Cyber Security

DCC Level 0 vs Level 1: Which One Does Your Contract Actually Need?

A thin and a thick stack of documents side by side on an office desk
On this page

Your prime has asked for Defence Cyber Certification Level 0 by the end of December. Somewhere in the same conversation, or in the small print of a tender, Level 1 has been mentioned, and the description of a typical Level 1 supplier sounds uncomfortably like your business.

This article is for the director or operations manager trying to answer a practical question: which level does our contract actually need, and if the answer is both, in what order do we do the work?

If you are new to the scheme, start with our explainer on what Defence Cyber Certification is and what MOD has asked suppliers to do. This article assumes the basics and goes straight to the comparison.

The contract decides, not you

The level is not a choice you make. It is set by the contract.

Every MOD contract that carries cyber security obligations is assigned a Cyber Risk Profile by the contracting authority, and the profile maps to a DCC level. Very low points to Level 0. Low to moderate points to Level 1. Moderate to high points to Level 2, and high points to Level 3. The clause that puts the obligation into your contract is DEFCON 658, and the controls behind it are set out in Def Stan 05-138 Issue 4.

You cannot pick a level, up or down. One rule does work in your favour: under Industry Security Notice 2026/02, a current DCC certificate at or above the required level satisfies the DEFCON 658 control requirement, so a higher level covers every lower one.

The question for your prime is therefore not "Level 0 or Level 1?" but "what Cyber Risk Profile has been assigned to our contract, and which DCC level does it require?" MOD has said as much: "If you are a subcontractor to a Prime, engage with your Prime and discuss what level you should be looking to achieve." Get the answer in writing. It anchors everything that follows.

Level 0 in one paragraph

Level 0 is three controls and six questions, and all three controls have to be fully met. The first is a current Cyber Essentials certificate covering every internet-connected device in your DCC scope, kept current for the three-year certificate period. The second is UK GDPR and data protection: ICO registration, right-sized policies and a Data Protection Impact Assessment process. The third is business resilience: an assessment naming your essential systems and their cyber risks, backed by evidence that the controls actually run, such as tested restore reports. Assessment is a documentation-led review by an IASME-licensed certification body. We have written up the three Level 0 controls, the evidence that passes and the mistakes that fail, so we will not repeat it here.

Level 0 is the December baseline MOD has asked every industry partner to reach. Level 1 is where it goes next.

Level 1: 101 controls across nine areas

Where Level 0 asks whether the basics exist, Level 1 assesses 101 controls drawn from Def Stan 05-138 Issue 4, grouped into nine areas:

  • Access and identity: who can reach what, and how accounts and privileged access are controlled.
  • Incident response and reporting: what happens when something goes wrong, who is told, and whether it has been practised.
  • Secure configuration: whether systems are built and kept to a known standard rather than left at defaults.
  • Patch and vulnerability management: how you learn about weaknesses and how reliably you fix them.
  • Awareness and training: whether your people know what is expected of them and can recognise an attack.
  • Asset management: whether you know what hardware, software, data and services you have, and who owns them.
  • Risk management: whether cyber risk is identified, owned and reviewed as part of running the business.
  • Physical security: how the buildings, rooms and equipment that hold MOD information are protected.
  • Supply chain and third parties: how you assure the suppliers who touch your systems or data, which is the question your prime is asking of you, one tier down.

Notice what has changed. Level 0 asks whether you hold a certificate, a set of policies and evidence of working backups. Level 1 asks how the organisation is actually run, area by area. Several of the nine are management disciplines rather than technical controls, and a firm with well-run IT can still be weak on risk management or supply chain assurance.

The pass rule is different too. Level 0 is all or nothing. Level 1 is scored, and you need at least 80% of the available points within each objective, so every objective has to clear the bar on its own.

Sources disagree on the number of Level 1 questions, so we do not publish one. The control count of 101 is consistent, and it is the honest measure of the work.

How Level 1 is assessed

Level 0 is a review of documents: your evidence pack goes to the certification body and an assessor checks that the three controls are met.

Level 1 adds interviews, demonstrations and a review of operational evidence. The assessor is not checking that a policy exists. They are checking how you actually do it. That means talking to the people responsible for each area, asking them to explain and show the process, and looking at the records the process leaves behind: the ticket that shows the patch was applied, the log that shows the leaver's account was disabled.

Level 1 therefore cannot be passed by a document-writing exercise in the run-up to assessment. If the policy says one thing and the reality is "when someone remembers", the interview will find the gap. Preparing for Level 1 is mostly about making the real operation match a defensible standard and leaving a trail.

At every level the assessment is carried out by an IASME-licensed certification body. There is no self-certification route and no fixed timescale: how long it takes depends on your starting point, the gaps you need to close and assessor availability. Certification-body capacity is expected to tighten towards the end of 2026 as the December Level 0 ask lands.

Who is typically Level 1

Level 1 is typically the level for suppliers with some access to MOD systems or OFFICIAL data. In practice that covers IT support providers, software companies, training providers, consultancies and logistics firms. They do not necessarily make anything, but they touch MOD information in the ordinary course of their work. The risk is not in what they build. It is in what they can see and reach.

