Micro
1-9 staff
Scoped quote · 3-year validity
- Dedicated consultant + Fig platform
- L1 assessment against DEFSTAN 05-138
- Three remediation rounds included
- 3-year validity with annual attestation
The Level 1 route for UK MOD suppliers. Range-priced from £9,999 + VAT - dedicated consultant, Fig platform access for automated gap analysis, three remediation rounds, three-year certificate validity.

£9,999
L1 starting range (Micro tier, ex VAT)
CSMv4 Level 1 CRP
Cyber Risk Profile this tier maps to
6-10 weeks
Typical engagement for a prepared organisation
Defence Cyber Certification trust evidence
Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.
Licence
Fig Group publishes its IASME licence evidence and Defence Cyber Certification Level 0 / Level 1 scope so procurement teams can verify the certification route before they buy.
Verify IASME licencePricing
Defence Cyber Certification Level 0 is flat-priced by organisation size. Level 1 is range-priced because contract context, evidence maturity, sites, cloud footprint, and remediation need vary.
Review Defence Cyber Certification pricingPrerequisite
Defence Cyber Certification Level 0 and Level 1 require Cyber Essentials as the prerequisite.
Cyber Essentials for defence suppliersClaims
Defence Cyber Certification speed, pricing, licence, and route claims are linked back to a public Defence Cyber Certification trust page rather than left as unqualified sales copy.
Review Defence Cyber Certification claim evidenceCheck the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.
Pricing
L1 scope complexity varies with site count, cloud footprint, legacy systems, supply chain depth, and existing maturity - so we publish ranges and name the drivers openly rather than quoting a single bespoke number.
Enhanced · CSMv4 Level 1 CRP
Micro
1-9 staff
Scoped quote · 3-year validity
Small
10-49 staff
Scoped quote · 3-year validity
Medium
50-249 staff
Scoped quote · 3-year validity
Large
250+ staff
Scoped quote · 3-year validity
Why Fig for L1
L1 is more than a documentation review. Fig delivers it as one coherent engagement rather than a sales-then-audit handoff with surprise line items.
01 · Dedicated consultant
Every L1 engagement includes consultant support for scoping, evidence preparation and remediation feedback. A qualified DCC assessor conducts the formal assessment with the impartiality required by IASME.
02 · Platform-supported
Fig's technology platform runs automated checks across patches, cloud config, identity coverage, endpoint posture, and exposed surface - so issues are surfaced and fixed before the formal assessment, not during.
03 · Three remediation rounds
L1 includes three structured remediation rounds before formal assessment. The assessor still makes an independent decision on the submitted evidence and verified controls.
The L1 process
Prepared organisations may complete L1 in 6-10 weeks, depending on scope, readiness, remediation and assessor availability. Three remediation rounds are included before formal assessment.
Step 1
We confirm your required DCC level from the contract Cyber Risk Profile, scope the engagement, and issue a fixed price within the published tier band.
Step 2
Cyber Essentials is required for Level 1. Arrange certification separately if needed; annual renewal remains your responsibility.
Step 3
Read-only access to in-scope systems. The platform runs automated gap analysis across patches, cloud config, identity, endpoint posture, and exposed surface.
Step 4
Your dedicated consultant works with you through identified gaps. Three structured rounds of remediation feedback are included before formal assessment.
Step 5
A qualified DCC assessor conducts the formal assessment against Def Stan 05-138 issue 4. The assessor verifies the controls and makes the certification decision independently.
Step 6
After a successful assessment, the certificate lasts three years. Annual attestation support and platform access are included within the agreed scope. Renew Cyber Essentials annually and arrange DCC reassessment before expiry.
Variance drivers
Six drivers determine where in the published range your engagement lands. We name them openly rather than quoting a bespoke number that changes by sales conversation.
Single-site engagements are faster than multi-site scopes. Hybrid or remote staffing complicates evidence collection.
Single-tenant Microsoft 365 estates are quick. Multi-cloud with custom IaC, hybrid identity, or significant PaaS surface adds engagement time.
In-scope legacy platforms (Windows Server 2012, unsupported network kit, bespoke applications with limited patching) require additional control evidence.
L1 requires evidence of flow-down controls to your own suppliers. Simple chains are quick; tier-two chains with multiple subcontractors add engagement time.
Small staff populations with clear role definitions move quickly. Organisations with large contractor or temp populations need more identity and access evidence.
Existing evidence and control maturity can reduce preparation work. The final quote depends on the agreed scope and the work actually needed.
Who needs Level 1
L1 is the right tier when the contract specifies a CSMv4 Level 1 Cyber Risk Profile. Three supplier types most often need this engagement.
Suppliers bidding on DE&S, DIO, or DSTL contracts where the Cyber Risk Profile specifies Level 1 under CSMv4. The required level is set by the contracting authority, not the supplier’s position in the supply chain.
Software, cloud, managed services and hardware vendors may need L1 when their customer assigns a CSMv4 Level 1 profile. Contract requirements and the full SAQ still apply.
Consultancies, legal, accountancy and recruitment firms may need L1 where the buyer assigns a CSMv4 Level 1 profile. The required level follows the customer’s risk assessment, not a generic data-sensitivity rule.
Bundled into the L1 fee
Some CBs publish a low L1 headline price that excludes consultancy, platform access, and remediation rounds - then add them as line items mid-engagement. Our fee bundles every component so the published range is the all-in price you pay.
L1 vs L0
L1 is required when the contract specifies CSMv4 Level 1 CRP. L0 covers CSMv4 Level 0 CRP only. The right tier is decided by the contract, not the supplier.
Level 0
Level 1
FAQ
For a contract, the MOD customer or prime assigns the required Cyber Risk Profile and Risk Assessment Reference. CSMv4 uses numeric Levels 0 to 3; legacy CSMv3 labels do not map automatically. You can seek certification voluntarily at any level, but confirm the buyer’s requirement before purchasing for a tender.
L0 scope is a constrained documentation review, so the fee can be flat. L1 scope complexity varies materially with site count, cloud footprint, legacy systems, supply chain depth, staff population, and existing maturity. Pricing as a range and naming the variance drivers openly is more honest than quoting a single number that bears no relation to the work.
Consultant support for scoping and preparation, Fig Group platform access for gap analysis, the independent L1 assessment, and three remediation rounds before formal assessment are included. A certificate is issued on passing and lasts three years, with annual attestation support. Cyber Essentials is a prerequisite and is arranged separately; annual renewal remains your responsibility.
Typically 6-10 weeks for a prepared organisation. The longest variable is remediation - if the platform identifies high or critical findings, the timeline depends on how quickly your team can close them. Three structured remediation rounds are built into the engagement.
Yes, consultant support is included within the agreed scope. Platform access is included for the three-year certificate period. The scoped Order Form confirms deliverables, annual-attestation support and any extensions; year-three recertification is a separate engagement.
It produces a more honest price comparison. Some CBs publish a low headline L1 fee that excludes consultancy, platform access, and remediation rounds - then add them as line items mid-engagement. Bundling means the price you see is the price you pay, and that price compares apples-to-apples against full-scope quotes.
Talk to an IASME-licensed DCC assessor. We confirm your required level from your contract Cyber Risk Profile, scope the engagement, and issue a fixed price within the published tier band - all in one conversation.