Understanding the Defence Cyber Certification (DCC): Levels, Requirements, and Benefits
Four levels, a control count that roughly quadruples between the entry tier and the top one, and a scheme its own administrator confirms is “currently not mandatory.”
How many controls does each DCC level actually require?
Select a level to see its verified control count, prerequisites and what it requires. Each bar's height is scaled to the level with the most controls.
Basic cyber security practices, forming the foundation for all higher levels. Normally assigned where MOD assesses a very low level of cyber risk to a supplier delivering an output.
MOD's Director of Cyber Defence & Risk, Eleanor Fairford, has asked all industry partners to achieve Level 0 by 31 December 2026, including obtaining Cyber Essentials for all applicable business-critical systems within scope. This is a stated MOD ask/target communicated via the Defence Digital blog, not a codified legal or contractual mandate as of this dataset's access date -- DCC as a whole remains, per IASME's own FAQ, 'currently not mandatory'.
Indicative only, not compliance advice. Confirm current requirements directly with IASME or the MoD before relying on any figure here for a live procurement or certification decision.
Four levels, a control count that roughly quadruples between the entry tier and the top one, and a scheme its own administrator confirms is “currently not mandatory.”
A bar chart sits at the top of this piece, plotting the number of controls required at each of the Defence Cyber Certification’s four levels, 0 through 3, against the data set behind this article. It is built to make one thing visible at a glance: the jump in scope is not gradual across the four levels. It happens almost entirely in one step, from Level 0’s 3 controls to Level 1’s 101, after which Levels 2 and 3 add a comparatively modest 38 and then 5 further controls on top.
Key findings
- The control-count figures for all four levels check out exactly against IASME’s own scheme page. Level 0 requires 3 controls, Level 1 requires 101, Level 2 requires 139, and Level 3 requires 144. These are stated as flat, precise counts, not approximations or a “control families” framing, directly on IASME’s Defence Cyber Certification page and repeated verbatim in its FAQ (“Level 0 – 3 controls,” “Level 1 – 101 controls,” “Level 2 – 139 controls,” “Level 3 – 144 controls”).
- The Cyber Essentials/Cyber Essentials Plus prerequisite structure works as follows, with one precision worth adding. IASME states plainly: “All levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus.” So Levels 0 and 1 require standard Cyber Essentials; Levels 2 and 3 require Cyber Essentials Plus. IASME’s FAQ adds a scope nuance worth noting: CE/CE+ only has to cover the internet-connected networks and systems that fall inside an applicant’s DCC scope, not necessarily its entire IT estate, and IASME’s assessor checks that the two scopes line up.
- Annual attestation and three-year full recertification apply, independently confirmed twice, a year apart. IASME’s scheme page states certification is “subject to annual attestation and re-certification every three years.” The Ministry of Defence’s own Defence Digital blog, marking DCC’s first anniversary on 8 May 2026, repeats the identical cadence: “Certification is supported by annual attestation, with full recertification every three years.” Both the scheme administrator and the sponsoring department state the same figures in the same terms.
- DCC’s launch date is 8 May 2025, but the operational rollout was phased and that nuance matters. IASME’s own announcement article, “New Cyber Security Certification Scheme to improve resilience throughout UK Defence supply chain,” is dated 8 May 2025 and announces “creation of the Defence Cyber Certification (DCC).” This is also the date the MOD’s Defence Digital blog treats as the anniversary baseline, publishing its “One Year of Defence Cyber Certification” retrospective on 8 May 2026. However, the scheme was not immediately operational at all four levels on that date: a follow-up IASME article dated 8 July 2025 confirms Level 0 went live for applicants that day, Levels 2 and 3 followed from the end of July 2025, and Level 1 did not open to applicants until the end of August 2025. The scheme’s May 2025 announcement date should not be read as when suppliers could actually begin a given level’s assessment; the later, level-specific dates above are what applied in practice.
- The MOD’s “Level 0 by end of 2026” target is real, and it is a named, dated, quoted ask — not a codified requirement. Eleanor Fairford, Director of Cyber Defence & Risk at the Ministry of Defence, is quoted directly in the MOD’s 8 May 2026 Defence Digital blog post: “I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope.” This is a genuine, attributable, primary-source statement — but it is phrased as something Fairford “asked” industry partners to do, not a rule stated to carry a compliance mechanism or contractual force, and it sits alongside IASME’s own FAQ statement that “DCC is currently not mandatory.”
- The benefits MOD/IASME actually claim are narrower and more specific than generic “resilience and compliance” language. IASME’s FAQ states the concrete benefit in operational terms: “This certificate will cover all of your contracts to the certified level, streamlining the process by requiring only one assessment to cover multiple contracts, rather than conducting separate assessments for each contract.” The 8 May 2025 announcement adds a broader framing — that certification “is a clear demonstration of an organisation’s ongoing commitment to cyber resilience” and supports “the security, resilience, and future prosperity of the UK” — but the FAQ’s own answer to “what is the benefit” is the assessment-consolidation point, not a claim about winning more contracts or a stated procurement advantage. Separately, GOV.UK’s own Cyber Security Model guidance notes a limit worth flagging: holding a valid DCC certificate does not yet exempt a supplier from also completing the MOD’s Supplier Assurance Questionnaire (SAQ) in full.
