DCC Level 0
The three controls, what evidence each one needs, and how assessment runs, from an appointed Level 0 Certification Body.
DCC Level 0 is three controls. You hold Cyber Essentials covering the contract scope, you process personal data in compliance with UK GDPR, and you build resilience against attack and failure into your systems. That is the whole of it. For most suppliers the substantive work is the Cyber Essentials; the other two are things a well-run business can usually already evidence.
The three controls in full
Control 0001: Cyber Essentials
The supplier shall have Cyber Essentials certification that covers the scope required for all aspects of the contract, and commit to maintaining it for the duration of the contract.
Two words there do the work. Scope: the certification has to cover everything the contract touches, so a certificate scoped to one office or one subsidiary will not carry a contract delivered from elsewhere. Maintaining: Cyber Essentials lasts twelve months, so on a three-year contract you are committing to three certifications, not one.
Control 2314: UK GDPR compliance
The supplier shall ensure that the processing of personal data is conducted in compliance with the General Data Protection Regulation.
This is not a new obligation; it is the one you already have. What Level 0 adds is that you are now asserting it to a defence buyer through an assessed certification. In practice: know what personal data you hold and why, have a lawful basis, have your ICO registration current, and be able to describe what happens if that data is breached.
Control 2500: Resilient networks and systems
The supplier shall build resilience against cyber attack and system failure into the design, implementation, operation and management of systems that support the operation of business functions and the protection of data.
The broadest of the three, and the one suppliers most often ask about. It is asking whether resilience is a design consideration rather than an afterthought: do you have backups you have actually tested, do you know which systems you cannot operate without, and would you be able to keep delivering if one of them failed.
What is NOT in Level 0
Governance (control 1100) and risk management (control 1200) are frequently listed as Level 0 controls in published summaries. They are not. Both apply from Level 1 upwards. If a provider is scoping a governance programme for you on the basis of a Level 0 requirement, ask them to point at the control in Def Stan 05-138 Issue 4.
How assessment runs
- Confirm your assigned level. Level 0 to 3 is set by the Cyber Risk Profile the MoD delivery team assigns to your contract. You do not pick it.
- Get Cyber Essentials for the right scope. This is usually the long pole. If you do not already hold it, start here.
- Assemble evidence for 2314 and 2500. Most organisations have this material already; it is rarely written down in one place.
- Assessment and certificate. We assess and issue. The certificate is valid for three years, subject to annual attestation that nothing material has changed and to renewing Cyber Essentials each year.
Because we are both an appointed DCC Level 0 Certification Body and an appointed IASME Certification Body for Cyber Essentials, both parts come from us on one timeline. See the full DCC guide for how the levels compare and what the 31 December 2026 date actually means, or fast DCC Level 0 if you are working to a date.
Common questions
Is Level 0 really just three controls?
Yes. Def Stan 05-138 Issue 4 applies exactly three controls at Level 0: Cyber Essentials (0001), UK GDPR compliance (2314) and resilient networks and systems (2500). Level 1 jumps to 101 controls, so the gap between the two is far larger than the numbering implies.
Does my Cyber Essentials scope need to change?
Possibly. The control requires certification covering the scope needed for all aspects of the contract. If your existing certificate was scoped to a single site or entity and the contract is delivered more broadly, the scope has to be widened. This is worth checking before you apply rather than during assessment.
We already comply with UK GDPR. Is that control automatic?
Effectively yes, but you need to be able to evidence it rather than assert it: a current ICO registration, a lawful basis for the processing you do, and a description of how a personal data breach would be handled. Most organisations have all three and have never written them down together.
What counts as evidence for the resilience control?
Tested backups, an understanding of which systems the business cannot operate without, and some demonstration that resilience was considered when those systems were designed or procured rather than bolted on. It is deliberately broad, because a three-person consultancy and a 200-person manufacturer answer it very differently.
How long does Level 0 certification last?
Three years from issue, subject to an annual attestation that nothing material has changed in your organisation and to renewing your Cyber Essentials every twelve months. So although the DCC certificate runs for three years, you have an annual commitment underneath it.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Talk to us about DCC Level 0
Tell us your requirement and we will agree the work and the assessment route. We assess and certify DCC Level 0, and we can certify the Cyber Essentials it requires at the same time, so it is one provider with no handoffs.
Ready for Defence Cyber Certification?
DCC Level 0 and the Cyber Essentials it requires, from one Certification Body.