How DCC Level 0 works
1. Confirm Your Cyber Essentials Scope
Before starting the DCC assessment, you will need a valid Cyber Essentials certificate. We will check that the scope of your Cyber Essentials certification aligns with the scope of your intended DCC assessment, as any misalignment could prevent certification.
2. Define Your DCC Scope
We will work with you to review your DCC scoping statement, ensuring it’s clear, logical, and accurately reflects your organisation. We will look at what’s included, what is excluded, and the reasoning behind your decisions to make sure everything stands up to scrutiny.
3. DCC Assessment
As an IASME Approved Certification Body, we will assess your organisation against the requirements of Def Stan 05-138 (Issue 4). We will review your evidence, explain anything that is not clear, and guide you through the process in plain English.
4. Achieve Certification
Once you have successfully met the requirements, we will issue your DCC Level 0 certificate. You will receive a digital certificate and verifiable certification badge, and your organisation will be listed on the IASME public registry. Your certification remains valid for three years.
Not Sure Where to Start?
Our experienced DCC assessors will help you understand the requirements, identify any gaps, and guide you through the certification process in plain English.
Book a free, no-obligation consultation to discuss your DCC Level 0 certification requirements.
What you're assessed against
DCC Level 0 assesses three key controls from Def Stan 05-138 (Issue 4). To achieve certification, your organisation must meet all three controls. There is no partial pass, but do not worry, we will explain the requirements in plain English and help you understand the evidence needed before your assessment.
Control 0001: Cyber Essentials
Cyber Essentials forms the foundation of DCC Level 0. Your Cyber Essentials certification must cover all internet-connected systems within your DCC scope, and you will need to demonstrate a commitment to maintaining that certification throughout the three-year validity period of your DCC certificate.
A mismatch between your Cyber Essentials scope and DCC scope will result in an unsuccessful assessment, so we will help you get this right from the start.
Cyber Essentials certificate covers the full DCC scope
Commitment to maintain Cyber Essentials throughout the DCC certification period
Renewal history or management attestation available
Control 2314: UK GDPR Compliance
You must demonstrate that your organisation appropriately manages personal data and complies with UK GDPR requirements.
This includes documented policies and procedures, as well as Data Protection Impact Assessments (DPIAs) relevant to the types of personal data your organisation stores or processes. The evidence required is proportionate to the size and complexity of your organisation.
We can help you understand exactly what documentation is expected and identify any gaps before assessment.
GDPR policies and procedures appropriate to your organisation
DPIAs completed for relevant data processing activities
Supporting evidence scaled to organisation size and risk
Control 2500: Resilient Networks and Systems
This control focuses on your organisation’s ability to withstand and recover from cyber incidents, system failures, and other disruptions.
You will need to demonstrate that you have assessed your resilience requirements and implemented appropriate measures to protect critical systems and data. Importantly, this is not just about having policies. You will need practical evidence that resilience measures are working in your environment.
Documented assessment of resilience requirements
Evidence of implemented resilience measures, such as backups and recovery processes
Demonstrable ability to recover and maintain critical services
Pricing - DCC costs for Level 0
| Micro 1-9 | Small 10-49 | Medium 50-249 | Large 250+ |
|---|---|---|---|
| From* £895 (With an existing, valid Cyber Essentials certification) | From* £1,295 (With an existing, valid Cyber Essentials certification) | From* £1,995 (With an existing, valid Cyber Essentials certification) | From* £2,995 (With an existing, valid Cyber Essentials certification) |
| One-off – Valid for 3 Years | One-off – Valid for 3 Years | One-off – Valid for 3 Years | One-off – Valid for 3 Years |
| L0 assessment | L0 assessment | L0 assessment | L0 assessment |
| Annual attestation | Annual attestation | Annual attestation | Annual attestation |
| From* £1,195 (including Cyber Essentials certification) | From* £1,695 (including Cyber Essentials certification) | From* £2,495 (including Cyber Essentials certification) | From* £3,595 (including Cyber Essentials certification) |
From* Starting price based on organisations with well-established cyber security processes, current and accurate documentation, and a maximum of two remediation cycles following the assessment. Additional remediation support, gap analysis, or documentation development may incur additional fees.
Ready to Take the Next Step?
Our experienced assessors will help you understand the additional requirements of DCC Level 1, identify any gaps, and prepare the evidence needed for a successful assessment..
