DCC Level 0 vs Level 1: Which Defence Cyber Certification Do You Need?
Compare DCC Levels 0 and 1: controls, scope, prerequisites, costs and planning timelines. Ask the buyer for the current numeric profile before choosing a level.

Section 01
DCC Level 0 vs Level 1: Which Defence Cyber Certification Do You Need?
The most common question Fig Group hears at DCC scoping is "can we save money by going with Level 0?" The honest answer is that you do not choose your DCC level - your contract Cyber Risk Profile (CRP) determines it. This guide compares Level 0 and Level 1 head-to-head, explains how to verify which level your contract actually requires, and explains when confirmed higher-level requirements may justify Level 1 preparation, without assuming a separate Level 0 fee for every contract.
The buyer assigns the contract profile and RAR. Current CSMv4 profiles are numeric Levels 0–3, with corresponding DCC evidence levels. Legacy Very Low, Low, Moderate and High wording is not a direct conversion; obtain the current requirement in writing before purchasing.
This post focuses on the L0 vs L1 comparison because those two cover the largest share of contracts in the UK MOD supply chain. For Level 2 and Level 3 referrals, Fig Group refers suppliers to IASME-licensed Certification Bodies that hold those scopes.
Section 02
What DCC Level 0 covers
Level 0 is the foundational tier for a current numeric Level 0 profile. Supplier size, professional-services role and absence of classified data do not determine the profile; obtain it from the buyer.
Key facts:
- 3 controls: appropriately scoped Cyber Essentials, board-level cyber responsibility and an organisation-wide cyber risk assessment
- Documentation review only - no on-site visit, no technical inspection
- Prerequisite: a current Cyber Essentials certificate (any IASME-licensed body)
- Fig Group published timeline: 2-3 weeks for prepared organisations
- Fig Group published pricing: £499.99 / £599.99 / £699.99 / £799.99 + VAT (Micro / Small / Medium / Large)
- Validity: 3 years, with annual attestation at end of years 1 and 2
Level 0 suitability follows the buyer’s assigned profile. Scope includes operationally essential business systems, not merely systems holding classified or MOD data; entity boundaries and exclusions must be documented.
Section 03
What DCC Level 1 covers
Level 1 applies to a current numeric Level 1 profile. Complex estates can affect preparation and price, but do not independently assign the contract profile.
Key facts:
- 101 controls across governance, identity, device, secure configuration, and supply-chain
- Documentation review with clarification rounds and remediation cycles - some scopes trigger evidence-verification calls
- Prerequisite: a current Cyber Essentials certificate (Cyber Essentials Plus is required at L2, not L1)
- Fig Group published timeline: 6-10 weeks for prepared organisations
- Fig Group published pricing: £9,999 to £49,999 + VAT, scoped by supplier complexity (sites, cloud footprint, legacy systems, supply chain, staff, existing maturity)
- Validity: 3 years, with annual attestation at end of years 1 and 2
Fig Group bundles a dedicated consultant and the Fig Technology compliance automation platform into the L1 base fee, with up to three structured feedback rounds before formal assessment, within the written service scope.
Section 04
Head-to-head comparison
Swipe across the table to view all columns.
| DCC Level 0 | DCC Level 1 | |
|---|---|---|
| Controls | 3 | 101 |
| Underlying standard | Def Stan 05-138 issue 4 | Def Stan 05-138 issue 4 |
| Current CSMv4 CRP | Level 0 | Level 1 |
| Assessment style | Documentation review | Documentation + clarification + remediation |
| On-site visit | No | Not typically - depends on scope |
| Prerequisite | Current Cyber Essentials | Current Cyber Essentials |
| Fig Group published price (Micro) | £499.99 + VAT | From around £9,999 + VAT (scoped) |
| Fig Group published price (Large) | £799.99 + VAT | Up to £49,999 + VAT (scoped) |
| Fig Group timeline | 2-3 weeks | 6-10 weeks |
| Certificate validity | 3 years | 3 years |
| Annual attestation | Years 1 + 2 | Years 1 + 2 |
| Year-3 re-assessment | Yes | Yes |
The price gap between L0 and L1 is real - roughly an order of magnitude at the Micro tier. The work gap is also real: L0 is three controls and a documentation review; L1 is 101 controls plus structured remediation. The right answer is the one that matches the contract requirement, not the one that minimises the immediate fee.
