Short answer
The published DCC package includes annual attestation support for Years 1 and 2. Year-three reassessment is separate. Underlying Cyber Essentials needs annual renewal, and additional work outside the accepted scope may be chargeable under your Order Form. Existing signed terms continue to apply.
Why this matters
Defence Cyber Certification (DCC) supports MOD supplier assurance at the numeric level required for a specific contract. The contracting authority assigns the Cyber Risk Profile and Risk Assessment Reference; older verbal risk bands do not determine a current level.
Check the authority’s written requirement, the scope of essential organisational services and current Cyber Essentials prerequisite. Level 0 and Level 1 use different assessment evidence. A DCC certificate does not replace the contract-specific Supplier Assurance Questionnaire. Fig Group assesses Levels 0 and 1 through its licensed certification body; a higher level needs a separately authorised body.
What to check next
- Ask the buyer for the current numeric level, contract version and Risk Assessment Reference.
- Map existing evidence to that level, record its date and scope, and identify gaps for independent assessment.
- Check the published Level 0 package or request a written Level 1 scope, price and schedule before purchasing.
Official sources and related Fig Group guidance
Confirm the assigned level with your contracting authority. Use the MOD Cyber Security Model and IASME DCC guidance to check the scheme, then review Fig Group’s DCC package and terms for the service you intend to buy.