Defence Cyber Certification (DCC)

The four levels, the controls behind each one, how your level is decided, and an honest account of what the MoD's 31 December 2026 date does and does not oblige you to do.

Solusec is an appointed Defence Cyber Certification Body for Level 0

Defence Cyber Certification is the MoD's independently assessed cyber certification for defence suppliers, created by the Ministry of Defence with IASME as the Certification Authority and built on Defence Standard 05-138 Issue 4. It has four levels, Level 0 to Level 3. Cyber Essentials is a control at every level, and Levels 2 and 3 require Cyber Essentials Plus as well. Solusec is an appointed Certification Body for Level 0 and a Cyber Essentials Certification Body, so both come from us without a handoff.

The four levels at a glance

Your level is not something you choose from a menu. It is set by the Cyber Risk Profile that the MoD delivery team assigns to the contract, which means the right question is rarely "which level should we get" but "which level has our contract been assessed at".

DCC levels, controls and Cyber Essentials requirements
LevelControlsAssessed riskCyber EssentialsCE Plus
Level 03Very lowRequiredNot required
Level 1101Low to moderateRequiredNot required
Level 2139HighRequiredRequired
Level 3144SubstantialRequiredRequired

Note the jump. Level 0 is three controls. Level 1 is a hundred and one. There is no gentle slope between them, and organisations that assume Level 1 is "Level 0 with a bit more paperwork" are in for a surprise. If your contract has been profiled at Level 1, treat it as a programme of work rather than an application.

One correction worth making, because it circulates widely and is wrong: Cyber Essentials Plus is not required at Level 1. Def Stan 05-138 Issue 4 lists Cyber Essentials (control 0001) as applying at all four levels, and Cyber Essentials Plus (control 0002) at Levels 2 and 3 only. The MoD's own Level 1 Supplier Assurance Questionnaire asks about Cyber Essentials and does not mention Plus at all. If a provider has told you that you need Plus for Level 1, check the standard.

What Level 0 actually asks for

Three controls. That is the whole of Level 0, and it is worth stating plainly because the scheme's name makes it sound heavier than it is.

  1. Cyber Essentials (control 0001). Hold Cyber Essentials certification covering the scope required for all aspects of the contract, and commit to maintaining it for the duration of the contract.
  2. UK GDPR compliance (control 2314). Ensure personal data is processed in compliance with the General Data Protection Regulation.
  3. Resilient networks and systems (control 2500). Build resilience against cyber attack and system failure into the design, implementation, operation and management of the systems supporting your business functions and protecting data.

Governance and risk management are not Level 0 controls, despite appearing in several published summaries. They start at Level 1. For almost every SME reading this, the substantive work in Level 0 is getting and keeping Cyber Essentials; the other two controls are things a well-run business can usually already evidence.

What the 31 December 2026 date really means

In May 2026 the MoD's Director of Cyber Defence and Risk wrote that she had "recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope". The MoD repeated the ask in July 2026.

We are going to be straight with you about the status of that date, because a lot of marketing around it is not.

  • It is an ask, not a contractual mandate. IASME, which runs the scheme, states plainly that DCC is currently not mandatory, and that applicants may still tender for MoD contracts through the normal process.
  • Holding DCC does not currently exempt you from the SAQ. Government guidance is explicit that suppliers with a valid DCC certificate are not yet exempt from completing elements of the Supplier Assurance Questionnaire. The word "yet" is clearly doing deliberate work, but no timeline for that change has been published.
  • The contractual hook is still DEFCON 658 and the Cyber Security Model. That already applies to you today, regardless of DCC.

So why bother before the end of the year? Because the direction of travel is unambiguous, because buyers are already asking, and because the Cyber Essentials underneath it is genuinely worth holding on its own merits. What we will not do is tell you that you will be barred from MoD work on 1 January. That is not what the MoD said, and you should be sceptical of anyone who tells you otherwise.

How DCC fits with the Cyber Security Model and the SAQ

If you supply the MoD you are already inside a system that predates DCC, and the two now share a structure.

Where DCC sits alongside existing MoD cyber requirements
MechanismWhat it isStatus for you today
DEFCON 658The contract clause that imposes the Cyber Security ModelContractual, applies now
Cyber Security Model v4The risk framework; uses Def Stan 05-138 Issue 4Current, use for new procurements
Cyber Risk ProfileLevel 0 to Level 3, assigned per contract by the MoDDecides your DCC level too
Supplier Assurance QuestionnaireSelf-assessment, now through the Supplier Cyber Protection ServiceStill required; DCC does not yet replace it
Defence Cyber CertificationIndependent third-party assessment of the same controlsVoluntary today, asked for by 31 Dec 2026

CSMv4 replaced the old five Cyber Risk Profiles (N/A, Very Low, Low, Moderate, High) with the four levels DCC certifies against. If your internal documentation still uses the old names, it is out of date.

