DCC Level 0 is the entry level of the Ministry of Defence’s Defence Cyber Certification scheme. It has three controls (Cyber Essentials, UK GDPR compliance, and resilient networks and systems), asked as six yes/no questions, and to pass you must fully meet all three. There is no partial credit. The MOD has asked every industry partner to hold it by 31 December 2026, which, at the time of writing, is about three months away.

Three controls sounds small. It is. But most organisations that struggle with Level 0 do not struggle with the controls. They struggle with the scope those controls sit on.

3
Controls at Level 0: 0001, 2314 and 2500
6
Yes/no questions, each answered with an explanation and evidence
100%
Of controls must be fully met to pass. No partial credit.

Where the 31 December 2026 date comes from

On 8 May 2026, marking the scheme’s first year, Eleanor Fairford, the MOD’s Director of Cyber Defence & Risk, wrote on the Defence Digital blog:

“I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems.”

Eleanor Fairford, Director of Cyber Defence & Risk, MOD

The MOD repeated the ask in a July 2026 post.

It is worth being precise about what that is. It is a request from the MOD to its supply chain, not a change in law. IASME’s own DCC FAQ still states that “DCC is currently not mandatory” and that you may still tender through the normal MOD process. The level a specific contract needs is set by the MOD or by your prime, based on the contract’s assessed cyber risk, and that can be higher than Level 0. If you want to keep winning defence work, treat the date as real.

What DCC is, briefly

Defence Cyber Certification is an organisation-wide cyber security certification developed by the MOD and IASME, assessed against Defence Standard 05-138 Issue 4. IASME, the MOD’s official cyber certification partner, runs it through a network of assured Certification Bodies. One certificate covers your organisation across every defence procurement at or below the certified level, instead of a separate assessment per contract.

There are four levels:

LevelControlsNormally assigned where the assessed cyber risk is…Cyber Essentials requirement
03Very lowCyber Essentials
1101Low to moderateCyber Essentials
2139HighCyber Essentials Plus
3144SubstantialCyber Essentials Plus

Def Stan 05-138 Issue 4 contains 148 controls in total, but no single level uses all of them, because some are replaced by more demanding versions higher up. Level 3 is currently assessed only as a combined Level 2/3 hybrid covering 145 controls. You do not have to work up through the levels, and no level is a self-assessment.

The three Level 0 controls, question by question

Level 0 is six questions. Each is answered Yes or No, with an explanation and evidence. These are the questions as they appear in the IASME Applicant Guide.

ControlQuestionWhat the guide expects as evidence
0001 Cyber Essentials0001.1Does the organisation hold Cyber Essentials certification(s) that cover(s) the required scope for this activity?Certificate number, the CE self-assessment questionnaire or report, and a diagram showing CE scope in relation to DCC scope
0001.2Does the organisation commit to maintaining Cyber Essentials certification for the duration of any function related to this activity or DCC certification?An attestation or a history showing regular renewal
2314 Ensure UK GDPR compliance2314.1Does the organisation have documented policies and procedures which ensure compliance with obligations under the UK General Data Protection Regulation (GDPR)?The policies or procedures, whether a dedicated policy or part of other documentation such as a risk register
2314.2Does the organisation conduct Data Protection Impact Assessments (DPIAs) against data types it stores or processes?Your DPIA procedure, the template or tool you use, or reports showing assessment output
2500 Resilient networks and systems2500.1Has the organisation assessed the degree to which its systems must be resilient to cyber-attack and system failure?A risk assessment showing which systems are essential and the risks to them, proportionate to your size
2500.2Has the organisation built resilience into its systems to meet its resilience needs?Tangible, practical measures that address the needs identified in 2500.1

0001: Cyber Essentials

The control requires you to hold Cyber Essentials covering the scope of your DCC assessment and to keep it for as long as the DCC certificate lasts. Holding a certificate is not enough on its own. It has to be the right certificate.

The complication is that the two schemes draw their boundaries differently. Cyber Essentials covers internet-connected devices and networks. DCC covers everything essential to the organisation, connected or not: operational technology, isolated test rigs, anything the business needs to function. So the guide does not expect the two scopes to match exactly. It expects every internet-connected device inside your DCC scope to be covered by Cyber Essentials, within Cyber Essentials’ own rules, and it expects you to explain the difference.

How the two scopes relate

DCC scope: everything essential to the organisation

Cyber Essentials scope

  • Internet-connected devices
  • Networks
  • Cloud services
  • User accounts

In DCC, outside CE

  • Operational technology
  • Isolated test rigs
  • Non-connected systems

Every internet-connected device inside the DCC scope must sit within the Cyber Essentials scope. A diagram showing this relationship is required for every organisation.

Two requirements follow, and both are hard lines:

  • A diagram showing how your Cyber Essentials scope relates to your DCC scope is required for every organisation, however small.
  • If the Cyber Essentials scope does not adequately align, it is an automatic failure.

This is the control where an existing Cyber Essentials certificate most often turns out to be the wrong shape, typically because it was scoped to a subset of the business years ago. If you are about to renew anyway, renew it to the scope DCC needs.

2314: UK GDPR compliance

The control asks you to show that personal data is processed in compliance with the Data Protection Act 2018, and the guide recommends following the Information Commissioner’s Office guidance. Two questions: documented policies and procedures, and Data Protection Impact Assessments.

Two points from the guide are worth taking literally. First, the DCC assessment “is limited in scope and does not guarantee compliance with GDPR”. A Level 0 certificate is not a GDPR certificate, and should not be presented as one. Second, the DPIA question asks whether you conduct DPIAs against the data you store or process, and the evidence is your procedure, your template or an actual output. An organisation that has a privacy policy but has never run a DPIA will find this is the gap.

