top of page
SHIELD button
Search

Who Needs to Achieve DCC Level 0?

  • natasha5042
  • Aug 3
  • 2 min read

Updated: 6 days ago

DCC Level 0 is intended for every organisation that supplies the UK Ministry of Defence (MoD), either directly or indirectly through the defence supply chain. The MoD has asked all industry partners to achieve DCC Level 0 by 31 December 2026 as the minimum baseline for cyber resilience.


This includes organisations such as:

  • Prime contractors delivering directly to the MoD

  • SMEs working as subcontractors within the defence supply chain

  • Manufacturers and engineering companies

  • IT, cyber security and software providers

  • Facilities management and maintenance providers

  • Professional services, consultancy and support organisations

  • Logistics, transport and warehousing providers

  • Any business that provides goods or services in support of defence contracts


What if I'm not currently an MoD supplier?


Even if you're not currently working with the MoD, achieving DCC Level 0 can be beneficial if you:


  • Plan to bid for future defence contracts

  • Supply organisations that work with the MoD

  • Want to demonstrate your cyber resilience to defence customers

  • Wish to avoid delays when DCC becomes a contractual requirement


Starting your preparation early will help ensure you meet contractual requirements, protect your business from evolving cyber threats and remain a trusted defence supplier.


What are the Benefits of DCC Level 0?




How can Fortis Cyber® Support Us to Achieve DCC Level 0?


Fortis Cyber® provides a range of consultancy services to support you on your journey to Defence Cyber Certification Level 0 and we can arrange certification:


Readiness Assessment and Gap Analysis:

  • Assessing current security posture

  • Identifying gaps against the framework and providing prioritised recommendations to meet compliance requirements

  • This is the theoretical scoring element


Technical Security Implementation:

  • Hardening systems and networks to meet secure configuration requirements

  • Cyber Essentials


Training and Awareness:

  • Workshops in preparation for evidence collection and audits

  • Staff cyber awareness training


Policy, Process and Documentation:

  • Developing or refining cyber policies and processes to ensure clear and auditable documentation

  • This is part of the assist/consult and implement stage to prepare the applicant for DCC


Security Testing and Assurance:

  • Secure configuration reviews and CREST-accredited Vulnerability Assessments

  • Automated Pen Testing as a Service

  • Penetration Testing


Information Security Officer as a Service:

  • Ongoing support with governance, security strategy and continuous improvement

  • Maintaining DCC compliance and managing annual attestations


You must achieve Cyber Essentials before applying for DCC Level 0, and for higher levels Cyber Essentials Plus is mandatory. Fortis Cyber® has guided organisations to certification and we currently have capacity to support your organisation in readiness for the end of the year deadline. Get in touch for more information and let our experts support you with clear, actionable guidance on DCC compliance.

 
 
 

Comments


bottom of page