Gareth Shaw, MD Pera Prometheus
Key Takeaways
- DCC Level 0 is the Ministry of Defence (MOD) baseline that all industry partners are asked to meet by 31 December 2026.
- Cyber Essentials is a mandatory prerequisite, but on its own it does not get you to Level 0.
- If you cannot meet the three DCC Level 0 requirements, you almost certainly have wider information security gaps worth fixing.
Most suppliers have now heard the headline. The Ministry of Defence (MOD) has asked all industry partners to achieve Defence Cyber Certification (DCC) Level 0 by 31 December 2026, as confirmed on the Defence Digital blog. Fewer know what Level 0 actually contains. I hear the same assumption almost every week: “Level 0 just means Cyber Essentials.” That is only a third of the answer. Level 0 is three separate controls and this blog explains all three in plain English.
What actually is DCC Level 0?
Defence Cyber Certification (DCC) is the MOD’s assurance scheme for its supply chain. It runs across four levels, 0 to 3, so an organisation can certify at a level that matches its risk appropriately. Level 0 is the most basic level, the minimum the MOD expects and it was designed to be achievable by businesses of every size.
The scheme is delivered through IASME’s network of certification bodies and is open to any organisation, whether or not you hold an MOD contract today. If you want the wider picture of how the levels map to contracts, we cover that in How to align your DCC Level with MOD contract expectations. So Level 0 is the floor. Let us look at what it is made of.
Control one: Cyber Essentials
The first control is Cyber Essentials, the government backed scheme covering five basic technical protections: firewalls, secure configuration, user access control, malware protection and security update management. For DCC Level 0, the appropriate level of Cyber Essentials must be in place for your business critical systems.
Cyber Essentials is a mandatory prerequisite. That word matters. It does not mean you have finished once you hold the certificate, it means you cannot achieve Level 0 without it. As an IASME approved certification body for Cyber Essentials, Cyber Essentials Plus and a DCC Level 0, we see a number suppliers stop here and assume the job is done. It is not. To understand why Cyber Essentials underpins everything else, read Cyber Essentials: The Foundation of DCC Level 0.
Control two: demonstrate UK GDPR compliance
The second control asks you to demonstrate compliance with UK GDPR. In plain terms, that means showing you handle personal data lawfully and that you can account for how you protect it.
You do not need a legal department for this. What an assessor wants is practical evidence that you have registered with the Information Commissioner’s Office where required, that you have a privacy notice, that you know what personal data you hold and that you have a basic process for a data breach or a subject access request. If you already take data protection seriously, this control is mostly about writing down what you already do. Once your data handling is documented, the third control looks at your network.
Control three: demonstrate network security and resilience
The third control is network security and resilience. It sounds the most technical, but the intent is simple. The MOD wants confidence that your systems can withstand disruption and recover from it.
In practice, that means showing you understand your own network, that you have protections such as backups and access controls and that you know what happens when something goes wrong. Can you restore from backup? Do you know who does what during an incident? You are demonstrating understanding of your environment and a plan for the bad day, not building a fortress. Much of this overlaps with what Cyber Essentials and good data protection already pushes you towards, which is the point.
Why Level 0 is the baseline, not the burden
Here is the honest view. If your organisation cannot meet these three controls, the problem is not DCC. DCC Level 0 is the baseline of what any responsible business should already be doing. I would go further. If you genuinely cannot achieve Level 0, you probably have serious information security vulnerabilities that need immediate attention.
That reframes the whole exercise. Level 0 is less of a hurdle the MOD invented and more of a health check with a certificate attached and suppliers who treat it that way tend to sail through. It is also why Cyber Essentials alone falls short. The common cyber essentials vs DCC question misses that DCC reaches beyond the technical basics into data and resilience. For where these obligations come from contractually, through DEFCON 658 and DefStan 05-138, see Cyber Security Model and DEFSTAN 05-138 in the Defence Industry.
Conclusion
DCC Level 0 has three controls, one deadline and a sensible minimum. Get your Cyber Essentials in place, show you handle personal data properly and prove you can keep your network running and recover it. Do that and you are not just certified, you are running a business with its basic information security in order.
Ready to Take the Next Step?
Getting to Level 0 is straightforward once you know what the three DCC Level 0 requirements ask of you, but the December 2026 deadline arrives faster than people expect. As an accredited DCC Level 0 certifying body, we can assess all three controls, sort your Cyber Essentials at the same time and issue your certificate directly, so there is no need to juggle separate providers. Get in touch and let us find out where you are.
Frequently Asked Questions
Q: Is DCC Level 0 the same as Cyber Essentials?
A: No. Cyber Essentials is one of three controls that make up DCC Level 0, alongside demonstrating UK GDPR compliance and network security and resilience.
Q: What is the deadline for DCC Level 0?
A: The MOD has asked all industry partners to achieve Level 0 by 31 December 2026.
Q: Do I need Cyber Essentials before DCC Level 0?
A: Yes. Cyber Essentials is a mandatory prerequisite, so it must be in place for your business critical systems before you can certify at Level 0.
Q: How long does DCC Level 0 take to get?
A: For a prepared organisation it is usually a matter of weeks, but it depends on how much groundwork you already have, so do not leave it until December.
Q: Who can certify me for DCC Level 0?
A: Any DCC certifying body accredited through IASME, such as Pera Prometheus, which can also handle your Cyber Essentials certification at the same time.
Stay Safe, Stay Secure


