Defence Cyber
Certification (L0-L3).
Secure your position in the Ministry of Defence (MOD) supply chain. We guide defence contractors through the Defence Cyber Protection Partnership (DCPP) Cyber Security Model (CSM) from Level 0 to Level 3.
Understanding the DCC Levels.
The Ministry of Defence assigns a cyber risk profile to every contract. Depending on the sensitivity of the information you handle, your organization must comply with one of four specific risk levels (L0 to L3).
Baseline Defence
Required for contracts with minimal risk exposure. At this level, organizations must prove foundational hygiene to protect against basic, untargeted cyber attacks.
Minimum Requirements- Cyber Essentials (CE) Certification
- Completion of the L0 SAQ
Verified Baseline
For contracts handling moderately sensitive information. The MOD requires independent technical verification that your foundational controls are actively working.
Minimum Requirements- Cyber Essentials Plus (CE+) Certification
- Completion of the L1 SAQ
Advanced Governance
Required when handling highly sensitive or secret information. In addition to technical controls, organizations must demonstrate robust security governance, often mapping to ISO 27001 or NIST frameworks.
Minimum Requirements- Cyber Essentials Plus (CE+)
- Advanced SAQ (Governance & Policy Checks)
- Formal Incident Management Processes
Continuous Defence
Reserved for the most critical defence contracts. Suppliers must prove they can detect, resist, and respond to sophisticated, highly targeted nation-state threats on a continuous basis.
Minimum Requirements- All Level 2 Requirements
- Active Threat Hunting & Monitoring (SOC/SIEM)
- Penetration Testing & Vulnerability Management
- Complex SAQ with Evidential Audits
How we help you achieve compliance.
Risk Assessment (RA) Review
The MOD buyer will complete a Risk Assessment to define the required level (L0-L3). We help you interpret this requirement and scope your technical environment accordingly.
Gap Analysis & Remediation
We review your current security posture against the required Level. If gaps are found—whether in technical controls (like CE+) or governance policies—our engineers help you remediate them.
SAQ Completion & Evidence
We guide you through the Supplier Assurance Questionnaire (SAQ), ensuring responses are accurate and backed by solid evidence, guaranteeing smooth acceptance by the MOD.
IASME & Certification - Practical guidance for a more secure business
Small Business Compliance: GDPR & Cyber Essentials
How SMEs can navigate UK Cyber Essentials, Cyber Essentials Plus, and IASME Cyber Assurance standards smoothly with certified assessor guidance.
Read full briefing →A Beginner’s Guide to Security Awareness & Verification
Building strong human defences and technical controls required to satisfy government and defence supply chain certification audits.
Read full briefing →GDPR Compliance for SMEs: A Practical 90-Day Roadmap
A step-by-step 90-day framework to build audit-ready GDPR compliance, data mapping, and evidence controls without operational overhead.
Read full briefing →Why Modern Businesses Need Continuous Cyber Protection
One-off assessments are no longer enough. Here is why continuous cyber protection has become the baseline for organisations serious about security.
Read full briefing →Ready to secure your Defence Cyber Certification?
Talk to our defence compliance experts about scoping your environment, preparing your SAQ, or achieving the required Cyber Essentials prerequisites.
Speak to an Expert → info@worldcomputing.co.uk