// MOD Supply Chain

GET DCC LEVEL 0
CERTIFIED.

The MOD supply chain deadline is 31 December 2026. We review your evidence before the formal assessment begins - most applicants already have the foundations, they just need correctly documenting. Direct lead assessor with defence sector background throughout. IASME fee included in the quoted price.

NAMED LEAD ASSESSOR3-YEAR CERTIFICATENO ADD-ONSFROM £650 + VAT
3yr
Certificate Validity
05-138
Def Stan Assessed
i4
Def Stan Issue 4
Dec '26
MOD Deadline
// Why Choose Us

WHY VINCENT CYBER DEFENCE FOR DCC?

The scheme requirements are fixed. The preparation and support you receive from your certification body is not.

// Consultative

WE REVIEW BEFORE WE ASSESS

Most certification bodies assess what you submit. We review your evidence before the formal assessment begins, identifying and resolving gaps before they affect your result. It is the difference between a preparation service and a tick-box process.

// Your Assessor

DIRECT ASSESSOR, NO HANDOFFS

You deal with your Lead Assessor from first contact through to certification. No helpdesk, no account managers, no rotating contacts. The person who knows your case is the person who certifies it.

// Included

ATTESTATION SUPPORT INCLUDED

Your DCC certificate requires attestation in Year 1 and Year 2 only, confirming controls are maintained. We include ongoing support for this as standard. Most certification bodies do not.

DCC Level 0 certification for MOD defence supply chain by Vincent Cyber Defence
// What Is DCC Level 0

DEFENCE CYBER CERTIFICATION EXPLAINED

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It strengthens the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.

DCC Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It is suitable for suppliers providing low-risk goods or services - requiring compliance with three basic controls.

As an IASME Approved Certification Body, Vincent Cyber Defence is authorised to deliver DCC Level 0 assessments and issue DCC certificates directly. Once certified, your organisation is published on the IASME public registry and receives a digital certificate and verifiable digital badge.

Who Is DCC Level 0 For?

  • Any organisation can apply - you do not need to be a current defence contractor
  • Suppliers whose MOD contract carries a Very Low Cyber Risk Profile (CRP)
  • Organisations certifying proactively ahead of future MOD opportunities
  • Businesses in the wider defence supply chain looking to strengthen their cyber posture

Is DCC Level 0 Currently Mandatory?

DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised. Read our full breakdown of the December 2026 deadline →

CERTIFY BEFORE YOU NEED IT

Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026. Certifying now means you're ready ahead of the deadline - not scrambling to catch up.

Start Your Assessment →DCC Readiness Checklist →
  • ASSESSED AGAINST DEF STAN 05-138

    The cornerstone of the DCC scheme. Issue 4 expands scope to enhancing overall organisational resilience, aligned to the CAF framework and NIST and ISO standards.

  • CYBER ESSENTIALS IS MANDATORY

    A valid Cyber Essentials certificate - with scope aligned to your DCC scope - is a prerequisite. Misalignment between scopes will result in certification failure. CE Plus is not required at Level 0.

  • 3-YEAR CERTIFICATE VALIDITY

    Valid for three years with annual Cyber Essentials recertification and attestation in Year 1 and Year 2 only, confirming controls are maintained and scope is unchanged.

  • LISTED ON THE IASME WEBSITE

    Once certified, your organisation is published on the IASME public registry and you receive a digital certificate and verifiable digital badge for use on your website or email footer.

// The Process

HOW DCC LEVEL 0 WORKS

1

CONFIRM CE SCOPE

Ensure you hold a valid Cyber Essentials certificate with a scope that aligns with your intended DCC assessment scope. Your DCC scope cannot extend beyond the boundary of your CE certificate.

2

DEFINE DCC SCOPE

We review your scoping statement - covering what is included, excluded, and your rationale - and challenge it to ensure it is logical and clearly documented.

3

ASSESSMENT

We assess your organisation against the Def Stan 05-138 (Issue 4) controls, reviewing evidence and confirming compliance as an IASME Approved Body.

4

CERTIFIED ✓

Your DCC Level 0 certificate is issued. You receive a digital certificate and verifiable badge. Your organisation is published on the IASME public registry. Valid for 3 years.

// The Controls

WHAT YOU'RE ASSESSED AGAINST

Level 0 covers three controls drawn from Def Stan 05-138 (Issue 4). All three must be met - there is no partial pass.

