Skip to content
Compliance

How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers

Practical MOD supplier guidance on How to Get Defence Cyber Certification (DCC). Confirm numeric CSMv4 levels, scope and prerequisites; DCC evidence does not replace the full SAQ.

a large satellite dish sitting on top of a fi

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

12 min read

Share

Section 01

How to Get Defence Cyber Certification (DCC): Step-by-Step Guide for UK MOD Suppliers

DCC provides organisation-wide independent evidence of compliance that can support multiple UK MOD procurements; it does not replace the full contract-specific SAQ. This guide walks the seven steps from contract clause to issued certificate. The buyer’s current numeric Cyber Risk Profile determines the required level. Cyber Essentials is a certification prerequisite at every level, with Plus at Levels 2 and 3. Fig Group’s planning estimates for prepared organisations are 2–3 weeks at Level 0 and 6–10 weeks at Level 1.

If you are a UK supplier reading this because a contract clause has just landed on your desk specifying a Cyber Risk Profile, or because a defence prime has flagged DCC as a flow-down requirement, you need a clear picture of the path between where you stand and an issued certificate. This guide describes the seven steps end-to-end, including what an IASME-licensed Certification Body can and cannot help you with along the way.

Disclosure: Fig Compliance Ltd holds separate IASME Certification Body licences for Cyber Essentials, Defence Cyber Certification Level 0 and Defence Cyber Certification Level 1. The scheme structure described here is set by IASME and the UK Ministry of Defence; the delivery details reflect how Fig Group runs the engagement. The same seven steps apply to any IASME-licensed Certification Body you choose - you can verify the Certification Body’s DCC licence scope.

Section 02

What DCC is, in one paragraph

Defence Cyber Certification is the UK MOD's organisation-wide cyber assurance scheme for defence suppliers. It is built on Defence Standard (Def Stan) 05-138 issue 4 and aligns with the NCSC Cyber Assessment Framework (CAF). Its certificate can support multiple MOD procurements where the entity, scope, level and validity fit. The full contract-specific SAQ remains mandatory. Certificates are valid for three years, with annual attestation at the end of years one and two. Assessments are delivered by IASME-licensed Certification Bodies; IASME is the MOD's official partner for the scheme.

Section 03

Step 1 - Confirm your contract's Cyber Risk Profile

The Cyber Risk Profile (CRP) is assigned by the MOD awarding body for each contract. Suppliers do not choose their CRP. Current CSMv4 uses numeric CRP Levels 0, 1, 2 and 3. Obtain the level and RAR from the buyer; do not convert legacy verbal profiles yourself:

Level 0 CRP → DCC Level 0

Three controls, documentation review only, no on-site visit. The lightest tier. Applies to contracts with the lowest assessed risk to the supplier delivering the output.

Level 1 CRP → DCC Level 1

101 controls covering governance, identity, device, secure configuration, and supply-chain. Documentation review with clarification rounds. Cyber Essentials prerequisite, no Cyber Essentials Plus required.

Level 2 CRP → DCC Level 2

139 controls. Cyber Essentials Plus prerequisite. Hands-on technical verification, multi-tier supply-chain assessment. Fig Group refers L2 engagements to IASME-licensed Certification Bodies that hold Level 2 scope.

Level 3 CRP → DCC Level 3

Currently delivered as a pilot scheme via a Level 2 + Level 3 hybrid (144 controls). Cyber Essentials Plus prerequisite. Fig Group refers L3 engagements.

If your contract clause does not name a CRP explicitly, ask the contracting authority in writing before incurring assessment cost. Choosing the wrong level is materially more expensive than confirming it - a failed Level 0 followed by a Level 1 re-engagement costs more than starting at Level 1 in the first place.

Section 04

Step 2 - Hold a current Cyber Essentials certificate

Cyber Essentials is a prerequisite for every DCC level. Levels 2 and 3 require Cyber Essentials Plus. The certificate must be current - within its 12-month validity window - and can come from any IASME-licensed Certification Body.

