Skip to main content
Defence

Defence Cyber Certification: the four levels, and what each one actually asks

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer · ISO 42001 Lead Auditor · ISO 27001 Senior Lead Implementer · ISO 27001 Lead Auditor · CISSP · PMP

9 min read

Contents

    The four levels, the control counts, and the three things that catch suppliers out.

    The short answer

    Defence Cyber Certification has four levels. Level 0 has 3 controls. Level 1 has 101. Level 2 has 139. Level 3 has 144.

    Every level starts with Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus. No level is self-assessed. You can apply for any level without working up through the ones below it.

    Your level is decided by the MOD or by your prime, not by you.

    Is it mandatory

    IASME's own FAQ says DCC is currently not mandatory, and that applicants may still tender for MOD contracts through the normal process.

    Alongside that, the MOD's Director of Cyber Defence and Risk has asked all industry partners to achieve Level 0 by 31 December 2026, published on the Defence Digital blog on 8 May 2026 and reiterated on 13 July 2026.

    Both are true at once. This is an instruction from your largest customer rather than a legal requirement. In practice that tends to move faster than legislation, because a prime can make it a condition of the next contract without waiting for anybody.

    The four levels

    Level 0, three controls. Assigned where the assessed cyber risk from your delivery is very low. Basic cyber security practices, and the foundation every higher level builds on.

    Level 1, 101 controls. Low to moderate risk. A comprehensive cyber security programme with good practices.

    Level 2, 139 controls. High risk. Advanced oversight and planning. Cyber Essentials Plus required.

    Level 3, 144 controls. Substantial risk. Expert capability using defence in depth. Cyber Essentials Plus required.

    The jump that surprises people is not Level 2 to 3. It is Level 0 to Level 1, which is three controls to 101.

    Three things that catch suppliers out

    Your scope is the whole organisation, not the MOD contract

    IASME is explicit: the scope is your whole organisation and the services and functions essential for it to operate, whether those functions are for MOD or non-MOD contracts. You cannot scope to only the network handling the MOD work.

    DefStan 05-138 Issue 3 focused on protecting MOD Identifiable Information. Issue 4 does not address data classification at all and instead looks at whole-organisation security and resilience. If your mental model is still Issue 3 you will scope too narrowly and have it challenged.

    Non-essential parts can be left out, but you must produce a scoping statement saying what is in, what is out, how it aligns to your Cyber Essentials scope, and why.

    The scope does not change between levels

    Whether you are going for Level 0 or Level 3, the scope is the same. What is essential to your organisation operating securely does not depend on the level being assessed.

    You cannot upgrade by assessing only the difference

    If you certify at Level 0 and later need Level 1, IASME's answer to whether you can assess only the additional controls is no. You reassess.

    If you already know a prime will want Level 1 in 2027, going for Level 0 now and Level 1 later means paying for two full assessments rather than one.

    Does DCC replace the DEFCON 658 SAQ

    Partly, and the wording matters.

    ISN 2026/02, dated 30 March 2026, states that holding a current DCC at the commensurate level satisfies the DEFSTAN 05-138 control requirements under DEFCON 658.

    IASME separately confirms that DCC uses the same questions as the MOD SAQ, with small differences from version syncing.

    So DCC satisfies the control requirements. It is not accurate to say it removes the SAQ, and that distinction is worth getting right in a bid response.

    Can the people who help you also certify you

    A Certification Body can help you identify gaps. But if that same body is acting as your DCC assessor, it cannot be involved in implementing or managing your security defences. IASME trains certification bodies in two distinct roles, implementation consultancy or assessment, and the boundary exists to protect impartiality.

    The practical version: you can get a gap assessment from the body that will assess you. You cannot have them build the thing they then mark.

    Maintaining it

    Re-certify annually to Cyber Essentials or Cyber Essentials Plus, and every three years to DCC. Complete an annual attestation that you are still meeting the controls and your scope has not significantly changed.

    Routine organisational and network change is normal business and does not trigger recertification. Significant change should be reviewed with your certification body.

    How the assessment runs

    Two scoring phases.

    Theoretical. Does not contribute to your final score. You explain what you do and how, and submit evidence. The assessor may grant a clarification round, which is your opportunity to fix gaps before they cost you.

    Practical. The one that counts. The assessor verifies you are actually implementing what you described.

    There is no defined timescale. It depends on how prepared you are, whether you need remediation, and certification body availability. That last one is worth thinking about with a December deadline in front of you.

    Sources

    All read on 29 August 2026.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    Defence

    8 min read

    DCC versus Cyber Essentials

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    It is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification, and Cyber Essentials Plus for Levels 2 and 3. What each one actually measures.

    • Defence
    • DCC
    • Cyber Essentials
    • DEFSTAN 05-138
    Defence

    7 min read

    What DCC Level 2 Requires That Level 1 Does Not

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The obvious answer is thirty eight controls. The expensive answer is that you cannot upgrade, Cyber Essentials Plus becomes a prerequisite, and the assessor starts looking for governance.

    • Defence
    • DCC
    • DEFSTAN 05-138
    • Cyber Essentials
    Defence

    8 min read

    DCC versus JOSCAR

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One is a certification against a defence standard, owned by the MOD. The other is a commercially operated supplier data platform. Neither substitutes for the other, and different people decide whether you need each.

    • Defence
    • DCC
    • JOSCAR
    • Supply Chain
    Defence

    8 min read

    Choosing a DCC Certification Body

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.

    • Defence
    • DCC
    • Certification
    • DEFSTAN 05-138
    Defence Supply Chain

    12 min read

    DEFSTAN 05-138 Risk Profiling Explained: Very Low to Very High and What Each Means in Evidence

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    DEFSTAN 05-138 risk profiling explained. The five profiles from Very Low to Very High, evidence at each level, and the DCC relationship for UK defence SMEs.

    • DEFSTAN 05-138
    • Defence
    • DCC
    • ISO 27001
    Defence Supply Chain

    11 min read

    DEFCON 658 Explained for UK Tier-2 and Tier-3 Defence Suppliers

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    DEFCON 658 explained for UK defence supply chain SMEs. What the clause requires, the five risk profiles, and the most common documentation mistakes.

    • DEFCON 658
    • Defence
    • DEFSTAN 05-138
    • MOD
    Defence Supply Chain

    11 min read

    JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    JOSCAR Stage 2 explained for UK tier-2 defence SMEs. The cyber security module, the evidence gaps, and the seven-question readiness checklist.

    • JOSCAR
    • Defence
    • ISO 27001
    • Cyber Essentials Plus

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.