The Ministry of Defence has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, including a requirement to maintain Cyber Essentials for all applicable business-critical systems within scope.
For many suppliers – particularly micro and small organisations – cyber requirements can appear to assume dedicated compliance and security functions, when in reality, responsibilities often sit with a small number of individuals.
Level 0 is a practical and achievable starting point that enables organisations of any size to demonstrate a recognised minimum baseline of cyber security, meet Defence expectations, and build towards higher levels of assurance over time.
Whether you are already operating within the defence supply chain or preparing to enter it, Level 0 is the most straightforward place to start – and it provides a strong foundation for what comes next.
What are the DCC levels?
DCC is an organisation-wide cyber security certification developed in partnership with UK Defence. It provides trusted assurance of a supplier’s cyber resilience and helps strengthen security across the defence supply chain.
The certification scheme is structured across four levels (0–3), with the required level determined by an organisation’s assessed cyber risk profile and the sensitivity of the work it supports. This tiered approach gives the MOD a consistent way to apply the right depth of assurance across a diverse supplier base—and it helps ensure suppliers are trusted to deliver the type of Defence work that matches the level of cyber resilience they can evidence.
Level 0 is the entry level. It’s designed for organisations with a basic assessed cyber risk profile and focuses on three key control areas drawn from Def Stan 05-138 (Issue 4). It’s also built on a baseline that is already widely understood and adopted in the UK: Cyber Essentials.
In short, Level 0 is about two things:
-
Proving you’ve got the baseline technical hygiene in place (via Cyber Essentials) for the business-critical systems in scope.
- Demonstrating that the organisation can look after data and recover from disruption, which is what buyers care about when they’re assessing real-world resilience.
Level 0 is achievable – even for micro organisations
Level 0 is achievable because it is deliberately bounded. It doesn’t ask you to implement hundreds of controls or build an enterprise security programme overnight. Instead, it focuses on a small number of high-impact requirements and expects evidence at a level that scales with your organisation’s size and complexity.
- Cyber Essentials does a lot of the heavy lifting
Cyber Essentials is a prerequisite for Level 0. For many organisations, getting Cyber Essentials in place is ‘most of the journey’, because it drives sensible, practical steps that reduce common attack paths: patching, secure configuration, access control, malware protection, and firewalls.
Crucially, Cyber Essentials is well-trodden ground in the UK. There is a mature ecosystem of support, guidance, and experienced Assessors, which reduces uncertainty and helps organisations move quickly.
- At Level 0, the requirements are clearly defined and limited in number
Level 0 is assessed against three controls:
- Cyber Essentials(including ensuring your CE scope aligns with your DCC scope and maintaining CE across the DCC certificate period)
- UK GDPR compliance(policies/procedures and DPIA evidence appropriate to your organisation)
- Resilient networks and systems(practical measures across the lifestyle of your systems to withstand cyber attacks or failures and recover quickly)
These three requirements map to what most organisations already need to be doing.
- Evidence expectations scale by size
A micro organisation doesn’t need a 40-page policy suite to be effective. What Assessors are looking for is that you’ve thought about what you do, you’ve documented the basics, and you can show that key resilience measures are real (for example, tested restores – not just a policy that says you do backups).
That’s an important principle: at Level 0, good security is more about clarity and consistency than volume.
Level 0 teaches the skill that unlocks Levels 1–3: scoping
One of the strongest reasons to start with Level 0 is that it forces a discipline that becomes essential later: getting scope right.
Scope is the boundary that tells everyone (including you) which systems, people, and processes are being assured. It is also where organisations most commonly stumble.
At Level 0, scoping has a very practical consequence: your Cyber Essentials scope needs to adequately align with your DCC scope, and Assessors will look closely at how the two relate. They won’t always be identical—Cyber Essentials focuses on internet-connected systems, while a DCC scope may also include non-internet-connected (including air‑gapped) elements. Equally, your Cyber Essentials scope may include internet-connected systems that aren’t business-critical and therefore sit outside the DCC scope.
Getting that relationship clear is essential. It can feel fiddly, but it forces you to define your business-critical systems and be precise about what is included, what is excluded, and why.
Once you have understood and documented your scope and you’ve proven you can maintain it through annual cycles, you’ve built a core operational capability that supports progression:
- You can identify which assets and services matter most.
- You can evidence controls against those assets.
- You can manage change without accidentally breaking compliance.
That capability becomes increasingly important as you move through the higher DCC levels.
A nationwide network of Certification Bodies
Another reason Level 0 is achievable is that you don’t have to interpret everything alone.
DCC is delivered through IASME’s nationwide network of assured Certification Bodies, built to provide consistent, high-quality assessment and broad accessibility across the UK. Over the first year of the scheme, that delivery community has grown quickly, with Assessors qualified to deliver all certification levels.
For suppliers – especially micro and small organisations – it means:
- You can find support locally.
- You can ask questions early and reduce the risk of misinterpretation.
- You can plan timelines realistically – particularly important as the December 2026 deadline approaches.
A good Certification Body won’t just assess you – they’ll help you understand what ‘good evidence’ looks like and steer clear of common pitfalls.
Level 0 – a thorough foundation for higher levels
Rather than a ‘minimum’ level of cyber security, for many organisations, L0 is a valuable and effective springboard into a stronger security posture.
- It builds a repeatable compliance rhythm
DCC is supported by annual attestation, with full recertification every three years. Level 0 gets you into that cycle early: renew Cyber Essentials annually, keep scope aligned, and confirm controls remain in place. That rhythm is what prevents cyber security from becoming a one-off project that quietly decays.
- It shifts security from ‘IT tasks’ to organisational resilience
Level 0 brings governance and resilience into the conversation—data protection responsibilities, DPIA thinking, and practical recovery evidence. That helps small organisations build habits that scale: ownership, documentation, and tested recovery.
- It creates a clear, authoritative benchmark
As organisations progress, they benefit from having an independently validated standard that is consistent and recognised in the defence context. Even at Level 0, you reduce the need to answer bespoke questionnaires repeatedly because you have a recognised baseline.
- It’s a learning opportunity that de-risks later assessments
Level 0 gives you the chance to learn the scheme’s language, evidence style, and scoping expectations while the control set is still compact.
Start now
One practical takeaway is this: don’t leave Level 0 to the end of the year.Even when requirements are straightforward, certification takes time—especially if you need to gather evidence, tighten scope, or test restore processes properly.
Starting earlier also helps with the supply chain reality: primes often need confidence in their suppliers’ security posture and may set earlier internal deadlines to manage their own risk.
What to do next
Find a DCC Certification Body (CB)
Start your certification by reading the DCC Process Guide and finding a DCC Certification Body.
