How DCC Level 0 works
DCC Level 1 is a cyber security certification for organisations operating within the UK defence supply chain that are required to meet a Low Cyber Risk Profile (CRP). Building on Cyber Essentials, DCC Level 1 assesses an organisation against 101 security controls covering areas such as governance, risk management, asset protection, incident response, and personnel security.
The certification process includes defining the assessment scope, providing evidence of compliance, and completing both theoretical and practical assessments to demonstrate that security controls are effectively implemented. Achieving DCC Level 1 gives the Ministry of Defence and prime contractors confidence that a supplier has an appropriate level of cyber resilience to protect defence-related information and services.
The certification is valid for three years, subject to annual attestation and the continued maintenance of prerequisite certifications such as Cyber Essentials.
DCC Level 1 requires organisations to show that security processes are formally documented, consistently followed, and supported by evidence. Assessors will typically review policies, procedures, records, reports, and technical documentation to verify compliance.
Examples of DCC Level 1 controls include:
- Maintaining an up-to-date inventory of IT assets.
- Defining cyber security roles and responsibilities.
- Conducting regular risk assessments.
- Managing user access and permissions.
- Protecting information shared with suppliers.
- Detecting and responding to security incidents.
- Backing up and testing the recovery of critical business data.
- Providing cyber security awareness training to employees.
To achieve certification, organisations must not only demonstrate that these controls exist but also provide evidence that they are operating effectively in practice. This helps give the Ministry of Defence, prime contractors, and other defence organisations confidence that suppliers can protect sensitive information and maintain cyber resilience across the defence supply chain.
Example DCC Level 1 Control
Control Reference: 1300.1 Asset Management (MOD 000031)
What the Control Requires
Organisations must maintain an inventory of their information assets, including devices, systems, and software used to support business operations. This helps ensure assets are known, managed, and protected throughout their lifecycle. [iasme.atlassian.net], [indelibledata.co.uk]
Example Evidence
- Asset register or inventory spreadsheet
- List of company laptops and mobile devices
- Device ownership records
- Endpoint management reports
- Hardware issue and return records
This Example
A company maintains an up-to-date asset register showing every laptop, server, and mobile device it owns, who it has been assigned to, and its current status. During the assessment, the organisation provides the asset register and supporting records as evidence that all devices are tracked and managed appropriately.
This is a simple example of how DCC Level 1 controls are assessed, with the organisation demonstrating both a documented process and evidence that it is being followed in practice.
DCC Level 1 Certification Process
DCC Level 1 demonstrates that your organisation has the cyber resilience required to operate within the UK defence supply chain. The assessment evaluates compliance against 101 controls from Def Stan 05-138 and provides certification valid for three years, subject to annual attestation.
1. Verify Your Cyber Essentials Scope
Cyber Essentials is a mandatory prerequisite. We’ll review your certification to ensure its scope aligns with your intended DCC assessment, helping avoid delays later in the process.
2. Define Your Assessment Scope
Together, we’ll establish the organisational boundary for assessment, including people, locations, systems, suppliers, and information assets. A clear scope is the foundation of a successful certification.
3. Prepare Your Evidence
You’ll need to demonstrate compliance with 101 controls covering governance, risk management, access control, asset management, supplier security, physical security, incident response, vulnerability management, and business continuity.
Typical evidence includes:
- Policies and procedures
- Risk assessments
- Asset registers
- Training records
- Access reviews
- Incident logs
- Technical reports
4. Assessment & Review
Our assessors review your documentation and supporting evidence, identifying any gaps and requesting clarification where required.
5. Theoretical Assessment
We evaluate your policies, processes, and governance arrangements to verify they meet DCC Level 1 requirements.
6. Practical Assessment
We confirm that controls are operating effectively in practice through reviews of system configurations, access controls, asset inventories, backups, and other operational evidence.
7. Certification
Once all requirements are met, you’ll receive your DCC Level 1 certificate, certification badge, and listing on the IASME certification register.
Pricing - DCC costs for Level 1
| Micro 1-9 | Small 10-49 | Medium 50-249 | Large 250+ |
|---|---|---|---|
| From* £9,500 | From* £14,500 | From* £19,500 | POA |
| One-off – Valid for 3 Years | One-off – Valid for 3 Years | One-off – Valid for 3 Years | One-off – Valid for 3 Years |
| Annual attestation | Annual attestation | Annual attestation | Annual attestation |
| Two remediation rounds included | Two remediation rounds included | Two remediation rounds included | Two remediation rounds included |
| Including DCC Scope Template and DCC L1 guide and examples | Including DCC Scope Template and DCC L1 guide and examples | Including DCC Scope Template and DCC L1 guide and examples | Including DCC Scope Template and DCC L1 guide and examples |
Ready to Take the Next Step?
Our experienced assessors will help you understand the additional requirements of DCC Level 1, identify any gaps, and prepare the evidence needed for a successful assessment..