The guide is explicit that documentation should be proportionate. A small organisation’s evidence can be simpler than a large one’s.

2500: Resilient networks and systems

The control requires you to build resilience against cyber-attack and system failure into the design, implementation, operation and management of the systems that support your business and protect your data. The guide’s own warning: “Although this control contains just two yes/no questions, it’s important not to underestimate its significance.”

The two questions run in order. 2500.1 asks whether you have worked out how resilient your systems need to be: a risk assessment that identifies which systems are essential and what threatens them. 2500.2 asks whether you have actually built that resilience in, and the evidence must connect back to what 2500.1 found.

“Avoid referencing policy documents or high-level plans.”

That instruction, in the evidence guidance for 2500.2, is the one that catches people. The assessor wants the concrete measures (the guide’s examples are automated backups and uninterruptible power supplies), not the document that says you intend to have them. A business continuity plan on its own does not answer this question.

Where Level 0 actually fails

The controls are small, but the scope underneath them is your whole organisation. That is where the Applicant Guide puts its hardest rules.

You set the scope, and you own it. The Certification Body can review and challenge your scope, but determining it is the applicant’s responsibility. It has to include every process, system and part of the business needed for the organisation to function securely and resiliently.

It is the whole organisation, not the MOD contract. IASME’s FAQ is direct: you cannot scope only the networks that handle MOD work or sensitive data. Essential functions are in scope whether they serve MOD or non-MOD customers. Cloud services the business relies on are in scope. Operational technology is in scope if the business depends on it.

The scope must be documented well enough to stand on its own. The guide asks for business organisation diagrams, network diagrams and lists of systems, with the systems covered by Cyber Essentials explicitly marked. An assessor must be able to understand the scope from your documentation alone. If the assessor decides the scope or its documentation is inadequate, the entire assessment fails.

The scope does not change between levels. What is essential to your organisation does not depend on which level you apply for, so a Level 0 scope is the same scope you will use at Level 1 and above. Getting it right now is not wasted effort.

Controls met by someone else still have to be shown as met. If an MSP, a parent company or a cloud provider delivers part of a control, you still have to evidence it, and that evidence may have to come from them.

Beyond scope, the remaining failure points are procedural. Level 0 requires 100% of controls to be fully met, so one unconvincing answer fails the assessment. Once you submit, you may not amend the submission or its evidence unless the assessor asks. And you must keep all assessment documentation for at least three and a half years, available to IASME or the MOD for moderation.

How the Level 0 assessment runs

Level 0 follows a lighter process than Levels 1 to 3. The IASME Process Guide sets it out:

  1. Preparation. You define the scope using the IASME Scoping Guide, consulting a Certification Body if your organisation is complex, and choose a Certification Body.

  2. Onboarding. The Certification Body registers you on the IASME portal at Level 0.

  3. Submission. You answer the six questions with explanations and evidence, then submit. Level 0 needs no separate Assessment Submission Record. The Level 0 portal route cannot be used to aim for a higher level; that needs the Level 1–3 process.

  4. Assessment. The Certification Body marks each question Compliant, Non-compliant or More information needed. If more information is needed, you update and resubmit.

  5. Certification. On a pass, the certificate is issued automatically through IASME’s BlockMark system, with a verifiable digital badge.

IASME gives no fixed timescale. It depends on how prepared you are, whether you need to fix gaps first, and your Certification Body’s availability. With a December deadline and every defence supplier aiming at the same date, the last factor is worth taking seriously.

What your Certification Body can and cannot do

This matters more than most applicants expect, so it is worth being clear about it. Under the scheme rules, a Certification Body can explain the scheme and the controls, help you understand what each question needs, describe the evidence an assessor will expect, verify your scope, provide blank templates, and help you achieve Cyber Essentials.

It cannot implement policies, controls or technical changes for you, answer the questions for you, or prepare answers and evidence it will later assess. If you need hands-on implementation, IASME’s guidance is to use a separate provider. That provider does not need to be a DCC Certification Body.

We work to those rules. As a DCC Certification Body we will guide you through every control and challenge your scope, but the answers and evidence have to be yours.

After Level 0

A DCC certificate is valid for three years. To keep it you must:

  • renew Cyber Essentials every year,
  • complete an annual attestation that you are still meeting the controls and that your scope has not changed significantly, and
  • discuss any significant change with your Certification Body, which will decide whether recertification is needed.

If a contract later needs Level 1 or above, you cannot upgrade by being assessed only on the extra controls; you apply for the higher level as a new assessment. Level 1 is a substantial step: 101 controls and a scoring threshold of at least 80% of the points in every objective, with no control left entirely unmet. Your Level 0 scope, Cyber Essentials alignment and resilience assessment carry straight across to it.

Getting to Level 0 before December

In order: check your Cyber Essentials certificate covers the scope DCC needs, and fix that first if it does not. Draw the scope: organisation, network, systems, and where Cyber Essentials sits inside it. Find your GDPR policies and your DPIA procedure, or write the missing one. Run and write down the resilience assessment, then gather evidence of the measures that answer it.

Layer 7 is an accredited DCC Certification Body and an IASME Cyber Essentials Certification Body, so Cyber Essentials and DCC Level 0 can be assessed by one team. If your contracts also call for Cyber Essentials Plus, our comparison of Cyber Essentials and Cyber Essentials Plus sets out the difference, and our defence supply chain page covers the wider MOD requirements.

Start your DCC Level 0 certification →


Sources (all checked 24 September 2026)

Start a conversation

Have a question about this topic?