Skip to content

DCC Level 0.
Your route to certification.

Check that your MOD customer or prime requires CSMv4 Level 0, then prepare your scope and evidence. Choose the size of the organisation being certified to see the published assessment price and purchase route.

DCC Level 0 certification body logo
How it works

The engagement, end to end.

  1. Confirm your level

    Check the level required by your MOD customer or prime contractor before purchasing. Level 0 is not a substitute where a higher level is required.

  2. Prepare your scope

    Identify the functions and services your organisation needs to operate securely. Discuss the proposed scope with Fig and check how it aligns with your Cyber Essentials coverage.

  3. Prepare your submission

    Use the IASME applicant guidance to answer the questions and organise supporting evidence. Level 0 does not require the Assessment Submission Record used for Levels 1–3.

  4. Work through the assessment

    Your assessor reviews the submission and verifies the controls. DCC is assessor-led, not a self-assessment certificate. Be ready to explain your evidence and respond to clarification requests.

  5. Address any gaps

    Your organisation or MSP implements required changes. Keep supporting records current and agree the next assessment steps with your assessor. Purchase does not guarantee certification.

  6. Maintain your certification

    After a successful assessment, keep meeting the controls. DCC requires annual attestation and recertification every three years; the underlying Cyber Essentials certification renews annually.

Before you begin

Level 0 assesses three control areas: Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. IASME explains the Level 0 controls and organisational scope.

Cyber Essentials must be current and cover the same scope before formal Level 0 assessment begins. If you do not hold a current certificate when ordering, Fig Group includes initial Cyber Essentials within the Level 0 engagement at no additional charge. Annual Cyber Essentials renewal remains your responsibility.

If an MSP helps prepare the submission, the applicant remains responsible for its accuracy, authorisation and required declarations. Evidence may also be needed from service providers.

Scheme guidance

Check the current IASME applicant and process guides and scheme FAQs. Timing depends on readiness, scope and assessor availability; the Cyber Essentials turnaround promise does not apply to DCC.

For a MOD contract, follow the Cyber Risk Profile set by your customer or prime and complete the required Supplier Assurance Questionnaire. MOD guidance says a DCC certificate currently does not exempt suppliers from the full SAQ.