For suppliers in the UK Ministry of Defence (MOD) supply chain, Defence Cyber Certification (DCC) Level 1 is typically the level required where a contract carries a low, but not negligible, level of assessed cyber risk. It sits above the self-assessed Level 0, and below Levels 2 and 3, which require independent, evidence-based verification through a Certification Body (CB).
Unlike Level 0, a short self-assessment completed entirely through the IASME portal, Level 1 moves to a full evidence-based review. You complete an Assessment Submission Record (ASR) covering 101 controls, and a Periculo assessor reviews your responses and evidence before certification is decided. It's a bigger step up than the jump from nothing to Level 0, so it's worth knowing exactly what the process looks like before you start.
Here's what to expect, split into what's on you to prepare, and what happens once your assessor takes over.
DCC assesses your organisation against DEFSTAN 05-138 Issue 4, the defence cyber security standard that underpins the whole scheme. Level 1 requires a valid Cyber Essentials (CE) certificate as a prerequisite. Cyber Essentials Plus isn't required until Level 2. If you don't already hold CE, this needs to be in place, with a scope that overlaps your intended DCC scope, before your Level 1 assessment can proceed.
Certification is valid for three years, with a short annual attestation to keep it live in between, the same renewal pattern as Level 0.
These four steps are yours to work through before your assessor gets involved in earnest.
Scope is, by IASME's own guidance, the single most important part of the DCC process, and an under-scoped assessment fails automatically, no matter how well-controlled the systems you did include actually are.
DCC scope is broader than your Cyber Essentials scope. CE only covers internet-connected devices: laptops, desktops, servers, cloud services. DCC covers the whole organisation: every process, system and business function needed to operate and deliver securely, including non-internet-connected systems such as operational technology (OT), industrial control systems, building entry systems, or environmental controls, where these are essential to how you operate.
Before you go further, define:
You can complete Periculo's DCC scoping form to capture this, or bring your own documented Statement of Scope to your Certification Body.
Level 1 cannot proceed without a valid CE certificate whose scope overlaps your DCC scope. If you don't hold CE yet, this needs to be delivered as a separate engagement first; it isn't something that can run in parallel with your DCC Level 1 assessment.
If you already hold CE, your Certification Body will validate the certificate and check the scope overlap before onboarding you, but confirming it's current and correctly scoped is on you to do first.
Once your scope and CE prerequisite are confirmed, engage an IASME-accredited Certification Body. They'll issue your Assessment Submission Record (ASR), the document you'll use to respond to all 101 Level 1 controls and set you up on a delivery ticket with an assigned assessor and key dates.
This is also the point to agree on your audit dates. Most assessments open with a kickoff call on day one, so it's worth having evidence gathering well underway before that date is booked.
For each of the 101 controls, you'll need to:
Your Certification Body won't draft responses for you; this is your organisation's evidence of its own controls, not the assessor's. Build this into a secure, access-controlled evidence folder, and share access with your assessor ahead of the audit date. Under scheme rules, this needs to be complete before the audit can go ahead.
Once your submission is in, the next four steps are largely out of your hands; your assessor leads, and you respond to what they find.
The assessment proper begins with a kickoff call, where your assessor confirms scope, checks your submission is complete, and walks through the audit timetable.
Your assessor reviews your ASR responses and evidence offline; this is the theoretical review. You'll get initial feedback, and any areas needing improvement are flagged early. Before moving to practical validation, your assessor runs a readiness check: if anything looks incomplete, unclear, or likely to trigger an automatic fail, you'll be given the chance to update your responses or evidence first. This exists precisely so you don't walk into practical scoring carrying an avoidable fail.
With the theoretical review complete, your assessor moves to practical validation, checking that what your evidence describes is actually true in practice. Depending on your environment, this might include:
All scoring is recorded against your ASR, with automatic-fail controls checked first. If your assessor raises non-conformities, these are worked through via your delivery ticket, on a remediation timeline you agree together; practical scoring can pause while this happens. Once scoring is finalised, your assessor signs off, the outcome is entered on the IASME platform, and your certificate is issued automatically through IASME.
Certification isn't the end of your obligations. You're required to keep your evidence accessible to your Certification Body for two months after the assessment, and to retain the full evidence set for 3.5 years after certification. It's worth setting up a dedicated, access-controlled repository for this before you start, rather than scrambling to reconstruct it later, particularly with an annual attestation due every year of your three-year certificate.
Before the audit — on you:
During and after — on your assessor, with your input:
Periculo is an IASME-authorised Certification Body, delivering DCC assessments at every level. If you're preparing for a Level 1 assessment, or you're not yet sure which level applies to your contracts, get in touch, and we'll talk you through it.