Control 0001

CYBER ESSENTIALS

Two sub-controls: your CE certificate must cover all internet-connected devices in your DCC scope (0001.1), and your organisation must commit to maintaining CE for the full 3-year duration of your DCC certificate (0001.2). Scope misalignment fails the assessment immediately.

  • CE certificate covers full DCC scope
  • Commitment to maintain CE throughout DCC period
  • Renewal history or attestation available
Control 2314

UK GDPR COMPLIANCE

Two sub-controls: documented policies and procedures for UK GDPR compliance (2314.1 - evidence requirements vary by org size), and DPIAs conducted against data types your organisation stores or processes (2314.2). Supporting evidence such as ICO registration, privacy notice, and data mapping may also be reviewed.

  • GDPR policies/procedures (size-appropriate)
  • DPIAs conducted against data types held
  • Evidence scaled to organisation size
Control 2500

RESILIENT NETWORKS AND SYSTEMS

Two sub-controls: a documented assessment of how resilient your systems need to be against cyber-attack and failure (2500.1 - varies by org size), and concrete evidence that resilience is built in (2500.2). Policy documents alone are not accepted for 2500.2 - practical implementation evidence is required.

  • Resilience needs assessment (size-appropriate)
  • Concrete implementation evidence (backups, restore)
  • Policies alone do not satisfy 2500.2

Automatic Failure Conditions

A missing or expired Cyber Essentials certificate, or a CE scope that does not adequately cover your DCC scope, results in immediate failure - no further controls are assessed.

// Evidence Requirements

WHAT YOU'LL NEED TO PROVIDE

A breakdown of the specific documents and evidence required under each of the six DCC Level 0 sub-controls. Evidence requirements for 2314.1 and 2500.1 vary by organisation size. Prepare everything below before your assessment begins.

Control 0001

SCOPING & BOUNDARY

Two sub-controls covering CE scope alignment and the commitment to maintain CE throughout the DCC certification period.

  • 0001.1 - CE Certificate & Scope AlignmentYour CE certificate number, CE self-assessment questionnaire or report, and a diagram showing your CE scope in relation to your DCC scope, along with an attestation. All internet-connected devices in your DCC scope must be covered by CE. Misalignment is an immediate failure - no further controls assessed.
  • 0001.2 - CE Maintenance CommitmentAn attestation confirming your organisation will maintain CE for the full duration of the DCC certificate, or a renewal history demonstrating regular annual recertification. DCC is valid for 3 years - CE must be renewed every year throughout.
Control 2314

UK GDPR & DATA PROTECTION

Two sub-controls covering GDPR policies (with size-dependent evidence requirements) and DPIAs conducted against data types your organisation holds.

  • 2314.1 - GDPR Policies & ProceduresDocumented policies and procedures ensuring UK GDPR compliance. Evidence varies by size: micro/small organisations may provide a simpler document or an incorporated section within existing company documentation. Medium/large organisations require a dedicated GDPR or Data Protection policy supported by a risk register. Supporting evidence that may also be reviewed includes ICO registration, a public privacy notice, data mapping records, and a named Data Protection Lead.
  • 2314.2 - Data Protection Impact AssessmentsEvidence that your organisation conducts DPIAs against the categories of personal data it stores or processes. Accepted evidence: your DPIA procedure outlining how assessments are conducted, the template or tool used, or an output report from a completed DPIA. If no high-risk processing has been identified, document the rationale.
Control 2500

BUSINESS RESILIENCE

Two sub-controls: first, assessing how resilient your systems need to be; second, demonstrating you have acted on that assessment with concrete implementation. Policy documents alone do not satisfy 2500.2.

  • 2500.1 - Resilience Needs AssessmentA document showing your organisation has assessed which systems must be resilient and to what degree. Evidence varies by size: micro organisations may provide a brief risk document. Small/medium organisations require a risk assessment covering essential systems and specific threats. Large organisations require a risk register and multiple supporting documents. The evidence must identify which systems are in scope and the threats assessed against them.
  • 2500.2 - Resilience Implementation EvidenceConcrete evidence that resilience has been built into your systems - not policy documents or plans. Accepted evidence: automated backup configuration records, offsite or cloud backup logs, tested restore reports with success logs, redundant infrastructure documentation, or UPS records. Assessors specifically require evidence of what has been done - plans or policies alone are not accepted for this sub-control.

