Loading...

What Are You Looking For?

How DCC Level 0 works

DCC Level 1 is a cyber security certification for organisations operating within the UK defence supply chain that are required to meet a Low Cyber Risk Profile (CRP). Building on Cyber Essentials, DCC Level 1 assesses an organisation against 101 security controls covering areas such as governance, risk management, asset protection, incident response, and personnel security. 

The certification process includes defining the assessment scope, providing evidence of compliance, and completing both theoretical and practical assessments to demonstrate that security controls are effectively implemented. Achieving DCC Level 1 gives the Ministry of Defence and prime contractors confidence that a supplier has an appropriate level of cyber resilience to protect defence-related information and services. 

The certification is valid for three years, subject to annual attestation and the continued maintenance of prerequisite certifications such as Cyber Essentials.

DCC Level 1 requires organisations to show that security processes are formally documented, consistently followed, and supported by evidence. Assessors will typically review policies, procedures, records, reports, and technical documentation to verify compliance.

Examples of DCC Level 1 controls include:

  • Maintaining an up-to-date inventory of IT assets.
  • Defining cyber security roles and responsibilities.
  • Conducting regular risk assessments.
  • Managing user access and permissions.
  • Protecting information shared with suppliers.
  • Detecting and responding to security incidents.
  • Backing up and testing the recovery of critical business data.
  • Providing cyber security awareness training to employees. 

To achieve certification, organisations must not only demonstrate that these controls exist but also provide evidence that they are operating effectively in practice. This helps give the Ministry of Defence, prime contractors, and other defence organisations confidence that suppliers can protect sensitive information and maintain cyber resilience across the defence supply chain.

Example DCC Level 1 Control

Control Reference: 1300.1 Asset Management  (MOD 000031)

What the Control Requires

Organisations must maintain an inventory of their information assets, including devices, systems, and software used to support business operations. This helps ensure assets are known, managed, and protected throughout their lifecycle. [iasme.atlassian.net], [indelibledata.co.uk]

Example Evidence

  • Asset register or inventory spreadsheet
  • List of company laptops and mobile devices
  • Device ownership records
  • Endpoint management reports
  • Hardware issue and return records

This Example

A company maintains an up-to-date asset register showing every laptop, server, and mobile device it owns, who it has been assigned to, and its current status. During the assessment, the organisation provides the asset register and supporting records as evidence that all devices are tracked and managed appropriately.

This is a simple example of how DCC Level 1 controls are assessed, with the organisation demonstrating both a documented process and evidence that it is being followed in practice.

DCC Level 1 Certification Process

DCC Level 1 demonstrates that your organisation has the cyber resilience required to operate within the UK defence supply chain. The assessment evaluates compliance against 101 controls from Def Stan 05-138 and provides certification valid for three years, subject to annual attestation.

1. Verify Your Cyber Essentials Scope

Cyber Essentials is a mandatory prerequisite. We’ll review your certification to ensure its scope aligns with your intended DCC assessment, helping avoid delays later in the process.

2. Define Your Assessment Scope

Together, we’ll establish the organisational boundary for assessment, including people, locations, systems, suppliers, and information assets. A clear scope is the foundation of a successful certification.

3. Prepare Your Evidence

You’ll need to demonstrate compliance with 101 controls covering governance, risk management, access control, asset management, supplier security, physical security, incident response, vulnerability management, and business continuity.

Typical evidence includes:

  • Policies and procedures
  • Risk assessments
  • Asset registers
  • Training records
  • Access reviews
  • Incident logs
  • Technical reports

4. Assessment & Review

Our assessors review your documentation and supporting evidence, identifying any gaps and requesting clarification where required.

5. Theoretical Assessment

We evaluate your policies, processes, and governance arrangements to verify they meet DCC Level 1 requirements.

6. Practical Assessment

We confirm that controls are operating effectively in practice through reviews of system configurations, access controls, asset inventories, backups, and other operational evidence.

7. Certification

Once all requirements are met, you’ll receive your DCC Level 1 certificate, certification badge, and listing on the IASME certification register.

Pricing - DCC costs for Level 1

Micro 1-9 Small 10-49Medium 50-249Large 250+
From* £9,500From* £14,500From* £19,500POA
One-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 YearsOne-off – Valid for 3 Years
Annual attestationAnnual attestationAnnual attestationAnnual attestation
Two remediation rounds includedTwo remediation rounds includedTwo remediation rounds includedTwo remediation rounds included
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
Including DCC Scope Template and DCC L1 guide and examples
From* Starting price based on organisations with an existing Cyber Essentials Plus and ISO 27001 certification, mature documentation, and a maximum of two remediation cycles following assessment. Additional remediation, gap analysis, or documentation development may incur additional fees.

Ready to Take the Next Step?

Our experienced assessors will help you understand the additional requirements of DCC Level 1, identify any gaps, and prepare the evidence needed for a successful assessment..

Speak to our team today for friendly, no-obligation advice on achieving DCC Level 1 certification.
For further information about the Defence Cyber Certification (DCC) scheme, please visit the official IASME guidance: