Industry

Defence Cyber Certification Pricing in 2026: What L0 and L1 Actually Cost, and Why

Fig platform analysis dashboard breaking down DCC Level 0 and Level 1 engagement scope, effort, and cost drivers

Defence Cyber Certification pricing is considerably more variable than Cyber Essentials pricing. A Cyber Essentials certificate from one IASME-licensed body costs within £50 of the same certificate from another body. A DCC L1 certificate can vary by £10,000 or more between providers, for reasons that are not always obvious until you read the quotes carefully.

This guide walks through what L0 and L1 DCC actually cost in the UK market as of 2026, what is included at each price point, and what the pricing gaps between Certification Bodies actually represent.

Level 0 pricing: reasonably standardised

DCC Level 0 pricing across the UK market is relatively consistent because the assessment itself is relatively constrained. L0 is a documentation-led review against a defined set of requirements, conducted primarily through the IASME portal, with a single assessor reviewing the submission. The economics are similar to Cyber Essentials - the labour component is contained, the audit work is structured, and there is limited scope for one body to take materially more effort than another.

Fig Group L0 pricing:

TierEmployee bandPrice
Micro1 – 9 employees£999.99 + VAT
Small10 – 49 employees£1,499.99 + VAT
Medium50 – 249 employees£2,499.99 + VAT
Large250+ employees£4,999.99 + VAT

Market context: L0 pricing across the UK's DCC Certification Bodies generally ranges from £800 + VAT for micro organisations up to £7,000 + VAT for large organisations. Fig's pricing sits at the competitive end of the range, with transparency - no consultancy add-ons priced separately and no per-submission fees. The Cyber Essentials prerequisite is priced separately and is not bundled into the L0 engagement fee.

What L0 pricing includes:

  • DCC L0 assessment against the current version of the Cyber Security Model (CSM v4, December 2025)
  • Review of governance documentation, supply chain risk management, incident response evidence, and technical controls
  • Up to three free rounds of assessor feedback
  • Certificate issuance and registration on the IASME DCC register
  • Three-year certificate validity with annual attestation pathway

The Cyber Essentials prerequisite is not bundled into the L0 engagement fee. A valid CE certificate must be held separately before L0 can begin; Fig can certify CE under our Cyber Essentials pricing where required.

What L0 pricing should NOT include surprise charges for:

  • Assessor clarification rounds - these should be covered by the base fee
  • Certificate delivery or badge generation
  • Re-submission following minor feedback

Level 1 pricing: genuine complexity, genuine variability

DCC Level 1 is where pricing becomes materially variable, for a simple reason: L1 is not a documentation review. It is a consultative engagement that includes evidence preparation, gap analysis, remediation support, formal assessment, and (at Fig) technology platform gap analysis. The difference between a £10,000 L1 quote and a £30,000 L1 quote is usually the difference between "we will audit you" and "we will work with you".

Fig Group L1 pricing (includes dedicated consultant + technology platform access):

TierEmployee bandPrice range
Micro1 – 9 employees£9,999.99 – £14,999.99 + VAT
Small10 – 49 employees£15,000 – £19,999 + VAT
Medium50 – 249 employees£20,000 – £24,999 + VAT
Large250+ employees£25,000 – £49,999 + VAT

Every Fig L1 engagement includes a dedicated consultant who works with the client throughout the process, plus access to Fig's technology platform that automatically surfaces gaps in cyber defences (unpatched systems, misconfigured cloud resources, excessive privilege, exposed credentials, and other issues) so they can be remediated before formal assessment rather than becoming findings.

Why the range within each tier: L1 engagements vary in scope complexity. Factors that push a quote toward the upper end of the range:

  • Multiple physical sites requiring assessment
  • Extensive cloud infrastructure (multi-region, multi-tenant, complex IAM)
  • Complex subcontractor chain requiring flow-down assurance
  • Legacy systems that require special scoping or compensating controls
  • High number of in-scope personnel requiring vetting documentation
  • Additional regulatory overlays (DSPT for healthcare-adjacent work, ISO 27001 alignment, etc.)

Factors that keep a quote toward the lower end:

  • Single site or fully remote
  • Modern cloud-native infrastructure
  • Minimal subcontractor chain
  • Clean, well-documented existing posture (often from prior Cyber Essentials Plus or ISO 27001 work)

Market context: L1 pricing across the UK's DCC Certification Bodies ranges from roughly £8,000 + VAT for a minimal-scope micro engagement with audit-only support, up to £60,000+ + VAT for a complex large-organisation engagement with full consultancy support. Fig's pricing sits in the middle of that range, with the consultancy and technology platform bundled in rather than sold as add-ons.

