Micro
1-9 staff
One-off · 3-year validity
- L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set, 3 controls)
- 3-year certificate validity
- Annual attestation support
Check the CSMv4 level required by your MOD contract or prime. Fig Group is licensed by IASME to assess DCC Level 0 and Level 1: buy a published-price Level 0 assessment by staff size, or request a scoped Level 1 quote. Consultant and platform support help you prepare for assessment.
Your contract or prime sets the required level. Level 0 has published staff-size prices; Level 1 is quoted after scope review.
Why Level 0 is flat-priced
Level 0 is a documentation-led review against a constrained requirement set. The work fits inside fixed boundaries, so the fee can too.
Why Level 1 is a range
L1 scope complexity drives the work. We name the drivers openly:
Every L1 engagement includes a dedicated consultant and Fig’s platform for automated gap identification - bundled into the base fee, never sold as add-ons.
Basic · CSMv4 Level 0 CRP
Micro
1-9 staff
One-off · 3-year validity
Small
10-49 staff
One-off · 3-year validity
Medium
50-249 staff
One-off · 3-year validity
Large
250+ staff
One-off · 3-year validity
Enhanced · CSMv4 Level 1 CRP
Micro
1-9 staff
Scoped quote · 3-year validity
Small
10-49 staff
Scoped quote · 3-year validity
Medium
50-249 staff
Scoped quote · 3-year validity
Large
250+ staff
Scoped quote · 3-year validity
Need an enterprise scope, multi-entity engagement, or a DCC L2/L3 referral?
Talk to the teamLevel 0 assesses Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. IASME describes the three controls. Preparation checklists describe evidence support, not extra scheme controls. Use the CSM version and numeric level specified by your contracting authority. Current MOD guidance says CSMv3 labels are not consistent with CSMv4 levels and that the full SAQ remains mandatory for contractual risk assessment and procurement, even for suppliers holding DCC certification.
Fast discovery paths for MOD suppliers comparing level, price, urgency, and procurement evidence.
Published price route
For a CSMv4 Level 0 requirement: compare published prices by staff size, then buy your Level 0 assessment.
Open routeConsultant-led route
For a CSMv4 Level 1 requirement: review the price band and request a scoped quote before payment.
Open routeEvaluation route
Side-by-side comparison of the two levels Fig is IASME-licensed to assess: controls, pricing, timeline, and how to choose.
Open routeEvidence route
Every Fig DCC claim mapped to verifiable evidence: licence scope, pricing logic, Cyber Essentials prerequisite handling, turnaround.
Open routeScoping route
How Fig scopes a DCC engagement: the six recurring rejection patterns, the four boundary tests, the readiness kit at L0 and L1.
Open routeThree buyer-facing references Fig assessors point MOD suppliers to before scoping. Read in any order.
Glossary
Plain-English definitions of the four CRP tiers (Level 0, Level 1, Level 2, Level 3) and the DCC level each one maps to. Read this first if your contract clause references a CRP and you do not yet know which DCC level you need.
Open glossaryScoping Guide
How Fig assessors scope a DCC engagement before you commit to a quote. The recurring rejection patterns we see, the boundary tests we run, and the evidence kit you can prepare in advance.
Read scoping guideFAQ
Buyer-facing questions on DCC scope, level decisions, prerequisites, timelines, pricing structure, and consultant + platform delivery - each question with its own deep-link URL for fast retrieval.
Open DCC FAQDefence Cyber Certification trust evidence
Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.
Licence
Fig Group publishes its IASME licence evidence and Defence Cyber Certification Level 0 / Level 1 scope so procurement teams can verify the certification route before they buy.
Verify IASME licencePricing
Defence Cyber Certification Level 0 is flat-priced by organisation size. Level 1 is range-priced because contract context, evidence maturity, sites, cloud footprint, and remediation need vary.
Review Defence Cyber Certification pricingPrerequisite
Defence Cyber Certification Level 0 and Level 1 require Cyber Essentials as the prerequisite.
Cyber Essentials for defence suppliersClaims
Defence Cyber Certification speed, pricing, licence, and route claims are linked back to a public Defence Cyber Certification trust page rather than left as unqualified sales copy.
