Skip to content

Defence Cyber Certification Levels 0 and 1.

Check the CSMv4 level required by your MOD contract or prime. Fig Group is licensed by IASME to assess DCC Level 0 and Level 1: buy a published-price Level 0 assessment by staff size, or request a scoped Level 1 quote. Consultant and platform support help you prepare for assessment.

L0 + L1
IASME-licensed scope
£499.99
L0 starting price + VAT
3 years
Certificate validity

Transparent DCC Pricing

Your contract or prime sets the required level. Level 0 has published staff-size prices; Level 1 is quoted after scope review.

Why Level 0 is flat-priced

One scope, one fee

Level 0 is a documentation-led review against a constrained requirement set. The work fits inside fixed boundaries, so the fee can too.

Why Level 1 is a range

Engagement size varies materially

L1 scope complexity drives the work. We name the drivers openly:

  • Site count
  • Cloud footprint
  • Legacy systems
  • Supply chain depth
  • Existing maturity

Every L1 engagement includes a dedicated consultant and Fig’s platform for automated gap identification - bundled into the base fee, never sold as add-ons.

DCC Level 0

Basic · CSMv4 Level 0 CRP

Micro

1-9 staff

£499.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set, 3 controls)
  • 3-year certificate validity
  • Annual attestation support
Buy nowSee package details

Medium

50-249 staff

£699.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set, 3 controls)
  • 3-year certificate validity
  • Annual attestation support
Buy nowSee package details

Large

250+ staff

£799.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set, 3 controls)
  • 3-year certificate validity
  • Annual attestation support
Buy nowSee package details

DCC Level 1

Enhanced · CSMv4 Level 1 CRP

Micro

1-9 staff

£9,999 - £14,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against Def Stan 05-138 issue 4 (Level 1 control set, 101 controls)
  • Three remediation rounds included
  • 3-year validity with annual attestation
Review scope and quote about Micro DCC Level 1

Medium

50-249 staff

£20,000 - £24,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against Def Stan 05-138 issue 4 (Level 1 control set, 101 controls)
  • Three remediation rounds included
  • 3-year validity with annual attestation
Review scope and quote about Medium DCC Level 1

Large

250+ staff

£25,000 - £49,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against Def Stan 05-138 issue 4 (Level 1 control set, 101 controls)
  • Three remediation rounds included
  • 3-year validity with annual attestation
Review scope and quote about Large DCC Level 1

Need an enterprise scope, multi-entity engagement, or a DCC L2/L3 referral?

Talk to the team

Level 0 assesses Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. IASME describes the three controls. Preparation checklists describe evidence support, not extra scheme controls. Use the CSM version and numeric level specified by your contracting authority. Current MOD guidance says CSMv3 labels are not consistent with CSMv4 levels and that the full SAQ remains mandatory for contractual risk assessment and procurement, even for suppliers holding DCC certification.

Defence Cyber Certification trust evidence

DCC evidence buyers should verify

Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.

Official IASME DCC directory

Check the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.

What is Defence Cyber Certification?

The UK MOD's independent cybersecurity certification for its supply chain.

Defence Cyber Certification, defined

The UK MOD’s framework for independently certifying the cybersecurity posture of its supply chain.

DCC adds independent certification evidence to the MOD's Cyber Security Model. Suppliers still complete the required SAQ in the Supplier Cyber Protection Service for their contract.

Contractual assurance - SAQ

Supplier self-assessment remains required

Suppliers complete the SAQ for the Cyber Risk Profile set by the MOD customer or prime. The full SAQ remains part of the current procurement and contract process.

Independent evidence - DCC

Independently assessed

DCC applicants are assessed by an IASME-licensed Certification Body against the relevant controls. A certificate provides independent evidence alongside the required SAQ where the contract calls for it.

Key facts

Scheme administration
IASME (also delivers Cyber Essentials on behalf of the NCSC).
Certification assessment
IASME-licensed Certification Bodies, including Fig Group.
SAQ relationship
A DCC certificate does not currently exempt suppliers from the full required SAQ.
Underlying specification
Defence Standard (Def Stan) 05-138 issue 4.
Levels
Four - L0 (Basic), L1 (Enhanced), L2 (Advanced), L3 (Expert).
Level selection
The MOD customer or prime sets the contract Cyber Risk Profile; applicants may also seek certification before a contract requires it.
Certificate validity
Three years, with annual attestation.
Fig Group certification
Level 0 and Level 1. Verify the IASME licence from the Fig trust evidence page before procurement approval.