If your business fits that description and you have been asked for Level 0 only, the sensible assumption is that Level 1 is coming, and the sensible question to your prime is when. An engineering supplier making parts to a drawing, with no access to MOD systems, may genuinely stay at Level 0. The Cyber Risk Profile of your contract is the answer either way.

MOD's sequencing: Level 0 by December, higher levels after

In May 2026, MOD's Director of Cyber Defence and Risk asked all industry partners to achieve Level 0 by 31 December 2026, including Cyber Essentials for all applicable business-critical systems within scope. In July 2026 the same blog set out how that should flow through the chain: primes should push Level 0 down to their subcontractors and set timescales for them, and "where higher levels of certification are required at lower tiers in the supply chain, these should be scheduled for delivery after 31 December 2026."

Two things follow for a subcontractor who suspects they are a Level 1 business.

First, nobody at MOD is asking you to reach Level 1 before December. The December ask is Level 0, for the whole chain. If a prime has put a Level 1 date on you this year, MOD's published position is a reasonable basis for asking them to look again.

Second, Level 1 at lower tiers is a 2027 conversation, but it is a conversation, not a cancellation. If your contract's profile points to Level 1, the requirement has been sequenced behind Level 0, not removed. Treat December as the first milestone, not the finish line.

Prerequisites: which Cyber Essentials, and when

Both Level 0 and Level 1 require a current Cyber Essentials certificate. Not Cyber Essentials Plus: the standard certificate. Cyber Essentials Plus, with its independent hands-on technical testing, becomes the prerequisite only at Level 2 and Level 3. Do not upgrade to Plus on the assumption that Level 1 needs it; it does not, and it is not a shortcut.

That matters for planning. If you already hold Cyber Essentials covering every internet-connected device in your DCC scope, you have the prerequisite for both levels, and moving from Level 0 to Level 1 does not need a different certificate. If your certificate covers only part of the business, it fails the first Level 0 control and would fail Level 1 for the same reason, so fix the scope first.

One more requirement applies at every level: a named individual responsible for cyber security. In a small business that is usually a director, and the role has to be real, because at Level 1 that person will be answering the assessor's questions.

A realistic order of work for 2026 and 2027

Assume Level 0 by December with Level 1 to follow. This is how we would sequence it.

Now: get the level in writing

Ask your prime for the Cyber Risk Profile assigned to your contract, the DCC level it requires, and when they expect any level above 0 to be in place. Do not build a plan on a guess.

Now: check the Cyber Essentials scope

Confirm that your certificate covers the whole DCC scope: corporate IT, identities, endpoints, connectivity, cloud services and backup. If it does not, re-scope and re-certify. Scope mismatch fails the first Level 0 control outright, and the same prerequisite applies at Level 1.

Before December: complete Level 0 and book early

Data protection evidence, then business resilience evidence, then submission. Do the resilience work honestly: tested restores, not a backup policy. And book the certification body early, because capacity is expected to tighten as the deadline approaches.

From December: build Level 1 into how you run

Once Level 0 is submitted, start the Level 1 gap analysis against the nine areas. Most of the work is operational rather than documentary: making sure patching, account management, asset records, risk reviews and incident processes actually happen and leave evidence. If a managed IT provider already runs your estate, much of this should be happening, and the job is to make it visible.

Through 2027: Level 1 assessment, then keep both current

Level 1 assessment follows when your prime's timescale requires it. Whichever level you hold, the certificate lasts three years with an annual attestation in years one and two, and Cyber Essentials has to be renewed every year throughout.

Where we fit

HGC IT Solutions is a UK-based managed service provider. We help suppliers with Defence Cyber Certification at Level 0 and Level 1: working out which level your contract requires, scoping or re-scoping Cyber Essentials, closing the gaps, building the evidence, and managing the assessment through CyberSmart, the IASME-accredited DCC certification body for Levels 0 and 1. We then keep you current through the annual attestations and the yearly Cyber Essentials renewal.

Two things worth saying plainly. HGC does not issue, assess or certify DCC; your certificate is assessed and issued by the certification body, and we manage that relationship for you. And we cover Levels 0 and 1 only. If your contract's Cyber Risk Profile points to Level 2 or Level 3, we will say so and point you to a specialist defence consultancy.

We hold our own in-date Cyber Essentials certificate, we are a Microsoft Cloud Solution Provider (CSP) partner, and we already support businesses in the defence supply chain. Our team is UK-based and we do not tie clients into long lock-in contracts.

If you have been asked for Level 0 and you think Level 1 is behind it, send us the wording. We will tell you which level it points to, whether December is realistic for Level 0, and what Level 1 would take. And if you would rather the Level 1 evidence came from how your IT is run every day, that is what our managed IT support is for.

Book a DCC readiness call

Related reading

Mastering IT Service Level Agreements

Managed IT

Mastering IT Service Level Agreements

An IT Service Level Agreement (SLA) is essentially a formal contract between an IT service provider and you, the client. It clearly lays out the level of service you can expect, defining everything from measurable performance metrics to the responsibilities of each party. Crucially, it also details

Talk to a real IT team

Plain-English advice from a UK team that picks up the phone. Call 01305 310006 or email [email protected].