Defence Cyber Certification has four levels: L0, L1, L2, and L3. Each level corresponds to a Cyber Risk Profile (CRP) tier that the MOD assigns to the contract the supplier is delivering. The level is not chosen by the supplier - it is set by the buyer based on the sensitivity of the work, and the supplier must certify at that level (or higher) to hold the contract.
This guide breaks down each level in detail, explains how the CRP-to-DCC mapping works in practice, walks through the effort and cost differences between the levels, and addresses the question suppliers most often ask: why start at L0 when higher levels exist?
For a broader overview, see the DCC explainer. For comparative pricing, see the DCC pricing guide.
The Cyber Risk Profile framework
Before DCC, the MOD's Defence Cyber Protection Partnership (DCPP) established the Cyber Risk Profile, which categorises contracts into four risk tiers based on the sensitivity of the data and systems the supplier will handle:
| CRP tier | Typical contract characteristics |
|---|
| Very Low | Non-sensitive support services, facilities, catering, low-data logistics |
| Low | Operationally significant but non-classified data, standard commercial systems |
| Moderate | Sensitive MOD data, systems with operational MOD network connectivity |
| High | Classified information, critical operational capabilities, deep MOD integration |
DCC maps these four CRP tiers directly to four assessment levels. The buyer specifies the required CRP in the procurement documentation; DCC then determines the certification level needed:
| CRP tier | Required DCC level |
|---|
| Very Low | L0 |
| Low | L1 |
| Moderate | L2 |
| High | L3 |
Level 0 in detail
Who needs it: Suppliers on Very Low CRP contracts. Typically 1–50 employees, UK-based, delivering support services, facilities work, or non-sensitive logistics to the MOD or a prime contractor.
Technical baseline: Cyber Essentials.
What is assessed: The five Cyber Essentials technical controls (see DCC L0 five controls) plus supplementary defence-specific governance: Information Security Policy, Incident Response Plan, Staff Vetting, Supply Chain Risk Management, Data Handling, and CSM v4 L0 attestation.
How it is assessed: Single assessor reviewing a portal-based submission. No interviews. No on-site visits.
Timeline: 14–21 days for a prepared organisation.
Price (Fig tier-based, 2026):
- Micro (1–9): £999.99 + VAT
- Small (10–49): £1,499.99 + VAT
- Medium (50–249): £2,499.99 + VAT
- Large (250+): £4,999.99 + VAT
When to aim higher: If your MOD pipeline includes contracts at mixed CRP levels, certifying at L1 instead of L0 lets you bid across a wider range without re-certifying per contract.
Level 1 in detail
Who needs it: Suppliers on Low CRP contracts. Typical profile: 10–250 employees, handling operationally significant but unclassified MOD information, often direct primes on mid-value contracts or tier-one subcontractors.
Technical baseline: Cyber Essentials (not CE Plus yet - that kicks in at L2).
What is assessed: Everything in L0 plus:
- Formal Information Security Management System (ISMS) documentation
- Risk management framework
- Business continuity planning
- Deeper access control evidence (privileged access management, session logging)
- Data lifecycle management
- Subcontractor flow-down assurance
- Structured CSM v4 L1 evidence
How it is assessed: Consultant-led engagement with documentary review, interviews with key personnel (IT lead, security lead, operations lead, executive sponsor), and technical verification of specific controls. At Fig, the technology platform runs across in-scope systems to surface gaps before formal assessment.
Timeline: 6–10 weeks for a prepared organisation; 12–20 weeks from a low starting baseline.
Price (Fig tier-based, 2026):
- Micro (1–9): £9,999.99 – £14,999.99 + VAT
- Small (10–49): £15,000 – £19,999 + VAT
- Medium (50–249): £20,000 – £24,999 + VAT
- Large (250+): £25,000 – £49,999 + VAT
What drives the range: Scope complexity, number of sites, subcontractor chain depth, and starting maturity.
