← Field notesThe misread · 18 Sep 2026

DCC Level 0 is three controls. Level 1 is 101.

Defence Digital has asked industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026. A lot of suppliers are reading that as a security programme. It is not one.

Def Stan 05-138 Issue 4, which the certification maps to, sets four Cyber Risk Profiles.

  1. Level 0, Basic: 3 controls.
  2. Level 1, Foundational: 101 controls.
  3. Level 2, Advanced: 139 controls.
  4. Level 3, Expert: 144 controls.

Level 0 is Cyber Essentials covering the contract scope, GDPR-compliant processing, and resilience built into how you design and operate. Vulnerability management (control 2402), penetration testing (2403) and patch management (2405) start at Level 1.

So the first question is not what to buy. It is which profile your contracts actually require. That is set by the MOD project team under DEFCON 658 and written into the contract. It is worth checking before anything else, because the answer decides whether your next step is a certification body or a vulnerability programme.

If it is Level 0, the honest route is Cyber Essentials and a certification body. If it is Level 1 or above, the 31 December date is the least of it.

Sources: Def Stan 05-138 Issue 4 (control counts per Cyber Risk Profile, read at source). ISN 2026/02, DCC as assurance under DEFCON 658. MOD Defence Digital blog, 8 May 2026, quoting Eleanor Fairford, Director of Cyber Defence and Risk: "I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026."

Written by Ben Brand, Velinor. The method behind these notes runs as Picket by Velinor.

More notes