September 29, 2026

Cyber Essentials

Defence Cyber Certification Level 0: check your Cyber Essentials scope first

Image to support the article titled: Defence Cyber Certification Level 0: check your Cyber Essentials scope first

The MOD wants every supplier at DCC Level 0 by 31 December. For most, the hold-up won’t be the three Level 0 controls. It will be a Cyber Essentials certificate that covers the wrong systems.

By Jonathan Krause | Founder and Managing Director, Forensic Control | 29 September 2026

The Ministry of Defence (MOD) has asked every company in its supply chain to reach Defence Cyber Certification (DCC) Level 0 by 31 December 2026. It made the request in May and repeated it on its Defence Digital blog on 24 September. Level 0 has only three controls, which makes it sound like a quick job. It often isn’t. You can’t get it without Cyber Essentials, and the Cyber Essentials certificate you already hold may not cover what DCC wants to see.

If you supply the MOD directly, or sit further down the defence supply chain under a prime contractor, you may already have been asked. The request comes from Eleanor Fairford, the MOD’s Director of Cyber Defence and Risk, who wrote in May that she had “recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026”. It is a request rather than a contract clause, and neither blog post says what happens to a supplier who misses the date. I wouldn’t take much comfort from that.

I started my career investigating computer crime at New Scotland Yard, and founded Forensic Control in 2008 to do the same work for businesses. The lesson I took from those years is that most of the incidents I examined were preventable. DCC is built on the same idea: set one basic standard and apply it to everyone in the chain, because the weakest supplier is the easiest way in.

What DCC Level 0 involves

DCC launched in May 2025. It is run for the MOD by IASME, the organisation that also runs Cyber Essentials certification, and assessments are carried out through IASME’s network of certification bodies. There are four levels, from 0 to 3. According to IASME, every level starts with Cyber Essentials, and Levels 2 and 3 need Cyber Essentials Plus, where an assessor tests your systems hands-on rather than relying on your self-assessment. Certification lasts three years, with an annual attestation in between.

Level 0 is the entry point, with three controls. Since March 2026, a DCC certificate at the right level can also count as evidence under Defence Condition (DEFCON) 658, the cyber clause in MOD contracts. I explain how that works in DEFCON 658 and Cyber Essentials for MOD suppliers. If your contracts carry that clause, Level 0 has real contractual weight, although each contract’s risk profile still decides which level it needs.

Why scoping holds suppliers up

The September blog post interviews the founder of one DCC certification body. His main point: “In our experience, scoping is the single biggest challenge for applicants and the most common cause of delays.” He goes on: “Although Level 0 contains only three controls, preparation can take longer than many organisations expect because Cyber Essentials is a prerequisite.”

That doesn’t surprise me. Deciding scope means asking which systems the business actually depends on, and that question pulls in finance, operations and whoever runs IT, not just the person filling in the questionnaire.

The catch is what DCC expects the scope to cover. According to the post, organisations should identify the systems, processes and business functions “essential for the organisation to operate securely and resiliently, not just those directly supporting MOD-related activities”. That can be a much wider test than the one a supplier applied when it first certified.

A Cyber Essentials certificate covers a scope, not an organisation. If you certified only the network or project environment that a particular contract asked about, that was a reasonable decision at the time. It may still fall short of what DCC is looking at. The post advises making sure your Cyber Essentials scope “aligns with the intended DCC scope”. Find the gap in October and it’s a planning problem. Find it in December and you probably won’t close it in time.

Working back from 31 December

Plan this backwards. The DCC Level 0 assessment comes last, and it needs a valid Cyber Essentials certificate covering the right systems. Before that comes the Cyber Essentials assessment and whatever it turns up that needs fixing. Before any of it, you need an agreed scope.

None of these steps has a fixed duration, and I’d be wary of anyone who promises one. IASME says most Cyber Essentials assessors aim to return results within three days, but that varies between certification bodies and assumes the questionnaire arrives complete. Remediation is the hardest part to predict. If the assessment finds unsupported software, or a cloud service without multi-factor authentication (MFA), the fix might need budget, a third party or a change window.

