Skip to content

Defence Cyber Certification

Defence Cyber Certification: Level 0 vs Level 1

Side-by-side comparison so UK MOD suppliers reading a Defence Cyber Certification Cyber Risk Profile clause for the first time can pick the right engagement and avoid the cost of buying the wrong level.

Defence Cyber Certification Level 0

For CSMv4 Level 0 CRP contracts

Documentation-led Defence Cyber Certification, foundational controls, flat-priced by organisation size.

Open Defence Cyber Certification Level 0 page

Defence Cyber Certification Level 1

For CSMv4 Level 1 CRP contracts

Consultant-led Defence Cyber Certification against 101 controls. Range-priced because remediation effort scales with organisation complexity. A current Cyber Essentials certificate is required before assessment and is arranged separately.

Open Defence Cyber Certification Level 1 page

Side-by-side comparison

FieldDefence Cyber Certification Level 0 (CSMv4 Level 0 CRP)Defence Cyber Certification Level 1 (CSMv4 Level 1 CRP)
MOD Cyber Risk ProfileCSMv4 Level 0CSMv4 Level 1
Typical contract patternNon-sensitive supply, tier-2/3 subcontract, OFFICIAL informationProfessional services / tech to DE&S, DIO, DSTL; OFFICIAL-SENSITIVE-adjacent
Cyber Essentials prerequisiteRequiredRequired; arrange separately if not held
Assessment shapeDocumentation-led self-assessment + IASME-licensed assessor reviewConsultant-led assessment against 101 controls drawn from Def Stan 05-138 issue 4
MFA enforcement scopeApplicable CE authentication requirements for in-scope servicesApplicable Level 1 access-control requirements, verified against the scheme control set; no universal product mandate
Supply-chain governanceDocumented direct-supplier listFlow-down of security clauses to direct suppliers; Cyber Essentials evidence where contractually required
Pricing logicFlat by organisation sizeRange by organisation size (consultant + remediation effort scales materially)
Fig price band£499.99 + VAT (Micro) to £799.99 + VAT (Large)£9,999 + VAT (Micro) to £49,999 + VAT (Large), as ranges
Typical timeline (prepared)2-3 weeks6-10 weeks
Certificate validity3 years with annual attestation3 years with annual attestation

Decision rules

If the CSMv4 contract requires Level 0

Buy Defence Cyber Certification Level 0. Do not over-buy L1 - it adds cost and time without changing what the buyer requires.

If the CSMv4 contract requires Level 1

Buy Defence Cyber Certification Level 1. L0 will not satisfy the buyer's requirement and you will be asked to upgrade mid-engagement, which is more expensive than starting at Defence Cyber Certification Level 1.

If the CSMv4 contract requires Level 2 or Level 3

You need Defence Cyber Certification Level 2 or Level 3. Fig is IASME-licensed at Defence Cyber Certification L0 and L1 only - we refer L2 / L3 work to specialist bodies rather than take an engagement we cannot deliver.

If the contract has no explicit CRP statement

Read the DEFCON 658 clause and any associated security schedule. If still unclear, ask the buying authority. Do not assume Level 0 - it is the buyer's call to make.

Still unsure?

Send us the contract clause and we will tell you which level applies before you buy. The Cyber Risk Profile reference is the canonical CRP-to-level mapping; the DCC scoping guide covers the boundary tests Fig assessors apply at L0 and L1. For an end-to-end view of the prerequisite Cyber Essentials route, see /cyberessentials.

Review DCC claims and evidence