If a customer has asked about DCC, the first step is to establish which level they expect and what your assessment needs to cover.
Be Secure Cyber provides DCC Level 0 assessment and certification, with direct access to an assessor throughout the engagement. We explain the process, discuss your scope and agree what you need to prepare before assessment begins.
What is DCC Level 0?
Defence Cyber Certification is an IASME and Ministry of Defence scheme for assessing the security and resilience of defence suppliers. Level 0 is its entry level, covering three controls. Applicants must demonstrate how they meet the requirements; the small control count does not remove the need for evidence.
Read the official DCC scheme overview .
Cyber Essentials and the assessment scope
You need current Cyber Essentials certification covering the applicable systems within your DCC scope, and must maintain it throughout your DCC certification. Cyber Essentials Plus is not a prerequisite for Level 0.
DCC considers the services, systems and functions essential to the organisation’s secure operation. Its scope extends beyond the network used for a particular MOD contract and can include technology that is not connected to the internet. Cyber Essentials has its own scoping rules, so the two scopes must be checked together rather than assumed to be identical.
We review your scope statement, supporting diagrams, sites and dependencies, including services supplied by other organisations. You remain responsible for describing your organisation accurately and explaining any exclusions.
What Level 0 examines
The current applicant guidance sets out three control areas. Each involves questions, explanations and supporting evidence, and all applicable Level 0 controls must be fully met.
- Cyber Essentials: holding certification with suitable coverage and committing to maintain it
- Data protection: documented policies and procedures addressing UK GDPR obligations, and evidence of Data Protection Impact Assessments
- System resilience: assessing how resilient essential systems need to be to cyber attacks and failures, and demonstrating the measures implemented to meet those needs
Evidence should reflect what your organisation actually does. A policy alone does not demonstrate that resilience measures have been implemented. The detail needed depends on the organisation and its operations.
DCC assesses the scheme’s specified data protection requirements. It is not a general legal certification of GDPR compliance.
What our service includes
Your assessment engagement includes:
- An initial discussion of your organisation, customer requirements and intended scope
- An explanation of the assessment process and the information we need from you
- Review of your existing Cyber Essentials certification and its scope
- Assessment of your Level 0 submission and supporting evidence, with clarification where needed
- Certification following a successful assessment
We agree the scope and fees in writing before work begins. If you also need Cyber Essentials or Cyber Essentials Plus, we can coordinate these through our defence supplier certification packages .
Preparing for assessment
It helps to nominate someone who can coordinate responses and involve the people responsible for your IT, policies and business operations. Your IT provider may need to contribute, but some answers will need input from within your organisation.
We can explain requirements and identify gaps. If you need help implementing changes, we will discuss the work and assessment arrangements separately so that the assessor remains impartial. This may require another provider. IASME explains these boundaries in its FAQs .
Our DCC Level 0 preparation guide gives you a practical starting point.
After certification
DCC certification runs on a three-year cycle, with annual attestation between reassessments. Any ongoing support will be set out separately in your proposal. See the IASME scheme overview .
Cyber Essentials must remain current, with its own annual renewal. Annual attestations are required at the end of years one and two, with recertification at the end of year three. Significant changes to your organisation or scope should be discussed with the assessing Certification Body.
Our company certification
Be Secure Cyber also holds DCC Level 0 certification.
Discuss your requirements
Tell us your organisation’s approximate size, whether you already hold Cyber Essentials or Plus, and any customer deadline. If you are unsure whether Level 0 is the right level, include the wording of the request without sending sensitive contract information.
We will use that information to discuss the assessment and provide a scoped quotation.