Search Valantus?

Valantus Logo_Sept 2024_aquamarine shield only

General Defence Cyber Certification Questions

What is Defence Cyber Certification (DCC)?

Defence Cyber Certification (DCC) is a cyber assurance framework designed to help organisations demonstrate that they have implemented appropriate cyber security controls when working within the defence supply chain. The framework helps organisations protect sensitive information, improve cyber resilience, and satisfy contractual cyber security requirements.

Why is Defence Cyber Certification important?

Cyber threats targeting supply chains continue to increase in frequency and sophistication. Defence Cyber Certification helps organisations demonstrate that they can appropriately protect sensitive information, systems, and services while improving trust across the supply chain. Valantus helps organisations understand and implement the controls needed to meet these requirements.

Who needs Defence Cyber Certification?

Any organisation bidding for, delivering, or supporting defence-related contracts may be required to achieve Defence Cyber Certification. Requirements are generally specified by the customer, contracting authority, or prime contractor.

How do I know which certification level I need?

The required certification level is usually defined in contract documentation. Valantus can help review your contractual requirements and determine which DCC level applies to your organisation.

What is Defence Cyber Certification?

Defence Cyber Certification is a cyber security assurance framework that enables organisations to demonstrate that appropriate security controls are in place when supporting defence contracts and handling defence-related information.

Why was Defence Cyber Certification introduced?

Defence Cyber Certification was introduced to strengthen cyber resilience across the defence supply chain and reduce the risk of cyber attacks impacting defence programmes, suppliers, and sensitive information.

Who oversees Defence Cyber Certification?

Defence Cyber Certification supports cyber assurance requirements throughout the defence supply chain and provides a structured approach for suppliers to demonstrate cyber security capability.

Which organisations need Defence Cyber Certification?

Any organisation that stores, processes, accesses, or transmits information related to defence contracts may require Defence Cyber Certification depending on the nature of their services and contractual obligations.

What industries require Defence Cyber Certification?

Defence Cyber Certification requirements can apply across many industries including manufacturing, engineering, aerospace, software development, professional services, logistics, facilities management, and consultancy services supporting defence customers.

What are the different Defence Cyber Certification levels?

The Defence Cyber Certification framework includes multiple certification levels designed to align cyber security requirements with the risk associated with a particular contract or service.

How do I determine my DCC certification requirements?

Certification requirements are generally determined by contract conditions and the type of information or systems involved. Valantus can review your requirements and identify the most appropriate compliance route.

Is Defence Cyber Certification mandatory?

Defence Cyber Certification becomes mandatory when it is specified within a defence contract, supplier onboarding process, or customer assurance requirement.

How does DCC improve cyber security?

DCC encourages organisations to implement appropriate cyber security controls, governance arrangements, risk management processes, security awareness programmes, and technical safeguards to reduce cyber risk.

What are the benefits of Defence Cyber Certification?

Benefits often include improved cyber resilience, increased customer confidence, enhanced supply chain assurance, reduced cyber risk, stronger governance, and access to defence-related business opportunities.

Does Defence Cyber Certification replace Cyber Essentials?

No. Cyber Essentials and Defence Cyber Certification are separate frameworks. Depending on customer requirements, organisations may need to demonstrate compliance with multiple assurance schemes.

Can small businesses achieve Defence Cyber Certification?

Yes. Defence Cyber Certification has been designed to be achievable for organisations of all sizes, including sole traders, start-ups, SMEs, and larger enterprises. Valantus regularly supports small businesses through the DCC certification journey.

How long does the Defence Cyber Certification process take?

The timescale depends on the required certification level, organisational size, and the maturity of existing cyber security controls. Well-prepared organisations can often achieve certification much more quickly, particularly with support from Valantus.

How much does Defence Cyber Certification cost?

Certification costs vary depending on the certification level required, the complexity of the environment, and whether remediation work is necessary before assessment. Valantus can help identify the most cost-effective route to certification.

What documentation is required for Defence Cyber Certification?

Documentation may include policies, procedures, asset inventories, risk assessments, training records, access control processes, and evidence demonstrating that cyber security controls are operating effectively.

Can Defence Cyber Certification help win defence contracts?

Yes. Achieving DCC certification demonstrates commitment to cyber security and can help organisations meet supplier assurance requirements when competing for defence opportunities.

