Cyber Security

DCC Level 0: The Three Controls, the Evidence That Passes, and the Mistakes That Fail

A three-item checklist on a clipboard in a UK engineering workshop
On this page

Level 0 is the entry point to Defence Cyber Certification, and on paper it is the easy one. Three controls. Six questions. A documentation review rather than a technical audit. If you already hold Cyber Essentials, it can look like a formality.

It is not a formality, and the firms it catches are rarely the careless ones. It catches well-run engineering and manufacturing suppliers who hold a Cyber Essentials certificate that does not quite cover the right things, who have a backup system that has never been asked to restore anything, or who registered with the Information Commissioner's Office years ago and never checked it was still live. None of those are signs of a badly run business. All of them fail Level 0.

This article goes through the three controls one at a time: what each asks for, what evidence a certification body will accept, and where suppliers go wrong. If you want the wider picture first, we have covered what Defence Cyber Certification is and what MOD has asked suppliers to do by 31 December 2026 separately. This is the practical view for the person who has to put the evidence together.

Three controls, six questions, all or nothing

Level 0 sits at the bottom of the four-level scheme and corresponds to the very low Cyber Risk Profile in Def Stan 05-138 Issue 4. It has three controls, assessed through six questions.

The pass rule is what makes it sharper than it looks. Level 1 uses a points-based threshold per objective. Level 0 does not. All three controls must be fully met, and there is no partial credit.

Assessment is carried out by an IASME-licensed certification body, not by you. Level 0 is a documentation-led review: you assemble the evidence, the certification body examines it against the three controls, and either every control is met or the certificate is not issued. Interviews and demonstrations arrive at Level 1, and hands-on technical testing at Level 2. Documentation-led does not mean light touch. The documents have to do all the talking, and one that describes an intention rather than proving a practice will be read for exactly what it is.

Control 0001: Cyber Essentials, and the scope trap

The first control is a current Cyber Essentials certificate, plus a commitment to keep it current for the full three-year DCC period.

The certificate has to cover every internet-connected device inside the DCC scope. This is where the trap sits, because the DCC scope is not something you choose. It is the whole organisation's essential functions: corporate IT, user identities, endpoints, connectivity, cloud services, backup and continuity. You cannot carve out the team that does the defence work and certify that on its own. A standalone product, such as a software platform you sell into the supply chain, cannot satisfy the scope by itself either.

Now consider how many engineering firms hold Cyber Essentials. Plenty of suppliers certified a defined subset: the office network, say, with the workshop or a legacy production network left outside the boundary. That was a legitimate Cyber Essentials decision at the time. For DCC it is a problem, because if the certificate's scope is narrower than the DCC scope, Control 0001 is not met, and under the all-or-nothing rule the assessment fails on that alone.

So before anything else, put your Cyber Essentials certificate next to a list of everything in the business that connects to the internet and check that the first covers the second. If it does not, the fix is to re-scope Cyber Essentials, which usually means the segregation and clean-up work that whole-organisation scope always demanded. Our Cyber Essentials service is built around exactly that.

The three-year commitment matters too. Cyber Essentials is renewed annually, so holding DCC means renewing it every year throughout the certificate's life, and the certification body will expect to see that planned for.

Control 2314: UK GDPR and data protection

The second control is about data protection, and for most small suppliers it is the one that gets waved through mentally and then turns out to have gaps.

It asks for three things. First, that you are registered with the Information Commissioner's Office. Second, that you have documented data protection policies. Third, that you can show a Data Protection Impact Assessment process: either a written procedure for when and how you carry one out, or a completed DPIA.

The policies are expected to be proportionate. The scheme simplifies the requirement for micro and small firms, so a twelve-person machining business is not being asked to produce the data protection manual of a bank. A short, honest set of policies describing what personal data you hold, why, where it lives, who can access it and how long you keep it, written so your own staff could follow them, is what an assessor is looking for. A long template downloaded and never read tends to introduce commitments you are not meeting.

Alongside the control, Level 0 expects the organisation to name an individual responsible for cyber security. Whether that is a director, the operations manager or the quality manager is your call. What matters is that a name is written down, rather than a shared understanding that "IT handles that".

Control 2500: Business resilience

The third control is where a well-run firm is most likely to be caught out, and it happens for a specific reason: suppliers answer it with a policy when it is asking for proof.

Control 2500 asks for two things. The first is a documented resilience needs assessment: a written statement of which systems are essential to the business continuing to operate, and what the cyber risks to each of them are. For an engineering supplier that typically means the ERP or MRP system, the CAD and CAM data, email and Microsoft 365, the finance system, and whatever controls or programs the production equipment. The assessment should say what would happen if each one were unavailable or corrupted, and what you have put in place to cope.

