The four levels, the control counts, and the three things that catch suppliers out.
The short answer
Defence Cyber Certification has four levels. Level 0 has 3 controls. Level 1 has 101. Level 2 has 139. Level 3 has 144.
Every level starts with Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus. No level is self-assessed. You can apply for any level without working up through the ones below it.
Your level is decided by the MOD or by your prime, not by you.
Is it mandatory
IASME's own FAQ says DCC is currently not mandatory, and that applicants may still tender for MOD contracts through the normal process.
Alongside that, the MOD's Director of Cyber Defence and Risk has asked all industry partners to achieve Level 0 by 31 December 2026, published on the Defence Digital blog on 8 May 2026 and reiterated on 13 July 2026.
Both are true at once. This is an instruction from your largest customer rather than a legal requirement. In practice that tends to move faster than legislation, because a prime can make it a condition of the next contract without waiting for anybody.
The four levels
Level 0, three controls. Assigned where the assessed cyber risk from your delivery is very low. Basic cyber security practices, and the foundation every higher level builds on.
Level 1, 101 controls. Low to moderate risk. A comprehensive cyber security programme with good practices.
Level 2, 139 controls. High risk. Advanced oversight and planning. Cyber Essentials Plus required.
Level 3, 144 controls. Substantial risk. Expert capability using defence in depth. Cyber Essentials Plus required.
The jump that surprises people is not Level 2 to 3. It is Level 0 to Level 1, which is three controls to 101.
Three things that catch suppliers out
Your scope is the whole organisation, not the MOD contract
IASME is explicit: the scope is your whole organisation and the services and functions essential for it to operate, whether those functions are for MOD or non-MOD contracts. You cannot scope to only the network handling the MOD work.
DefStan 05-138 Issue 3 focused on protecting MOD Identifiable Information. Issue 4 does not address data classification at all and instead looks at whole-organisation security and resilience. If your mental model is still Issue 3 you will scope too narrowly and have it challenged.
Non-essential parts can be left out, but you must produce a scoping statement saying what is in, what is out, how it aligns to your Cyber Essentials scope, and why.
The scope does not change between levels
Whether you are going for Level 0 or Level 3, the scope is the same. What is essential to your organisation operating securely does not depend on the level being assessed.
You cannot upgrade by assessing only the difference
If you certify at Level 0 and later need Level 1, IASME's answer to whether you can assess only the additional controls is no. You reassess.
If you already know a prime will want Level 1 in 2027, going for Level 0 now and Level 1 later means paying for two full assessments rather than one.
Does DCC replace the DEFCON 658 SAQ
Partly, and the wording matters.
ISN 2026/02, dated 30 March 2026, states that holding a current DCC at the commensurate level satisfies the DEFSTAN 05-138 control requirements under DEFCON 658.
IASME separately confirms that DCC uses the same questions as the MOD SAQ, with small differences from version syncing.
So DCC satisfies the control requirements. It is not accurate to say it removes the SAQ, and that distinction is worth getting right in a bid response.
Can the people who help you also certify you
A Certification Body can help you identify gaps. But if that same body is acting as your DCC assessor, it cannot be involved in implementing or managing your security defences. IASME trains certification bodies in two distinct roles, implementation consultancy or assessment, and the boundary exists to protect impartiality.
The practical version: you can get a gap assessment from the body that will assess you. You cannot have them build the thing they then mark.
Maintaining it
Re-certify annually to Cyber Essentials or Cyber Essentials Plus, and every three years to DCC. Complete an annual attestation that you are still meeting the controls and your scope has not significantly changed.
Routine organisational and network change is normal business and does not trigger recertification. Significant change should be reviewed with your certification body.
How the assessment runs
Two scoring phases.
Theoretical. Does not contribute to your final score. You explain what you do and how, and submit evidence. The assessor may grant a clarification round, which is your opportunity to fix gaps before they cost you.
Practical. The one that counts. The assessor verifies you are actually implementing what you described.
There is no defined timescale. It depends on how prepared you are, whether you need remediation, and certification body availability. That last one is worth thinking about with a December deadline in front of you.
Sources
All read on 29 August 2026.
- IASME, Defence Cyber Certification: https://iasme.co.uk/defence-cyber-certification/
- IASME, DCC Frequently Asked Questions: https://iasme.co.uk/defence-cyber-certification/frequently-asked-questions/
- ISN 2026/02, 30 March 2026: https://assets.publishing.service.gov.uk/media/69cba72ba60a12ca3913c610/ISN_2026-02_Use_of_Defence_Cyber_Certification__DCC__as_assurance_of_control_requirements_under_DEFCON_658.pdf
- MOD Defence Digital blog, 8 May 2026: https://defencedigital.blog.gov.uk/2026/05/08/one-year-of-defence-cyber-certification-building-stronger-cyber-resilience-together/
- DefStan 05-138 Issue 4 mapping document: https://www.gov.uk/government/publications/mapping-document-cyber-security-for-defence-suppliers-def-stan-05-138-issue-4