What happens if my organisation fails a DCC assessment?

If gaps are identified during assessment, organisations can typically address the findings through corrective actions and remediation activities before pursuing certification again. Valantus can provide practical guidance to help close compliance gaps.

Can Valantus help us prepare for Defence Cyber Certification?

Yes. Valantus provides Defence Cyber Certification gap assessments, readiness reviews, evidence reviews, remediation planning, policy development support, and consultancy services to help organisations achieve certification efficiently.

Does Defence Cyber Certification apply to cloud services?

Yes. Cloud environments such as Microsoft 365 and other cloud platforms may fall within scope where they are used to store, process, or transmit information associated with defence contracts.

Why choose Valantus for DCC support?

Valantus combines practical cyber security expertise with extensive experience supporting organisations throughout compliance and assurance programmes. Our consultants provide clear, pragmatic guidance to help businesses achieve Defence Cyber Certification while strengthening their overall security posture.

What is the difference between Defence Cyber Certification and Cyber Essentials?

Cyber Essentials focuses on a baseline set of technical controls, whereas Defence Cyber Certification assesses a broader range of security, governance, and assurance requirements relevant to the defence supply chain.

Can existing ISO 27001 certification help with DCC?

Yes. Organisations with ISO 27001 certification may already have many of the governance and security controls required for DCC. However, a separate review should be performed to identify any additional DCC-specific requirements. Valantus can assist with this gap analysis.

Do subcontractors require Defence Cyber Certification?

Potentially. Subcontractors within the defence supply chain may also be required to demonstrate compliance where they have access to defence information, systems, or services.

Can Defence Cyber Certification be achieved remotely?

Many preparation and assessment activities can be completed remotely, including evidence reviews, interviews, readiness assessments, and implementation support provided by Valantus.

Defence Cyber Certification (DCC) Level 0 Questions

What is DCC Level 0?

DCC Level 0 is the entry point into the Defence Cyber Certification framework. It is designed for organisations that need to demonstrate basic cyber security controls and awareness when supporting defence-related activities. Level 0 focuses on establishing fundamental cyber security practices that help protect business systems and information.

Who is DCC Level 0 suitable for?

DCC Level 0 is typically suitable for organisations that have limited exposure to defence information or systems. It is commonly required for suppliers providing lower-risk services where sensitive defence information is not routinely processed, stored, or transmitted.

What are the key requirements for Level 0?

Level 0 focuses on foundational cyber security measures such as password management, software updates, malware protection, access controls, cyber awareness training, and secure handling of business information. Organisations should be able to demonstrate that these controls are implemented and maintained.

How long does a Level 0 assessment take?

Assessment times vary according to organisational size and readiness. Many organisations can achieve Level 0 relatively quickly if they already have basic cyber security controls in place. Valantus can help accelerate the process by identifying gaps early and supporting evidence collection.

Do I need technical expertise to achieve Level 0?

No. Many organisations achieve DCC Level 0 without dedicated cyber security staff. Valantus provides practical guidance and support to help organisations understand requirements and implement the necessary controls.

Can small businesses achieve Level 0 certification?

Absolutely. DCC Level 0 has been designed to be achievable for SMEs, start-ups, and micro-businesses. Valantus regularly supports smaller organisations through the certification process using practical and proportionate approaches.

Is DCC Level 0 mandatory for defence suppliers?

DCC Level 0 may become mandatory where it is specified by a customer, defence organisation, or prime contractor as part of a contract requirement. Suppliers should review contract documents carefully to understand their obligations.

What cyber security controls are required for DCC Level 0?

Typical controls include secure passwords, anti-malware protection, software patching, access control management, user awareness training, secure configuration of devices, and basic information security procedures.

Can a start-up achieve DCC Level 0 certification?

Yes. Start-ups and newly established organisations can achieve DCC Level 0 provided they implement the required security controls and can demonstrate compliance with the framework requirements.

How much does DCC Level 0 certification cost?

The cost depends on organisational size, current cyber maturity, and whether external assistance is required. Valantus can conduct a readiness review and help identify the most cost-effective route to achieving compliance.

Is DCC Level 0 similar to Cyber Essentials?

There are similarities between DCC Level 0 and Cyber Essentials, particularly around cyber hygiene and foundational security controls. However, organisations should review specific DCC requirements to ensure full compliance with contractual obligations.