- “Organisation-wide” is real MOD/IASME framing, but it is not synonymous with “every system, unscoped.” IASME’s FAQ is explicit that DCC “encompasses a much broader scope, addressing overall organisational security and resilience” than Cyber Essentials/Cyber Essentials Plus, which “focuses specifically on internet-connected networks and systems.” That said, applicants still define and document a formal DCC scope: IASME’s FAQ states the scope “should include all essential functions and services necessary for your organisation to operate securely and resiliently,” that “non-essential parts of your organisation do not need to be included,” and that applicants must submit a scoping statement an assessor reviews and can challenge. “Organisation-wide” is best read as a contrast with Cyber Essentials’ narrower internet-facing-systems scope, not as a claim that every DCC applicant certifies literally its entire global operation with no scoping exercise at all.
- Who is in scope: DCC is open to any organisation, and no published MOD document states which specific contracts or supplier tiers will require it. IASME’s FAQ answers “Which contracts require the Defence Cyber Certification?” directly: “This will be decided by the MOD. However, any organisation can apply for certification, whether they are a current defence contractor or not.” The Defence Digital blog echoes this: DCC “is open to any organisation,” which “can apply at any level and at any time, regardless of whether they are currently bidding for, or delivering, defence or public sector contracts.” As of this piece’s access date, that means DCC is available broadly across the supply chain and to prospective suppliers, but which specific contracts, tiers or procurement categories will eventually mandate a given level is stated to be a decision MOD has not yet published in the sources checked for this piece.
What DCC is, and where it comes from
The Defence Cyber Certification (DCC) is a cyber security certification framework for UK defence suppliers, developed jointly by the Ministry of Defence (MOD) and IASME, the MOD’s official cyber certification partner. IASME manages delivery through a network of Assured Certification Bodies. DCC assesses suppliers against Defence Standard 05-138 Issue 4, the technical standard underpinning the MOD’s wider Cyber Security Model (CSMv4), which itself moved in 2025 from a narrower focus on protecting “MOD Identifiable Information” (under the earlier DefStan 05-138 Issue 3 and CSMv3) to the current, broader emphasis on “overall organisational security and resilience.” IASME’s FAQ describes the certification process as “a point-in-time assessment against a UK Defence standard,” with applicants responsible for demonstrating and evidencing their own compliance with the controls at their chosen level.
The four levels and their control counts
DCC is available at four levels, Level 0 through Level 3, each corresponding to the degree of cyber risk MOD associates with a supplier’s role in its supply chain:
- Level 0 — 3 controls. Assigned where MOD assesses a very low level of cyber risk. Requires basic cyber security practices and forms the foundation for all higher levels. Prerequisite: Cyber Essentials.
- Level 1 — 101 controls. Assigned where MOD assesses a low-to-moderate level of cyber risk. Requires “a comprehensive cyber security programme with good practices.” Prerequisite: Cyber Essentials.
- Level 2 — 139 controls. Assigned where MOD assesses a high level of cyber risk. Requires “advanced cyber security oversight and planning which drives robust organisational and cyber practices.” Prerequisite: Cyber Essentials Plus.
- Level 3 — 144 controls. Assigned where MOD assesses a substantial level of cyber risk. Requires “expert cyber security capabilities that fully take advantage of the ‘defence in depth’ methodology.” Prerequisite: Cyber Essentials Plus.
The scale of the jump between levels is worth stating plainly, since it is the entire premise of this piece’s bar-chart widget: going from Level 0 to Level 1 multiplies the control count by roughly 34, while going from Level 1 to Level 2 adds only 38 more controls (a 38% increase), and Level 2 to Level 3 adds just 5 (a 4% increase). Applicants do not have to work sequentially up through the levels to reach a higher one, and IASME’s FAQ confirms certification is not self-assessed at any level — all four require an independent Certification Body assessment.
Cyber Essentials as the baseline, not the whole picture
Every DCC level requires the applicant to already hold, or hold concurrently, either Cyber Essentials or Cyber Essentials Plus: standard Cyber Essentials for Levels 0 and 1, Cyber Essentials Plus for Levels 2 and 3. IASME frames this explicitly as DCC “reinforcing the requirement for appropriate adoption of Cyber Essentials at its core.” But Cyber Essentials and DCC do not share an identical scope. Cyber Essentials/Cyber Essentials Plus is limited to an organisation’s internet-connected networks and systems; DCC’s assessment reaches further, into organisational governance, risk management and resilience practices. IASME’s FAQ requires that any internet-connected devices or networks falling inside an applicant’s DCC scope must also be covered by Cyber Essentials/Cyber Essentials Plus, and its assessors specifically check that the two scopes are consistent with one another, rather than treating Cyber Essentials as an unrelated, separate exercise.
