This is one of the most common questions from UK defence suppliers, and the honest answer is that it is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification. You do not pick one. You hold Cyber Essentials in order to be assessed for DCC at all.
The question is entirely reasonable. Both schemes are run by IASME, both are UK government backed, both arrive in procurement documents, and nobody explains the relationship in the covering email. Here is the relationship.
What IASME actually states
From IASME's own DCC scheme pages, read on 1 September 2026:
"All levels start with Cyber Essentials certification, with Levels 2 and 3 requiring Cyber Essentials Plus."
And on prerequisites:
"Other than Cyber Essentials or Cyber Essentials Plus, there are not."
So the dependency runs one way and it is absolute. Level 0 and Level 1 need Cyber Essentials. Levels 2 and 3 need Cyber Essentials Plus.
They are not measuring the same thing
Once you stop treating them as alternatives, the more useful question is what each one actually looks at, because the scopes are genuinely different and this catches people out at assessment.
| Cyber Essentials | Defence Cyber Certification | |
|---|---|---|
| Owner | IASME, on behalf of NCSC | The Ministry of Defence, managed by IASME |
| Assessed against | The five technical controls | DefStan 05-138 Issue 4 |
| Scope | Internet-connected networks and systems | The whole organisation, and the functions essential for it to operate |
| Levels | One, plus the audited Plus variant | Four: Level 0, 1, 2 and 3 |
| Self-assessment | Cyber Essentials is a self-assessed questionnaire, verified | None. No DCC level is self-assessment |
| Renewal | Annually | Recertify every three years, with an annual attestation |
| Sector | Any organisation | UK defence supply chain, though anyone may apply |
The scope difference is the one that costs time. Cyber Essentials looks at internet-connected devices and systems. DCC looks at your whole organisation and everything essential to it operating securely and resiliently, which pulls in operational technology, cloud services essential to your business, and the policies by which you manage your own suppliers.
IASME are explicit that the two scopes have to be reconciled rather than assumed to match: any internet-connected device or network inside your DCC scope must be covered by your Cyber Essentials or Cyber Essentials Plus certification, and the DCC assessor reviews both scopes to check they align.
The four levels, and where Cyber Essentials Plus starts to bite
Each level corresponds to the degree of cyber risk associated with a supplier's role in the MOD supply chain, and the control counts are published:
- Level 0, 3 controls. Very low assessed risk. Basic practices, and the foundation for everything above it.
- Level 1, 101 controls. Low to moderate assessed risk. A comprehensive programme with good practices.
- Level 2, 139 controls. High assessed risk. Advanced oversight and planning. Cyber Essentials Plus required.
- Level 3, 144 controls. Substantial assessed risk. Expert capability using defence in depth. Cyber Essentials Plus required.
The jump from Cyber Essentials to Cyber Essentials Plus is not paperwork. Plus is technically audited by an assessor rather than self-assessed and verified, so if a Level 2 requirement is heading your way, that audit is on the critical path and it is often the longest lead item.
The four levels are set out in more detail here, and what Level 2 adds over Level 1 has its own article, because the answer is not the thirty eight extra controls people expect.
Does holding Cyber Essentials get you any of the DCC controls?
Some evidence, yes. Compliance, no.
IASME's position is direct: you can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls. So Cyber Essentials will furnish evidence for parts of a DCC submission. It will not discharge them, and no other certificate does either.
Is any of this mandatory?
No, and it is worth being precise about this, because the market is not.
IASME's own FAQ states plainly that DCC is currently not mandatory, and separately that applicants may still tender for MOD contracts via the normal MOD process. Which contracts will require it is a matter for the MOD, and the level you need is decided by the MOD or by your prime rather than by you.
Nobody is legally required to hold DCC. The belief that they are is an easy one to arrive at, because the MOD has asked industry to move and a request from your largest customer feels a great deal like an obligation. It is still worth separating the two, because a supplier who buys on the belief that it is compulsory has bought it for the wrong reason, even if they turn out to need it later for the right one.
What to do, in order
- Get Cyber Essentials if you do not hold it. It is the gate to everything else and it is the cheapest thing on this list.
- Ask your prime or contracting authority which DCC level applies to you. They decide it, and the answer changes what you need to do next by a very large margin.
- If the answer is Level 2 or 3, start Cyber Essentials Plus now, because it is audited and it is a prerequisite.
- Scope before you buy anything else. DCC scope is your whole organisation, and it is where most of the cost variation sits.
Goldline's DCC requirement and scope review exists for step 2 and step 4. Goldline is not a certification body and cannot certify DCC, which is a separate role held by assessors working for IASME-licensed certification bodies.
Sources
- IASME, Defence Cyber Certification scheme page, read 1 September 2026. Four levels with control counts of 3, 101, 139 and 144. "All levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus." Point-in-time assessment against a UK Defence standard, organisation-level assurance, annual attestation and recertification every three years.
- IASME, Defence Cyber Certification Frequently Asked Questions, read 1 September 2026. "Is DCC mandatory? DCC is currently not mandatory." "Applicants may still tender for MOD contracts via the normal MOD process, DCC is not mandatory at this stage." "Other than Cyber Essentials or Cyber Essentials Plus, there are not." "You can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls." "Are any levels self-assessment? No." Scope guidance on the alignment of Cyber Essentials and DCC scopes, and on the level being decided by the MOD or your prime.
- DefStan 05-138 Issue 4 was first published as an advance, informational publication in May 2024, per the same IASME FAQ.
