Loading...

What Are You Looking For?

Calculating...

From December 2026, defence suppliers are expected to hold DCC certification to meet MOD cyber assurance requirements. Whether you're responding to a new tender or preparing for future requirements, Valantus helps you achieve DCC certification quickly, simply and with confidence.

admin-ajax.tuxpi

DCC - Defence Cyber Certification Explained

If your organisation works within the defence supply chain, you may be asked to demonstrate that you have appropriate cyber security controls in place. Defence Cyber Certification (DCC) provides a clear framework for assessing and improving your organisation’s cyber security posture.

At Valantus, we help businesses navigate the DCC process with confidence. We explain the requirements in plain English, identify what is needed for your chosen certification level, and guide you through every stage of the journey.

Whether you are pursuing DCC Level 0 certification or DCC Level 1 certification, our experienced team will work closely with you to ensure you understand the requirements, address any gaps, and achieve certification as efficiently as possible.

No confusing terminology. No unnecessary complexity. Just practical, expert support to help you meet defence industry requirements and demonstrate your commitment to cyber security.

The MOD has mandated that all defence supply chain organisations achieve at least DCC Level 0 by 31 December 2026.

DCC Level 0 Certification

How DCC Level 0 works

1. Confirm Your Cyber Essentials Scope

Before starting the DCC assessment, you will need a valid Cyber Essentials certificate. We will check that the scope of your Cyber Essentials certification aligns with the scope of your intended DCC assessment, as any misalignment could prevent certification.

2. Define Your DCC Scope

We will work with you to review your DCC scoping statement, ensuring it’s clear, logical, and accurately reflects your organisation. We will look at what’s included, what is excluded, and the reasoning behind your decisions to make sure everything stands up to scrutiny.

3. DCC Assessment

As an IASME Approved Certification Body, we will assess your organisation against the requirements of Def Stan 05-138 (Issue 4). We will review your evidence, explain anything that is not clear, and guide you through the process in plain English.

4. Achieve Certification

Once you have successfully met the requirements, we will issue your DCC Level 0 certificate. You will receive a digital certificate and verifiable certification badge, and your organisation will be listed on the IASME public registry. Your certification remains valid for three years.

Not Sure Where to Start?

Our experienced DCC assessors will help you understand the requirements, identify any gaps, and guide you through the certification process in plain English.

Book a free, no-obligation consultation to discuss your DCC Level 0 certification requirements.

What you're assessed against

DCC Level 0 assesses three key controls from Def Stan 05-138 (Issue 4). To achieve certification, your organisation must meet all three controls. There is no partial pass, but do not worry, we will explain the requirements in plain English and help you understand the evidence needed before your assessment.

Control 0001: Cyber Essentials

Cyber Essentials forms the foundation of DCC Level 0. Your Cyber Essentials certification must cover all internet-connected systems within your DCC scope, and you will need to demonstrate a commitment to maintaining that certification throughout the three-year validity period of your DCC certificate.

A mismatch between your Cyber Essentials scope and DCC scope will result in an unsuccessful assessment, so we will help you get this right from the start.

Cyber Essentials certificate covers the full DCC scope
Commitment to maintain Cyber Essentials throughout the DCC certification period
Renewal history or management attestation available
Control 2314: UK GDPR Compliance

You must demonstrate that your organisation appropriately manages personal data and complies with UK GDPR requirements.

This includes documented policies and procedures, as well as Data Protection Impact Assessments (DPIAs) relevant to the types of personal data your organisation stores or processes. The evidence required is proportionate to the size and complexity of your organisation.

We can help you understand exactly what documentation is expected and identify any gaps before assessment.

GDPR policies and procedures appropriate to your organisation
DPIAs completed for relevant data processing activities
Supporting evidence scaled to organisation size and risk
Control 2500: Resilient Networks and Systems

This control focuses on your organisation’s ability to withstand and recover from cyber incidents, system failures, and other disruptions.

You will need to demonstrate that you have assessed your resilience requirements and implemented appropriate measures to protect critical systems and data. Importantly, this is not just about having policies. You will need practical evidence that resilience measures are working in your environment.

Documented assessment of resilience requirements
Evidence of implemented resilience measures, such as backups and recovery processes
Demonstrable ability to recover and maintain critical services

DCC costs for Level 0

Micro 1-9 Small 10-49Medium 50-249Large 250+
From £950 (With an existing, valid Cyber Essentials certification)From £1,550 (With an existing, valid Cyber Essentials certification)From £2,750 (With an existing, valid Cyber Essentials certification)From £4,750 (With an existing, valid Cyber Essentials certification)
One-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 Years
L0 assessmentL0 assessmentL0 assessmentL0 assessment
Annual attestationAnnual attestationAnnual attestationAnnual attestation
From £1,250 (including Cyber Essentials certification)From £1,950 (including Cyber Essentials certification)From £3,250 (including Cyber Essentials certification)From £5,350 (including Cyber Essentials certification)
From* Starting price based on organisations with well-established cyber security processes, current and accurate documentation, and a maximum of two remediation cycles following the assessment. Additional remediation support, gap analysis, or documentation development may incur additional fees.

Need Help Understanding the Requirements?

Our experienced assessors will explain each control in plain English, help you identify any gaps, and ensure you have the right evidence ready for assessment.

Speak to our team today for friendly, no-obligation advice on achieving DCC Level 0 certification.

DCC Level 1 Certification

DCC Level 1 is a cyber security certification for organisations operating within the UK defence supply chain that are required to meet a Low Cyber Risk Profile (CRP). Building on Cyber Essentials, DCC Level 1 assesses an organisation against 101 security controls covering areas such as governance, risk management, asset protection, incident response, and personnel security. 