Do I need a formal cyber security policy for DCC Level 0?

Level 0 expects organisations to define basic security responsibilities and information protection measures. Having documented policies and procedures can help demonstrate that security controls are understood and consistently applied.

Can remote workers be included within a DCC Level 0 scope?

Yes. Remote workers can be included provided appropriate controls are implemented to protect devices, systems, accounts, and information accessed from home or remote locations.

Do employees need cyber security training for Level 0?

Yes. Staff awareness is an important requirement. Employees should understand common cyber threats such as phishing, malware, password attacks, social engineering, and the importance of following company security procedures.

Can DCC Level 0 help us win defence contracts?

Achieving DCC Level 0 demonstrates a commitment to cyber security and may help satisfy supplier assurance requirements within the defence supply chain. This can improve customer confidence and strengthen bidding opportunities.

How long does DCC Level 0 certification remain valid?

Organisations should maintain compliance throughout the duration of their contracts and regularly review cyber security controls. Certification validity requirements may vary depending on customer expectations and future framework updates.

Can DCC Level 0 be achieved without dedicated IT staff?

Yes. Many organisations successfully achieve DCC Level 0 without employing dedicated IT personnel. Valantus can provide practical support and guidance to help organisations implement and evidence the required controls.

What evidence do we need for DCC Level 0?

Evidence may include security policies, training records, password management procedures, software update processes, anti-malware protection records, device inventories, and documentation showing that security controls are operating as intended.

Can cloud-based businesses achieve DCC Level 0?

Yes. Organisations using cloud platforms such as Microsoft 365 can achieve DCC Level 0 provided suitable security controls, account protections, and management processes are implemented and maintained.

What happens after achieving DCC Level 0?

After certification, organisations should continue monitoring, reviewing, and improving their cyber security controls. Some suppliers may eventually require DCC Level 1 if they begin supporting contracts with higher security requirements.

How can Valantus help with DCC Level 0 certification?

Valantus provides DCC readiness assessments, gap analysis, policy reviews, evidence validation, remediation planning, and practical implementation support. Our consultants help organisations understand requirements, address gaps, and achieve certification with confidence.

What are the most common DCC Level 0 compliance gaps?

Common gaps include missing cyber security policies, weak password controls, inconsistent software patching, inadequate staff awareness training, poor asset management, and a lack of documented security procedures. Valantus can help identify and address these gaps before assessment.

Do we need Cyber Essentials before achieving DCC Level 0?

Not necessarily. However, organisations that have already implemented Cyber Essentials often find that they have many of the fundamental technical controls that support DCC Level 0 compliance.

How can we prepare for a DCC Level 0 assessment?

Preparation typically includes reviewing existing cyber security controls, documenting procedures, ensuring systems are patched, providing staff awareness training, and gathering evidence that demonstrates compliance. Valantus can conduct a readiness review to identify any areas requiring improvement.

How quickly can DCC Level 0 be achieved?

The timeframe depends on your organisation's existing cyber maturity. Businesses with established controls may achieve compliance within a few weeks, while those starting from scratch may require additional time for remediation and evidence gathering.

Do I need antivirus software for DCC Level 0?

Organisations should implement appropriate malware protection across all devices used for business purposes. Effective anti-malware protection is a fundamental component of good cyber hygiene.

Does Microsoft 365 help with DCC Level 0 compliance?

Microsoft 365 provides a range of security capabilities including multi-factor authentication, account protection, email security, device management, and security monitoring that can support DCC Level 0 compliance when properly configured.

Do we need multi-factor authentication for DCC Level 0?

Multi-factor authentication is considered a cyber security best practice and significantly reduces the risk of unauthorised access. Many organisations implement MFA as part of their DCC Level 0 compliance programme.

Can home workers be included in DCC Level 0 certification?

Yes. Home workers are commonly included within scope. Organisations should ensure that devices, user accounts, remote access methods, and information handling practices are adequately protected.

What documents should we have before a DCC Level 0 assessment?

Typical documents include acceptable use policies, password policies, user access records, employee training records, software update procedures, device inventories, and basic cyber security policies.

Is DCC Level 0 suitable for sole traders?

Yes. Sole traders supporting defence contracts may be required to demonstrate cyber security compliance. DCC Level 0 has been designed to be achievable regardless of organisational size.