What it costs, and how long it lasts

There is no published standard price for DCC. IASME does not set one, because the effort varies enormously between applicants, so every Certification Body prices its own assessments. Be wary of anyone quoting you a "standard DCC fee" as though the scheme set it.

For Level 0 the cost that actually matters to most suppliers is the Cyber Essentials underneath it, which we price transparently:

Cyber Essentials, the Level 0 prerequisite (Solusec pricing, excluding VAT)
Organisation sizeCertification+ urgent turnaround+ gap analysis
Micro, 1 to 9 staff£320£420£720
Small, 10 to 49 staff£440£540£840
Medium, 50 to 249 staff£500£600£900
Large, 250+ staff£600£700£1,000

Ask us for a DCC Level 0 assessment quote and we will give you a fixed figure for your scope. A DCC certificate is valid for three years, subject to annual attestation that nothing material has changed in your organisation and to keeping your Cyber Essentials (or Cyber Essentials Plus at Levels 2 and 3) renewed each year. So the recurring commitment is annual, even though the certificate runs for three.

How Solusec helps

We are an appointed Certification Body for DCC Level 0, and an appointed IASME Certification Body for Cyber Essentials and IASME Cyber Assurance. In practice that means:

  • Level 0: we assess and issue the certificate, and we certify the Cyber Essentials it requires at the same time. One organisation, one timeline, no handoff.
  • Level 1: the jump to 101 controls is substantial. We provide scope reviews, gap analysis across the control set and evidence preparation so you go into assessment with the work done.
  • Levels 2 and 3: these require Cyber Essentials Plus as well, and we refer those assessments to a body appointed for them. We will say so rather than stretch.

You can verify our appointments independently on the BlockMark registry and through IASME's DCC scheme pages. We are based in Shropshire and work with defence suppliers across the UK.

Common questions

Is DCC Level 0 mandatory?

Not currently. IASME, which runs the scheme, states that DCC is not mandatory and that suppliers may still tender for MoD contracts through the normal process. What exists is an ask: in May 2026 the MoD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026, and the MoD repeated that in July 2026. The contractual requirement that binds you today is DEFCON 658 and the Cyber Security Model, not DCC.

Do I need Cyber Essentials Plus for DCC Level 1?

No, and this is a common and expensive misunderstanding. Def Stan 05-138 Issue 4 applies Cyber Essentials at all four levels and Cyber Essentials Plus at Levels 2 and 3 only. The MoD's own Level 1 Supplier Assurance Questionnaire asks about Cyber Essentials and does not mention Plus. If you have been quoted for Plus on the basis of a Level 1 requirement, ask the provider to point at the control.

How do I know which level I need?

You do not choose it. MoD delivery teams carry out a risk assessment and assign a Cyber Risk Profile of Level 0 to Level 3 to the contract, and that is the level you certify to. If you are not sure, ask the buying authority or check the contract documentation. Certifying at a higher level than your contract needs is money spent for no procurement benefit.

What are the three Level 0 controls?

Cyber Essentials certification covering the contract scope and maintained for its duration; processing personal data in compliance with UK GDPR; and building resilience against cyber attack and system failure into the design, operation and management of your systems. Governance and risk management are not Level 0 controls, despite what several published summaries claim: they begin at Level 1.

Does holding DCC mean I can skip the Supplier Assurance Questionnaire?

Not yet. Government guidance is explicit that suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ, which is now submitted through the Supplier Cyber Protection Service. The wording clearly anticipates that changing, but no date has been published, so plan on doing both for now.

How long does a DCC certificate last?

Three years from the date of issue, subject to an annual attestation that nothing material has changed in your organisation and to renewing your Cyber Essentials (or Cyber Essentials Plus at Levels 2 and 3) every year. So although the certificate runs three years, the commitment is an annual one.

How much does DCC cost?

There is no standard scheme fee. IASME does not publish one, because the assessment effort varies significantly between applicants, so each Certification Body sets its own prices. For Level 0 the main cost for most suppliers is the Cyber Essentials underneath it, which we price transparently from £320 excluding VAT. Ask us for a fixed quote for your scope.

We already do the SAQ. Is DCC just the same questions again?

Largely, yes. IASME confirms DCC uses the same questions as the MoD SAQ, with small differences arising from version syncing. The substantive change is not the questions but who answers for them: the SAQ is your self-assessment, DCC is an independent third-party assessment of the same ground. That is the whole point of it from a buyer's perspective.

Related

Talk to us about DCC Level 0

Tell us your requirement and we will agree the work and the assessment route. We assess and certify DCC Level 0, and we can certify the Cyber Essentials it requires at the same time, so it is one provider with no handoffs.

Your details are handled by a real person, never fed into AI.

Ready for Defence Cyber Certification?

DCC Level 0 and the Cyber Essentials it requires, from one Certification Body.