Review Defence Cyber Certification claim evidenceCheck the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.
The UK MOD's independent cybersecurity certification for its supply chain.
Defence Cyber Certification, defined
The UK MOD’s framework for independently certifying the cybersecurity posture of its supply chain.
DCC adds independent certification evidence to the MOD's Cyber Security Model. Suppliers still complete the required SAQ in the Supplier Cyber Protection Service for their contract.
Contractual assurance - SAQ
Suppliers complete the SAQ for the Cyber Risk Profile set by the MOD customer or prime. The full SAQ remains part of the current procurement and contract process.
Independent evidence - DCC
DCC applicants are assessed by an IASME-licensed Certification Body against the relevant controls. A certificate provides independent evidence alongside the required SAQ where the contract calls for it.
Procurement teams can verify Fig Group's IASME status before approval on the IASME licence evidence page.
Bidding tip - mixed CRP pipelines
A higher-tier DCC certificate covers tenders at lower tiers - the reverse is not true. If you bid on contracts spanning multiple Cyber Risk Profiles, target the top of your range and let it cascade down.
Mapped to the MOD's four Cyber Risk Profile tiers.
CSMv4 Level 0 CRP
Foundational tier. Documentation-led review of three control areas under Def Stan 05-138 issue 4: Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. A current Cyber Essentials certificate is required before assessment and is arranged separately.
Fig offers this level
CSMv4 Level 1 CRP
Formal engagement. Scoping, evidence preparation, remediation support, and third-party assessment. Cyber Essentials is a prerequisite. Fig bundles consultant and platform into the base fee.
Fig offers this level
CSMv4 Level 2 CRP
Requires Cyber Essentials Plus plus substantial operational security maturity. Typically a multi-month engagement including technical verification against Def Stan 05-138 issue 4 (Level 2 control set, 139 controls).
Fig refers to a body listed on the IASME directory
CSMv4 Level 3 CRP
The most demanding tier. Comparable to a full ISMS audit with defence-specific technical depth, assessed against Def Stan 05-138 issue 4 (Level 3 control set, 144 controls). Requires Cyber Essentials Plus and sustained control maturity across the supply chain.
Fig refers to a body listed on the IASME directory
2–3 weeks for a prepared organisation (already holds Cyber Essentials, governance documentation in place, clear scope).
4–8 weeks for organisations starting from a lower baseline.
6–10 weeks for a prepared organisation with consultant support and Fig platform gap analysis.
12–20 weeks for organisations starting from a lower baseline. Most variance is supplier preparation, not our timeline.
For tender-deadline acceleration, contact us at quote stage. We prioritise engagement sequencing where possible.
How Fig delivers DCC differently from audit-only Certification Bodies.
Every L1 engagement includes a named consultant through scoping, evidence preparation, remediation, and formal assessment. No hand-off between sales, delivery, and audit. L0 engagements include scoping-level consultant support.
Fig’s platform runs automated gap analysis across in-scope systems - unpatched CVEs, cloud misconfiguration, identity coverage, endpoint posture, exposed surface - so issues are fixed before the assessor arrives, not during audit.
Level 0 has a published price for each staff-size tier. Level 1 has published bands and needs a scoped quote before payment.
We publish the price bands and explain the scope factors used to prepare a Level 1 quote.
Single-site engagements are faster than multi-site scopes. Hybrid or remote staffing complicates evidence collection.
Single-tenant Microsoft 365 estates are quick. Multi-cloud with custom IaC, hybrid identity, or significant PaaS surface adds engagement time.
In-scope legacy platforms (Windows Server 2012, unsupported network kit, bespoke applications with limited patching) require additional control evidence.
L1 requires evidence of flow-down controls to your own suppliers. Simple chains are quick; tier-two chains with multiple subcontractors add engagement time.
Small staff populations with clear role definitions move quickly. Organisations with large contractor or temp populations need more identity and access evidence.
Current ISO 27001 or NCSC CAF evidence may reduce preparation work where it covers the DCC scope. Your quote depends on the evidence gaps, required support and agreed scope.
