Skip to content
Defence Cyber Certification · L1

DCC Level 1, consultant-led and platform-supported.

The Level 1 route for UK MOD suppliers. Range-priced from £9,999 + VAT - dedicated consultant, Fig platform access for automated gap analysis, three remediation rounds, three-year certificate validity.

DCC Level 1 certification body logo

£9,999

L1 starting range (Micro tier, ex VAT)

CSMv4 Level 1 CRP

Cyber Risk Profile this tier maps to

6-10 weeks

Typical engagement for a prepared organisation

Defence Cyber Certification trust evidence

DCC evidence buyers should verify

Defence Cyber Certification buyers usually need four proof points before procurement approval: licence scope, price basis, Cyber Essentials prerequisite handling, and where the claim evidence lives.

Official IASME DCC directory

Check the CSM version and numeric Cyber Risk Profile assigned by your MOD customer or prime. CSMv4 Levels 0 to 3 do not convert automatically from the old verbal risk bands. Fig Group assesses Levels 0 and 1; ask for a suitable referral if your contract requires Level 2 or 3. A DCC certificate does not currently exempt suppliers from the full contract SAQ.

Pricing

Range-priced by organisation size

L1 scope complexity varies with site count, cloud footprint, legacy systems, supply chain depth, and existing maturity - so we publish ranges and name the drivers openly rather than quoting a single bespoke number.

DCC Level 1

Enhanced · CSMv4 Level 1 CRP

Micro

1-9 staff

£9,999 - £14,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against DEFSTAN 05-138
  • Three remediation rounds included
  • 3-year validity with annual attestation
Get quote

Medium

50-249 staff

£20,000 - £24,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against DEFSTAN 05-138
  • Three remediation rounds included
  • 3-year validity with annual attestation
Get quote

Large

250+ staff

£25,000 - £49,999+ VAT

Scoped quote · 3-year validity

  • Dedicated consultant + Fig platform
  • L1 assessment against DEFSTAN 05-138
  • Three remediation rounds included
  • 3-year validity with annual attestation
Get quote

Why Fig for L1

Consultant-led, platform-supported, no unbundling

L1 is more than a documentation review. Fig delivers it as one coherent engagement rather than a sales-then-audit handoff with surprise line items.

01 · Dedicated consultant

A named expert from scoping to certificate

Every L1 engagement includes consultant support for scoping, evidence preparation and remediation feedback. A qualified DCC assessor conducts the formal assessment with the impartiality required by IASME.

02 · Platform-supported

Automated gap analysis before audit

Fig's technology platform runs automated checks across patches, cloud config, identity coverage, endpoint posture, and exposed surface - so issues are surfaced and fixed before the formal assessment, not during.

03 · Three remediation rounds

Findings before the final review

L1 includes three structured remediation rounds before formal assessment. The assessor still makes an independent decision on the submitted evidence and verified controls.

The L1 process

Six stages from scoping to certificate

Prepared organisations may complete L1 in 6-10 weeks, depending on scope, readiness, remediation and assessor availability. Three remediation rounds are included before formal assessment.

  1. 01

    Step 1

    Scoping and quote

    We confirm your required DCC level from the contract Cyber Risk Profile, scope the engagement, and issue a fixed price within the published tier band.

  2. 02

    Step 2

    Prerequisite check

    Cyber Essentials is required for Level 1. Arrange certification separately if needed; annual renewal remains your responsibility.

  3. 03

    Step 3

    Platform onboarding

    Read-only access to in-scope systems. The platform runs automated gap analysis across patches, cloud config, identity, endpoint posture, and exposed surface.

  4. 04

    Step 4

    Remediation support

    Your dedicated consultant works with you through identified gaps. Three structured rounds of remediation feedback are included before formal assessment.

  5. 05

    Step 5

    Formal assessment

    A qualified DCC assessor conducts the formal assessment against Def Stan 05-138 issue 4. The assessor verifies the controls and makes the certification decision independently.

  6. 06

    Step 6

    Certification

    After a successful assessment, the certificate lasts three years. Annual attestation support and platform access are included within the agreed scope. Renew Cyber Essentials annually and arrange DCC reassessment before expiry.

Variance drivers

What moves a quote within the band

Six drivers determine where in the published range your engagement lands. We name them openly rather than quoting a bespoke number that changes by sales conversation.

Site count

Single-site engagements are faster than multi-site scopes. Hybrid or remote staffing complicates evidence collection.

Cloud footprint

Single-tenant Microsoft 365 estates are quick. Multi-cloud with custom IaC, hybrid identity, or significant PaaS surface adds engagement time.

