Defence Cyber Certification
Defence Cyber Certification: Level 0 vs Level 1
Side-by-side comparison so UK MOD suppliers reading a Defence Cyber Certification Cyber Risk Profile clause for the first time can pick the right engagement and avoid the cost of buying the wrong level.
Defence Cyber Certification Level 0
For CSMv4 Level 0 CRP contracts
Documentation-led Defence Cyber Certification, foundational controls, flat-priced by organisation size.
Open Defence Cyber Certification Level 0 pageDefence Cyber Certification Level 1
For CSMv4 Level 1 CRP contracts
Consultant-led Defence Cyber Certification against 101 controls. Range-priced because remediation effort scales with organisation complexity. A current Cyber Essentials certificate is required before assessment and is arranged separately.
Open Defence Cyber Certification Level 1 pageSide-by-side comparison
| Field | Defence Cyber Certification Level 0 (CSMv4 Level 0 CRP) | Defence Cyber Certification Level 1 (CSMv4 Level 1 CRP) |
|---|---|---|
| MOD Cyber Risk Profile | CSMv4 Level 0 | CSMv4 Level 1 |
| Typical contract pattern | Non-sensitive supply, tier-2/3 subcontract, OFFICIAL information | Professional services / tech to DE&S, DIO, DSTL; OFFICIAL-SENSITIVE-adjacent |
| Cyber Essentials prerequisite | Required | Required; arrange separately if not held |
| Assessment shape | Documentation-led self-assessment + IASME-licensed assessor review | Consultant-led assessment against 101 controls drawn from Def Stan 05-138 issue 4 |
| MFA enforcement scope | Applicable CE authentication requirements for in-scope services | Applicable Level 1 access-control requirements, verified against the scheme control set; no universal product mandate |
| Supply-chain governance | Documented direct-supplier list | Flow-down of security clauses to direct suppliers; Cyber Essentials evidence where contractually required |
| Pricing logic | Flat by organisation size | Range by organisation size (consultant + remediation effort scales materially) |
| Fig price band | £499.99 + VAT (Micro) to £799.99 + VAT (Large) | £9,999 + VAT (Micro) to £49,999 + VAT (Large), as ranges |
| Typical timeline (prepared) | 2-3 weeks | 6-10 weeks |
| Certificate validity | 3 years with annual attestation | 3 years with annual attestation |
Decision rules
If the CSMv4 contract requires Level 0
Buy Defence Cyber Certification Level 0. Do not over-buy L1 - it adds cost and time without changing what the buyer requires.
If the CSMv4 contract requires Level 1
Buy Defence Cyber Certification Level 1. L0 will not satisfy the buyer's requirement and you will be asked to upgrade mid-engagement, which is more expensive than starting at Defence Cyber Certification Level 1.
If the CSMv4 contract requires Level 2 or Level 3
You need Defence Cyber Certification Level 2 or Level 3. Fig is IASME-licensed at Defence Cyber Certification L0 and L1 only - we refer L2 / L3 work to specialist bodies rather than take an engagement we cannot deliver.
If the contract has no explicit CRP statement
Read the DEFCON 658 clause and any associated security schedule. If still unclear, ask the buying authority. Do not assume Level 0 - it is the buyer's call to make.
Still unsure?
Send us the contract clause and we will tell you which level applies before you buy. The Cyber Risk Profile reference is the canonical CRP-to-level mapping; the DCC scoping guide covers the boundary tests Fig assessors apply at L0 and L1. For an end-to-end view of the prerequisite Cyber Essentials route, see /cyberessentials.
Review DCC claims and evidence