Logo Transparent
The foundation level of Defence Cyber Certification, designed for suppliers where there is a very low level of assessed cyber risk.

MOD Level 0 Target

Days
Hours

DCC level 0 is the lowest level of the DCC scheme and is normally assigned where there is a very low level of assessed cyber risk to a supplier delivering an output. It requires supplier organisations to demonstrate basic cyber security practices and forms the foundation level for all future assessments higher than level 0. The Ministry of Defence has asked all industry partners to achieve DCC Level 0 by 31 December 2026, including Cyber Essentials for all applicable business-critical systems within scope.

DCC Level 0 Controls

Cyber Essentials

Establishing your baseline​

Cyber Essentials

Your organisation must hold and maintain a current Cyber Essentials certification that appropriately covers all applicable internet-connected systems within the required DCC scope.
Learn More

Data Security

Protecting personal information

Data Security

Your organisation must have documented policies and procedures to demonstrate compliance with UK GDPR.

System Resilience

Keeping critical systems resilient

Network and System Resilience​

Your organisation must assess the resilience its critical systems require and implement appropriate measures, such as backups, recovery, redundancy and business continuity.

DCC Level 0

DCC level 0 is the lowest level of the DCC scheme and is normally assigned where there is a very low level of assessed cyber risk to a supplier delivering an output. It requires supplier organisations to demonstrate basic cyber security practices and forms the foundation level for all future assessments higher than level 0.  DCC Level 0 focuses on three core areas: Cyber Essentials, Data Security, and Network & System Resilience, providing a practical baseline for cyber security, information protection and organisational resilience.

How is DCC Level 0 assessed?

DCC Level 0 is independently assessed by a qualified DCC Assessor. Unlike Cyber Essentials, it is not a self-assessment. Your organisation will need to explain how it meets each of the Level 0 requirements and provide suitable supporting evidence to demonstrate that the controls are in place and operating in practice.

DCC Process

1. Theoretical Assessment

Your Assessor reviews your answers, explanations and supporting evidence to understand how your organisation meets each Level 0 control. Where further information is required, the Assessor may request clarification or additional evidence before progressing to the Practical Assessment.

2. Practical Assessment

Your Assessor reviews your answers, explanations and supporting evidence to understand how your organisation meets each Level 0 control. Where further information is required, the Assessor may request clarification or additional evidence before progressing to the Practical Assessment.

3. Certification

Once the required Level 0 controls have been successfully demonstrated, KEYSIGMA, as an authorised DCC Certification Body, can issue your DCC Level 0 certificate, which is valid for 3 years, subject to annual attestation and continued Cyber Essentials certification.

DCC Scope

Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.

DCC Scope

Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.

Unsure what DCC Level 0 means for your organisation?

Schedule a free 30 minute consultation with a KEYSIGMA Defence Cyber Certification Specialist

Support or Certification

Keeping the Assessment Independent

To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.

To give you flexibility, KEYSIGMA offers two clear routes:

✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.

✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.

Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.

Support or Certification

Keeping the Assessment Independent

To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.

To give you flexibility, KEYSIGMA offers two clear routes:

✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.

✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.

Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.