DCC Level 1: coordinate controls, evidence and assessment
For defence suppliers preparing for DCC Level 1, which covers 101 controls across technical, organisational and supplier responsibilities. Cyber Essentials certification is a prerequisite.
Discuss DCC Level 1Level 1 depends on coordinated evidence, not isolated documents
Preparation should connect each requirement to how the control operates in practice, who owns it and what evidence supports it. For complex organisations this often means coordinating security, IT, governance, procurement and supplier inputs before assessment.
Build your assessment plan
- Define the organisation and dependencies in scope.
- Allocate owners for controls and evidence.
- Coordinate technical, governance and supplier inputs.
Prepare useful evidence
- Use the current Level 1 applicant guidance and Assessment Submission Record.
- Connect each answer to evidence of implementation.
- Review inconsistencies and gaps before the assessment.
Scheme reference: IASME DCC applicant resources
Scale the readiness model to the organisation
Independent assessment verifies how your organisation implements the controls. Evidence coordination should reflect the actual scope, with no assumed certification outcome. DCC certification runs on a three-year cycle with annual attestation; Cyber Essentials must be renewed annually.
Explore DCC readiness →Discuss your Level 1 requirements
Tell us the Level 1 requirement, proposed organisational boundary, current certification position and target timeframe. We can help establish the appropriate assessment route.