Can contractors and consultants achieve DCC Level 0?

Yes. Independent consultants, contractors, and specialist advisers frequently require DCC Level 0 when supporting defence programmes, projects, or organisations.

What is the difference between DCC Level 0 and DCC Level 1?

DCC Level 0 focuses on fundamental cyber security controls and awareness. DCC Level 1 generally requires additional governance, formal documentation, risk management processes, and stronger evidence demonstrating that controls are operating effectively.

Can Valantus conduct a DCC Level 0 readiness assessment?

Yes. Valantus can assess your current cyber security posture, identify compliance gaps, review available evidence, and provide a practical roadmap to help your organisation achieve DCC Level 0 certification efficiently.

Why do defence customers require DCC Level 0?

Defence customers require assurance that suppliers have implemented appropriate cyber security controls to reduce the likelihood of cyber attacks, information compromise, and supply chain vulnerabilities.

Can DCC Level 0 improve our overall cyber security?

Yes. Many organisations find that implementing DCC Level 0 controls improves password security, patch management, employee awareness, access control, and overall cyber resilience across the business.

Defence Cyber Certification (DCC) Level 1 Questions

What is DCC Level 1?

DCC Level 1 is a higher level of Defence Cyber Certification that requires organisations to demonstrate a more mature cyber security capability. In addition to implementing controls, organisations must provide evidence that security processes are documented, maintained, and operating effectively.

How does DCC Level 1 differ from DCC Level 0?

DCC Level 0 focuses on fundamental cyber security controls and awareness. DCC Level 1 introduces additional governance, documented processes, risk management activities, and evidence requirements to demonstrate ongoing cyber security management.

Who needs DCC Level 1 certification?

DCC Level 1 is typically required where organisations have increased exposure to defence information, systems, or services and need to demonstrate a stronger level of cyber assurance.

What evidence is required for a DCC Level 1 assessment?

Evidence may include policies, procedures, risk assessments, training records, vulnerability management activities, access control documentation, asset inventories, incident management processes, and management reviews.

How should we prepare for a DCC Level 1 assessment?

Preparation typically involves reviewing requirements, documenting processes, gathering evidence, conducting internal reviews, addressing compliance gaps, and ensuring security controls are operating effectively. Valantus can help organisations prepare through readiness assessments and gap analyses.

What happens if we do not meet all DCC Level 1 requirements?

Any identified gaps should be addressed through corrective actions and remediation activities. Valantus can help organisations prioritise findings and implement practical improvements before reassessment.

How long does it take to become DCC Level 1 certified?

Timescales depend on existing cyber maturity, available evidence, and organisational complexity. Some businesses may be ready within a few weeks, while others require a longer remediation programme.

Do we need documented cyber security policies?

Yes. Level 1 organisations should maintain documented and controlled security policies that define responsibilities, expectations, and security requirements across the organisation.

Do we need a cyber security risk assessment process?

Yes. Organisations should have a structured process for identifying, assessing, recording, and managing cyber security risks affecting systems, information, and services.

Is multi-factor authentication required for DCC Level 1?

Multi-factor authentication is widely recognised as a security best practice and is strongly recommended for privileged accounts, cloud services, remote access, and critical systems.

Do employees require cyber security awareness training?

Yes. Employees should receive regular awareness training to understand cyber threats, phishing attacks, password security, information handling requirements, and their security responsibilities.

What role does vulnerability management play in DCC Level 1?

Organisations should identify, assess, prioritise, and remediate vulnerabilities in a timely manner to reduce cyber security risk and maintain a secure operating environment.

Do we need an asset inventory?

Yes. Organisations should maintain an inventory of hardware, software, and information assets so they can understand what needs to be protected and managed.

Do we require an incident response process?

Yes. Organisations should have clear procedures for identifying, reporting, responding to, and recovering from cyber security incidents.

Can cloud services be used within a DCC Level 1 environment?

Yes. Cloud platforms such as Microsoft 365 can support DCC Level 1 compliance when configured and managed securely with appropriate security controls.

What documentation should we have before a DCC Level 1 assessment?

Most organisations should have policies, procedures, risk assessments, training records, user access records, asset inventories, vulnerability management activities, and evidence showing controls are operating effectively.

Do we need a password policy?