What L1 pricing should include (and does at Fig):

  • Full DCC L1 assessment against CSM v4
  • Dedicated consultant for the engagement duration
  • Technology platform gap analysis
  • Evidence preparation support
  • Up to three rounds of remediation feedback
  • Certificate issuance, IASME register listing, three-year validity
  • Annual attestation support

What L1 pricing should NOT include as hidden add-ons:

  • Pre-engagement "readiness assessment" at a separate fee
  • Per-interview charges during the assessor phase
  • Additional fees for multi-site coverage within the agreed scope
  • Separate charges for the initial CSM v4 gap review

How to read a DCC quote

When comparing quotes across Certification Bodies, the questions that matter:

  1. Is Cyber Essentials included? L0 and L1 both require a valid CE certificate. If the CB charges for CE separately, add that to the base quote.
  1. Is there a dedicated consultant, or does the CB only provide an assessor? A pure-audit engagement is cheaper but places more remediation burden on the supplier. A consultant-supported engagement is more expensive but materially reduces the risk of findings.
  1. Is there technology platform support? Some CBs offer automated gap analysis to identify technical issues before assessment. This is a meaningful differentiator - issues found by a platform can be fixed quietly; issues found by an assessor become formal findings on the certification record.
  1. Are remediation rounds included, or priced separately? L1 engagements frequently need clarification or remediation. A quote that includes three rounds is substantively different from one that charges per round.
  1. What is the assessor-to-client ratio? CBs running high throughput per assessor will respond faster than CBs running lean. Ask about average turnaround from submission to certificate.
  1. What happens at annual attestation? DCC is valid for three years with annual check-ins. The annual attestation is included in some pricing models and charged separately in others. Clarify before signing.

The honest bottom line on pricing

L0 DCC is a commoditised product. Pick the CB that offers the best combination of price, turnaround, and service quality. The price gap between providers is not large.

L1 DCC is not a commoditised product. The £10,000 difference between two quotes typically represents a fundamentally different service model - audit-only versus consultant-led, with or without technology platform support, with or without remediation cycles included. Choose based on the model that matches your needs, not on the headline number alone.

For suppliers new to the MOD supply chain, L1 consultant-led engagement with platform support is usually the right choice. The upfront cost is higher but the probability of a clean first-pass certification is materially higher. For suppliers with deep existing maturity from prior ISO 27001 or NCSC CAF work, an audit-only engagement may be sufficient and faster.

Fig's L1 pricing bundles consultant-led engagement and technology platform access into the base fee rather than charging them as add-ons, because most defence suppliers coming to DCC for the first time need both to succeed. Audit-only pricing is available on request for suppliers with genuine existing maturity who only need the formal assessment.

L1 pricing is presented as ranges (e.g., £9,999.99 – £14,999.99 for micro organisations) because the final price depends on the complexity of your scope. The variance within each tier is driven by scope size and complexity, starting maturity, technology platform findings, and subcontractor assurance needs. The consultant works with you upfront to scope the engagement accurately, providing a firm quote based on your specific situation. This transparency ensures no surprises - the price reflects the work needed, not arbitrary markups.

Primary sources

Get an L1 quote → | See full pricing →

Article FAQ

Frequently asked questions

Key questions from MOD suppliers researching this topic.

What is the typical market price range for DCC Level 0?

Level 0 pricing across the UK market generally ranges from £800 + VAT for micro organisations up to around £7,000 + VAT for large organisations. Fig's L0 pricing sits at the competitive end: £999.99 + VAT micro, £1,499.99 small, £2,499.99 medium, £4,999.99 large.

Why does DCC Level 1 pricing vary so much between providers?

Level 1 pricing reflects different delivery models: audit-only versus consultant-led, with or without technology platform support, scope complexity, and how much remediation support is included. A £10,000 quote and a £30,000 quote typically represent fundamentally different service models, not price inflation.

What should a strong DCC quote include?

A strong quote should define scope assumptions, assessor and consultant involvement, number of included feedback rounds, expected timeline, annual attestation terms, and clear exclusions. Fig includes up to three feedback rounds in the base fee.

Is Cyber Essentials included in DCC pricing?

Usually no. Cyber Essentials is generally a separate prerequisite and should be treated as a distinct line item unless a provider explicitly bundles it. Always confirm whether CE is included when comparing DCC quotes.

How do we compare two DCC quotes fairly?

Compare service model, not just headline price. Match what is included for scoping, evidence support, remediation cycles, assessor time, and post-certification obligations. A cheaper audit-only quote can end up more expensive if it fails at first pass.

Related DCC articles

Keep reading.

Technical Guides

How Long Does Defence Cyber Certification Take? A Realistic Timeline for L0 and L1 Assessment

The honest answer to "how long does DCC take" depends more on the supplier's starting posture than on the Certification Body's turnaround. L0 can complete in under three weeks for a prepared organisation. L1 is a six to twelve week engagement. This guide walks through both, with the specific factors that lengthen or shorten each phase.

Technical Guides

DCC Requirements Checklist 2026: The Full L0 and L1 Readiness List Against CSM v4

A consolidated, practical readiness checklist for DCC Level 0 and Level 1 against CSM v4 (December 2025). Use it to audit your starting posture before engaging a Certification Body. Organised by control family, with specific evidence artefacts and pass/fail criteria for each item.

Technical Guides

DCC Levels Explained: How L0, L1, L2, and L3 Map to Contract Risk, and Which One You Actually Need

DCC has four levels: L0, L1, L2, and L3. Each maps to a Cyber Risk Profile tier set by the MOD for a given contract. This guide explains the differences between the levels in detail, how to determine which one your contract requires, the practical differences in assessment effort, and why most suppliers new to the scheme start at L0 or L1.