Skip to main content
Home/ Defence Cyber Certification
Defence Cyber Certification

Defence Cyber Certification for the UK defence supply chain

A clear route through DCC Level 0 and Level 1, from understanding the requirement and defining scope through readiness, evidence and independent assessment.

Discuss your DCC requirements

Understand the requirement. Define the scope.

Defence Cyber Certification provides a structured way to demonstrate cyber resilience in the UK defence supply chain. Start by confirming the level required in your commercial context, then define the organisational boundary, dependencies and evidence needed for assessment.

DCC Level 0

Prepare for independent assessment of 3 controls at Level 0. Cyber Essentials certification is a prerequisite.

Explore Level 0 →

DCC Level 1

Prepare for independent assessment of 101 controls at Level 1. Cyber Essentials certification is a prerequisite.

Explore Level 1 →

Scheme reference: IASME DCC FAQs

Scope and evidence deserve early attention.

For SMEs and specialist suppliers

Bring together the people who own your systems, policies and supplier relationships. Identify where responsibilities sit and where you need practical support.

For large organisations

Clarify the entity boundary, shared services, distributed operations and evidence ownership before beginning a large assessment programme.

Your DCC preparation route.

  • Confirm your required level and commercial context.
  • Agree organisational scope and relevant dependencies.
  • Review the applicant guidance and allocate evidence owners.
  • Identify gaps and plan any remediation.
  • Prepare for assessment and ongoing assurance.
Explore DCC readiness →

Choose the route that matches where you are now

Some organisations arrive with a defined DCC level and assessment target. Others first need to understand scope, evidence ownership and readiness. Choose the route that reflects your current position.

DCC Level 0

For organisations that have been asked to meet Level 0 and need to understand the foundation-level requirement, scope and assessment route.

Go to Level 0 →

DCC Level 1

For organisations preparing for the broader evidence-led assurance expected at Level 1, with more coordination across controls and stakeholders.

Go to Level 1 →

Not assessment-ready yet?

Start with readiness if scope is unclear or evidence is fragmented. Where MDLabs acts as your DCC assessor, we can identify gaps and clarify requirements, but cannot implement or manage your security defences. Readiness support does not guarantee certification.

Explore DCC readiness →

DCC questions

How does Cyber Essentials relate to DCC?

Cyber Essentials is a prerequisite at Levels 0 and 1 and must be renewed annually. Discuss scope alignment with your assessor. DCC requires annual attestation and recertification every three years.

How much does DCC cost?

Pricing depends on scope, level, readiness and assessment effort. We provide an engagement-specific proposal after discussing these factors.

How long does DCC certification take?

There is no universal timeline. Readiness, remediation and assessor availability affect the assessment plan.

Is our defence contract the only part of the business in scope?

Do not assume so. Scoping considers the organisation and the systems and services needed for its secure and resilient operation.

Can existing evidence help?

Bring relevant policies, assurance work and technical records to the scoping conversation. The assessor will determine how evidence supports the DCC controls.

Scheme reference: IASME applicant, scope and process guidance

Talk to a DCC assessor

Tell us the DCC level you have been asked to meet, what part of the organisation may be in scope and your target timeframe. We can help establish the right next step.

Discuss your requirements →