Accredited and recognised


What Level 0 actually requires
Defence Cyber Certification has four levels, and the numbering is misleading. Level 0 carries three controls. Level 1 carries 101. There is no gentle slope between them, so the single most valuable thing you can do before spending anything is confirm which level your contract has actually been profiled at.
You do not choose that. MoD delivery teams assign a Cyber Risk Profile to the contract, and that decides your level. If you are not sure, ask the buying authority or check the contract documentation.
| Level | Controls | Assessed risk | Cyber Essentials | CE Plus |
|---|---|---|---|---|
| Level 0 | 3 | Very low | Required | Not required |
| Level 1 | 101 | Low to moderate | Required | Not required |
| Level 2 | 139 | High | Required | Required |
| Level 3 | 144 | Substantial | Required | Required |
Two corrections worth making, because both circulate widely and both cost suppliers money. Cyber Essentials Plus is not required at Level 1 — control 0002 applies at Levels 2 and 3 only, and the MoD's own Level 1 questionnaire does not mention it. And governance and risk management are not Level 0 controls; they are controls 1100 and 1200, and they start at Level 1.
What evidence each control needs
Control 0001, Cyber Essentials
Certification covering the scope required for all aspects of the contract, maintained for its duration. Two words do the work there. Scope: a certificate covering one office will not carry a contract delivered from three. Maintained: certification lasts twelve months, so a three-year contract means three certifications.
Control 2314, UK GDPR compliance
Not a new obligation, just the one you already have, now asserted to a defence buyer through an assessed certification. Know what personal data you hold and why, have a lawful basis, keep the ICO registration current, and be able to describe what happens if it is breached.
Control 2500, resilient networks and systems
The broadest of the three and the one suppliers ask about most. It asks whether resilience was a design consideration rather than an afterthought: tested backups, a clear view of which systems you cannot operate without, and some evidence that this was thought about when those systems were chosen.
Not sure which DCC level your contract sits at, or whether your evidence stands up?
The 31 December 2026 date, honestly
In May 2026 the MoD's Director of Cyber Defence and Risk wrote that she had asked all industry partners to achieve Level 0 by 31 December 2026, and the MoD repeated that in July. It is a clear expectation and the direction of travel is not in doubt.
It is not a contractual mandate. IASME, which runs the scheme, states that DCC is currently not mandatory and that suppliers may still tender through the normal process. Government guidance also confirms that holding DCC does not yet exempt you from the Supplier Assurance Questionnaire. What binds you contractually today is DEFCON 658 and the Cyber Security Model.
Certify anyway, for reasons that have nothing to do with a deadline: buyers are already asking, and an independently assessed certificate carries more weight in a procurement than a self-assessment. But be wary of anyone telling you that you will be barred from MoD work in January. That is not what the MoD said.
How long it takes, and what it costs
For a supplier that already holds Cyber Essentials with the right scope, Level 0 is days. For one that does not, the timeline is however long Cyber Essentials takes: one to two weeks on a managed estate, four to six on an unmanaged one.
There is no standard scheme fee. IASME does not publish one because effort varies, so every Certification Body prices its own assessments. Be sceptical of anyone quoting a "standard DCC fee" as though the scheme set it. A DCC certificate is valid for three years, subject to annual attestation that nothing material has changed and annual Cyber Essentials renewal.
Where Level 0 sits, and what comes next
Defence Cyber Certification has four levels, 0 to 3, set by the Cyber Risk Profile of the contract rather than by the size of your business. A small supplier on a high-risk contract can sit at Level 2; a large one on a low-risk contract can sit at Level 0. The profile is determined by the buying authority through the Cyber Security Model, not by you.
One point is worth stating plainly because it is widely got wrong, including on other suppliers' websites: Cyber Essentials is required at every DCC level, including Level 0, under Def Stan 05-138 Issue 4. Cyber Essentials Plus is required in addition at Levels 2 and 3. You will see it written elsewhere that Levels 0 and 1 need Cyber Essentials and Levels 2 and 3 need Plus instead. That is not what the standard says, and planning around it leaves you short.
What the evidence actually looks like
Level 0 is evidence-based rather than interview-based, and the gap between a smooth assessment and a slow one is almost entirely about whether the evidence already exists in a form somebody else can read.
A screenshot of a setting is weaker than an exported policy. A statement that patching happens is weaker than a report showing patch levels across the estate on a date. An asset list assembled the week of the assessment is weaker than one with a revision history. None of this means you need a document management system; it means the person compiling the evidence should be able to show where each item came from.
Who this applies to
If you hold a contract with a DEFCON 658 clause, or you supply someone who does, DCC applies to you. The requirement flows down the supply chain, which is why a great many firms first hear about it from a customer rather than from the Ministry of Defence. Manufacturers, fabricators, logistics providers, software suppliers and professional services firms all end up in scope through that route.
If a customer has sent you a Supplier Assurance Questionnaire or mentioned a Cyber Risk Profile, that is the conversation starting. The useful question to put back to them is which profile the contract carries, because that determines your level and everything follows from it.
Common mistakes we see
Assuming Level 0 means no Cyber Essentials. Covered above, and the most expensive one, because it is usually discovered late.
Scoping to the contract rather than the systems. The scope is the systems that handle the defence information, which rarely maps neatly to one contract or one team.
Leaving it until the customer asks. Certification takes time you will not have once a tender is live, and the prerequisite Cyber Essentials work takes longer still if there is remediation in it.
The three-control readiness check
Def Stan 05-138 Issue 4 applies exactly three controls at Level 0. Tick the ones you could evidence today.