Skip to content
Defence Cyber Certification · L0

DCC Level 0, from £499.99 + VAT.

The entry point for UK MOD supplier cyber assurance. Documentation-led review against the Def Stan 05-138 issue 4, three-year certificate validity. Fig Group is IASME-licensed at Level 0.

£499.99

Starting price (Micro tier, ex VAT)

CSMv4 Level 0

Cyber Risk Profile this tier maps to

3 years

Certificate validity, annual attestation

Defence Cyber Certification trust evidence

DCC evidence buyers should verify

Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.

Official IASME DCC directory

Check the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.

Pricing

Flat-priced by organisation size

L0 scope is a constrained documentation review, so the fee is flat per tier - no scoping surcharge, no consultancy retainer, no quote round.

DCC Level 0

Basic · CSMv4 Level 0 CRP

Micro

1-9 staff

£499.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set)
  • 3-year certificate validity
  • Annual attestation support
Buy now

Medium

50-249 staff

£699.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set)
  • 3-year certificate validity
  • Annual attestation support
Buy now

Large

250+ staff

£799.99+ VAT

One-off · 3-year validity

  • L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set)
  • 3-year certificate validity
  • Annual attestation support
Buy now

What L0 covers

Three things every L0 engagement delivers

01 · Documentation-led review

Evidence on paper, verified by an assessor

L0 assesses Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. The assessor reviews your answers and evidence, then verifies that the controls are in place.

02 · Def Stan 05-138 mapping

Mapped to the official spec

L0 assesses against Def Stan 05-138 issue 4 - the same Defence Standard used across DCC, scoped to the Level 0 control set relevant for CSMv4 Level 0 Cyber Risk Profile contracts.

03 · Certificate maintenance

Support after assessment

On passing, the DCC certificate lasts three years. Annual attestation support is included for Years 1 and 2; Cyber Essentials must be renewed annually and DCC reassessment is due after three years.

The L0 process

From CRP confirmation to certificate

Five stages from purchase to assessment and, on passing, certificate issue. Prepared organisations may complete L0 in 2-3 weeks, depending on scope, evidence and assessor availability.

  1. 01

    Step 1

    Confirm CRP and scope

    For a contract, we check the customer-assigned Cyber Risk Profile and Risk Assessment Reference. We then agree the DCC scope, including the functions and services essential to your organisation, against the IASME scoping guidance.

  2. 02

    Step 2

    Check Cyber Essentials

    Current Cyber Essentials is a prerequisite. If you do not hold it, arrange certification separately before formal DCC assessment.

  3. 03

    Step 3

    Evidence collection

    You provide evidence of Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. Existing CE evidence supports the prerequisite; the assessor confirms the additional data-protection and resilience evidence needed.

  4. 04

    Step 4

    Assessor review

    An IASME-licensed assessor reviews the documentation against the Def Stan 05-138 issue 4 Level 0 control set. Findings are returned with structured remediation guidance.

  5. 05

    Step 5

    Certificate issued

    After a successful assessment, the DCC Level 0 certificate is issued for three years. Annual attestation and Cyber Essentials renewal are required; DCC reassessment is due at the end of the certificate period.

Who needs Level 0

Three buyer profiles

L0 is the right tier when the contract specifies a CSMv4 Level 0 Cyber Risk Profile. Three supplier types most often land here.

Tier-2 / tier-3 MOD suppliers

Subcontractors whose flow-down obligations specify a CSMv4 Level 0 Cyber Risk Profile. The contract-specific SAQ still applies even when the supplier holds a DCC certificate.

Professional services into MOD

Consultants, recruiters, training providers and other professional services whose customer assigns a CSMv4 Level 0 profile. The business sector alone does not determine the required level.

New defence-sector entrants

Organisations entering the defence supply chain can seek L0 certification voluntarily. Check each tender before purchase; a future contract may require a different level.

L0 vs L1

How Level 0 differs from Level 1

Both tiers are IASME-licensed DCC engagements. The right tier depends on the Cyber Risk Profile the contract specifies.

Level 0

Documentation-led review

  • Maps to CSMv4 Level 0 Cyber Risk Profile
  • Flat per-tier pricing (£499.99 - £799.99)
  • 2-3 week typical engagement
  • CE prerequisite, no L1 consultant
  • Assessor review and verification of three controls

Level 1

Consultant + platform engagement

  • Maps to CSMv4 Level 1 Cyber Risk Profile
  • Range pricing (£9,999 - £49,999)
  • 6-10 week typical engagement
  • Dedicated consultant + Fig platform
  • Three remediation rounds before assessment

FAQ

Level 0 questions answered

How do I know I need DCC Level 0 specifically?

For a contract, the MOD customer or prime assigns the required Cyber Risk Profile and Risk Assessment Reference. CSMv4 uses numeric Levels 0 to 3; legacy CSMv3 labels do not map automatically. You can seek certification voluntarily at any level, but confirm the buyer’s requirement before purchasing for a tender.

What's included in the L0 fee?

The L0 assessment covers Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems under Def Stan 05-138 issue 4, certificate issuance on passing, three years of validity, annual attestation support in Years 1 and 2, and limited consultant access during preparation. Cyber Essentials certification and annual renewals are arranged separately; Year 3 reassessment is also separate.

How long does Level 0 take?

Typically 2-3 weeks for a prepared organisation. The longest variable is evidence collection for CE scope and maintenance, UK GDPR compliance, and resilient networks and systems. Prepared organisations with current CE and suitable data-protection and resilience evidence move faster.

Do I need Cyber Essentials before DCC L0?

Yes - L0 requires a current Cyber Essentials certificate as a prerequisite.

How does L0 differ from Level 1?

L0 is a documentation-led review at a flat published price. L1 adds a formal scoping engagement, dedicated consultant, platform-supported gap analysis, and is priced as a range rather than flat (because L1 scope complexity varies materially). L1 is required when the contract specifies CSMv4 Level 1 rather than Level 0.

How long is the certificate valid?

Three years from issue, with annual attestation. The annual attestation confirms that controls remain in place during the validity window - it's a lighter check than the initial assessment, not a full re-issue.

DCC Level 0, on a published price.

Confirm your authority-required numeric level before choosing a tier. If unsure, request a scope review before purchase. For direct Level 0 checkout, the intake template and scoping call follow payment; formal assessment begins only after scope and prerequisites are confirmed.