Procurement teams can verify Fig Group's IASME status before approval on the IASME licence evidence page.

Bidding tip - mixed CRP pipelines

Certify at the highest level your pipeline requires.

A higher-tier DCC certificate covers tenders at lower tiers - the reverse is not true. If you bid on contracts spanning multiple Cyber Risk Profiles, target the top of your range and let it cascade down.

The four DCC levels

Mapped to the MOD's four Cyber Risk Profile tiers.

Level 0

Basic

CSMv4 Level 0 CRP

Foundational tier. Documentation-led review of three control areas under Def Stan 05-138 issue 4: Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. A current Cyber Essentials certificate is required before assessment and is arranged separately.

Fig offers this level

Level 1

Enhanced

CSMv4 Level 1 CRP

Formal engagement. Scoping, evidence preparation, remediation support, and third-party assessment. Cyber Essentials is a prerequisite. Fig bundles consultant and platform into the base fee.

Fig offers this level

Level 2

Advanced

CSMv4 Level 2 CRP

Requires Cyber Essentials Plus plus substantial operational security maturity. Typically a multi-month engagement including technical verification against Def Stan 05-138 issue 4 (Level 2 control set, 139 controls).

Fig refers to a body listed on the IASME directory

Level 3

Expert

CSMv4 Level 3 CRP

The most demanding tier. Comparable to a full ISMS audit with defence-specific technical depth, assessed against Def Stan 05-138 issue 4 (Level 3 control set, 144 controls). Requires Cyber Essentials Plus and sustained control maturity across the supply chain.

Fig refers to a body listed on the IASME directory

How long does Defence Cyber Certification take?

DCC Level 0

2–3 weeks for a prepared organisation (already holds Cyber Essentials, governance documentation in place, clear scope).

4–8 weeks for organisations starting from a lower baseline.

DCC Level 1

6–10 weeks for a prepared organisation with consultant support and Fig platform gap analysis.

12–20 weeks for organisations starting from a lower baseline. Most variance is supplier preparation, not our timeline.

For tender-deadline acceleration, contact us at quote stage. We prioritise engagement sequencing where possible.

Consultant + platform, not audit-only

How Fig delivers DCC differently from audit-only Certification Bodies.

Dedicated consultant from day one

Every L1 engagement includes a named consultant through scoping, evidence preparation, remediation, and formal assessment. No hand-off between sales, delivery, and audit. L0 engagements include scoping-level consultant support.

Gaps found before assessment

Fig’s platform runs automated gap analysis across in-scope systems - unpatched CVEs, cloud misconfiguration, identity coverage, endpoint posture, exposed surface - so issues are fixed before the assessor arrives, not during audit.

Published Level 0 prices and Level 1 bands

Level 0 has a published price for each staff-size tier. Level 1 has published bands and needs a scoped quote before payment.

What moves an L1 quote within its tier band

We publish the price bands and explain the scope factors used to prepare a Level 1 quote.

Site count

Single-site engagements are faster than multi-site scopes. Hybrid or remote staffing complicates evidence collection.

Cloud footprint

Single-tenant Microsoft 365 estates are quick. Multi-cloud with custom IaC, hybrid identity, or significant PaaS surface adds engagement time.

Legacy systems

In-scope legacy platforms (Windows Server 2012, unsupported network kit, bespoke applications with limited patching) require additional control evidence.

Supply chain

L1 requires evidence of flow-down controls to your own suppliers. Simple chains are quick; tier-two chains with multiple subcontractors add engagement time.

Staff population

Small staff populations with clear role definitions move quickly. Organisations with large contractor or temp populations need more identity and access evidence.

Existing maturity

Current ISO 27001 or NCSC CAF evidence may reduce preparation work where it covers the DCC scope. Your quote depends on the evidence gaps, required support and agreed scope.

How Fig's DCC pricing compares

Honest context on where Fig sits in the IASME-licensed CB market.

L0 market range (Fig estimate)

~£800 - £7,000 + VAT

Fig’s estimate of typical UK L0 pricing, based on review of public IASME-directory listings - roughly £800 + VAT at the lowest end (micro) up to £7,000 + VAT at the highest end (large). This is not an IASME or MOD-published figure. Fig’s published L0 pricing of £499.99 - £799.99 + VAT sits at the competitive end of that range; verify any body’s pricing directly before comparison.