Automatic Failure Condition

If your Cyber Essentials scope does not align with your DCC scope (0001.1), or if 2500.2 evidence consists only of policy documents with no concrete implementation proof, the assessment will trigger an automatic failure condition. We review your documentation before the formal assessment begins to identify and resolve any gaps before they become failures.

Most organisations are closer than they think

If you trade commercially, you almost certainly already hold the foundations. A privacy policy on your website and ICO registration satisfy much of Control 2314. A scheduled cloud backup - even OneDrive or Google Drive - can satisfy Control 2500 if it is configured, runs automatically, and you can show it has been tested. The gap for most small suppliers is not having nothing - it is having things undocumented or untested. We help you identify what you already have and map it to what the assessment requires.

// What We Need From You

SHARING YOUR EVIDENCE WITH US

Before the formal assessment begins, we'll ask you to share read-only access to your evidence documents - SharePoint, Google Drive, or equivalent works fine.

We review what you already have, identify any gaps, and tell you exactly what needs completing before the assessment begins - so nothing catches you out on the day.

You don't need everything to be perfect before sharing. Incomplete evidence is fine at this stage - that's what the pre-assessment review is for.

// Transparent Pricing

HOW MUCH DOES DCC LEVEL 0 COST?

Fixed prices based on organisation size. IASME certification fee included. No hidden charges. Read our plain-English DCC Level 0 guide →

Organisation SizeEmployeesPrice + VAT
Micro1–9 employees£650
Small10–49 employees£700
Medium50–249 employees£800
Large250+ employees£1000

CYBER ESSENTIALS PREREQUISITE

DCC Level 0 requires a valid Cyber Essentials certificate. If you do not yet hold one, we can manage both certifications together as a single engagement - Cyber Essentials first, then DCC Level 0. Learn about Cyber Essentials →

// CE Prerequisite

NEED CYBER ESSENTIALS TOO?

Cyber Essentials is a mandatory prerequisite for DCC Level 0. If you need both, we manage them together as a single engagement - CE first, then straight into DCC Level 0 once certified.