If you already hold CE from another body, your DCC engagement starts from there. Fig Group does not require you to re-certify CE with us if you already hold a current certificate. If CE is absent, arrange certification separately before formal DCC assessment. Annual CE renewals remain your responsibility. £299.99 + VAT is the standalone Micro CE price.

The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.

For suppliers transitioning from the prior DCPP regime, the Cyber Essentials evidence you already hold typically maps directly into Level 0 - you keep that work. Talk to the assessor at scoping; they will review what reuses cleanly and what needs updating against Def Stan 05-138 issue 4.

Section 05

Step 3 - Book a scoping call with an IASME-licensed Certification Body

Choose a Certification Body that holds the IASME licence at your required level. Some bodies are licensed for L0 / L1 only, others for L2 / L3 - verify licence status on the IASME directory before you commit. The scoping call confirms scope, level, timeline, and price band, and it is normally free of charge before any engagement fee.

What an assessing Certification Body may do during the engagement, per the IASME Applicant Guide:

  • Help you prepare for and attain Cyber Essentials and Cyber Essentials Plus where these are prerequisites
  • Explain the DCC scheme and its levels
  • Explain the controls and how to meet them
  • Clarify the questions and the components needed for a complete answer
  • Describe the evidence needed to demonstrate that a control has been met
  • Verify scope
  • Supply blank template documents

What the assessing Certification Body may not do, by scheme rule:

  • Implement any policy
  • Implement any change
  • Answer any question on behalf of the applicant
  • Complete any documentation or prepare any answers or evidence that they will later assess

This independence rule applies to the assessing Certification Body, not merely the individual assessor. The assessing body cannot prepare the answers or evidence it later assesses. A separate technology provider does not remove that boundary: the applicant must own and approve its evidence, and any preparation service must remain demonstrably independent of assessment. If you need additional support beyond the advisory role of the Certification Body, you have the option to engage a separate technology provider.

Section 06

Step 4 - Determine and document scope

The IASME Scoping Guide warns that inaccurate or incomplete scope can prevent certification even when included controls are met. Scoping is the most critical first step.

Def Stan 05-138 issue 4 is intentionally broad. The standard's scope is the supplier's overarching corporate or enterprise environment - all systems, processes, procedures, and data necessary for the effective protection of the data and functions in scope of the MOD contract. This goes beyond protecting just the information provided to the supplier in support of the contracted output. The scope is not just about the data held: if the processes and systems are essential for the organisation to operate as a business in support of the contract, they are within scope.

To document scope, your assessor will expect:

  • A list of systems, services, and functions that are in scope and out of scope for DCC
  • A list of systems, services, and functions that are in scope and out of scope for Cyber Essentials and Cyber Essentials Plus
  • Diagrams showing how the different scopes overlap
  • A list of sites and their functions (workshop, head office, etc.)

The assessor reviews and may challenge your scoping statement. Both under-scoping (excluding too much) and over-scoping (including too much) cause problems. The scope must include operationally essential corporate systems and dependencies supporting the contract, even where they hold no MOD data. Exclusions need an evidenced boundary and assessor agreement.

Section 07

Step 5 - Collect evidence

For Level 0, evidence is focused on three foundational controls: appropriately scoped Cyber Essentials, board-level cyber responsibility and an organisation-wide cyber risk assessment. For Level 1, the evidence pack covers all 101 controls in the same domains, in greater depth.

At Level 0, prepare evidence against the actual three scheme controls: current Cyber Essentials with the applicable business-critical scope, board-level responsibility for cyber security, and an organisation-wide cyber risk assessment. Additional policies and inventories can help demonstrate these controls, but are not a separate universal Level 0 checklist.

A Level 1 evidence pack adds depth to each of those domains, plus secure-configuration baselines, supply-chain Supplier Capability Assessments (SCAs), and evidence of identity and access control under load. Fig Group's compliance automation platform pre-checks evidence against the L0 / L1 control requirements before formal assessment, so gaps surface in days rather than after a failed audit.