L1 market range (Fig estimate)

~£8,000 - £60,000+ + VAT

Fig’s estimate of typical UK L1 pricing, based on review of public IASME-directory listings. The range is genuinely wide because engagement models differ - audit-only at the low end, full consultancy with platform support at the high end. This is not an IASME or MOD-published figure. Fig sits in the middle because we bundle consultant and platform into the base fee rather than unbundling them; verify any body’s pricing directly before comparison.

Procurement note

Compare scope, not sticker.

A cheaper headline L1 fee that excludes consultancy, platform access, and remediation rounds typically lands similar or higher all-in once those are added back in.

The assessment process

What happens from quote to certificate - L0 takes 2-3 weeks, L1 takes 6-10 weeks for a prepared organisation.

1

Check your requirement

Your MOD customer or prime sets the Cyber Risk Profile. We check the contract level and scope: Level 0 has published staff-size prices; Level 1 needs a scoped quote within its published band.

2

Prerequisite check

Cyber Essentials (L0/L1) or Cyber Essentials Plus (L2/L3) is required.

3

Platform onboarding

Read-only access to in-scope systems. The platform runs automated gap analysis across patches, cloud config, identity, endpoint posture, and exposed surface.

4

Remediation support

Your dedicated consultant works with you through identified gaps. Three rounds of remediation feedback are included before formal assessment.

5

Formal assessment

An IASME-licensed assessor reviews the submitted scope and evidence against the applicable DCC controls. Gaps may require further work before certification.

6

Certification

Certificate issued with three-year validity. Annual attestation support included. Platform continues running across the certificate period.

Who DCC applies to

Defence suppliers can seek certification at the level relevant to their work. DCC is not universally mandatory; check each tender or contract for its requirement.

Defence primes and tier-1 subcontractors bidding on DE&S, DIO, or DSTL contracts.
Technology suppliers to the MOD - software, cloud, managed services, hardware.
Professional services suppliers with MOD contracts handling sensitive or personal information.
Construction and facilities contractors working on MOD sites and DIO programmes.
Research and academic partners under MOD-funded research contracts.
Legal, accountancy, and consultancy firms holding MOD or prime-contractor engagements.

Frequently asked questions - DCC

Answers on scope, pricing, prerequisites, timelines, and the consultant + platform model.

What is Defence Cyber Certification?

DCC provides independent assurance against the MOD Cyber Security Model and is delivered by IASME. The current scheme has numeric Levels 0 to 3. It supports, rather than replaces, contract-specific supplier assurance: the full Supplier Assurance Questionnaire remains required under current MOD guidance.

Does DCC replace the DCPP Supplier Assurance Questionnaire?

No. Current MOD guidance requires the full contract-specific Supplier Assurance Questionnaire through the Supplier Cyber Protection Service, including for DCC certificate holders. DCC independently evidences organisational assurance against Def Stan 05-138 Issue 4; the buyer-assigned risk profile and contractual process still apply.

Is DCC mandatory?

Check the written MOD or prime-contractor requirement and its transition date. IASME guidance says DCC is not currently mandatory across all contracts; the MOD’s published 8 May 2026 request for industry partners to reach Level 0 by 31 December 2026 is a separate request, not a universal legal rule. Ask the contracting authority to confirm the numeric Cyber Risk Profile, Risk Assessment Reference and applicable tender clause.

How do I know which DCC level I need?

Use the numeric Cyber Risk Profile assigned by the MOD or contracting customer, its Risk Assessment Reference and the current contract version. CSM v4 uses Levels 0 to 3; older Very Low, Low, Moderate and High labels do not convert automatically. If a tender still uses verbal wording or two buyers require different levels, obtain written authority clarification before selecting an assessment scope or package.

Does Fig Group offer L2 and L3 assessment?

Fig Group delivers DCC Level 0 and Level 1 through its licensed certification body. For Level 2 or Level 3, use the IASME DCC Certification Body directory to find a body licensed for the required level; Fig Group can refer you to an appropriately authorised provider. Check the assigned level and licence before buying.

Do I need Cyber Essentials before DCC?

Current Cyber Essentials is a prerequisite for DCC Levels 0 and 1, with Plus required at Levels 2 and 3. Arrange Cyber Essentials certification separately if you do not hold a current, same-scope certificate before formal assessment. Maintaining the underlying annual certification remains your responsibility during DCC validity.

How much does DCC cost with Fig Group?

