DCC vs Cyber Essentials: What UK MOD Suppliers Must Know
CE covers in-scope devices, networks and cloud services. DCC provides independent organisation-level evidence; both certificate prerequisites and the full contract SAQ still matter.

Section 01
DCC vs Cyber Essentials: What UK MOD Suppliers Must Know
A common misconception among UK suppliers entering the MOD supply chain: "I have got Cyber Essentials, do I still need DCC?" The honest answer is yes, where the contract requires DCC. Cyber Essentials and Defence Cyber Certification are complementary schemes, not substitutes. CE is your technical baseline across in-scope endpoints, network devices, cloud services and access controls. DCC is the organisation-level resilience the MOD expects. CE is a prerequisite at every DCC level (CE Plus is required at L2 and L3). This guide explains the relationship, the practical pathways depending on your situation, and the budget and timeline implications.
If you have just won a contract requiring DCC, or you are a supplier holding Cyber Essentials and your prime contractor has flagged DCC as a coming flow-down requirement, this is the framing you need.
Section 02
Cyber Essentials in plain English
Cyber Essentials is the UK NCSC-backed cyber security baseline scheme, delivered by IASME and a network of IASME-licensed Certification Bodies. It covers five technical control families: firewalls, secure configuration, user access control, malware protection, and security update management. Assessment is by self-assessment plus IASME-licensed assessor review. The certificate is valid for 12 months. Pricing across the UK market starts from around £299.99 + VAT for Micro organisations.
Best understood as: your endpoint, network, and access baseline is hardened to the NCSC standard. CE proves the basics are in place across the systems and devices in scope.
Fig Group issues Cyber Essentials in 6 working hours for compliant submissions, with pricing from £299.99 + VAT for Micro organisations.
The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.
Section 03
DCC in plain English
Defence Cyber Certification is the UK MOD organisation-wide cyber assurance scheme for the defence supply chain. Built on Defence Standard (Def Stan) 05-138 issue 4 and aligned with the NCSC Cyber Assessment Framework (CAF). 148 controls in total across four progressively stringent levels (L0 = 3 controls, L1 = 101, L2 = 139, L3 = 144). Provides organisation-wide evidence that can support multiple procurements; the full contract-specific SAQ remains mandatory for DCC holders. Validity is three years, with annual attestation at the end of years one and two. Assessments are delivered by IASME-licensed Certification Bodies; IASME is the MOD official partner for the scheme.
Best understood as: the organisation as a whole - governance, identity, supply-chain flow-down, secure configuration, incident response - is at the level of resilience the MOD expects for the contract Cyber Risk Profile.
Fig Group is IASME-licensed at DCC Level 0 and Level 1. Level 0 is published from £499.99 + VAT (2-3 week typical engagement); Level 1 is range-priced (£9,999 to £49,999 + VAT, 6-10 week typical engagement). Fig Group refers Level 2 and Level 3 to IASME-licensed Certification Bodies that hold those scopes.
Section 04
How they relate
CE is a prerequisite at every DCC level. The relationship is layered, not parallel:
Cyber Essentials is the foundation
Required at every DCC level. L0 and L1 require standard CE; L2 and L3 require Cyber Essentials Plus. Early DCC scoping can start before CE is issued; a current CE certificate is required for DCC certification.
DCC builds on top
DCC L0 reviews three controls including a check that your CE evidence is current and aligned to the supplier role you are certifying for. L1 expands to 101 controls covering governance maturity, supply-chain flow-down, evidence retention, and incident response - all things CE does not cover.
CE evidence partially feeds DCC
At L0, CE evidence is one of three controls reviewed. At L1, CE evidence underpins parts of the secure-configuration and identity controls but is not sufficient on its own. Evidence must be mapped to each applicable Level 1 control; five Cyber Essentials control families are not thirteen DCC controls and cannot be subtracted from 101.
Validity and rhythm differ
CE validity is annual; DCC validity is three years with annual attestation at year 1 and year 2. So the rhythm is: CE every 12 months, DCC re-assessed every 36 months.
