Defence Cyber Certification

Defence Cyber Certification Level 0

DCC Level 0 evidences the Def Stan 05-138 controls to the MOD and the primes above you, and it is the level the MOD has asked industry to hold by the end of 2026. As an IASME-assured certification body we would assess you and issue the certificate ourselves.

  • IASME-assured, and listed on the public register of certification bodies
  • We carry out the assessment and issue the certificate ourselves
  • We certify Cyber Essentials as well, which Level 0 requires
Defence Cyber Certification Certification Body, Level 0

Licensed by IASME to assess and certify at Level 0.

  • 3
    controls at Level 0
  • 6
    questions in the submission
  • 3
    years the certificate lasts
  • 100%
    of controls must be met

The four levels

What we would do at each level.

The level is set by the Cyber Risk Profile on your contract rather than chosen by you, and the levels are not the same size, so the first step is usually working out which one you are being asked for.

  • Level 03 controlsWe implement and we assess
  • Level 1101 controlsWe implement, and a licensed body assesses
  • Level 2139 controlsWe implement, and a licensed body assesses
  • Level 3144 controlsWe implement, and a licensed body assesses

Our licence to assess covers Level 0, so at Levels 1, 2 and 3 we would do the implementation work to get the controls in place and the assessment would be carried out by a certification body licensed at that level.

What Level 0 assesses.

There are three, they are the same for every organisation, and all of them have to be fully met, so they are worth reading before you start.

  1. 01

    Cyber Essentials

    A current Cyber Essentials certificate covering the same scope as the DCC assessment, kept in place while the DCC certificate runs. If you do not hold it yet, we can certify that as well.

  2. 02

    UK GDPR compliance

    Your data protection policies and procedures, and the impact assessments behind them, with enough evidence to show that they are used day to day.

  3. 03

    Resilient networks and systems

    A resilience risk assessment and the measures that follow from it, which would cover how your systems keep running, automated backups, and restores that have been tested.

31 Dec
2026

The MOD has asked all industry partners to hold DCC Level 0 by 31 December 2026.

DCC is not mandatory at this stage and IASME states that directly, with the MOD deciding which contracts require it, so the date is an expectation rather than a legal requirement.

However it is already appearing in tenders and primes are increasingly asking their own supply chains for it, and Industry Security Notice 2026/02 instructs MOD buyers to accept a valid DCC certificate as evidence against the Def Stan 05-138 Issue 4 requirement under DEFCON 658, so it affects bids well before the date itself does.

How we would work with you

Where you start depends on whether you hold Cyber Essentials.

Cyber Essentials is the first of the three Level 0 controls, so it has to be in place and correctly scoped before a Level 0 submission can pass.

  • DCC Level 0 assessment

    You already hold Cyber Essentials

    We would assess your Level 0 submission and issue the certificate. The first thing we would check is that your Cyber Essentials scope lines up with the DCC scope, because a mismatch there is the most common reason an application stalls.

  • Cyber Essentials and DCC Level 0 together

    You do not hold Cyber Essentials yet

    We certify Cyber Essentials directly as an IASME certification body, so we would handle both as one piece of work, with Cyber Essentials first and Level 0 following once it is in place.

We do not publish a price list, because cost depends on the size of the organisation and what the scope turns out to cover, so we would quote once we know what we are assessing.

Accredited technology partner
  • Cyber Essentials certified
  • IASME accredited partner
  • Cyber Advisor (Cyber Essentials)
  • NCSC Assured Service Provider for Cyber Advisor (Cyber Essentials)
  • Microsoft Solutions Partner

How the assessment runs.

  1. 01

    Scope

    We would agree what the assessment covers before anything is submitted, and the scope is the whole organisation rather than only the systems used on MOD work.

  2. 02

    Cyber Essentials

    Cyber Essentials has to be in place and scoped to match, and where it is missing or scoped differently this is the point at which it would be sorted.

  3. 03

    Submit

    You answer the six Level 0 questions in the IASME portal and attach the evidence that supports each one.

  4. 04

    Assess

    We mark each answer against the standard and would come back to you where anything is short, and once it passes the certificate is issued.

Common questions.

Osiris is based in Norwich and we assess organisations across Norfolk, the East of England and the rest of the UK, and because the assessment itself runs through the IASME portal your location would not hold it up. You can also see the rest of our cyber security work.

Does Osiris issue the certificate, or hold one?

We issue them. IASME licenses us as a Defence Cyber Certification Body at Level 0, which means we carry out the assessment and the certificate is then issued to your organisation rather than to us, and our listing sits on the IASME register of certification bodies if you would like to check it before getting in touch.

What if our contract requires Level 1, 2 or 3?

We would still be able to help, just in a different role. Certification bodies are licensed level by level and our licence to assess covers Level 0, so at Levels 1, 2 and 3 we would carry out the implementation and readiness work to get the controls in place, and the assessment itself would be done by a certification body licensed at that level.

Is DCC mandatory?

Not at present, and IASME states that directly, with the MOD deciding which contracts require it. In practice it reaches most organisations through tendering and through the primes above them rather than through law.

Do we still complete the Supplier Assurance Questionnaire?

Yes. As of the March 2026 Cyber Security Model guidance, holding DCC does not exempt you from completing the full Supplier Assurance Questionnaire in the Supplier Cyber Protection Service, although DCC uses the same question set, so the evidence gathered for one would cover the other.

Is Level 0 a self-assessment?

No level of DCC is self-assessed, including Level 0, which is a submission in the IASME portal that a certification body marks question by question, and all three controls have to be fully met because there is no partial credit at this level.

Does the assessment cover our MOD work, or the whole organisation?

The whole organisation. Def Stan 05-138 Issue 4 moved the focus away from protecting specific information and towards the security and resilience of the organisation as a whole, which means the assessment cannot be scoped down to the systems that happen to touch the MOD contract, and scoping is where most applicants come unstuck.

The next step would be to confirm your scope.

Tell us who has asked you for DCC and what you already have in place, and we would confirm the scope, identify anything missing on the Cyber Essentials side, and send you a price for the assessment.