Managed Cyber Security

Iron Sentinel,
DCC Level 0.

Certification based on Def Stan 05-138 Issue 4 for the UK defence supply chain, delivered through Iron Sentinel, our managed service covering DCC Levels 0 to 3.

DCC Level 0, delivered through Iron Sentinel

DCC Level 0 is the entry point of the Defence Cyber Certification scheme, for organisations assigned a Very Low Cyber Risk Profile against Def Stan 05-138 Issue 4 . We deliver it as part of Iron Sentinel, our managed service covering DCC Levels 0 to 3, rather than as a standalone, one-off certificate. Most clients need it as a starting point, not an end point, and Iron Sentinel is built to carry them further when they do.

  • Just three controls from Def Stan 05-138 Issue 4 (six sub-controls), covering basic governance, identity, device and supply-chain awareness.
  • A genuine, independently assessed certification, delivered by an IASME-approved DCC Certification Body, not a self-declaration.
  • A digital certificate and verifiable badge on award, ready to display on your website or email footer.
  • Valid for three years, with annual attestation required each year to keep it active.

Level 0

Ascertained Risk: Very Low

Controls
3 controls
CE prerequisite
Cyber Essentials
Assessment Submission Record
Not required

Level 1

Ascertained Risk: Low–Moderate

Controls
101 controls
CE prerequisite
Cyber Essentials
Assessment Submission Record
Required

Level 2

Ascertained Risk: High

Controls
139 controls
CE prerequisite
Cyber Essentials Plus
Assessment Submission Record
Required

Level 3

Ascertained Risk: Substantial

Controls
144 controls
CE prerequisite
Cyber Essentials Plus
Assessment Submission Record
Required

Who needs it, and why now

  • Your MOD contract, or a contract with a prime contractor in the supply chain, has been assigned a Very Low Cyber Risk Profile.
  • You want to pre-qualify for future MOD work before a contract requires it.
  • You currently rely on the older Supplier Assurance Questionnaire (SAQ) and want a recognised, reusable certificate instead.

Timing matters

The MOD has set a public deadline : all defence industry partners have been asked to achieve DCC Level 0 by 31 December 2026, including holding Cyber Essentials for all applicable systems. Leaving this late risks assessment-slot bottlenecks as demand for Certification Bodies increases.

MOD deadline

Time remaining to 31 December 2026

Shown in your local time.

Your chosen DCC implementation partner

The scheme keeps assessment independent by design: a Certification Body is barred from implementing your controls, writing your answers, or preparing the evidence it will later assess. The official guidance is explicit that this work sits with a separate technology provider, which need not be a DCC Certification Body. That is where Iron Sentinel fits: we do the preparation, evidence and ongoing management, while an independent, IASME-approved Certification Body carries out the actual assessment.

Certification Body

Independent. Assesses your evidence and issues the certificate. Cannot advise on or prepare it.

Iron Sentinel

Your implementation partner. Handles the controls, evidence and submission, then manages renewal.

The Cyber Essentials prerequisite

You cannot apply for DCC Level 0 without first holding a valid, in-scope Cyber Essentials certificate, a hard prerequisite. Cyber Essentials assesses five control themes, firewalls, secure configuration, security update management, user access control and malware protection, verified through a self-assessment questionnaire. DCC Level 0 only needs standard Cyber Essentials; Cyber Essentials Plus, which assesses the same five themes with added independent technical testing, is not required until Level 2.

Iron Sentinel's price includes your DCC assessment and gap analysis; it does not include Cyber Essentials itself. If you do not already hold a current certificate, that is handled separately, either through Core, our fully managed Cyber Essentials service, or as a standalone one-off certificate from any provider, before Iron Sentinel picks up from there.

How Iron Sentinel works

DCC Level 0, and any future move to a higher level, run as one ongoing managed relationship, not separate projects, from first call through to renewal:

  1. Step 1

    Discovery call

    A short call about your systems, contracts and MOD relationships, to confirm your assigned Cyber Risk Profile and that Level 0 is the right target for now.

