Defence Cyber Certification (DCC) Assessment
Defence Cyber Certification for MOD suppliers
Know what your contract requires. Prove your organisation meets it.
If an MOD contract or prime contractor calls for Defence Cyber Certification (DCC), your IT team needs to understand the required level, establish an accurate organisational scope and demonstrate that the controls work. Risk Crew is an assessing Certification Body for DCC Levels 0 and 1. We guide you through the assessment, explain the evidence required and issue your certificate when you meet the standard.
What is Defence Cyber Certification?
Defence Cyber Certification is the Ministry of Defence’s organisation-level scheme for assessing cyber resilience in its supply chain. It is based on Defence Standard 05-138 issue 4 and delivered by IASME. There are four levels, aligned with increasing Cyber Risk Profiles. Your MOD customer or prime contractor can tell you which level applies to the work. Risk Crew assesses Levels 0 and 1.
The MOD has asked its industry partners to achieve at least Level 0 by 31 December 2026. DCC is not yet generally mandatory for every MOD tender; check the terms and timescale of your specific procurement or prime contractor requirement. A certificate can support multiple contracts at or below the certified level, subject to the scheme’s ongoing requirements.
| Level 0 | Level 1 | |
|---|---|---|
| Typical assessed risk | Very low | Low to moderate |
| Controls | 3 | 101 |
| Focus | Cyber Essentials, UK data protection and resilient networks and systems | A comprehensive cyber security programme, including security risk, protection, detection and resilience |
| Assessment | Review of answers and evidence, with live verification | Theoretical assessment of answers and evidence, followed by a practical demonstration of control effectiveness |
What does Risk Crew deliver?
Level 1 theoretical scoring has an 80% pass mark. The practical stage verifies that relevant controls operate as described. Levels 2 and 3 exist but are outside Risk Crew’s DCC assessment service for now.
We discuss your required level, review your proposed organisational scope and check how it aligns with your Cyber Essentials certification.
We explain the applicable controls, assessment questions and evidence expectations. You provide answers and evidence.
At Level 0, we review the three controls and verify them. At Level 1, we score the submission, request clarifications where needed and carry out a remote practical demonstration or an agreed site visit.
You receive an assessment report and a debrief on the outcome and any gaps. Where the standard is met, the certificate is issued through the IASME scheme.
Our assessors can explain what a control asks for and advise on gaps. As the body assessing your submission, we cannot implement your controls, write your policies or prepare the evidence we later assess. If implementation is needed, we can discuss an appropriate separate route that preserves assessment independence.
Get the scope right before you start
DCC assesses the organisation responsible for delivering the work, including the processes and systems it needs to operate securely and resiliently. Scope is broader than a single MOD contract or IT environment. Depending on your organisation, HR, payroll, building access and operational technology may matter too. Any exclusions must be justified.
You need Cyber Essentials or Cyber Essentials Plus covering the relevant scope. If your existing certificate excludes essential parts of the business, address that early; a new or revised Cyber Essentials assessment may be needed. At Levels 0 and 1, Cyber Essentials is the baseline; Cyber Essentials Plus is accepted but is not an additional requirement at those levels.
FAQs
MOD has asked industry partners to reach Level 0 by 31 December 2026, and a particular contract or prime contractor may set its own certification requirement. You can confirm your required level and deadline with the contracting party.
The MOD or your prime contractor sets the applicable Cyber Risk Profile. Ask them to confirm it if the contract documentation is unclear. You can also pursue a level voluntarily.
Yes. Every level starts with Cyber Essentials; Levels 0 and 1 accept Cyber Essentials or Cyber Essentials Plus. The scope of that certification must be addressed alongside the DCC scope.
Usually no. DCC is organisation-level assurance. Your assessment scope must include the business functions, processes and systems necessary for the organisation to function and deliver securely. The assessor reviews the scope, including any proposed exclusions.
Following theoretical scoring, you can clarify answers and submit updated evidence for reassessment within the agreed process. A failed practical demonstration requires a return to the initial theoretical stage after the control is corrected; further assessment is separately scoped and quoted.
Risk Crew cannot implement controls or produce evidence that we will assess as your Certification Body. We can explain findings and discuss independent implementation support where appropriate.
Risk Crew combines governance, risk and compliance expertise with practical assessment experience. We assess DCC Levels 0 and 1 and have delivered Cyber Essentials Plus certification since the scheme’s inception. You receive a clear assessment process, constructive explanations and a useful account of any remaining gaps.