Attestation and recertification
Once certified, a DCC holder does not simply keep the certificate indefinitely without further engagement. Both IASME and the MOD state the same maintenance cadence: an annual attestation, and a full recertification assessment every three years. This detail is confirmed identically in two independent primary sources published a year apart: IASME’s own scheme page, and the MOD’s Defence Digital blog’s first-anniversary retrospective.
Is it mandatory, and who needs which level
DCC is, in IASME’s own words as of this piece’s access date, “currently not mandatory.” Any organisation can apply for any level at any time, whether or not it currently holds an MOD contract — IASME frames this as letting suppliers “demonstrate their commitment to cyber resilience, prepare for future opportunities, and avoid the need for repeated assessments on a contract-by-contract basis.” Which specific contracts will eventually require which level is, per IASME’s FAQ, a decision MOD has not yet published: “This will be decided by the MOD.” The clearest signal of direction of travel found in this research is the MOD’s own stated ask, not yet a rule: Eleanor Fairford, the department’s Director of Cyber Defence & Risk, has asked all industry partners to reach Level 0 by 31 December 2026. Suppliers assessing their own priority should treat that as a genuine, named, dated MOD statement of intent, and treat “mandatory” as not yet accurate.
Sources
- IASME, “Defence Cyber Certification” scheme page (control counts of 3/101/139/144 for Levels 0-3; “all levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus”; “subject to annual attestation and re-certification every three years”). https://iasme.co.uk/defence-cyber-certification/. Accessed 3 August 2026.
- IASME, “Frequently Asked Questions,” Defence Cyber Certification (per-level descriptions and control counts; “Other than Cyber Essentials or Cyber Essentials Plus, there are not” prerequisites; “DCC is currently not mandatory”; “This will be decided by the MOD” on which contracts require it; benefit statement on consolidated assessments; scope definition and scoping-statement requirement; CE/CE+ scope-alignment requirement; origins in DefStan 05-138 Issue 4; no standardised per-level cost). https://iasme.co.uk/defence-cyber-certification/frequently-asked-questions/. Accessed 3 August 2026.
- IASME, “New Cyber Security Certification Scheme to improve resilience throughout UK Defence supply chain,” published 8 May 2025 (original scheme announcement date; MOD/IASME partnership; “reinforces the requirement for appropriate adoption of Cyber Essentials at its core”). https://iasme.co.uk/articles/new-cyber-security-certification-scheme-to-improve-resilience-throughout-uk-defence-supply-chain/. Accessed 3 August 2026.
- IASME, “IASME Launches Defence Cyber Certification (DCC) Scheme for UK Ministry of Defence Suppliers,” published 8 July 2025 (phased operational rollout: Level 0 live 8 July 2025, Levels 2-3 live from end of July 2025, Level 1 live from end of August 2025; per-level control counts and risk descriptions repeated). https://iasme.co.uk/articles/iasme-launches-defence-cyber-certification-dcc-scheme-for-uk-ministry-of-defence-suppliers/. Accessed 3 August 2026.
- Ministry of Defence, Defence Digital blog, “One Year of Defence Cyber Certification: Building Stronger Cyber Resilience Together,” posted by the Defence Cyber Certification Team, 8 May 2026 (first-anniversary framing dating launch to 8 May 2025; annual attestation/three-year recertification cadence restated; “DCC is open to any organisation”; direct quote from Eleanor Fairford, Director of Cyber Defence & Risk, MOD, on the Level 0-by-31-December-2026 ask and its Cyber Essentials component). https://defencedigital.blog.gov.uk/2026/05/08/one-year-of-defence-cyber-certification-building-stronger-cyber-resilience-together/. Accessed 3 August 2026.
- GOV.UK, “Cyber Security Model” guidance (CSMv4’s shift from protecting “MOD Identifiable Information” to “organisational security and resilience”; DefStan 05-138 Issue 4 as the controls standard; DCC as independent evidence of CSM compliance; confirmation that a valid DCC certificate does not yet exempt a supplier from completing the Supplier Assurance Questionnaire in full). https://www.gov.uk/guidance/cyber-security-model. Accessed 3 August 2026.
This is informed journalism, not compliance or legal advice. Defence Cyber Certification is, as of this piece’s access date, a scheme its own administrator (IASME) describes as “currently not mandatory,” and the specific contracts or supplier tiers that will eventually require a given level have not been published in any source checked for this piece. The Ministry of Defence’s Level-0-by-end-2026 figure is a named individual’s stated ask, quoted directly from a Defence Digital blog post, not a confirmed contractual or legal deadline. Any organisation planning certification timelines against live tender requirements should confirm current requirements directly with IASME or the relevant contracting authority before committing budget or resource.

