Cookie Consent by Free Privacy Policy Generator

Defence Cyber Certification (DCC) Level 0 & Level 1

Strengthen your cyber resilience. Demonstrate your readiness for the UK defence supply chain.

Tell us your current cyber challenges

What is Defence Cyber Certification?

Defence Cyber Certification (DCC) is a cyber security certification framework designed for organisations operating within, or looking to work within, the UK defence supply chain.

Developed by the UK Ministry of Defence (MOD) and IASME, DCC provides organisation-level assurance against the cyber security requirements set out within Defence Standard 05-138.

Rather than assessing security against individual contracts, DCC looks at the security and resilience of your organisation and provides a certification that can support multiple UK Defence procurements at the certified level.

Secarma supports organisations through Defence Cyber Certification Level 0 and Level 1, helping you understand your scope, prepare the required evidence and complete your assessment with a qualified DCC Assessor.

3
Controls at DCC Level 0
101
Controls at DCC Level 1
3 Years
DCC certification period
Why is Defence Cyber Certification Important?

The MOD relies on a broad supply chain of organisations providing the products, services and technology needed to support UK Defence. Defence Cyber Certification provides a consistent way for those organisations to demonstrate that appropriate cyber security and resilience measures are in place.

Unlike an assessment tied to an individual contract, DCC provides organisation-level assurance that can be used in support of multiple UK Defence procurements at the certified level. For organisations already working within the defence supply chain - or preparing to pursue future opportunities - certification provides a clear way to demonstrate cyber resilience and readiness.

Which Defence Cyber Certification Level Do I Need?

Defence Cyber Certification has four levels, with the required level reflecting the cyber risk associated with an organisation's role within the UK Defence supply chain.

Secarma currently provides DCC Level 0 and Level 1 certification assessments.

DCC Level 0

Designed for organisations presenting a very low level of assessed cyber risk. Level 0 covers 3 controls and focuses on fundamental cyber security, data protection and organisational resilience.

DCC Level 1

Designed for organisations presenting a low to moderate level of assessed cyber risk. Level 1 expands to 101 controls and assesses the organisation's wider cyber security programme, including governance, technical security, monitoring, incident response and resilience.

Where DCC is required for a defence contract, the level you need will normally be determined by the MOD or your Prime contractor. You do not need to complete Level 0 before applying for Level 1.

Which Defence Cyber Certification Level Do I Need?
What Do We Assess at DCC Level 0?
What Do We Assess at DCC Level 0?

Cyber Essentials

Confirming that your organisation holds the required Cyber Essentials certification and that its scope appropriately aligns with your DCC assessment.

Data Protection

Reviewing how your organisation manages its data protection responsibilities and demonstrates that appropriate policies and practices are in place.

Organisational Resilience

Assessing how critical systems and services are protected so your organisation can continue to operate securely and resiliently.

What Do We Assess at DCC Level 1?

Governance & Risk

How cyber security is governed across your organisation, including responsibilities, risk management, assets and supply chain security.

People, Identity & Access

How users are authenticated, access is controlled, privileges are managed and employees understand their security responsibilities.

Systems, Data & Networks

How your devices, systems, networks and data are protected through secure configuration, vulnerability management and appropriate technical controls.

Monitoring & Detection

How security events are logged, monitored and investigated so potential cyber incidents can be identified and acted upon.

Incident Response & Resilience

How your organisation prepares for, responds to and recovers from cyber security incidents and disruption.

What Do We Assess at DCC Level 1?
How Does DCC Certification Work?
How Does DCC Certification Work?

1. Confirm Your Level & Scope

We'll confirm the DCC level you're working towards and review the scope of your assessment to ensure the right parts of your organisation are included.

2. Prepare Your Submission

You'll work through the requirements for your certification level, explaining how your organisation meets each control and preparing the supporting evidence.

3. Assessment & Verification

Your DCC Assessor reviews your submission and supporting evidence. Where required, controls are practically verified to confirm that they are implemented and operating effectively.

4. Certification

Once the requirements have been successfully met, your organisation receives its Defence Cyber Certification at the achieved level.

Certification is valid for three years, subject to the applicable annual requirements and maintaining the required Cyber Essentials certification.

Already Have Cyber Essentials?

You're already one step ahead.

Cyber Essentials certification is a prerequisite for both DCC Level 0 and Level 1.

If your organisation doesn't currently hold Cyber Essentials, Secarma can support you through certification before beginning your DCC journey.

Need Cyber Essentials too?

Speak to our team about completing both your Cyber Essentials and Defence Cyber Certification journey with Secarma.

Already Have Cyber Essentials?
How Secarma Delivers Value
Experienced Certification Specialists
Our certification team works with organisations across a wide range of industries, helping translate complex security standards into clear, manageable assessment journeys.
Qualified DCC Assessors
Your assessment is completed by trained Defence Cyber Certification professionals who understand both the scheme requirements and the practical challenges organisations face when demonstrating compliance.
Clear Scoping From the Start
DCC applies more broadly than simply the systems handling an individual MOD contract. We help ensure your assessment scope is clearly understood at the beginning of the process, reducing the risk of issues later in the assessment.
Straightforward, No-Jargon Approach
Certification shouldn't require you to decode technical language. We explain what is required, what evidence your Assessor needs to see and what happens next in clear, practical terms.
Cyber Essentials and DCC Under One Roof
As Cyber Essentials is a prerequisite for DCC Level 0 and Level 1, working with Secarma means you can manage both certification requirements through one security partner.
Support Beyond Certification
Where an assessment identifies wider security improvements your organisation should consider, Secarma's broader Advise, Certify and Test capabilities mean we can help you understand the next steps and build a stronger long-term security posture.
Resources
Stay up to date with expert-written blogs, security labs, downloadable guides and more, all designed to support your journey.
Secarma Threat Intelligence Report | August 2026
Secarma Threat Intelligence Report | July 2026
1
2
3
4
5
6
Get in touch
See how we’ve helped hundreds of businesses to improve their cyber security and regain their calm.

Alternatively, you can call us on 0161 513 0960

News and blog posts
The National Cyber Security Centre has published new guidance recommending that...
UK charity CRM provider Beacon has confirmed that a compromised AWS access key...
Security researchers have identified a global exploitation campaign targeting...
The North Korean threat actor known as Lazarus Group has been linked to the...
Cyber Essentials Certification Body Cyber Essentials Plus ISO 9001 ISO 27001 CREST IoTSF IASME Cyber Assurance NCSC Assured Service Provider IoT Cyber Scheme