How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
DCC Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. The slowest end of the L1 band stretches to 16+ weeks. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.

Section 01
How Long Does Defence Cyber Certification Take? Realistic Timelines for L0 and L1
The honest headline: Defence Cyber Certification Level 0 is typically 2-3 weeks; Level 1 is typically 6-10 weeks for a prepared organisation. Variance is real - the slowest end of the L1 band stretches to 16+ weeks for organisations with widespread evidence gaps, legacy systems, or large supplier flow-down requirements. This guide breaks down where the time actually goes, what you can compress, and what you cannot. Caveat: these timelines reflect Fig Group published delivery model. Other IASME-licensed Certification Bodies may publish different timelines - verify before committing to a tender deadline.
If you have a tender deadline and a contract clause specifying DCC, the operative question is not whether DCC is achievable but whether it is achievable in the window you have. This guide covers Level 0 and Level 1 stage by stage, then describes the levers you actually control versus the ones built into the scheme.
Section 02
DCC Level 0 timeline breakdown
Swipe across the table to view all columns.
| Stage | Time | What happens |
|---|---|---|
| Scoping call | 1 day | Confirm the contract Cyber Risk Profile, agree in-scope assets, agree timeline + price |
| Cyber Essentials (if not held) | Same day | Fig Group 6-hour SLA for compliant submissions |
| Evidence collection | 1-2 weeks | Three scheme controls: current appropriately scoped CE, board responsibility and organisation-wide cyber risk assessment |
| Assessor review | 3-5 working days | Documentation review, no on-site visit |
| Certificate issuance | Allow scheduling buffer | 3-year validity from issue date |
The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.
Fastest realistic path: around 10 working days when Cyber Essentials is already held and governance documentation is current and well-organised.
Slowest realistic path: 4-6 weeks when starting from no CE and evidence collection is uncoordinated (multiple contributors, no internal lead, scattered policy documents).
What moves the needle on L0:
- CE status. Holding a current Cyber Essentials certificate saves at least one working day immediately and removes the dependency on CE remediation cycles.
- Internal project lead. A single named owner compresses the engagement materially compared to distributed responsibility. Distributed teams produce conflicting evidence; a single owner does not.
- Documentation availability. Policies, procedures, and inventory lists already in place move faster than ones being written during the engagement.
Section 03
DCC Level 1 timeline breakdown
Swipe across the table to view all columns.
| Stage | Time | What happens |
|---|---|---|
| Scoping call + variance review | 3-5 working days | Confirm CRP, scope, variance drivers, price band |
| Cyber Essentials (if not held) | Same day for an eligible compliant submission | Fig Group six-working-hour service; purchase CE separately |
| Platform onboarding | 2-3 working days | Fig Technology platform configured for evidence pre-checking |
| Evidence gathering | 2-3 weeks | 101 controls across governance, identity, device, secure config, supply-chain |
| Remediation cycles (typically 2-3) | 2-3 weeks | Where most variance lives - depends on your team velocity |
| Formal assessment | 1 week | Assessor review + clarification rounds |
| Certificate issuance | Allow scheduling buffer | 3-year validity, annual attestation Years 1 + 2 |
The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.
Fastest realistic path: around 6 weeks for a prepared organisation with strong governance, ISO 27001 alignment, single-site / single-cloud, and a small supply chain.
Slowest realistic path: 16+ weeks for an organisation with widespread evidence gaps, legacy systems requiring decommissioning, multi-site / multi-cloud infrastructure, or large supplier flow-down requirements.
The variance lives in the remediation cycles. A clean evidence pack with five to ten minor findings runs through remediation in around ten working days. A pack with fifty-plus findings - including legacy decommissioning - can stretch to eight or more weeks of remediation alone.
Section 04
What slows DCC down most often
Five recurring delays account for most timeline overruns:
- Starting with no Cyber Essentials. CE is same-day at Fig Group if the submission is compliant. If the submission is not compliant, CE itself can take two to four weeks of remediation while early DCC scoping proceeds in parallel; CE must be current before certification.
- Legacy systems without a decommissioning plan. Unsupported operating systems or end-of-life software in scope are high-severity findings. Upgrade or decommission unsupported software, or establish a genuinely isolated and permitted scope exclusion. Generic compensating controls do not waive Cyber Essentials support requirements. All take time.
