DCC Level 0 by 31 December: What Your Business Needs to Do

1 minute read

The MOD has asked every defence industry partner to hold Defence Cyber Certification (DCC) Level 0 by 31 December 2026.

If you supply the MOD or a defence prime, at any tier, this applies to you.

What is DCC Level 0?

  • An organisation-wide cyber certification run by IASME for the MOD.
  • The entry level of four. It replaces per-contract cyber assessments.
  • Valid for three years, with a yearly attestation.
  • Just 3 controls, but you must pass all of them.

The three controls

  1. Cyber Essentials. A current certificate that covers your business-critical systems, kept in place for the full three years.
  2. UK GDPR. A documented data protection policy and Data Protection Impact Assessments (DPIAs) for the data you hold.
  3. Resilience. A risk assessment of your essential systems, and real measures to back it up, such as tested backups.

Where businesses fail

  • Scope. Your Cyber Essentials scope must line up with your DCC scope, shown on a diagram. If it does not, you fail outright.
  • Thin answers. “Yes” is not enough. Each answer needs an explanation and evidence that points to the exact proof.
  • Paper over practice. For resilience, policies do not count. The assessor wants to see controls working.

How Baigent’s Information Security Services can help

Baigent’s Information Security Services Ltd gets you assessment-ready, quickly and without the jargon.

  • Readiness check: we tell you where you stand against all three controls.
  • Scoping: we help you define your DCC scope and build the diagram assessors require.
  • Cyber Essentials: we help you achieve or re-scope it to match.

Contact us

Updated: