How does a UK defence SME achieve DCC Level 0?
To achieve Defence Cyber Certification (DCC) Level 0, a UK defence SME needs three things: a valid Cyber Essentials certificate, evidence of UK GDPR compliance, and evidence of resilient networks, meaning working backups and a disaster recovery plan. Certification is assessed through an IASME-approved certification body, is valid for three years, and requires annual attestation.
That is the whole requirement. The rest of this guide explains each step, what evidence assessors expect, and how long it takes.
What is DCC Level 0?
DCC is the MOD's certification scheme for the defence supply chain, launched alongside Cyber Security Model v4 (CSM v4) in December 2025 and administered by IASME. It has four levels, 0 to 3, which correspond directly to the Cyber Risk Profiles used in CSM v4 and the control sets in Defence Standard 05-138.
Level 0 is the entry level, for contracts assessed as very low cyber risk. It is deliberately achievable for small companies. The MOD has asked all industry partners to achieve Level 0 by 31 December 2026, and the MOD's Chief Information Security Officer has written to suppliers stating that certification will increasingly be specified as a precursor requirement for contracting with Defence.
The scheme is not theoretical. Lockheed Martin has already achieved the first DCC Level 3 certification, which tells you the assessment machinery is running and that primes are moving.
Step 1: Get Cyber Essentials
Cyber Essentials is the prerequisite for DCC Level 0. It covers five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. It is achieved through a self-assessment questionnaire verified by a certification body and typically costs a few hundred pounds.
If you already hold a valid Cyber Essentials certificate, you have done the hardest part. If not, a well-configured Microsoft 365 environment gets you most of the way, and certification is achievable in days to weeks depending on your starting posture.
One caution: the questionnaire is easy to underestimate. Declaring controls you do not actually operate is worse than failing, because a later DCC assessment is designed to find exactly that gap.
Step 2: Evidence UK GDPR compliance
Assessors will want to see that you are registered with the ICO, know what personal data you process, and have a clear privacy policy. For most SMEs this is administrative work rather than technical work, but it needs to exist in writing before the assessment.
Step 3: Evidence resilient networks
This means demonstrating data security fundamentals: your critical business data is backed up, the backups work, and you have a plan for recovering if systems go down. A tested backup process and a short, honest disaster recovery plan meet the bar. A document nobody has read since 2023 does not.
Step 4: Book the assessment
DCC assessments are delivered by IASME's network of assured certification bodies. Register interest with IASME, who will provide a list of certification bodies assessing at your required level. The certification body explains the process, quotes, and conducts the assessment. Assessors identify gaps and advise, but they do not implement fixes for you.
Once your Cyber Essentials, GDPR evidence, and resilience evidence are in place, the Level 0 assessment itself is straightforward. Certification lasts three years, with an annual attestation to confirm nothing material has changed.
How long does it take?
For an SME with a reasonable Microsoft 365 setup: Cyber Essentials in one to four weeks, the remaining Level 0 evidence in parallel, and assessment shortly after.
The realistic constraint is assessor availability, which will tighten as the December 2026 date approaches. If you are starting now, start with Cyber Essentials this month.
What if the assessment does not go well?
A failed assessment is not a public event. You receive a report setting out where you fell short, you remediate, and you reapply. Failed assessment details are kept confidential.
The cost of failing is time and a second fee. That is an argument for being honest with yourself about your evidence before you book, not an argument for delay.
Do I need a higher level?
Only if your contract's Cyber Risk Profile demands it. Level 1 introduces 101 controls, Level 2 (which requires Cyber Essentials Plus) has 139, and Level 3 has 144. The MOD or your prime contractor specifies the required level in the invitation to tender.
Do not over-certify speculatively. Hit the right bar at the right time.
Getting help with Level 0
Most of Level 0 is achievable without outside help if your environment is tidy and someone has the time. Where it stops being straightforward is when your Microsoft 365 setup has grown organically, nobody has written down the governance, or the founders simply do not have the hours.
Where we come in is AEGIS, and it is worth being clear what that is. It is not a compliance exercise. It is operational cyber security: we bring your Microsoft 365 environment up to defence standard, protect it around the clock, and produce the evidence you need for Cyber Essentials and DCC as an output of that work. Built by us, protected by us, owned by you, so the tenant stays yours.
AEGIS runs at every DCC level, 0 to 3, sized to the Cyber Risk Profile your contracts carry. At Level 0 it is sold as a fixed-price package that includes the Microsoft licences and the certification body fee, delivered by SC and DV cleared people who helped build the MOD's own requirements.
Find out where you actually stand
The instant CSM v4 readiness check is free, takes a few minutes, and gives you a downloadable report. No obligation to buy anything from us afterwards.