The certification process includes defining the assessment scope, providing evidence of compliance, and completing both theoretical and practical assessments to demonstrate that security controls are effectively implemented. Achieving DCC Level 1 gives the Ministry of Defence and prime contractors confidence that a supplier has an appropriate level of cyber resilience to protect defence-related information and services. 

The certification is valid for three years, subject to annual attestation and the continued maintenance of prerequisite certifications such as Cyber Essentials.

DCC Level 1 requires organisations to show that security processes are formally documented, consistently followed, and supported by evidence. Assessors will typically review policies, procedures, records, reports, and technical documentation to verify compliance.

Examples of DCC Level 1 controls include:

  • Maintaining an up-to-date inventory of IT assets.
  • Defining cyber security roles and responsibilities.
  • Conducting regular risk assessments.
  • Managing user access and permissions.
  • Protecting information shared with suppliers.
  • Detecting and responding to security incidents.
  • Backing up and testing the recovery of critical business data.
  • Providing cyber security awareness training to employees. 

To achieve certification, organisations must not only demonstrate that these controls exist but also provide evidence that they are operating effectively in practice. This helps give the Ministry of Defence, prime contractors, and other defence organisations confidence that suppliers can protect sensitive information and maintain cyber resilience across the defence supply chain.

Example DCC Level 1 Control

Control Reference: 1300.1 Asset Management  (MOD 000031)

What the Control Requires

Organisations must maintain an inventory of their information assets, including devices, systems, and software used to support business operations. This helps ensure assets are known, managed, and protected throughout their lifecycle. [iasme.atlassian.net], [indelibledata.co.uk]

Example Evidence

  • Asset register or inventory spreadsheet
  • List of company laptops and mobile devices
  • Device ownership records
  • Endpoint management reports
  • Hardware issue and return records

This Example

A company maintains an up-to-date asset register showing every laptop, server, and mobile device it owns, who it has been assigned to, and its current status. During the assessment, the organisation provides the asset register and supporting records as evidence that all devices are tracked and managed appropriately.

This is a simple example of how DCC Level 1 controls are assessed, with the organisation demonstrating both a documented process and evidence that it is being followed in practice.

DCC Level 1 Certification Process

DCC Level 1 demonstrates that your organisation has the cyber resilience required to operate within the UK defence supply chain. The assessment evaluates compliance against 101 controls from Def Stan 05-138 and provides certification valid for three years, subject to annual attestation.

1. Verify Your Cyber Essentials Scope

Cyber Essentials is a mandatory prerequisite. We’ll review your certification to ensure its scope aligns with your intended DCC assessment, helping avoid delays later in the process.

2. Define Your Assessment Scope

Together, we’ll establish the organisational boundary for assessment, including people, locations, systems, suppliers, and information assets. A clear scope is the foundation of a successful certification.

3. Prepare Your Evidence

You’ll need to demonstrate compliance with 101 controls covering governance, risk management, access control, asset management, supplier security, physical security, incident response, vulnerability management, and business continuity.

Typical evidence includes:

  • Policies and procedures
  • Risk assessments
  • Asset registers
  • Training records
  • Access reviews
  • Incident logs
  • Technical reports

4. Assessment & Review

Our assessors review your documentation and supporting evidence, identifying any gaps and requesting clarification where required.

5. Theoretical Assessment

We evaluate your policies, processes, and governance arrangements to verify they meet DCC Level 1 requirements.

6. Practical Assessment

We confirm that controls are operating effectively in practice through reviews of system configurations, access controls, asset inventories, backups, and other operational evidence.

7. Certification

Once all requirements are met, you’ll receive your DCC Level 1 certificate, certification badge, and listing on the IASME certification register.

DCC costs for Level 1

Micro 1-9 Small 10-49Medium 50-249Large 250+
From £9,500From £14,500From £19,500POA
One-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 Years
L0 assessmentL0 assessmentL0 assessmentL0 assessment
Annual attestationAnnual attestationAnnual attestationAnnual attestation
Two remediation rounds includedTwo remediation rounds includedTwo remediation rounds includedTwo remediation rounds included
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
From* Starting price based on organisations with an existing Cyber Essentials Plus and ISO 27001 certification, mature documentation, and a maximum of two remediation cycles following assessment. Additional remediation, gap analysis, or documentation development may incur additional fees.

Ready to Take the Next Step?

Our experienced assessors will help you understand the additional requirements of DCC Level 1, identify any gaps, and prepare the evidence needed for a successful assessment..

Speak to our team today for friendly, no-obligation advice on achieving DCC Level 1 certification.
For further information about the Defence Cyber Certification (DCC) scheme, please visit the official IASME guidance:
cyber_security_networks

At Valantus, we are cybersecurity specialists and an IASME Approved Certification Body, delivering Cyber Essentials (CE), Cyber Essentials Plus (CE+), and DCC Level 0 and 1 certifications.

We believe certification should not be complicated. That is why we speak in plain English, cut through the jargon, and guide you through every step of the process.

Whether you’re applying for certification for the first time or renewing an existing accreditation, our experienced team will help you understand what Is required, identify any gaps, and achieve certification with confidence.

Our goal is simple:

To make cybersecurity compliance straightforward, stress-free, and valuable for your business. By combining practical cybersecurity expertise with a supportive, hands-on approach, we help organisations strengthen their security, meet regulatory requirements, and build trust with customers and partners.

Simple advice. Expert guidance. Certification made easy.

Our Credentials

IS0 9001 and ISO 27001 certified
IASME Approved Certification Body (Cyber Essentials & DCC)
Authorised to certify organisations for DCC Level 0, 1
UK-based with extensive industry experience
Fully remote assessment capability
microsoft_sign-in