The same certification body founder warns that “organisations that leave preparation until the final months may struggle to secure assessment capacity and complete any remediation work required.” Then there’s Christmas. It falls in the last fortnight of December, when plenty of businesses close or run with fewer staff, so you have less time than the calendar suggests. If I were starting today, I’d want the scope agreed in October, leaving November for the assessments and any fixes.

What to check this week

You can start all of this today without calling a meeting.

First, look up your organisation on IASME’s certificate search and read the scope statement on your current Cyber Essentials certificate. Does it say whole organisation, or does it name a subset of your systems?

Second, check the expiry date against 31 December, and against when you’d expect a DCC assessment to take place.

Third, write down the systems your business can’t run without, such as email, finance, file storage and remote access. Mark which of them your current certificate covers.

If the two lists don’t match, speak to whoever runs your IT, and to your certification body, before you book anything. While you’re at it, find the DEFCON 658 clause and the risk profile in each current MOD contract. The risk profile tells you whether that contract expects Cyber Essentials or Cyber Essentials Plus.

If you’re a prime contractor

Primes face the same date with a longer list, because DEFCON 658 obligations flow down to subcontractors that handle MOD identifiable information. Don’t wait for your subcontractors to raise it. I’d ask each of them now for three things: their Cyber Essentials certificate and its scope, their plan for Level 0, and the name of the person responsible for it. Our guide to running a Cyber Essentials supplier check explains how to verify a certificate and what to record.

If several subcontractors need certifying at once, using one certification body across the chain keeps scope decisions consistent. Tell smaller suppliers why you’re asking, and give them time to check with their IT provider before you agree a date.

Frequently asked questions

What is Defence Cyber Certification Level 0?

Defence Cyber Certification (DCC) Level 0 is the entry level of the Ministry of Defence’s cyber certification scheme for its suppliers. It has three controls and requires Cyber Essentials first. DCC is delivered by IASME through its certification bodies and has four levels, from 0 to 3, with Levels 2 and 3 requiring Cyber Essentials Plus. Certification lasts three years with an annual attestation.

When does the MOD want suppliers to have DCC Level 0?

By 31 December 2026. The MOD’s Director of Cyber Defence and Risk has asked all industry partners to reach Level 0 by that date. The request was published on the MOD’s Defence Digital blog in May 2026 and repeated there in September 2026. It is described as a request rather than a contract condition.

Do I need Cyber Essentials before I can get DCC Level 0?

Yes. Every DCC level starts with Cyber Essentials, so you need a valid Cyber Essentials certificate before a DCC Level 0 assessment. Its scope should line up with the scope intended for DCC, which the MOD’s September 2026 blog post describes as the systems, processes and business functions essential for the organisation to operate securely and resiliently, not only those supporting MOD work.

Will my existing Cyber Essentials certificate be enough for DCC?

It depends on what the certificate covers. A Cyber Essentials certificate applies to a declared scope, which may be the whole organisation or a named part of it, such as one network or project environment. If your certificate was scoped narrowly for a particular contract, it may not match the wider scope DCC expects, and you may need to re-scope and recertify before a DCC assessment.

Does DCC count towards DEFCON 658?

Yes, at the right level. Since March 2026, the MOD has accepted a valid DCC certificate at or above the level a contract’s cyber risk profile requires as evidence under DEFCON 658, the cyber security clause in MOD contracts. Each contract’s risk profile still sets the level needed, so check the profile in every current contract.

How long does it take to get DCC Level 0?

There is no fixed timescale. It depends on how long it takes to agree the scope, whether a current Cyber Essentials certificate already covers it, how much remediation the Cyber Essentials assessment finds and how quickly a DCC certification body can schedule the assessment. Certification bodies have warned that suppliers who leave preparation until the final months before 31 December 2026 may struggle to find assessment capacity.

Ready to take control of your cyber security?

Safeguard your business with our expert cyber security solutions. Whether you require digital forensics, penetration testing or proactive security assessments, our team is ready to assist. Contact us today to discuss your security needs and take the first step towards a more secure future.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.