Honest context on where Fig sits in the IASME-licensed CB market.
L0 market range (Fig estimate)
Fig’s estimate of typical UK L0 pricing, based on review of public IASME-directory listings - roughly £800 + VAT at the lowest end (micro) up to £7,000 + VAT at the highest end (large). This is not an IASME or MOD-published figure. Fig’s published L0 pricing of £499.99 - £799.99 + VAT sits at the competitive end of that range; verify any body’s pricing directly before comparison.
L1 market range (Fig estimate)
Fig’s estimate of typical UK L1 pricing, based on review of public IASME-directory listings. The range is genuinely wide because engagement models differ - audit-only at the low end, full consultancy with platform support at the high end. This is not an IASME or MOD-published figure. Fig sits in the middle because we bundle consultant and platform into the base fee rather than unbundling them; verify any body’s pricing directly before comparison.
Procurement note
A cheaper headline L1 fee that excludes consultancy, platform access, and remediation rounds typically lands similar or higher all-in once those are added back in.
What happens from quote to certificate - L0 takes 2-3 weeks, L1 takes 6-10 weeks for a prepared organisation.
Your MOD customer or prime sets the Cyber Risk Profile. We check the contract level and scope: Level 0 has published staff-size prices; Level 1 needs a scoped quote within its published band.
Cyber Essentials (L0/L1) or Cyber Essentials Plus (L2/L3) is required.
Read-only access to in-scope systems. The platform runs automated gap analysis across patches, cloud config, identity, endpoint posture, and exposed surface.
Your dedicated consultant works with you through identified gaps. Three rounds of remediation feedback are included before formal assessment.
An IASME-licensed assessor reviews the submitted scope and evidence against the applicable DCC controls. Gaps may require further work before certification.
Certificate issued with three-year validity. Annual attestation support included. Platform continues running across the certificate period.
Defence suppliers can seek certification at the level relevant to their work. DCC is not universally mandatory; check each tender or contract for its requirement.
Answers on scope, pricing, prerequisites, timelines, and the consultant + platform model.
DCC provides independent assurance against the MOD Cyber Security Model and is delivered by IASME. The current scheme has numeric Levels 0 to 3. It supports, rather than replaces, contract-specific supplier assurance: the full Supplier Assurance Questionnaire remains required under current MOD guidance.
No. Current MOD guidance requires the full contract-specific Supplier Assurance Questionnaire through the Supplier Cyber Protection Service, including for DCC certificate holders. DCC independently evidences organisational assurance against Def Stan 05-138 Issue 4; the buyer-assigned risk profile and contractual process still apply.
Check the written MOD or prime-contractor requirement and its transition date. IASME guidance says DCC is not currently mandatory across all contracts; the MOD’s published 8 May 2026 request for industry partners to reach Level 0 by 31 December 2026 is a separate request, not a universal legal rule. Ask the contracting authority to confirm the numeric Cyber Risk Profile, Risk Assessment Reference and applicable tender clause.
Use the numeric Cyber Risk Profile assigned by the MOD or contracting customer, its Risk Assessment Reference and the current contract version. CSM v4 uses Levels 0 to 3; older Very Low, Low, Moderate and High labels do not convert automatically. If a tender still uses verbal wording or two buyers require different levels, obtain written authority clarification before selecting an assessment scope or package.
Fig Group delivers DCC Level 0 and Level 1 through its licensed certification body. For Level 2 or Level 3, use the IASME DCC Certification Body directory to find a body licensed for the required level; Fig Group can refer you to an appropriately authorised provider. Check the assigned level and licence before buying.
Current Cyber Essentials is a prerequisite for DCC Levels 0 and 1, with Plus required at Levels 2 and 3. Arrange Cyber Essentials certification separately if you do not hold a current, same-scope certificate before formal assessment. Maintaining the underlying annual certification remains your responsibility during DCC validity.