Realistic effort: Level 0 evidence work is typically one to two weeks of focused activity for a prepared organisation; Level 1 evidence work is typically two to three weeks plus two to three remediation cycles.

Section 08

Step 6 - Formal assessment and remediation

The IASME-licensed assessor reviews your evidence pack against the controls for your level. At Level 0, this is a documentation review with no on-site visit. At Level 1, it is documentation plus clarification rounds, with some scopes triggering evidence-verification calls. Findings are returned with structured remediation guidance.

Remediation rounds at Level 1 are typically two to three. A clean evidence pack with minor findings runs through them in two weeks. A pack with widespread gaps - for example, unpatched critical vulnerabilities in scope, unsupported operating systems, or missing supplier flow-down clauses - can stretch remediation to six or eight weeks before the formal assessment can complete.

As Fig Group planning advice, if pervasive gaps emerge (for example, around 20% of controls non-compliant), the honest path is to pause the formal assessment, run a focused remediation programme, and re-enter assessment. Pushing through with widespread gaps risks a failed audit and a re-engagement.

Section 09

Step 7 - Receive your certificate and plan attestation

When the assessor recommends certification and IASME issues the certificate, it is valid for three years. Annual attestation at the end of year one and the end of year two confirms the controls in scope at the original assessment remain in place. Year three is full re-assessment.

The certificate is organisation-level evidence that may support several contracts when its legal entity, scope, level and dates match their requirements. A current Level 1 certificate may support Level 0 and Level 1 requirements without separate certification for every contract. This does not remove each contract’s SAQ or flow-down process, and two Level 0 contracts do not automatically require two paid Level 0 engagements.

Section 10

Common mistakes that delay or fail certification

Five practical risks to check at scoping:

  • Wrong level chosen. Running Level 0 when the contract requires Level 1, or vice versa.
  • Scoping too narrow or too broad. Either misjudgement causes the assessment to stall.
  • Stale Cyber Essentials evidence. A CE certificate that lapses mid-engagement forces a re-issue.
  • Underestimating supply-chain evidence depth. L1 requires SCAs against direct suppliers - send these in week one of the engagement, not week five.
  • Legacy systems in scope without a remediation plan. Unsupported operating systems are a high-severity finding; upgrade or decommission it, or establish a genuinely isolated and permitted scope exclusion before assessment. Generic compensating controls cannot waive Cyber Essentials supported-software requirements.

For a deeper treatment, see DCC scoping mistakes that fail certification.

Section 11

Realistic total cost of getting DCC for the first time

Pricing varies across IASME-licensed Certification Bodies. Fig Group's published DCC pricing:

  • Level 0: £499.99 to £799.99 + VAT, flat-priced by organisation size
  • Level 1: £9,999 to £49,999 + VAT, scoped according to the variance drivers named on the DCC hub (sites, cloud footprint, legacy systems, supply chain, staff population, existing maturity)

Hidden costs to budget for separately: internal time (one or two FTEs across six to ten weeks at L1), legacy decommissioning where applicable, and supplier SCA response wait time (suppliers respond on their own schedules; allow buffer).

For pricing context, see the DCC hub pricing detail - which includes a Fig Group estimate of typical UK market ranges based on review of public IASME-directory listings - and the DCC Level 0 vs Level 1 comparison for the timeline detail.

Section 12

Conclusion

DCC is a seven-step process: confirm CRP, hold or buy Cyber Essentials, scope with an IASME-licensed Certification Body, document scope, collect evidence, complete formal assessment with remediation, receive the certificate and plan annual attestation. Level 0 is typically two to three weeks for a prepared organisation; Level 1 is typically six to ten weeks. The cost of getting the level wrong materially exceeds the cost of confirming it - book a scoping call before you commit.

If you are ready to talk to an IASME-licensed assessor, contact Fig Group for a fifteen-minute scoping call. We will confirm your level, walk through what evidence you already hold, and give you a realistic timeline before any fee is incurred. To verify Fig Group's licence, see our IASME licence evidence page or check the IASME directory.

Section 13

Scheme sources and contract checks

Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.

IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.

The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.