Defence Cyber Certification (DCC) Level 0

DCC Level 0 assessment and certification for defence suppliers. Discuss your scope, evidence and Cyber Essentials requirements with Be Secure Cyber.

If a customer has asked about DCC, the first step is to establish which level they expect and what your assessment needs to cover.

Be Secure Cyber provides DCC Level 0 assessment and certification, with direct access to an assessor throughout the engagement. We explain the process, discuss your scope and agree what you need to prepare before assessment begins.

Discuss a DCC Level 0 assessment

What is DCC Level 0?

Defence Cyber Certification is an IASME and Ministry of Defence scheme for assessing the security and resilience of defence suppliers. Level 0 is its entry level, covering three controls. Applicants must demonstrate how they meet the requirements; the small control count does not remove the need for evidence.

Read the official DCC scheme overview .

Cyber Essentials and the assessment scope

You need current Cyber Essentials certification covering the applicable systems within your DCC scope, and must maintain it throughout your DCC certification. Cyber Essentials Plus is not a prerequisite for Level 0.

DCC considers the services, systems and functions essential to the organisation’s secure operation. Its scope extends beyond the network used for a particular MOD contract and can include technology that is not connected to the internet. Cyber Essentials has its own scoping rules, so the two scopes must be checked together rather than assumed to be identical.

We review your scope statement, supporting diagrams, sites and dependencies, including services supplied by other organisations. You remain responsible for describing your organisation accurately and explaining any exclusions.

What Level 0 examines

The current applicant guidance sets out three control areas. Each involves questions, explanations and supporting evidence, and all applicable Level 0 controls must be fully met.

  • Cyber Essentials: holding certification with suitable coverage and committing to maintain it
  • Data protection: documented policies and procedures addressing UK GDPR obligations, and evidence of Data Protection Impact Assessments
  • System resilience: assessing how resilient essential systems need to be to cyber attacks and failures, and demonstrating the measures implemented to meet those needs

Evidence should reflect what your organisation actually does. A policy alone does not demonstrate that resilience measures have been implemented. The detail needed depends on the organisation and its operations.

DCC assesses the scheme’s specified data protection requirements. It is not a general legal certification of GDPR compliance.

What our service includes

Your assessment engagement includes:

  • An initial discussion of your organisation, customer requirements and intended scope
  • An explanation of the assessment process and the information we need from you
  • Review of your existing Cyber Essentials certification and its scope
  • Assessment of your Level 0 submission and supporting evidence, with clarification where needed
  • Certification following a successful assessment

We agree the scope and fees in writing before work begins. If you also need Cyber Essentials or Cyber Essentials Plus, we can coordinate these through our defence supplier certification packages .

Preparing for assessment

It helps to nominate someone who can coordinate responses and involve the people responsible for your IT, policies and business operations. Your IT provider may need to contribute, but some answers will need input from within your organisation.

We can explain requirements and identify gaps. If you need help implementing changes, we will discuss the work and assessment arrangements separately so that the assessor remains impartial. This may require another provider. IASME explains these boundaries in its FAQs .

Our DCC Level 0 preparation guide gives you a practical starting point.

After certification

DCC certification runs on a three-year cycle, with annual attestation between reassessments. Any ongoing support will be set out separately in your proposal. See the IASME scheme overview .

Cyber Essentials must remain current, with its own annual renewal. Annual attestations are required at the end of years one and two, with recertification at the end of year three. Significant changes to your organisation or scope should be discussed with the assessing Certification Body.

Our company certification

Be Secure Cyber also holds DCC Level 0 certification.

View our certificate on BlockMark

Discuss your requirements

Tell us your organisation’s approximate size, whether you already hold Cyber Essentials or Plus, and any customer deadline. If you are unsure whether Level 0 is the right level, include the wording of the request without sending sensitive contract information.

We will use that information to discuss the assessment and provide a scoped quotation.

Enquire about DCC Level 0