requirements in detail and guided us through every control clearly. We had our DCC certificate well before our contract deadline."
- HEAD OF COMPLIANCE / Defence Supply Chain
"We were unsure whether our Cyber Essentials scope aligned with DCC requirements. Vincent Cyber Defence identified the gap before we started and we avoided a costly restart. Excellent service."
- MANAGING DIRECTOR / Engineering Services
Client names are withheld in line with confidentiality requirements; character references are available upon request.
Before reaching out, confirm you hold a valid Cyber Essentials certificate with a scope that covers your intended DCC scope. Then contact our UK team - no jargon, no add-ons, no hard sell.
DCC Level 0 proves your baseline cyber posture to the MOD. Here are the natural next steps to strengthen your security position further.
Add an independent technical audit to your CE certification. CE Plus verifies that your five controls are correctly implemented in practice, satisfying stricter supply chain requirements.
Explore CE Plus →// Next StepTest your defences under real attack conditions. Audit-ready CVSS-scored reports for SOC 2, ISO 27001, PCI DSS, and defence supply chain requirements. Free 30-day retest included.
Explore Pen Testing →// Next StepRetain a named virtual CISO to manage CE recertification, annual DCC attestation, security policies, and ongoing tender support. From £195/month + VAT, rolling monthly after 3 months.
Explore vCISO →