View Pricing →
// FAQ

DCC LEVEL 0 QUESTIONS

The Defence Cyber Certification (DCC) is a comprehensive cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD). It aims to strengthen the cyber resilience of the UK's defence supply chain, with Cyber Essentials at its core.
Level 0 is the entry-level certification, designed for organisations with a Very Low assessed cyber risk profile. It requires compliance with three controls: an active Cyber Essentials certificate (the mandatory baseline), GDPR compliance demonstrating secure processing of personal data in line with ICO standards, and resilient network operation showing internal systems are configured to minimise basic cyber threats. It is suitable for suppliers providing low-risk goods or services - for example, non-technical goods, facilities management, or similar. You deal directly with your named lead assessor throughout - no handoffs, no account managers, no helpdesk.
DCC is currently not mandatory. Applicants may still tender for MOD contracts via the normal process at this stage. However, Eleanor Fairford, Director of Cyber Defence & Risk at the MOD, has mandated that all defence industry partners achieve at least DCC Level 0 by 31 December 2026 - so early certification is strongly advised.
Yes. Cyber Essentials is a mandatory baseline requirement for DCC Level 0. Your Cyber Essentials certification scope must align with or overlap the scope of your intended DCC assessment - misalignment will result in certification failure. Note: Level 0 requires standard Cyber Essentials only - Cyber Essentials Plus is not required at this level.
DCC Level 0 is assessed against the Cyber Security Defence Standard - Def Stan 05-138. Its latest iteration, Issue 4, expands scope beyond protecting MOD-identifiable information to enhancing the overall resilience of an organisation against threats. It aligns to national and international standards, including the CAF framework and NIST and ISO standards.
Start with one question: what does your organisation need to keep operating? From there, work through five areas - the tools and technology you rely on, your operations and logistics, your administration, your staff, and your physical locations. Whatever falls inside those categories as essential to delivering your MOD-related work belongs in your DCC scope. It’s also fine to under-include as a first pass and adjust - we review and challenge every scoping statement before assessment, checking both for gaps and for scope that’s been drawn wider than it needs to be, which just adds unnecessary work.
Your DCC scope should include all essential functions and services necessary for your organisation to operate securely and resiliently. Non-essential parts of your organisation do not need to be included. You must provide a clear scoping statement outlining what is included and excluded, how it aligns with your Cyber Essentials scope, and the rationale behind your decisions. We will review and challenge your scope to ensure it is logical and clearly documented.
Yes - the DCC Level 0 certificate covers all of your contracts at or below the certified level. This streamlines the process by requiring only one assessment rather than separate assessments for each individual contract.
Your DCC certificate is valid for three years. You must re-certify annually to Cyber Essentials and complete an annual attestation confirming you are meeting and maintaining the controls and that your scope has not significantly changed. Normal organisational changes are considered routine and do not typically require recertification - however, significant changes should be reviewed with us to determine whether the scope has been substantially impacted.
The MOD determines the required certification level based on the nature and sensitivity of the contracted work - its Cyber Risk Profile (CRP). This will be decided by the MOD or your Prime contractor. If you are unsure of your required level, speak to us and we can help clarify this before you start the process.
No. This is a common misconception. MOD guidance is explicit that suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ - full completion of the SAQ to the required level remains mandatory. The MOD has stated an intention for the two to eventually converge, but that has not happened yet. Plan for both requirements to sit alongside each other for now.
Control 2314 covers two sub-questions. Sub-control 2314.1 asks whether your organisation has documented policies and procedures ensuring UK GDPR compliance - evidence requirements vary by size (smaller organisations can provide a simpler or incorporated document; larger organisations need a dedicated policy and risk register). Sub-control 2314.2 asks whether your organisation conducts DPIAs against the data types it holds, evidenced by your DPIA procedure, the template or tool used, or an output report. Supporting evidence such as ICO registration, a public privacy notice, and a named Data Protection Lead may also be reviewed. If you already have a solid data protection framework in place, this control is unlikely to present a significant challenge.
Control 2500 covers two sub-questions. Sub-control 2500.1 asks whether you have assessed how resilient your systems need to be against cyber-attack and failure - evidence requirements vary by size (micro organisations can provide a brief risk document; large organisations need a risk register and multiple supporting documents). Sub-control 2500.2 asks whether you have actually built that resilience into your systems. Critically, policy documents are not accepted for 2500.2 - assessors require concrete implementation evidence such as backup configuration records, offsite backup logs, tested restore reports with success logs, or redundant infrastructure documentation. If you can describe what you have done rather than what you plan to do, and can show the evidence, this control should be straightforward.
Each control is scored on a three-point scale: 0 points if not met, 1 point if partially met (some of the control’s questions meet the baseline while others don’t), and 2 points if fully met. At Level 0, you must meet 100% of the controls - every single one fully met, with no partial compliance allowed. Since each Level 0 control has two questions, one strong answer and one weak one is enough to fail that control, and one failed control fails the whole assessment. This is stricter than Levels 1 and 2, which only need 80% of the total points available per objective, with the sole extra condition that no individual control can score zero. Level 3 returns to the same 100% standard as Level 0.
We specialise in DCC Level 0 assessments. If your MOD contract requires Level 1, 2, or 3, you will need to work with a Certification Body accredited for those higher levels. We are happy to advise you on this and help point you in the right direction.
No, and by design. IASME’s rules for certification bodies are specific: we can explain the scheme, clarify what a control means, describe the evidence a question needs, verify and challenge your scope, and provide blank templates. We cannot implement controls or technical changes on your behalf, answer questions for you, or write documentation that we will later assess. If you need someone to build controls or draft evidence from scratch, that’s implementation work - we can point you to a provider, or you can use your own. Keeping preparation and assessment separate is what keeps the certificate meaningful once you hold it.
DCC obligations flow down the supply chain. If your prime contractor has included DEFCON 658 or DCC requirements in your subcontract terms, you are in scope regardless of whether you hold a direct MOD contract. Prime contractors are increasingly cascading these requirements to their subcontractors and lower-tier suppliers. Whether you need DCC Level 0 specifically depends on the cyber risk profile assigned to your work. If your prime has asked you to obtain DCC, that is your answer. If you are unsure, check your contract terms and speak to your prime contractor's procurement or compliance team.
Def Stan 05-139 is the MOD's Secure by Design (SbD) standard. It focuses on building cyber security into the design of defence platforms, systems, and equipment - primarily through the acquisition lifecycle. It is separate from DCC: DCC applies to your organisation's cyber posture, Def Stan 05-139 applies to the security engineering of products or systems being delivered. Most DCC Level 0 applicants are not assessed against Def Stan 05-139. If your contract involves delivering a platform, system, or integrated solution, your prime or the MOD's SRO may impose Def Stan 05-139 obligations separately. If you are unsure which standard applies, check with your MOD contract manager or prime contractor.
When your assessment passes you receive an official IASME-issued DCC Level 0 certificate, a digital DCC badge for use on your website, email footer, and tender submissions, and a public listing on the IASME registry of certified organisations. The certificate is valid for three years. You will also be provided with documentation confirming your annual attestation obligations - you must re-certify annually to Cyber Essentials and complete an annual attestation to confirm controls are maintained and your scope has not significantly changed.
Timeline depends on how prepared your evidence is when we begin. Once your Cyber Essentials certificate is confirmed and your scoping statement is agreed, the assessment itself typically completes within one to two weeks. Organisations that need to prepare GDPR documentation or resilience evidence from scratch should allow additional time - typically two to four weeks of preparation. We review your evidence before the formal assessment begins so that any gaps are identified and resolved before they affect your result. Most clients complete the full process from first contact to certificate within four to six weeks.
Annual attestation is a formal but lightweight process compared to the initial assessment. You do not redo the full DCC assessment every year - the three-year certificate covers the period. What you must do annually is re-certify to Cyber Essentials (required every year regardless of DCC) and complete an annual attestation confirming that the controls assessed at Level 0 are still in place and that your scope has not significantly changed. Routine organisational changes are generally considered normal and do not trigger recertification. If your scope changes materially - for example, significant changes to your IT infrastructure or business structure - notify us and we will advise whether recertification is required.
At Level 0, you answer the assessment questions and submit your evidence through the IASME platform directly - we review and mark it there. There’s also a retention obligation: your submission, evidence, and any assessment records must be kept for three and a half years from the date of certification. That’s longer than your first annual attestation cycle, so it’s worth giving it a proper, permanent home - such as SharePoint - rather than a folder on one person’s laptop.
More often than not, yes - at least in part. Most organisations that trade commercially will already hold a privacy policy, ICO registration, and some form of backup. Those are the building blocks for Controls 2314 and 2500. The gap is usually not a missing capability but a missing record: a backup that runs but has never been tested and documented, or a GDPR policy that exists but has not been applied to a DPIA. We go through what you already have at the start of the process and help you identify what needs documenting, testing, or formalising before the assessment begins.
We'll ask you to share read-only access to a folder containing your evidence documents - SharePoint, Google Drive, or equivalent works fine. You don't need everything to be complete before sharing. We review what you already have, identify any gaps, and tell you exactly what needs completing before the formal assessment begins. Incomplete evidence is expected at this stage - that's what the pre-assessment review is for.

