Skip to content

Defence Cyber Certification (DCC)

How do I know which DCC level I need?

Use the numeric Cyber Risk Profile assigned by the MOD or contracting customer, its Risk Assessment Reference and the current contract version. CSM v4 uses Levels 0 to 3; older Very Low, Low, Moderate and High labels do not convert automatically. If a tender still uses verbal wording or two buyers require different levels, obtain written authority clarification before selecting an assessment scope or package.

Short answer

Use the numeric Cyber Risk Profile assigned by the MOD or contracting customer, its Risk Assessment Reference and the current contract version. CSM v4 uses Levels 0 to 3; older Very Low, Low, Moderate and High labels do not convert automatically. If a tender still uses verbal wording or two buyers require different levels, obtain written authority clarification before selecting an assessment scope or package.

Why this matters

Defence Cyber Certification (DCC) supports MOD supplier assurance at the numeric level required for a specific contract. The contracting authority assigns the Cyber Risk Profile and Risk Assessment Reference; older verbal risk bands do not determine a current level.

Check the authority’s written requirement, the scope of essential organisational services and current Cyber Essentials prerequisite. Level 0 and Level 1 use different assessment evidence. A DCC certificate does not replace the contract-specific Supplier Assurance Questionnaire. Fig Group assesses Levels 0 and 1 through its licensed certification body; a higher level needs a separately authorised body.

What to check next

  • Ask the buyer for the current numeric level, contract version and Risk Assessment Reference.
  • Map existing evidence to that level, record its date and scope, and identify gaps for independent assessment.
  • Check the published Level 0 package or request a written Level 1 scope, price and schedule before purchasing.

Official sources and related Fig Group guidance

Confirm the assigned level with your contracting authority. Use the MOD Cyber Security Model and IASME DCC guidance to check the scheme, then review Fig Group’s DCC package and terms for the service you intend to buy.