The foundation level of Defence Cyber Certification, designed for suppliers where there is a very low level of assessed cyber risk.
MOD Level 0 Target
DCC level 0 is the lowest level of the DCC scheme and is normally assigned where there is a very low level of assessed cyber risk to a supplier delivering an output. It requires supplier organisations to demonstrate basic cyber security practices and forms the foundation level for all future assessments higher than level 0. The Ministry of Defence has asked all industry partners to achieve DCC Level 0 by 31 December 2026, including Cyber Essentials for all applicable business-critical systems within scope.
DCC Level 0 Controls
Cyber Essentials
Establishing your baseline
Cyber Essentials
Data Security
Protecting personal information
Data Security
System Resilience
Keeping critical systems resilient
Network and System Resilience
DCC Level 0
DCC level 0 is the lowest level of the DCC scheme and is normally assigned where there is a very low level of assessed cyber risk to a supplier delivering an output. It requires supplier organisations to demonstrate basic cyber security practices and forms the foundation level for all future assessments higher than level 0. DCC Level 0 focuses on three core areas: Cyber Essentials, Data Security, and Network & System Resilience, providing a practical baseline for cyber security, information protection and organisational resilience.
How is DCC Level 0 assessed?
DCC Level 0 is independently assessed by a qualified DCC Assessor. Unlike Cyber Essentials, it is not a self-assessment. Your organisation will need to explain how it meets each of the Level 0 requirements and provide suitable supporting evidence to demonstrate that the controls are in place and operating in practice.
1. Theoretical Assessment
Your Assessor reviews your answers, explanations and supporting evidence to understand how your organisation meets each Level 0 control. Where further information is required, the Assessor may request clarification or additional evidence before progressing to the Practical Assessment.
2. Practical Assessment
Your Assessor reviews your answers, explanations and supporting evidence to understand how your organisation meets each Level 0 control. Where further information is required, the Assessor may request clarification or additional evidence before progressing to the Practical Assessment.
3. Certification
Once the required Level 0 controls have been successfully demonstrated, KEYSIGMA, as an authorised DCC Certification Body, can issue your DCC Level 0 certificate, which is valid for 3 years, subject to annual attestation and continued Cyber Essentials certification.
DCC Scope
Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.
DCC Scope
Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.
Unsure what DCC Level 0 means for your organisation?
Schedule a free 30 minute consultation with a KEYSIGMA Defence Cyber Certification Specialist
Support or Certification
Keeping the Assessment Independent
To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.
To give you flexibility, KEYSIGMA offers two clear routes:
✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.
✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.
Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.
Support or Certification
Keeping the Assessment Independent
To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.
To give you flexibility, KEYSIGMA offers two clear routes:
✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.
✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.
Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.