- Supplier evidence collection. L1 supply-chain controls require Supplier Capability Assessments. Suppliers respond on their own timelines - some take two to three weeks to return a signed SCA. Send them in week one of the engagement, not week five.
- No internal project lead. Distributed responsibility produces slower decisions, more clarification rounds, and longer evidence cycles. A single named owner compresses every engagement.
- Surprises in scope. Discovering a system, site, or supplier mid-engagement that should have been in scope at week one forces a re-scope that adds two to four weeks. Front-load scoping discovery.
For a deeper treatment of scoping failure modes, see DCC scoping mistakes that fail certification.
Section 05
What you can compress
Compressible:
- Cyber Essentials issuance - same-day with Fig Group for compliant submissions
- Platform onboarding - 2-3 days; faster if you are already a Fig Technology platform customer
- Scoping decision-making - book the call early, bring contract clauses, arrive with a defined Cyber Risk Profile
- Internal sign-off cadence - have your authorised representative ready to sign at each gate, not three days later
Not compressible:
- Assessor review time - IASME-licensed assessors work to a defined process. Cutting this corner risks a failed audit, not a faster certificate.
- Remediation work - you cannot move faster than the remediation requires. Rushing causes findings on top of findings.
- Supplier response time - third-party SCAs come back when they come back. Allow buffer.
- Certificate issuance - IASME process governs this and is not negotiable per engagement.
Section 06
Three realistic scenarios
These are illustrative planning scenarios, not authenticated customer cases or scheme deadlines. Stages can overlap and calendar totals depend on availability:
Scenario A - Defence subcontractor, 30 staff, current CE, single-site SaaS, Level 1 CRP contract
- Scoping: 3 days
- Evidence gathering: 3 weeks
- Remediation: 2 weeks (clean pack, minor findings)
- Formal assessment + certificate: 1 week
- Total: around 7 weeks for L1
Scenario B - Same supplier but at L0 (Level 0 CRP)
- Scoping: 1 day
- Evidence gathering: 1.5 weeks
- Assessor review: 4 days
- Certificate: 1 day
- Total: around 2.5 weeks for L0
Scenario C - Defence contractor, 200 staff, no CE, multi-site, Level 1 CRP, 50+ suppliers, legacy Windows estate
- CE issuance + remediation: 3 weeks
- Scoping: 5 days
- Evidence gathering: 3 weeks
- Remediation: 8 weeks (multiple rounds, legacy decommissioning)
- Formal assessment: 2 weeks
- Certificate: 1 day
- Total: around 16 weeks for L1
A cleaner estate and smaller supply chain may reduce preparation time. These scenarios vary several factors, so they do not establish that the legacy estate alone caused eight extra weeks.
Section 07
Conclusion
L0 in 2-3 weeks; L1 in 6-10 weeks for prepared organisations. The biggest lever you control is preparation: hold Cyber Essentials, organise evidence early, name a single internal owner, contact suppliers in week one, identify legacy systems at scoping.
If you have a tender deadline, tell us at scoping. Where the timeline is realistic, Fig Group sequences assessor scheduling around your deadline. Where it is not, we will say so honestly rather than take the engagement and miss. To start, book a 15-minute scoping call - we will confirm your level, review your existing evidence, and give you a realistic deadline-aware timeline before any fee is incurred.
For the level-detail breakdown, see DCC Level 0 and DCC Level 1. For pricing, see the DCC hub pricing detail. For the broader scheme overview, the DCC hub is the right starting point.
Section 08
Scheme sources and contract checks
Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.
IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.
The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Related guides
Continue reading
Compliance
Cyber Essentials Turnaround Times: Every Major UK Body Compared
How long does Cyber Essentials certification actually take? We compare the published turnaround commitments from every major IASME-licensed body in the UK.
Read articleCompliance
How Long Does Cyber Essentials Take? Honest Timelines for 2026
From readiness to certificate, how long does Cyber Essentials really take? This guide walks through every stage with realistic timelines and the factors that speed it up or slow it down.
Read articleCompliance
DCC Level 0 vs Level 1: Which Defence Cyber Certification Do You Need?
Compare DCC Levels 0 and 1: controls, scope, prerequisites, costs and planning timelines. Ask the buyer for the current numeric profile before choosing a level.
Read article

