Cyber Essentials and DCC for defence suppliers

Coordinate Cyber Essentials, optional Cyber Essentials Plus and DCC Level 0 with Be Secure Cyber. Clear assessment scope and one point of contact.

When a customer asks for more than one certification, it helps to plan the work together. You need to know what is required, which assessments come first and who will provide the information.

Be Secure Cyber offers coordinated Cyber Essentials and DCC Level 0 packages, with Cyber Essentials Plus available where you also need technical testing. You have one point of contact for planning and delivery, while each scheme retains its own assessment and certificate.

Discuss a certification package

Choose the route that fits your organisation

Cyber Essentials and DCC Level 0

For organisations starting certification or renewing Cyber Essentials alongside a DCC application.

We agree the work for both schemes in one proposal and plan the assessments around your readiness and customer deadline. This includes the Cyber Essentials verified self-assessment and DCC Level 0 assessment, with certification following successful completion of each.

Cyber Essentials Plus and DCC Level 0

For organisations that also want independent technical testing, or whose customer requires Cyber Essentials Plus.

This option includes Cyber Essentials, the additional Plus assessment and DCC Level 0. We discuss the systems involved and the arrangements for technical testing before agreeing the engagement.

Plus is optional for DCC Level 0. Adding it does not change your DCC certification level. The IASME overview explains the certification prerequisites .

DCC Level 0 with existing Cyber Essentials

If you already hold Cyber Essentials or Plus, send us the certificate details and scope. We will review how these relate to your proposed DCC assessment before recommending the next steps. A package should reflect the work you need, including certification already in place.

How we coordinate the work

We start with a scoping discussion and a written proposal covering the assessments, fees, responsibilities and any separately agreed support.

We check each scheme’s scope and assessment timing, including the Cyber Essentials Plus assessment window. A scope accepted for one scheme is not automatically sufficient for another.

We then plan who needs to contribute and when. Where the same background information is relevant to more than one assessment, we use it consistently, while still checking the requirements of each scheme.

You remain responsible for accurate responses, providing evidence and making any necessary changes. Certification depends on meeting the relevant requirements.

What needs a separate agreement?

Remediation, policy development, ongoing security management and annual attestation support are outside the certification package unless expressly included in your proposal. Any implementation work also needs appropriate impartiality arrangements.

We will make those boundaries clear before you commit, including whether another provider is needed for part of the work.

Check what your customer requires

Confirm the required DCC level and any additional certification conditions with your customer. Do not assume that Level 0 meets every defence contract’s requirements.

DCC does not currently replace applicable Supplier Assurance Questionnaire obligations. The MOD’s Cyber Security Model guidance explains the procurement process.

Ask about a combined package

Tell us which certificates you hold, your approximate employee count, the sites involved and any deadline. We will discuss the work with you and provide a quotation based on the agreed scope.

Request a certification package quotation

For the individual assessments, see Cyber Essentials and Cyber Essentials Plus .

For more detail, see our DCC Level 0 assessment service or preparation guide .