Accredited DCC Certification Body
We carry out the assessment and issue the certificate ourselves. There is no third party in the middle.
The Ministry of Defence's cyber assurance scheme for its supply chain. As an accredited DCC Certification Body, we assess defence suppliers and issue the certificate ourselves: quickly, simply and directly.

The MOD has asked all defence industry partners to achieve DCC Level 0 by 31 December 2026.
DCC is an organisation-wide cyber security certification developed by the Ministry of Defence with IASME.
It gives independent assurance that a supplier has implemented the controls required by Defence Standard 05-138 (Issue 4) at the level it is certified to. One certificate covers your organisation and can be presented across multiple defence procurements, rather than completing a separate assessment for each contract.
The controls align with relevant parts of the NCSC Cyber Assessment Framework, with Cyber Essentials at the core. Every level starts with Cyber Essentials, Levels 2 and 3 require Cyber Essentials Plus, and no level is a self-assessment.
The MOD or your prime contractor sets the level you need, based on the cyber risk profile of the contract. Certifying at a higher level satisfies the requirements of the levels below it.
Very low cyber risk
Basic cyber security practices. The foundation for every higher level.
We assess and certify
Low to moderate cyber risk
A comprehensive cyber security programme with good practices.
High cyber risk
Advanced cyber security oversight and planning. Requires Cyber Essentials Plus.
Substantial cyber risk
Expert, defence-in-depth capability against new and evolving threats. Requires Cyber Essentials Plus. Currently assessed only as a combined Level 2/3 hybrid of 145 controls.
Level 0 is the minimum the MOD expects. To pass, every control must be fully met: there is no partial credit at this level.
Cyber Essentials certification covering your DCC scope, maintained for the life of the certificate. If the Cyber Essentials scope does not align, the assessment fails automatically. We are an IASME-licensed Cyber Essentials Certification Body, so we can certify both.
Documented policies and procedures showing personal data is processed in line with the UK Data Protection Act 2018.
Resilience against cyber-attack and system failure built into how you design, implement, operate and manage the systems that support your business and protect your data. This starts with a risk assessment of your essential systems.
One Layer 7 assessor works with you from the first call to the certificate.
We agree your applicant, certification boundary and the essential functions and services that must stay secure. We challenge the scope so it is logical and clearly documented.
We check your Cyber Essentials certificate covers the same scope. If it does not, or you do not hold one yet, we certify you first.
We explain each control, the questions behind it and the evidence the assessor will expect. You prepare your responses and evidence; as your Certification Body we can guide, but we cannot write them for you.
Our assessor marks your submission against the controls and verifies that they operate as described, remotely or on site. Clarification rounds let you respond to any questions.
We issue your DCC certificate and you are listed on the IASME public registry. It is valid for three years, with an annual attestation and annual Cyber Essentials renewal.
We carry out the assessment and issue the certificate ourselves. There is no third party in the middle.
An IASME-licensed Cyber Essentials Certification Body since the scheme launched, so the prerequisite and DCC come from one team.
We deliver security to defence and public sector clients, including MOD-accredited cloud work, through G-Cloud 14, DOS 7 and CCS frameworks.
DCC sits within a wider practice covering penetration testing, ISO 27001 readiness and managed defence, which helps when you move up a level.
In IASME’s words, “DCC is currently not mandatory”. However, the MOD has asked all defence industry partners to achieve Level 0 by 31 December 2026, and higher levels are set contract by contract.
The MOD or your prime contractor assigns the level based on the cyber risk profile of the work. Most suppliers start at Level 0.
Yes. Every DCC level starts with Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus. Its scope must align with your DCC scope. We can certify both.
No. No DCC level is a self-assessment. A Certification Body reviews your evidence and verifies the controls.
All three controls must be fully met. Higher levels score each control and require at least 80% of the points in every objective.
Yes, within the scheme rules. We can explain the controls, clarify the questions, describe the evidence needed and verify your scope. We cannot implement changes or prepare the answers we later assess; for hands-on implementation you can use a separate provider.
Three years, with an annual attestation and annual renewal of Cyber Essentials in between.
Pricing is fixed once scope is agreed.
Tell us about your organisation and the contracts you support. We'll agree the scope, give you a fixed-price quote and a clear route to certification before the December 2026 deadline.