DCC Level 0.
Your route to certification.
Know what happens before, during and after your assessment. A clear process for your organisation, or for the clients you support.

The engagement, end to end.
Confirm your level
Check the level required by your MOD customer or prime contractor before purchasing. Level 0 is not a substitute where a higher level is required.
Prepare your scope
Identify the functions and services your organisation needs to operate securely. Discuss the proposed scope with Fig and check how it aligns with your Cyber Essentials coverage.
Prepare your submission
Use the IASME applicant guidance to answer the questions and organise supporting evidence. Level 0 does not require the Assessment Submission Record used for Levels 1–3.
Work through the assessment
Your assessor reviews the submission and verifies the controls. DCC is assessor-led, not a self-assessment certificate. Be ready to explain your evidence and respond to clarification requests.
Address any gaps
Your organisation or MSP implements required changes. Keep supporting records current and agree the next assessment steps with your assessor. Purchase does not guarantee certification.
Maintain your certification
After a successful assessment, keep meeting the controls. DCC requires annual attestation and recertification every three years; the underlying Cyber Essentials certification renews annually.
Before you begin
Have a valid Cyber Essentials certificate and confirm that its scope covers the relevant internet-connected systems within your DCC scope. Cyber Essentials is a separate purchase, not included in the DCC assessment price.
If an MSP helps prepare the submission, the applicant remains responsible for its accuracy, authorisation and required declarations. Evidence may also be needed from service providers.
Scheme guidance
Check the current IASME applicant and process guides and scheme FAQs. Timing depends on readiness, scope and assessor availability; the Cyber Essentials turnaround promise does not apply to DCC.