    One single point of contact who knows your full certification history, across every DCC level you hold or are working toward.

  2. Step 2

    Cyber Essentials readiness

    Delivered first, through Core or as a standalone one-off certificate, if you do not already hold a current one. This is priced separately from Iron Sentinel, since Cyber Essentials is a hard prerequisite but not part of the DCC Level 0 service itself.

  3. Step 3

    Statement of Scope

    Your DCC Level 0 scope is aligned to your existing Cyber Essentials scope, so we are not starting from a blank page: we confirm and document that boundary as the formal Statement of Scope the assessor works from.

  4. Step 4

    Gap analysis against the Level 0 controls

    Your current setup is assessed against the three Def Stan 05-138 Issue 4 controls (six sub-controls) covering governance, identity, devices and supply-chain awareness, and you get a clear list of what is missing.

  5. Step 5

    Evidence pack and remediation

    We build and collate the evidence for every control, from policy documents to configuration screenshots, and help you close any gaps identified, so nothing is missing when the assessor asks for it.

    One evidence library, built once here and reused as the base layer for any future level, not started again from a blank page.

  6. Step 6

    Application submission

    We prepare and submit your application to an independent, IASME-approved DCC Certification Body on your behalf.

  7. Step 7

    Assessment support

    We are on hand throughout the assessor's review, answering technical questions and helping you respond to any follow-up requests, without ever assessing you ourselves; that stays independent.

    Coordination with the independent Certification Body handled for you, so you have one channel to manage, not several.

  8. Step 8

    Certification and badge

    You receive your digital certificate and a verifiable badge, ready to display on your website or email footer.

  9. Step 9

    Ongoing management

    Certification is not a one-off. We track renewal dates and keep your evidence current between now and your next attestation.

    Quarterly reviews of your policies and any organisational changes, such as new starters, new systems and new sites, so drift is caught between formal renewals, not at them.

  10. Step 10

    Renewal, or the next DCC level

    When it is time to recertify, or if you need to move to a higher DCC level, we reuse the scope statement and evidence library already built, rather than starting again from zero.

    A unified compliance calendar covering Cyber Essentials renewal, DCC attestation and three-year recertification.

Pricing

Up to 49 employees

£350 /month

Excluding VAT, on a 36-month commitment, matching your DCC certificate's 3-year lifetime.

  • Evidence gathering
  • Remediation
  • Gap analysis
  • DCC Level 0 certificate
  • Quarterly policy reviews
  • Annual attestation
Book a call

Get a quote

Tell us a little about your business and we'll come back with pricing tailored to you.

Frequently asked questions

Do we need Cyber Essentials Plus for DCC Level 0?

No. Standard Cyber Essentials is sufficient for Levels 0 and 1. Cyber Essentials Plus is only required from Level 2 upwards, delivered as part of Iron Sentinel at that level.

Can we apply if we don't currently hold an MOD contract?

Yes. Any organisation can apply for DCC certification at any level, regardless of whether they currently hold defence work. Many apply proactively ahead of bidding.

Is DCC Level 0 mandatory yet?

Not on every contract yet, but the MOD has directed all defence industry partners to achieve Level 0 by 31 December 2026.

What happens if our risk profile changes and we need a higher level later?

If you later need to move from Level 0 to a higher level, that builds on the evidence library and scope statement already in place under your Iron Sentinel engagement, rather than starting again from zero.

Who actually assesses and certifies us?

DCC Certification Bodies cannot both consult on implementation and assess the same client. We are your preparation and management partner through Iron Sentinel; your assessment and certification is carried out by our IASME-approved DCC certification partner. We oversee this process and ensure you move in the right direction.

Ready to talk through
DCC Level 0?

Book a call and we'll walk through Iron Sentinel, our managed DCC service, and what it covers for your business.