Micro
1-9 staff
One-off · 3-year validity
- L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set)
- 3-year certificate validity
- Annual attestation support
The entry point for UK MOD supplier cyber assurance. Documentation-led review against the Def Stan 05-138 issue 4, three-year certificate validity. Fig Group is IASME-licensed at Level 0.
£499.99
Starting price (Micro tier, ex VAT)
CSMv4 Level 0
Cyber Risk Profile this tier maps to
3 years
Certificate validity, annual attestation
Defence Cyber Certification trust evidence
Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.
Licence
Fig Group publishes its IASME licence evidence and Defence Cyber Certification Level 0 / Level 1 scope so procurement teams can verify the certification route before they buy.
Verify IASME licencePricing
Defence Cyber Certification Level 0 is flat-priced by organisation size. Level 1 is range-priced because contract context, evidence maturity, sites, cloud footprint, and remediation need vary.
Review Defence Cyber Certification pricingPrerequisite
Defence Cyber Certification Level 0 and Level 1 require Cyber Essentials as the prerequisite.
Cyber Essentials for defence suppliersClaims
Defence Cyber Certification speed, pricing, licence, and route claims are linked back to a public Defence Cyber Certification trust page rather than left as unqualified sales copy.
Review Defence Cyber Certification claim evidenceCheck the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.
Pricing
L0 scope is a constrained documentation review, so the fee is flat per tier - no scoping surcharge, no consultancy retainer, no quote round.
Basic · CSMv4 Level 0 CRP
Micro
1-9 staff
One-off · 3-year validity
Small
10-49 staff
One-off · 3-year validity
Medium
50-249 staff
One-off · 3-year validity
Large
250+ staff
One-off · 3-year validity
What L0 covers
01 · Documentation-led review
L0 assesses Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. The assessor reviews your answers and evidence, then verifies that the controls are in place.
02 · Def Stan 05-138 mapping
L0 assesses against Def Stan 05-138 issue 4 - the same Defence Standard used across DCC, scoped to the Level 0 control set relevant for CSMv4 Level 0 Cyber Risk Profile contracts.
03 · Certificate maintenance
On passing, the DCC certificate lasts three years. Annual attestation support is included for Years 1 and 2; Cyber Essentials must be renewed annually and DCC reassessment is due after three years.
The L0 process
Five stages from purchase to assessment and, on passing, certificate issue. Prepared organisations may complete L0 in 2-3 weeks, depending on scope, evidence and assessor availability.
Step 1
For a contract, we check the customer-assigned Cyber Risk Profile and Risk Assessment Reference. We then agree the DCC scope, including the functions and services essential to your organisation, against the IASME scoping guidance.
Step 2
Current Cyber Essentials is a prerequisite. If you do not hold it, arrange certification separately before formal DCC assessment.
Step 3
You provide evidence of Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems. Existing CE evidence supports the prerequisite; the assessor confirms the additional data-protection and resilience evidence needed.
Step 4
An IASME-licensed assessor reviews the documentation against the Def Stan 05-138 issue 4 Level 0 control set. Findings are returned with structured remediation guidance.
Step 5
After a successful assessment, the DCC Level 0 certificate is issued for three years. Annual attestation and Cyber Essentials renewal are required; DCC reassessment is due at the end of the certificate period.
Who needs Level 0
L0 is the right tier when the contract specifies a CSMv4 Level 0 Cyber Risk Profile. Three supplier types most often land here.
Subcontractors whose flow-down obligations specify a CSMv4 Level 0 Cyber Risk Profile. The contract-specific SAQ still applies even when the supplier holds a DCC certificate.
Consultants, recruiters, training providers and other professional services whose customer assigns a CSMv4 Level 0 profile. The business sector alone does not determine the required level.
Organisations entering the defence supply chain can seek L0 certification voluntarily. Check each tender before purchase; a future contract may require a different level.
L0 vs L1
Both tiers are IASME-licensed DCC engagements. The right tier depends on the Cyber Risk Profile the contract specifies.
Level 0
Level 1
FAQ
For a contract, the MOD customer or prime assigns the required Cyber Risk Profile and Risk Assessment Reference. CSMv4 uses numeric Levels 0 to 3; legacy CSMv3 labels do not map automatically. You can seek certification voluntarily at any level, but confirm the buyer’s requirement before purchasing for a tender.
The L0 assessment covers Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems under Def Stan 05-138 issue 4, certificate issuance on passing, three years of validity, annual attestation support in Years 1 and 2, and limited consultant access during preparation. Cyber Essentials certification and annual renewals are arranged separately; Year 3 reassessment is also separate.
Typically 2-3 weeks for a prepared organisation. The longest variable is evidence collection for CE scope and maintenance, UK GDPR compliance, and resilient networks and systems. Prepared organisations with current CE and suitable data-protection and resilience evidence move faster.
Yes - L0 requires a current Cyber Essentials certificate as a prerequisite.
L0 is a documentation-led review at a flat published price. L1 adds a formal scoping engagement, dedicated consultant, platform-supported gap analysis, and is priced as a range rather than flat (because L1 scope complexity varies materially). L1 is required when the contract specifies CSMv4 Level 1 rather than Level 0.
Three years from issue, with annual attestation. The annual attestation confirms that controls remain in place during the validity window - it's a lighter check than the initial assessment, not a full re-issue.
Confirm your authority-required numeric level before choosing a tier. If unsure, request a scope review before purchase. For direct Level 0 checkout, the intake template and scoping call follow payment; formal assessment begins only after scope and prerequisites are confirmed.