Defence Cyber Certification (DCC) Level 0 - the entry-level certification for UK defence supply chain organisations assessed at Very Low cyber risk. Assessed against Def Stan 05-138 (Issue 4) by Vincent Cyber Defence, an IASME Approved Certification Body.

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It strengthens the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.
DCC Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It is suitable for suppliers providing low-risk goods or services - requiring compliance with three basic controls.
As an IASME Approved Certification Body, Vincent Cyber Defence is authorised to deliver DCC Level 0 assessments and issue DCC certificates directly. Once certified, your organisation is published on the IASME public registry and receives a digital certificate and verifiable digital badge.
DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised. Read our full breakdown of the December 2026 deadline →
DCC certification is expected to become mandatory across all Defence procurement. Certifying now means you're ready when the requirement lands - not scrambling to catch up.
With the Cyber Security Model (CSM) in place, a DCC certificate also replaces the ad-hoc supplier questionnaires that MOD and prime contractors previously used - proving your cyber posture once, to a recognised standard, rather than answering bespoke requests for every contract.
Start Your Assessment →DCC Readiness Checklist →The cornerstone of the DCC scheme. Issue 4 expands scope to enhancing overall organisational resilience, aligned to the CAF framework and NIST and ISO standards.
A valid Cyber Essentials certificate - with scope aligned to your DCC scope - is a prerequisite. Misalignment between scopes will result in certification failure. CE Plus is not required at Level 0.
Valid for three years with annual Cyber Essentials recertification and an annual attestation confirming controls are maintained and scope is unchanged.
Once certified, your organisation is published on the IASME public registry and you receive a digital certificate and verifiable digital badge for use on your website or email footer.
Ensure you hold a valid Cyber Essentials certificate with a scope that aligns with your intended DCC assessment scope - misalignment will cause certification failure.
We review your scoping statement - covering what is included, excluded, and your rationale - and challenge it to ensure it is logical and clearly documented.
We assess your organisation against the Def Stan 05-138 (Issue 4) controls, reviewing evidence and confirming compliance as an IASME Approved Body.
Your DCC Level 0 certificate is issued. You receive a digital certificate and verifiable badge. Your organisation is published on the IASME public registry. Valid for 3 years.
Level 0 covers three controls drawn from Def Stan 05-138 (Issue 4). All three must be met - there is no partial pass.
Two sub-controls: your CE certificate must cover all internet-connected devices in your DCC scope (0001.1), and your organisation must commit to maintaining CE for the full 3-year duration of your DCC certificate (0001.2). Scope misalignment fails the assessment immediately.
Two sub-controls: documented policies and procedures for UK GDPR compliance (2314.1 - evidence requirements vary by org size), and DPIAs conducted against data types your organisation stores or processes (2314.2). Supporting evidence such as ICO registration, privacy notice, and data mapping may also be reviewed.
Two sub-controls: a documented assessment of how resilient your systems need to be against cyber-attack and failure (2500.1 - varies by org size), and concrete evidence that resilience is built in (2500.2). Policy documents alone are not accepted for 2500.2 - practical implementation evidence is required.
Automatic Failure Conditions
A missing or expired Cyber Essentials certificate, or a CE scope that does not adequately cover your DCC scope, results in immediate failure - no further controls are assessed.
A breakdown of the specific documents and evidence required under each of the six DCC Level 0 sub-controls. Evidence requirements for 2314.1 and 2500.1 vary by organisation size. Prepare everything below before your assessment begins.
Two sub-controls covering CE scope alignment and the commitment to maintain CE throughout the DCC certification period.
Two sub-controls covering GDPR policies (with size-dependent evidence requirements) and DPIAs conducted against data types your organisation holds.
Two sub-controls: first, assessing how resilient your systems need to be; second, demonstrating you have acted on that assessment with concrete implementation. Policy documents alone do not satisfy 2500.2.
Automatic Failure Condition
If your Cyber Essentials scope does not align with your DCC scope (0001.1), or if 2500.2 evidence consists only of policy documents with no concrete implementation proof, the assessment will trigger an automatic failure condition. We review your documentation before the formal assessment begins to identify and resolve any gaps before they become failures.
Fixed prices based on organisation size. IASME certification fee included. No hidden charges.
DCC Level 0 requires a valid Cyber Essentials certificate. If you do not yet hold one, we can manage both certifications together as a single engagement - Cyber Essentials first, then DCC Level 0. Learn about Cyber Essentials →
"VCD managed our Cyber Essentials and DCC Level 0 together as one engagement. The scoping guidance was invaluable - we passed first time with no issues."
- CONTRACTS DIRECTOR / MOD Supplier, South East
"The team understood the Def Stan 05-138 requirements in detail and guided us through every control clearly. We had our DCC certificate well before our contract deadline."
- HEAD OF COMPLIANCE / Defence Supply Chain
"We were unsure whether our Cyber Essentials scope aligned with DCC requirements. VCD identified the gap before we started and we avoided a costly restart. Excellent service."
- MANAGING DIRECTOR / Engineering Services
Client names are withheld in line with confidentiality requirements; character references are available upon request.
Vincent Cyber Defence has signed the Government Cyber Resilience Pledge - including the commitment to require Cyber Essentials across our supply chain. Action 3 of the pledge directly mirrors the supply chain cyber security requirements being rolled out across MOD procurement. View our signed declaration →
Before reaching out, confirm you hold a valid Cyber Essentials certificate with a scope that covers your intended DCC scope. Then contact our UK team - no jargon, no hard sell.