Skip to content

Cyber Essentials glossary

DCC Level 1

Defence Cyber Certification against current numeric Level 1 requirements, with broader assurance than Level 0. Confirm the applicable Cyber Essentials prerequisite, scope and evidence with the certification body. It is not simply a renaming of the legacy Low risk band. Fig Group offers Level 1 assessment; contract-specific SAQ responsibilities continue.

Why this term matters for defence suppliers

The MOD buyer assigns a numeric Cyber Risk Profile and contract-specific assurance requirements. Check the current contract version and Risk Assessment Reference before choosing a Defence Cyber Certification level. Legacy verbal risk bands do not determine a current numeric level.

A supplier asked for Level 1 should confirm the written requirement, map the essential organisational services and current Cyber Essentials prerequisite, then plan the appropriate independent assessment. A DCC certificate does not replace the contract-specific Supplier Assurance Questionnaire.

How Fig Group uses this term

Fig Group uses DCC Level 1 as part of a practical Cyber Essentials and compliance vocabulary. The purpose is to make assessment decisions easier to verify: what the term means, where it appears in evidence, which control it supports, and which buyer or assessor question it helps answer.

If this term affects your DCC assessment, treat it as an evidence question rather than a definition question. Document the relevant owner, system, configuration, policy, or workflow so an assessor can see how the control works in your environment.

Official sources and related guidance

For scheme interpretation, verify against official MOD and IASME material. Fig Group's glossary is designed to translate those concepts into implementation language for UK organisations, MSPs, and procurement teams.