Published Level 0 prices run from £499.99 + VAT for Micro to £799.99 + VAT for Large. Level 1 published ranges run from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large, depending on agreed scope. Years 1 and 2 include annual attestation support within the package; Year 3 reassessment is separately priced. Arrange Cyber Essentials certification and annual renewal separately, and check any work outside the Order Form before purchase.
Level 0 has a published staff-band price from £499.99 to £799.99 + VAT. Level 1 ranges from £9,999–£14,999 + VAT for Micro to £25,000–£49,999 + VAT for Large because scope, evidence gaps and assessor effort vary. The published package includes scoped consultancy and assessment; optional work outside the accepted Order Form may cost extra. Request a written Level 1 quote rather than treating a range endpoint as a fixed checkout price.
The published Level 1 package includes consultant support for the agreed scoping, evidence preparation and assessment programme. The applicant implements required controls and supplies accurate evidence. Confirm deliverables, feedback and remediation rounds, any extension charges and separately requested work in the accepted written Order Form; the package is not unlimited consultancy.
The published Level 1 offer includes scoped platform support for evidence mapping and annual attestations. Confirm the actual access duration, included integrations and functionality, support, post-certification charges and any separate consultancy retainer in a written Order Form. Evidence mapping alone does not prove an unconditional three-year platform entitlement. Year 3 reassessment is separately purchased.
As at 29 September 2026, Fig Group estimates two to three weeks end to end for a prepared Level 0 applicant and four to eight weeks where prerequisite certification, governance documents or scope need work. These are indicative supplier estimates, not an IASME deadline. Confirm the numeric level, current Cyber Essentials, three-control evidence, written assessment schedule and buyer deadline before relying on a target date.
As at 29 September 2026, Fig Group estimates six to ten weeks end to end for a prepared Level 1 applicant and twelve to twenty weeks from a lower baseline. Scope, 101-control evidence, remediation, assessor availability and current prerequisite certification affect timing. Obtain a written scope and schedule against the tender deadline; neither estimate guarantees certificate issue.
The published DCC package includes annual attestation support for Years 1 and 2. Year-three reassessment is separate. Underlying Cyber Essentials needs annual renewal, and additional work outside the accepted scope may be chargeable under your Order Form. Existing signed terms continue to apply.
Share the written tender deadline and required numeric level with Fig Group at quote stage. Check current Cyber Essentials, assessment scope, evidence readiness and whether an assessor can agree a written schedule. Preparation may be shortened, but assessment findings and remediation still determine certification; no deadline guarantee applies.
Fig Group’s platform can organise scoped DCC evidence and highlight gaps from supported data sources such as connected identity, endpoint and cloud systems. Available checks depend on the agreed integrations, permissions and data quality; a detected issue is reviewed by the applicant and assessor, not automatically certified. Confirm included Level 1 access and functionality in the Order Form.
Some dated SAQ policies and technical records can be reused if they cover the same organisation, systems and control period. For example, map an access-control policy dated June to the applicable DCC control, note missing MFA enforcement evidence, then arrange independent review of the gap. The contract-specific SAQ still remains due; reuse does not replace the DCC assessment.
Fig Compliance Ltd holds separate IASME licences for DCC Level 0 and Level 1, and Cyber Essentials and Plus. Verify each scheme and authorised level through the relevant registry and IASME DCC directory; a Cyber Essentials badge alone does not prove a DCC licence. Fig Group does not assess DCC Levels 2 or 3.
An IASME-licensed DCC Certification Body authorised for the required level can issue a certificate following a successful assessment. Fig Group delivers Levels 0 and 1 through its licensed body; see the IASME DCC directory for level-specific verification and other providers. Cyber Essentials certification and annual renewal are arranged separately. For Levels 2 and 3, use a body authorised for those levels.
Authoritative reading on DCC levels, scoping, timelines, and the relationship between Cyber Essentials and Defence Cyber Certification.
Step-by-step · 12 min read
Level decision · 10 min read
Scheme comparison · 9 min read
Scoping · 11 min read
Timeline · 9 min read
Check the Cyber Risk Profile set by your MOD customer or prime. Choose a published-price Level 0 assessment, or ask Fig Group to scope a Level 1 quote within the published price band.