Section 05
How to verify which level your contract actually requires
Three patterns to read in your contract clause:
1. The clause names a current CSMv4 CRP explicitly - numeric Level 0, 1, 2 or 3. Confirm its RAR and applicable DCC requirement. Ask the buyer to clarify any legacy verbal profile.
2. The clause names DCC Level X explicitly. Use that level.
3. The clause is vague - phrases like "industry-standard cyber security", "appropriate cyber controls", or "compliance with Defence Standards" without naming the level. Ask the contracting authority in writing. Never assume L0 to save cost.
Phrases that do NOT determine your DCC level on their own:
- "Cyber Essentials required" - this means CE is required, not that DCC is. The contract may be a non-DCC contract.
- "Compliance with Defence Standards" - verify which CRP / DCC level.
- "Industry-standard cyber security" - too vague; ask for explicit CRP.
Section 06
The cost of getting it wrong
Two failure modes erode value:
- Level 0 when Level 1 was required. The assessor reviews the L0 evidence pack against L0 controls and issues the certificate. Then the prime contractor or contracting authority rejects the certificate as insufficient for the contract requirement. The supplier re-engages at Level 1 - paying again, restarting scoping, and missing the contract acceptance window.
- Level 1 when Level 0 was sufficient. The supplier pays an additional £8,000+ and absorbs four to six extra weeks of work for an outcome that L0 would have delivered.
When uncertain, ask the contracting authority for its profile and evidence requirement in writing. Uncertainty is not a reason to buy Level 1 automatically; unnecessary higher-level assessment can add substantial cost.
Section 07
When a strategic Level 1 may make sense
A higher-level certificate can support a mixed pipeline if the entity, scope and validity fit each contract. Two Level 0 contracts within the same certificate’s three-year validity do not automatically mean two Level 0 fees. Compare one Level 0 engagement plus any later upgrade against a single Level 1 engagement using written quotes and confirmed contract requirements; there is no universal £1,000 saving. Each contract still needs its full SAQ.
For a pipeline containing confirmed Level 1 requirements, early Level 1 preparation may avoid later disruption. For Level 0-only requirements, Level 0 may be sufficient.
Section 08
When to consider L1 even if your CRP says L0
A few additional cases push the decision toward L1 even when L0 would technically satisfy the immediate contract:
- You expect to win Level 1 CRP contracts within 12 months and want to be tender-ready
- You are entering the defence supply chain and want to demonstrate maturity beyond the minimum
- Your prime contractor signals that L1 will be the flow-down requirement on the next contract round
- Your in-scope estate is more complex than the contract itself implies (multi-cloud, legacy systems, multi-tier supply chain)
In these cases, the strategic L1 buys positioning that L0 does not.
Section 09
Conclusion
You do not choose your DCC level - your contract CRP does. Level 0 is the right level for Level 0 CRP contracts with bounded scope; Level 1 is the right level for Level 1 CRP contracts and for suppliers with mixed CRP pipelines that can be covered by one engagement. Level 2 and Level 3 are higher tiers that Fig Group refers to other IASME-licensed bodies.
Two next steps. Read the DCC Level 0 detail page and the DCC Level 1 detail page to see the full scope at each tier. Or book a 15-minute scoping call and an IASME-licensed assessor will confirm the level your contract requires before any fee is incurred.
For the broader pricing landscape, see the DCC hub pricing detail - including a Fig Group estimate of typical UK market ranges based on public IASME-directory review.
Section 10
Scheme sources and contract checks
Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.
IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.
The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Related guides
Continue reading
Compliance
How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers
Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.
Read articleCompliance
How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.
Read articleCompliance
DEFSTAN 05-138 - What does it mean for suppliers?
DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.
Read article

