Scope at this tier
Most micro suppliers run a single-site, single-cloud footprint with a small direct supplier list. Evidence prep for an organisation already holding Cyber Essentials is typically a focused week of work.
Your MOD customer or prime sets the required contract level. Current MOD guidance requires the full Supplier Assurance Questionnaire for procurement even when you hold a DCC certificate.
What's included in the package
- Current, same-scope Cyber Essentials required before formal assessment; arrange certification separately if needed
- IASME-licensed L0 assessment against Def Stan 05-138 issue 4 (Level 0 control set)
- Documentation-led assessment of Cyber Essentials scope and maintenance, UK GDPR compliance, and resilient networks and systems
- 3-year certificate validity from issue date
- Annual attestation support at end of Year 1 and Year 2 (included in the published price)
- Structured intake template plus Fig consultant access during evidence preparation
What we expect you to have ready
L0 assesses three scheme controls. The assessor reviews your answers and evidence, then verifies that the controls are in place. The first three groups describe evidence for those controls; the wider groups are Fig Group's preparation checklist, tailored by the assessor, not additional mandatory scheme controls. Fig sends a structured intake template at scoping.
Cyber Essentials scope and maintenance
- Current CE evidence aligned with business-critical internet-connected systems in DCC scope
- Plan for annual CE renewal throughout the DCC certificate period
UK GDPR compliance
- Applicable data-protection policies and procedures
- DPIA evidence where required and appropriate to the organisation
Resilient networks and systems
- Documented recovery and resilience measures
- Evidence that recovery measures work, such as tested restores
Governance
- Information security policy (one document or a small policy framework)
- Roles and responsibilities for cyber security (named individuals or job titles)
- Incident response plan or procedure (even a one-pager covering detect, contain, notify)
- Acceptable use / staff awareness materials
Identity
- Joiner / mover / leaver process documentation
- Privileged access principles (who has admin, how it is reviewed)
- Authentication evidence (multi-factor enforcement on admin and remote access)
Device
- Patch management cadence (scheduled or as-released)
- Endpoint malware protection in place (Cyber Essentials evidence usually covers this)
- Device inventory - a maintained list is acceptable, a real-time tool is not required
Supply chain
- List of direct suppliers in scope of the MOD contract
- Standard supplier security clauses or DPA template (signed copies if available)
- Cyber Essentials evidence from suppliers where contractually required
Need scoping help, readiness work, or post-cert support?
The basic package covers the in-scope assessment. If you need help getting ready for assessment - scoping the in-scope estate, standing up missing governance, running a pre-cert readiness review, or putting a Year 2 retainer in place - Fig offers consultancy outside the basic package. Talk to us about what you need and we will scope it transparently.
Talk to us about scoping supportReference reading before you commit
Two canonical references Fig points buyers to before they sign: the CRP glossary if you want to confirm the level your contract clause requires, and the DCC scoping guide for the rejection patterns and boundary tests Fig runs at scoping.