Published Level 0 prices run from £499.99 + VAT for Micro to £799.99 + VAT for Large. Level 1 published ranges run from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large, depending on agreed scope. Years 1 and 2 include annual attestation support within the package; Year 3 reassessment is separately priced. Arrange Cyber Essentials certification and annual renewal separately, and check any work outside the Order Form before purchase.

Why is DCC L1 priced as a range and L0 is flat?

Level 0 has a published staff-band price from £499.99 to £799.99 + VAT. Level 1 ranges from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large because scope, evidence gaps and assessor effort vary. The published package includes scoped consultancy and assessment; optional work outside the accepted Order Form may cost extra. Request a written Level 1 quote rather than treating a range endpoint as a fixed checkout price.

Is the consultant really included in DCC L1 pricing?

The published Level 1 package includes consultant support for the agreed scoping, evidence preparation and assessment programme. The applicant implements required controls and supplies accurate evidence. Confirm deliverables, feedback and remediation rounds, any extension charges and separately requested work in the accepted written Order Form; the package is not unlimited consultancy.

Is the technology platform extra for DCC L1?

The published Level 1 offer includes scoped platform support for evidence mapping and annual attestations. Confirm the actual access duration, included integrations and functionality, support, post-certification charges and any separate consultancy retainer in a written Order Form. Evidence mapping alone does not prove an unconditional three-year platform entitlement. Year 3 reassessment is separately purchased.

How long does DCC L0 take?

As at 29 September 2026, Fig Group estimates two to three weeks end to end for a prepared Level 0 applicant and four to eight weeks where prerequisite certification, governance documents or scope need work. These are indicative supplier estimates, not an IASME deadline. Confirm the numeric level, current Cyber Essentials, three-control evidence, written assessment schedule and buyer deadline before relying on a target date.

How long does DCC L1 take?

As at 29 September 2026, Fig Group estimates six to ten weeks end to end for a prepared Level 1 applicant and twelve to twenty weeks from a lower baseline. Scope, 101-control evidence, remediation, assessor availability and current prerequisite certification affect timing. Obtain a written scope and schedule against the tender deadline; neither estimate guarantees certificate issue.

Are there annual fees during the three-year DCC certificate period?

The published DCC package includes annual attestation support for Years 1 and 2. Year-three reassessment is separate. Underlying Cyber Essentials needs annual renewal, and additional work outside the accepted scope may be chargeable under your Order Form. Existing signed terms continue to apply.

Can I accelerate the DCC timeline for a specific MOD tender deadline?

Share the written tender deadline and required numeric level with Fig Group at quote stage. Check current Cyber Essentials, assessment scope, evidence readiness and whether an assessor can agree a written schedule. Preparation may be shortened, but assessment findings and remediation still determine certification; no deadline guarantee applies.

What does the Fig Group DCC platform actually do?

Fig Group’s platform can organise scoped DCC evidence and highlight gaps from supported data sources such as connected identity, endpoint and cloud systems. Available checks depend on the agreed integrations, permissions and data quality; a detected issue is reviewed by the applicant and assessor, not automatically certified. Confirm included Level 1 access and functionality in the Order Form.

Can my existing SAQ evidence be reused for DCC?

Some dated SAQ policies and technical records can be reused if they cover the same organisation, systems and control period. For example, map an access-control policy dated June to the applicable DCC control, note missing MFA enforcement evidence, then arrange independent review of the gap. The contract-specific SAQ still remains due; reuse does not replace the DCC assessment.

Is Fig Group IASME-accredited for DCC?

Fig Compliance Ltd holds separate IASME licences for DCC Level 0 and Level 1, and Cyber Essentials and Plus. Verify each scheme and authorised level through the relevant registry and IASME DCC directory; a Cyber Essentials badge alone does not prove a DCC licence. Fig Group does not assess DCC Levels 2 or 3.

Who can issue Defence Cyber Certification at Level 0 and Level 1?

An IASME-licensed DCC Certification Body authorised for the required level can issue a certificate following a successful assessment. Fig Group delivers Levels 0 and 1 through its licensed body; see the IASME DCC directory for level-specific verification and other providers. Cyber Essentials certification and annual renewal are arranged separately. For Levels 2 and 3, use a body authorised for those levels.

Ready to start your DCC engagement?

Check the Cyber Risk Profile set by your MOD customer or prime. Choose a published-price Level 0 assessment, or ask Fig Group to scope a Level 1 quote within the published price band.