Iron Sentinel,
DCC Level 0.
Certification based on Def Stan 05-138 Issue 4 for the UK defence supply chain, delivered through Iron Sentinel, our managed service covering DCC Levels 0 to 3.
DCC Level 0, delivered through Iron Sentinel
DCC Level 0 is the entry point of the Defence Cyber Certification scheme, for organisations assigned a Very Low Cyber Risk Profile against Def Stan 05-138 Issue 4 . We deliver it as part of Iron Sentinel, our managed service covering DCC Levels 0 to 3, rather than as a standalone, one-off certificate. Most clients need it as a starting point, not an end point, and Iron Sentinel is built to carry them further when they do.
- Just three controls from Def Stan 05-138 Issue 4 (six sub-controls), covering basic governance, identity, device and supply-chain awareness.
- A genuine, independently assessed certification, delivered by an IASME-approved DCC Certification Body, not a self-declaration.
- A digital certificate and verifiable badge on award, ready to display on your website or email footer.
- Valid for three years, with annual attestation required each year to keep it active.
Level 0
Ascertained Risk: Very Low
- Controls
- 3 controls
- CE prerequisite
- Cyber Essentials
- Assessment Submission Record
- Not required
Level 1
Ascertained Risk: Low–Moderate
- Controls
- 101 controls
- CE prerequisite
- Cyber Essentials
- Assessment Submission Record
- Required
Level 2
Ascertained Risk: High
- Controls
- 139 controls
- CE prerequisite
- Cyber Essentials Plus
- Assessment Submission Record
- Required
Level 3
Ascertained Risk: Substantial
- Controls
- 144 controls
- CE prerequisite
- Cyber Essentials Plus
- Assessment Submission Record
- Required
Who needs it, and why now
- Your MOD contract, or a contract with a prime contractor in the supply chain, has been assigned a Very Low Cyber Risk Profile.
- You want to pre-qualify for future MOD work before a contract requires it.
- You currently rely on the older Supplier Assurance Questionnaire (SAQ) and want a recognised, reusable certificate instead.
Timing matters
The MOD has set a public deadline : all defence industry partners have been asked to achieve DCC Level 0 by 31 December 2026, including holding Cyber Essentials for all applicable systems. Leaving this late risks assessment-slot bottlenecks as demand for Certification Bodies increases.
MOD deadline
Time remaining to 31 December 2026
Shown in your local time.
Your chosen DCC implementation partner
The scheme keeps assessment independent by design: a Certification Body is barred from implementing your controls, writing your answers, or preparing the evidence it will later assess. The official guidance is explicit that this work sits with a separate technology provider, which need not be a DCC Certification Body. That is where Iron Sentinel fits: we do the preparation, evidence and ongoing management, while an independent, IASME-approved Certification Body carries out the actual assessment.
Certification Body
Independent. Assesses your evidence and issues the certificate. Cannot advise on or prepare it.
Iron Sentinel
Your implementation partner. Handles the controls, evidence and submission, then manages renewal.
The Cyber Essentials prerequisite
You cannot apply for DCC Level 0 without first holding a valid, in-scope Cyber Essentials certificate, a hard prerequisite. Cyber Essentials assesses five control themes, firewalls, secure configuration, security update management, user access control and malware protection, verified through a self-assessment questionnaire. DCC Level 0 only needs standard Cyber Essentials; Cyber Essentials Plus, which assesses the same five themes with added independent technical testing, is not required until Level 2.
Iron Sentinel's price includes your DCC assessment and gap analysis; it does not include Cyber Essentials itself. If you do not already hold a current certificate, that is handled separately, either through Core, our fully managed Cyber Essentials service, or as a standalone one-off certificate from any provider, before Iron Sentinel picks up from there.
How Iron Sentinel works
DCC Level 0, and any future move to a higher level, run as one ongoing managed relationship, not separate projects, from first call through to renewal:
-
Step 1
Discovery call
A short call about your systems, contracts and MOD relationships, to confirm your assigned Cyber Risk Profile and that Level 0 is the right target for now.
One single point of contact who knows your full certification history, across every DCC level you hold or are working toward.
-
Step 2
Cyber Essentials readiness
Delivered first, through Core or as a standalone one-off certificate, if you do not already hold a current one. This is priced separately from Iron Sentinel, since Cyber Essentials is a hard prerequisite but not part of the DCC Level 0 service itself.
-
Step 3
Statement of Scope
Your DCC Level 0 scope is aligned to your existing Cyber Essentials scope, so we are not starting from a blank page: we confirm and document that boundary as the formal Statement of Scope the assessor works from.
-
Step 4
Gap analysis against the Level 0 controls
Your current setup is assessed against the three Def Stan 05-138 Issue 4 controls (six sub-controls) covering governance, identity, devices and supply-chain awareness, and you get a clear list of what is missing.
-
Step 5
Evidence pack and remediation
We build and collate the evidence for every control, from policy documents to configuration screenshots, and help you close any gaps identified, so nothing is missing when the assessor asks for it.
One evidence library, built once here and reused as the base layer for any future level, not started again from a blank page.
-
Step 6
Application submission
We prepare and submit your application to an independent, IASME-approved DCC Certification Body on your behalf.
-
Step 7
Assessment support
We are on hand throughout the assessor's review, answering technical questions and helping you respond to any follow-up requests, without ever assessing you ourselves; that stays independent.
Coordination with the independent Certification Body handled for you, so you have one channel to manage, not several.
-
Step 8
Certification and badge
You receive your digital certificate and a verifiable badge, ready to display on your website or email footer.
-
Step 9
Ongoing management
Certification is not a one-off. We track renewal dates and keep your evidence current between now and your next attestation.
Quarterly reviews of your policies and any organisational changes, such as new starters, new systems and new sites, so drift is caught between formal renewals, not at them.
-
Step 10
Renewal, or the next DCC level
When it is time to recertify, or if you need to move to a higher DCC level, we reuse the scope statement and evidence library already built, rather than starting again from zero.
A unified compliance calendar covering Cyber Essentials renewal, DCC attestation and three-year recertification.
Pricing
Up to 49 employees
£350 /month
Excluding VAT, on a 36-month commitment, matching your DCC certificate's 3-year lifetime.
- Evidence gathering
- Remediation
- Gap analysis
- DCC Level 0 certificate
- Quarterly policy reviews
- Annual attestation
Frequently asked questions
Do we need Cyber Essentials Plus for DCC Level 0?
No. Standard Cyber Essentials is sufficient for Levels 0 and 1. Cyber Essentials Plus is only required from Level 2 upwards, delivered as part of Iron Sentinel at that level.
Can we apply if we don't currently hold an MOD contract?
Yes. Any organisation can apply for DCC certification at any level, regardless of whether they currently hold defence work. Many apply proactively ahead of bidding.
Is DCC Level 0 mandatory yet?
Not on every contract yet, but the MOD has directed all defence industry partners to achieve Level 0 by 31 December 2026.
What happens if our risk profile changes and we need a higher level later?
If you later need to move from Level 0 to a higher level, that builds on the evidence library and scope statement already in place under your Iron Sentinel engagement, rather than starting again from zero.
Who actually assesses and certifies us?
DCC Certification Bodies cannot both consult on implementation and assess the same client. We are your preparation and management partner through Iron Sentinel; your assessment and certification is carried out by our IASME-approved DCC certification partner. We oversee this process and ensure you move in the right direction.
Ready to talk through
DCC Level 0?
Book a call and we'll walk through Iron Sentinel, our managed DCC service, and what it covers for your business.