Level 2 in detail
Who needs it: Suppliers on Moderate CRP contracts. Typical profile: mid-sized to large defence suppliers, primes on medium-value contracts, specialist suppliers handling sensitive MOD data or providing critical operational systems.
Technical baseline: Cyber Essentials Plus (CE Plus), not CE basic. This is a material step up because CE Plus requires hands-on technical testing by an assessor, not just documentary review.
What is assessed: Everything in L1 plus:
- Formal risk assessment against CSM v4 L2
- Privileged access management programme
- Continuous vulnerability monitoring
- Documented security operations capability
- Regularly tested incident response
- Multi-tier supply chain assurance
- Staff vetting to higher standards (BPSS or SC where applicable)
How it is assessed: Formal assessor engagement with significant document review, structured interviews, and technical verification. Some controls may require on-site or remote verification.
Timeline: 3–6 months typical.
Who delivers it: L2 is not delivered by every DCC Certification Body. Accreditation is specifically at L2/L3 - suppliers typically engage NCC Group, Bridewell, or C3IA. See the DCC certification body comparison.
Level 3 in detail
Who needs it: Suppliers on High CRP contracts. Typical profile: major defence primes, suppliers handling classified information, critical technology suppliers, systems integrators on high-value operational contracts.
Technical baseline: Cyber Essentials Plus.
What is assessed: Everything in L2 plus:
- Demonstrable operational maturity of ISMS
- Active threat intelligence capability
- Tested incident response including defence-specific scenarios
- Advanced security operations (24/7 monitoring where relevant)
- Stringent staff vetting (SC or above where applicable)
- On-site verification of specific controls
- Multi-tier supply chain assurance with active verification, not just attestation
How it is assessed: In-depth assessor engagement including on-site verification, interviews across the organisation, and technical testing of specific controls.
Timeline: 4–9 months typical.
Who delivers it: L3 requires specific L3 accreditation. NCC Group, Bridewell, and C3IA are the main L3-accredited bodies in the UK market.
Why most suppliers start at L0 or L1
Three reasons:
- Contract pipeline reality. Most new MOD suppliers start with Very Low or Low CRP contracts. Over-certifying at L2 to chase contracts you do not yet have is expensive and does not create a commercial advantage in the market you are actually competing in.
- Maturity curve. L2 and L3 require substantially more operational discipline than L0/L1. Most organisations benefit from building to that maturity over time rather than attempting it cold.
- Cost discipline. L0 is a four-figure engagement. L1 is a five-figure engagement. L2 and L3 are six-figure engagements. Match the investment to the commercial return.
That said, there is a valid case for certifying one tier higher than your current pipeline requires if your pipeline is trending toward that tier - it avoids having to re-engage at a more pressured deadline when the higher-CRP opportunity arrives.
How to decide which level you need
- Confirm your contract's CRP. The buyer specifies it in the tender documentation. If it is not stated, ask before bidding.
- Check your pipeline. If you are bidding on multiple contracts, certify at the level matching the highest CRP in your pipeline.
- Confirm Cyber Essentials baseline. L0/L1 need CE. L2/L3 need CE Plus. If you do not hold the baseline, that is the first step.
- Engage a Certification Body accredited at your required level. Not every body delivers every level - see the certification body comparison.
The path from L0 to L1
L0 certification is commonly used as a stepping stone to L1. The practical progression:
- Certify CE and DCC L0 first (14–21 days). This establishes the technical baseline and governance foundation.
- Build the additional L1 artefacts over the following 3–6 months - formal ISMS, risk register, business continuity plan, subcontractor assurance programme, privileged access management.
- Engage L1 assessment when the L1 pipeline becomes credible.
This is a more sustainable path than attempting L1 cold. Fig's L1 engagements for clients who already hold L0 typically complete faster and with fewer findings than engagements that skip the L0 step.
Primary sources
Talk to a DCC assessor → | View pricing →