Short answer
The published Level 1 offer includes scoped platform support for evidence mapping and annual attestations. Confirm the actual access duration, included integrations and functionality, support, post-certification charges and any separate consultancy retainer in a written Order Form. Evidence mapping alone does not prove an unconditional three-year platform entitlement. Year 3 reassessment is separately purchased.
Why this matters
Defence Cyber Certification (DCC) supports MOD supplier assurance at the numeric level required for a specific contract. The contracting authority assigns the Cyber Risk Profile and Risk Assessment Reference; older verbal risk bands do not determine a current level.
Check the authority’s written requirement, the scope of essential organisational services and current Cyber Essentials prerequisite. Level 0 and Level 1 use different assessment evidence. A DCC certificate does not replace the contract-specific Supplier Assurance Questionnaire. Fig Group assesses Levels 0 and 1 through its licensed certification body; a higher level needs a separately authorised body.
What to check next
- Ask the buyer for the current numeric level, contract version and Risk Assessment Reference.
- Map existing evidence to that level, record its date and scope, and identify gaps for independent assessment.
- Check the published Level 0 package or request a written Level 1 scope, price and schedule before purchasing.
Official sources and related Fig Group guidance
Confirm the assigned level with your contracting authority. Use the MOD Cyber Security Model and IASME DCC guidance to check the scheme, then review Fig Group’s DCC package and terms for the service you intend to buy.