The second is evidence that those arrangements actually run. Backup logs showing jobs completing. Reports from restore tests showing that data was recovered from backup and checked. Records of any redundancy you rely on, such as a secondary internet connection or a failover for a critical service. This is the part the control is really about. A backup policy stating that all critical data is backed up nightly and restores are tested regularly is a description of an intention. A log of nightly jobs and a dated report from the last restore test are evidence. The certification body wants the second.

The phrase to hold on to is this: a policy is not evidence. If your backups have never been restored, you do not know whether they work, and neither does the assessor. Run a restore test, document it, keep the report. If that exercise turns out to be harder than it should be, that is worth knowing before a real incident rather than during one. Our managed cloud backup service exists partly so that the logs and tested restores are produced as a by-product of the service running, rather than assembled for an audit.

The mistakes that fail

These are the failure modes to check for before you book anything.

  • A Cyber Essentials certificate whose scope is narrower than the DCC scope. The common version is a subset certificate covering the office and excluding the workshop, or one that predates a move to cloud services. Control 0001 is not met and the assessment fails.
  • Backups that have never been tested. The logs show the jobs ran, but there is no restore report. Control 2500 asks for implementation evidence, and a job log on its own does not prove data can come back.
  • ICO registration that has lapsed or was never done. Check the public register rather than assuming.
  • Nobody named. The business does its security well, but no individual is written down as responsible for it. The scheme asks for a name.
  • Treating a product as the scope. A software or services supplier certifies the platform it delivers to the prime and leaves the corporate estate out. DCC scope is the organisation, not the product, and a standalone product cannot satisfy it.

What the assessment feels like

For a Level 0 assessment you are essentially assembling an evidence pack and submitting it to the certification body for review. In HGC's engagements that body is CyberSmart, which is IASME-accredited to certify Defence Cyber Certification at Levels 0 and 1. HGC prepares, remediates and evidences. CyberSmart assesses and issues the certificate. HGC does neither.

The pack will typically contain the Cyber Essentials certificate and its scope statement, the ICO registration confirmation, the data protection policy set and DPIA procedure, the resilience needs assessment, the backup and restore evidence, and the name of the cyber security owner. The certification body reviews it against the three controls, comes back with questions if anything is unclear, and issues the certificate if everything is met.

There is no fixed timescale for this. How long it takes depends on where your Cyber Essentials stands, how many gaps the readiness review finds, and when the certification body can review it. That last point is worth taking seriously: capacity at certification bodies is expected to tighten in the last quarter of 2026 as more suppliers move towards the December date at once. A firm that starts in September with a scope-matched Cyber Essentials certificate and tested backups is in a very different position from one that starts in November with neither.

After the certificate

Defence Cyber Certification is valid for three years. In years one and two you complete an annual attestation confirming that the controls are still in place. Throughout the three years, Cyber Essentials must be renewed every year, because Control 0001 requires the certificate to be current, not to have been current on the day you certified.

In practice, that makes Level 0 a maintenance commitment rather than a project. The backup logs need to keep accumulating, the restore tests need to keep happening, the ICO registration needs to stay live, and the named individual needs to still own the role. None of that is difficult. It just has to be someone's job.

Cost, without a number

We do not publish prices for this. What we can tell you is how the cost is made up, because it has three parts and only the third is genuinely variable.

  • The assessment fee charged by the certification body for the Level 0 review. IASME does not set this fee; each certification body prices independently.
  • Cyber Essentials, which is a prerequisite and carries its own annual fee, tiered by the size of your organisation. If you already hold a current certificate with the right scope, this is a renewal you would pay anyway.
  • Remediation: whatever it takes to close the gaps between where you are and what the three controls require. For one supplier that is a restore test and an afternoon writing the resilience assessment. For another it is re-scoping Cyber Essentials to bring a production network inside the boundary, which is real work.

We scope all three after a readiness call, once we have seen your current Cyber Essentials scope, your backup arrangements and your data protection position. We would rather give you an accurate picture of the work than a number that turns out to be wrong.

Start with the checklist

If you want to know where you stand before you talk to anyone, the DCC Level 0 readiness checklist walks through the items above in order: Cyber Essentials scope, ICO registration, the policy set, the DPIA procedure, the essential-systems list, the restore test log and the named owner. Work through it honestly and you will know which of the three controls you can evidence today and which you cannot.

When you have that picture, or if you would rather we built it with you, our Defence Cyber Certification support covers the scoping, the remediation, the evidence pack and the assessment through CyberSmart, then keeps you current through the annual attestations and Cyber Essentials renewals. We will tell you honestly on the first call whether December is realistic for your business, and what it will take to get there.

More on Cyber Security

Talk to a real IT team

Plain-English advice from a UK team that picks up the phone. Call 01305 310006 or email [email protected].