Legacy systems

In-scope legacy platforms (Windows Server 2012, unsupported network kit, bespoke applications with limited patching) require additional control evidence.

Supply chain

L1 requires evidence of flow-down controls to your own suppliers. Simple chains are quick; tier-two chains with multiple subcontractors add engagement time.

Staff population

Small staff populations with clear role definitions move quickly. Organisations with large contractor or temp populations need more identity and access evidence.

Existing maturity

Existing evidence and control maturity can reduce preparation work. The final quote depends on the agreed scope and the work actually needed.

Who needs Level 1

Three buyer profiles

L1 is the right tier when the contract specifies a CSMv4 Level 1 Cyber Risk Profile. Three supplier types most often need this engagement.

Defence primes and tier-1 subcontractors

Suppliers bidding on DE&S, DIO, or DSTL contracts where the Cyber Risk Profile specifies Level 1 under CSMv4. The required level is set by the contracting authority, not the supplier’s position in the supply chain.

Technology suppliers to MOD

Software, cloud, managed services and hardware vendors may need L1 when their customer assigns a CSMv4 Level 1 profile. Contract requirements and the full SAQ still apply.

Professional services with sensitive data

Consultancies, legal, accountancy and recruitment firms may need L1 where the buyer assigns a CSMv4 Level 1 profile. The required level follows the customer’s risk assessment, not a generic data-sensitivity rule.

Bundled into the L1 fee

One price, every component included

Some CBs publish a low L1 headline price that excludes consultancy, platform access, and remediation rounds - then add them as line items mid-engagement. Our fee bundles every component so the published range is the all-in price you pay.

Dedicated IASME-licensed consultant
Fig platform access for automated gap analysis
L1 assessment against DEFSTAN 05-138
Three structured remediation rounds
Three-year certificate validity + annual attestation

L1 vs L0

How Level 1 differs from Level 0

L1 is required when the contract specifies CSMv4 Level 1 CRP. L0 covers CSMv4 Level 0 CRP only. The right tier is decided by the contract, not the supplier.

Level 0

Documentation-led review

  • Maps to CSMv4 Level 0 Cyber Risk Profile
  • Flat per-tier pricing (£499.99 - £799.99)
  • 2-3 week typical engagement
  • CE prerequisite, no L1 consultant
  • Assessor review and verification of three controls

Level 1

Consultant + platform engagement

  • Maps to CSMv4 Level 1 Cyber Risk Profile
  • Range pricing (£9,999 - £49,999)
  • 6-10 week typical engagement
  • Dedicated consultant + Fig platform
  • Three remediation rounds before assessment

FAQ

Level 1 questions answered

How do I know I need DCC Level 1 specifically?

For a contract, the MOD customer or prime assigns the required Cyber Risk Profile and Risk Assessment Reference. CSMv4 uses numeric Levels 0 to 3; legacy CSMv3 labels do not map automatically. You can seek certification voluntarily at any level, but confirm the buyer’s requirement before purchasing for a tender.

Why is L1 priced as a range and L0 is flat?

L0 scope is a constrained documentation review, so the fee can be flat. L1 scope complexity varies materially with site count, cloud footprint, legacy systems, supply chain depth, staff population, and existing maturity. Pricing as a range and naming the variance drivers openly is more honest than quoting a single number that bears no relation to the work.

What's included in the L1 fee?

Consultant support for scoping and preparation, Fig Group platform access for gap analysis, the independent L1 assessment, and three remediation rounds before formal assessment are included. A certificate is issued on passing and lasts three years, with annual attestation support. Cyber Essentials is a prerequisite and is arranged separately; annual renewal remains your responsibility.

How long does Level 1 take?

Typically 6-10 weeks for a prepared organisation. The longest variable is remediation - if the platform identifies high or critical findings, the timeline depends on how quickly your team can close them. Three structured remediation rounds are built into the engagement.

Is the consultant really included in the L1 price?

Yes, consultant support is included within the agreed scope. Platform access is included for the three-year certificate period. The scoped Order Form confirms deliverables, annual-attestation support and any extensions; year-three recertification is a separate engagement.

Why bundle consultant and platform rather than sell them separately?

It produces a more honest price comparison. Some CBs publish a low headline L1 fee that excludes consultancy, platform access, and remediation rounds - then add them as line items mid-engagement. Bundling means the price you see is the price you pay, and that price compares apples-to-apples against full-scope quotes.

Ready to start an L1 engagement?

Talk to an IASME-licensed DCC assessor. We confirm your required level from your contract Cyber Risk Profile, scope the engagement, and issue a fixed price within the published tier band - all in one conversation.