Yes. Organisations should define requirements for password creation, management, protection, and periodic review to help reduce the risk of unauthorised access.

Is remote working allowed under DCC Level 1?

Yes. However, organisations should ensure devices, user accounts, communications, and remote access methods are protected appropriately.

Can SMEs achieve DCC Level 1?

Absolutely. Many SMEs successfully achieve DCC Level 1. Valantus works with organisations of all sizes to develop practical and achievable compliance programmes.

How much does DCC Level 1 certification cost?

Costs vary according to organisational size, complexity, current cyber maturity, and the amount of remediation work required. Valantus can help identify the most efficient certification pathway.

How long does a DCC Level 1 assessment take?

The assessment duration depends on organisational scope, available evidence, and the maturity of security controls. Preparation is often the most time-consuming element.

Does ISO 27001 help with DCC Level 1 compliance?

Yes. Organisations with ISO 27001 certification often already have many of the management system and governance controls expected within DCC Level 1.

Does Cyber Essentials help with DCC Level 1?

Yes. Cyber Essentials provides a strong foundation of technical controls which can support DCC Level 1 preparation.

Can Microsoft 365 support DCC Level 1 compliance?

Yes. Features such as multi-factor authentication, conditional access, device management, auditing, and security monitoring can contribute to Level 1 compliance when implemented correctly.

Do suppliers need regular security reviews?

Yes. Security controls should be reviewed regularly to ensure they remain effective and continue to address evolving threats and business risks.

Do we need user access reviews?

Yes. Organisations should periodically review user access rights to ensure individuals only have access to systems and information required for their roles.

What are the most common DCC Level 1 compliance gaps?

Common gaps include missing documentation, incomplete risk assessments, weak asset management, inconsistent vulnerability remediation, poor access reviews, and insufficient evidence collection.

Can contractors and consultants achieve DCC Level 1?

Yes. Contractors, consultants, and specialist service providers may require DCC Level 1 certification depending on the nature of the services they provide.

What is a DCC Level 1 readiness assessment?

A readiness assessment reviews existing controls, identifies compliance gaps, assesses available evidence, and provides a roadmap towards successful certification.

Can Valantus perform a DCC Level 1 gap analysis?

Yes. Valantus can review your current environment against DCC Level 1 requirements, identify compliance gaps, and provide practical remediation recommendations.

Can Valantus provide DCC Level 1 consultancy?

Yes. Valantus supports organisations through readiness assessments, gap analyses, policy development, risk management activities, evidence reviews, remediation planning, and certification preparation.

Why do defence customers require DCC Level 1?

Defence customers require assurance that suppliers can adequately protect sensitive information, systems, and services from cyber threats and security incidents.

Can DCC Level 1 help win defence contracts?

Yes. Demonstrating DCC Level 1 compliance can help satisfy supplier assurance requirements, strengthen customer confidence, and improve competitiveness within the defence sector.

Does DCC Level 1 apply to subcontractors?

Potentially. Subcontractors may also need to demonstrate compliance where they have access to defence information, systems, or services.

Can DCC Level 1 improve overall cyber security maturity?

Yes. Organisations often find that implementing DCC Level 1 controls improves governance, risk management, incident response, user management, and overall cyber resilience.

What are the benefits of DCC Level 1 certification?

Benefits can include reduced cyber risk, improved customer confidence, enhanced supply chain assurance, stronger governance, and increased eligibility for defence sector opportunities.

How can we start our DCC Level 1 journey?

Most organisations begin by carrying out a readiness assessment. Valantus can review your current position, identify compliance gaps, and develop a practical roadmap towards successful DCC Level 1 certification.

Why choose Valantus for your Defence Cyber Certification?

Valantus is an IASME Approved Certification Body authorised to assess and certify organisations against Defence Cyber Certification (DCC) requirements. Our experienced assessors provide practical, jargon-free guidance to help organisations understand the requirements, prepare evidence, and achieve certification efficiently. As specialists in cyber assurance, compliance, and defence sector requirements, we support businesses throughout the entire certification journey

Ready to Achieve Defence Cyber Certification?
Whether you’re preparing for your first assessment or need support meeting defence supply chain requirements, our experts can help you navigate the certification process with confidence. Contact Us Today
Please enable JavaScript in your browser to complete this form.
Name