GOVERNMENT CYBER RESILIENCE PLEDGE SIGNATORY

Vincent Cyber Defence has signed the Government Cyber Resilience Pledge - including the commitment to require Cyber Essentials across our supply chain. Action 3 of the pledge directly mirrors the supply chain cyber security requirements being rolled out across MOD procurement. View our signed declaration →

DIRECT LEAD ASSESSOR ACCESS

Every client works directly with a qualified lead assessor from first contact through to certification. No helpdesk, no handoffs, no rotating contacts - consistent, senior-level support throughout. This is a deliberate part of how Vincent Cyber Defence operates, not an afterthought.

All of our staff come from military and defence backgrounds. We understand the obligations and pressures of the MOD supply chain from direct experience - not just the certification standard.

// Client Reviews

WHAT OUR CLIENTS SAY

★★★★★
"Vincent Cyber Defence managed our Cyber Essentials and DCC Level 0 together as one engagement. The scoping guidance was invaluable - we passed first time with no issues."

- CONTRACTS DIRECTOR / MOD Supplier, South East

★★★★★
"The team understood the Def Stan 05-138 requirements in detail and guided us through every control clearly. We had our DCC certificate well before our contract deadline."

- HEAD OF COMPLIANCE / Defence Supply Chain

★★★★★
"We were unsure whether our Cyber Essentials scope aligned with DCC requirements. Vincent Cyber Defence identified the gap before we started and we avoided a costly restart. Excellent service."

- MANAGING DIRECTOR / Engineering Services

Client names are withheld in line with confidentiality requirements; character references are available upon request.

START YOUR DCC LEVEL 0 ASSESSMENT

Before reaching out, confirm you hold a valid Cyber Essentials certificate with a scope that covers your intended DCC scope. Then contact our UK team - no jargon, no add-ons, no hard sell.

// Blog & Guides

LATEST INSIGHTS

View All Articles →