No, DCC Level 1 does not require Cyber Essentials Plus
It is one of the most repeated claims about Defence Cyber Certification, and it is wrong. Here is what the standard actually says, how to check it yourself, and why so many providers have it the wrong way round.
If you have been told that Defence Cyber Certification Level 1 requires Cyber Essentials Plus, you have been told something that is not in the standard. Defence Standard 05-138 Issue 4 applies Cyber Essentials at all four DCC levels, and Cyber Essentials Plus at Levels 2 and 3 only. Believing otherwise can cost a supplier several weeks and a good deal of money for a certification their contract does not ask for.
We are an appointed Certification Body for DCC Level 0 and an appointed IASME Certification Body for Cyber Essentials, so we look at this control set regularly. This particular error turns up often enough, and costs enough when it lands, that it seemed worth writing down properly.
What the standard actually says
Defence Cyber Certification is built on Defence Standard 05-138 Issue 4, published 14 May 2024. The standard sets out every control and, in an applicability table, marks which levels each control applies to. Two controls matter here.
Control 0001, Cyber Essentials. "The Supplier shall have Cyber Essentials certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract." Marked for Levels 0, 1, 2 and 3.
Control 0002, Cyber Essentials Plus. "The Supplier shall have Cyber Essentials Plus certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract." Marked for Levels 2 and 3 only.
So the correct position is this.
| Level | Controls | Cyber Essentials | Cyber Essentials Plus |
|---|---|---|---|
| Level 0 | 3 | Required | Not required |
| Level 1 | 101 | Required | Not required |
| Level 2 | 139 | Required | Required |
| Level 3 | 144 | Required | Required |
The MoD's own paperwork agrees
You do not have to take the Def Stan on its own. The MoD publishes the Supplier Assurance Questionnaire for each level, and the Level 1 questionnaire asks:
"Does the organisation hold Cyber Essentials (CE) certification that covers the required scope for this activity?"
That is the only certification question in it. Cyber Essentials Plus is not mentioned anywhere in the Level 1 questionnaire. If Plus were a Level 1 requirement, the MoD's own assessment document for Level 1 would ask about it.
Why the error spread, which is more interesting than the error
This is not a case of providers inventing a requirement to sell more work. The real explanation is duller and more forgivable.
The control applicability table in Def Stan 05-138 Issue 4 is a wide, multi-page PDF table with a column per level and a mark in the applicable cells. When that table is extracted automatically, which is how most people read a 200-page standard in 2026, the column alignment frequently slips by one. The mark that belongs in the Level 2 column lands in Level 1. Do that to control 0002 and you get "Cyber Essentials Plus is required at Levels 1, 2 and 3", which is exactly the claim in circulation.
We know this because it happened to us. Our first automated pass at the table produced the same wrong answer, and it only came apart when we checked the rows individually against the page headers. If you have repeated this claim, that is almost certainly why, and it is a good argument for reading the control rows rather than a summary of them.
What believing it costs a supplier
Cyber Essentials and Cyber Essentials Plus are not two grades of the same purchase. Cyber Essentials is a verified self-assessment: you answer the questionnaire, an assessor reviews it, and on a pass the certificate is issued, typically within days. Cyber Essentials Plus adds a hands-on technical audit carried out by an assessor against a sample of your devices, which has to be scheduled, and which requires the base Cyber Essentials certification first.
For a supplier working to a Level 1 requirement, being told they need Plus means:
- Two to three extra weeks, because the audit has to be booked into an assessor's diary rather than done from a submission.
- A materially larger bill, because you are buying assessor time on site or remotely rather than a review of a questionnaire.
- Real remediation risk, because Plus tests your devices rather than your answers, and will find things a self-assessment does not.
None of which is wasted if your contract genuinely needs Plus. All of which is wasted if it does not. And the suppliers most likely to be caught are the small ones at the bottom of a defence supply chain, who are the least able to absorb either the delay or the cost.
Two more DCC claims worth checking
Level 0 is not "Cyber Essentials, governance and risk management"
Several published summaries list the three Level 0 controls as Cyber Essentials, governance and risk management. Governance is control 1100 and risk management is control 1200, and both are marked for Levels 1, 2 and 3. Neither applies at Level 0.
The actual three Level 0 controls are Cyber Essentials (0001), ensuring personal data is processed in compliance with UK GDPR (2314), and building resilience against cyber attack and system failure into your systems (2500). That is a genuinely light requirement, and describing it as a governance programme is not a small difference if somebody is quoting you for one.
The 31 December 2026 date is an ask, not a mandate
In May 2026 the MoD's Director of Cyber Defence and Risk wrote that she had "recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026". The MoD repeated that in July. It is a clearly signposted expectation and the direction of travel is not in doubt.
It is not, however, a contractual mandate. IASME, which runs the scheme, states plainly that DCC is currently not mandatory and that applicants may still tender for MoD contracts through the normal process. Government guidance also confirms that suppliers holding a valid DCC certificate are "not yet" exempt from completing elements of the Supplier Assurance Questionnaire. The instrument that binds you contractually today is DEFCON 658 and the Cyber Security Model, not DCC.
We think you should certify anyway, for reasons that have nothing to do with a deadline: buyers are already asking, the Cyber Essentials underneath it is worth holding on its own merits, and an independently assessed certificate is worth more in a procurement than a self-assessment. But "you will be barred from MoD work in January" is not what the MoD said, and you should be wary of anyone who tells you it is.
How to check any of this yourself
- Download Def Stan 05-138 Issue 4 from GOV.UK. It is public.
- Find the control by its number rather than reading a summary. 0001 is Cyber Essentials, 0002 is Cyber Essentials Plus.
- Read the applicability marks against the column headers on that page, not on the first page of the table. This is where automated extraction goes wrong.
- Cross-check against the Supplier Assurance Questionnaire for your level, also published on GOV.UK.
If you have already been quoted for Cyber Essentials Plus on the basis of a Level 1 requirement, ask the provider to point at the control. That is a reasonable question and any competent assessor will welcome it. If the answer is a summary document rather than a control number, you have your answer.
Sources
- Defence Standard 05-138 Issue 4, Cyber Security Standard for Suppliers, 14 May 2024. Controls 0001, 0002, 1100, 1200, 2314 and 2500, and the applicability table.
- Cyber Security Model Supplier Assurance Questionnaire, Level 1.
- Cyber Security Model guidance, GOV.UK, on CSMv4 and SAQ exemption.
- One Year of Defence Cyber Certification, MoD Digital and Data blog, 8 May 2026.
- IASME Defence Cyber Certification FAQ, on levels, control counts and mandatory status.
If you are working out which level applies to you, or whether your Cyber Essentials scope covers the contract, our DCC guide sets out all four levels, and DCC Level 0 goes through the three controls in detail. If you would rather just ask, get in touch.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Not sure which you need? Ask us.
Direct from the Certification Body, with one accountable team.