Both delivered by IASME-licensed bodies
The same network of Certification Bodies delivers both schemes, but each body is licensed at specific scopes. A body can be IASME-licensed for CE but not for DCC, or licensed for some DCC levels but not others. Verify the Certification Body’s DCC licence scope.
Section 05
What you actually need to do, depending on your situation
Four common starting points. Find the one that matches your case:
Situation 1 - You hold current CE; you have just won an MOD contract requiring DCC
Use your current CE as the prerequisite for DCC scoping immediately. Confirm the contract Cyber Risk Profile with the contracting authority and book a scoping call with an IASME-licensed Certification Body. Total time for a prepared organisation: around 3 weeks for L0, around 8 weeks for L1.
Situation 2 - You hold current CE; you are bidding for an MOD contract that may require DCC
Hold CE and confirm with the prime contractor or contracting authority whether DCC is required at award. If signalled, start DCC scoping pre-tender - being DCC-ready before the award is a competitive advantage. Do not certify at DCC speculatively if there is no contract requirement; DCC is contract-driven.
Situation 3 - You do not hold CE; you have just won an MOD contract requiring DCC
Start CE preparation alongside DCC scoping; CE must be current before certification. Total estimated time including CE issuance: around 3 weeks for L0, around 8 weeks for L1.
Situation 4 - You are in the defence supply chain and want to be future-proof
Maintain CE where your actual contract and certification require it; it is a prerequisite for every DCC certificate. Add DCC at L0 or L1 only when a contract triggers it (or strategically when your pipeline justifies it). For the strategic L1 case, see DCC Level 0 vs Level 1: which do you need?.
Section 06
Total cost picture
Approximate published Fig Group pricing across the bundle:
- CE only: from £299.99 + VAT (Micro), 12-month renewal cycle.
- CE + DCC L1: confirm any combined assessment scope, inclusions, total and invoice arrangement in the accepted Order Form. Cyber Essentials certification is arranged separately.
- CE Plus + DCC L2 / L3: out of Fig Group licensed scope - refer to IASME directory.
Section 07
Common misconceptions, corrected
- "DCC replaces Cyber Essentials." No - CE is a prerequisite at every DCC level. They are layered.
- "My CE is from a different Certification Body, do I need to redo it for Fig Group DCC?" No - any current CE certificate from any IASME-licensed body satisfies the prerequisite.
- "DCC is just CE for defence." No - CE covers in-scope devices, network and cloud services; DCC is org-level resilience. They cover different layers.
- "L0 is just CE with extra paperwork." No - L0 adds board-level cyber responsibility and an organisation-wide cyber risk assessment alongside appropriately scoped CE, plus formal assessment by an IASME-licensed assessor against Def Stan 05-138 issue 4.
Section 08
Conclusion
Maintain Cyber Essentials where your actual contract and certification require it. It is a prerequisite for every DCC certificate, with Plus at Levels 2 and 3. Add DCC at the level your contract requires when it requires it. CE covers in-scope devices, network and cloud services; DCC is org-level resilience. The two are layered, not parallel.
If you are a defence supplier without CE, start with Cyber Essentials - Fig Group issues in 6 working hours for compliant submissions. If you hold CE and have a contract requiring DCC, book a 15-minute DCC scoping call - we will confirm your level, review your existing CE evidence, and give you a realistic timeline before any fee is incurred. The defence sector hub walks the CE-to-DCC pathway for MOD supply-chain organisations specifically.
The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.
Section 09
Scheme sources and contract checks
Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.
IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.
The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Related guides
Continue reading
Compliance
How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers
Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.
Read articleCompliance
Do I Need DCC for MOD Contracts? MOD Asks Suppliers for DCC Level 0 by End of 2026
The MOD's Director of Cyber Defence and Risk, Eleanor Fairford, has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including Cyber Essentials for business-critical systems. This guide explains what the MOD has actually said, who it affects, how DCC levels map to your contract, and what suppliers should do now - with the primary gov.uk sources.
Read articleCompliance
DEFSTAN 05-138 - What does it mean for suppliers?
DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.
Read article

