DCC Level 0 and Level 1 Audits

back to our services...


Defence Cyber Certification Level 0 and Level 1 assessment services for suppliers who need to book an audit, understand the route, and get a clear view of likely assessment cost.


DCC Level 0 and Level 1 Audits
Book a Defence Cyber Certification assessment with a clearer route, clearer cost assumptions, and fewer surprises. Punk Security provides DCC Level 0 and Level 1 audit services for suppliers who need certification evidence for MOD or prime contractor requirements.
Build a DCC assessment quote

Assessment, not implementation

This page is for organisations that want to book or price the DCC assessment route itself.

If you need help getting ready, writing evidence, remediating gaps, or implementing controls before the audit, see our DCC support and implementation service.

Who this assessment is for

  • You have been asked for DCC Level 0 or Level 1 by MOD or a prime contractor.
  • You want to understand the likely assessment route before committing budget.
  • You need to include Cyber Essentials in the plan, or confirm that your existing certificate is enough.
  • You need Level 0 fixed-price assessment or a Level 1 quote based on scope, scoring effort, and site assumptions.
  • You want a short conversation with auditors before booking so the quote is based on sensible assumptions.

Why Punk Security

  • Security-cleared auditors who understand the expectations, handling standards, and trust needed in defence environments.
  • Defence sector experience across MOD, prime contractor, and supplier assurance expectations.
  • Strong customer experience: clear communication, practical next steps, and no vague requirement dumping.
  • Level 0 and Level 1 coverage, including Cyber Essentials, readiness gates, theoretical scoring, practical scoring, and certification issue.

Level 0 assessment

Level 0 is the lighter DCC route for very low assessed cyber risk. It is based on 3 controls and does not require an Assessment Submission Record.

The Level 0 assessment route covers:

  • Current Cyber Essentials certification.
  • Scope alignment between Cyber Essentials and the DCC assessment boundary.
  • Evidence against the 3 Level 0 controls.
  • A simpler assessment route than Level 1.
  • Fixed assessment pricing based on organisation size.

Level 1 assessment

Level 1 is for low to moderate assessed cyber risk. It is based on 101 controls and involves a broader assessment process, including scope, evidence, theoretical scoring, and practical scoring.

The Level 1 assessment route can include:

  • Cyber Essentials as the starting point.
  • Scope confirmation before the assessment progresses.
  • A readiness check so you can decide whether to continue or pause.
  • Review of the Assessment Submission Record and supporting evidence.
  • Theoretical scoring rounds.
  • Practical scoring, including site assumptions.
  • Certification issuing.
  • Optional management report and debrief.

Level 0 and Level 1 compared

Area Level 0 Level 1
Typical risk profile Very low assessed cyber risk Low to moderate assessed cyber risk
Control volume 3 controls 101 controls
Cyber Essentials Required Required
Scope effort Important, but usually concise Critical and often the biggest early task
Evidence depth Policy, register, mapping, and resilience evidence Broader evidence pack across the Level 1 controls
Assessment style Lighter audit route More detailed readiness, evidence, theoretical, and practical work
Cost risk Usually predictable Depends on scope, readiness, sites, and evidence quality

What the quote builder covers

Our DCC audit cost builder gives an indicative route before you speak to us.

It lets you choose:

  • Organisation size: micro, small, medium, or large.
  • Cyber Essentials status: already certified or need certification.
  • DCC level: Level 0 or Level 1.
  • Level 1 scoping support, where needed.
  • Level 1 template package, where needed.
  • Theoretical scoring rounds.
  • Practical scoring site assumptions.
  • Optional reporting and debrief.

For Level 0, the builder gives a fixed assessment price based on organisation size. For Level 1, the builder gives a working estimate because the final assessment effort depends on scope, evidence quality, scoring rounds, and site assumptions.

Open the DCC quote builder

What happens after you request a quote

  • The quote request includes your chosen DCC level, organisation size, Cyber Essentials position, Level 1 options, and cost summary.
  • We review the route and check whether the assumptions look sensible.
  • You can use the free 30-minute consultation to confirm the level, Cyber Essentials position, scope, site assumptions, and next step.
  • If Level 0 is the right route, the assessment can usually move forward on fixed pricing.
  • If Level 1 is the right route, we confirm scope and effort before the formal assessment work proceeds.
  • After a consultation, we can provide the Level 0 template pack referenced on the quote-builder page. Wider template implementation and gap fixing sits under DCC support and implementation.

Level 1 stages and exit points

Level 1 should not feel like a runaway project. The assessment route is staged so you can make sensible decisions before committing to the most expensive parts.

  1. Confirm the operational scope.
  2. Check readiness before going further.
  3. Exit if the organisation is not ready and needs support or implementation work.
  4. Score the evidence through theoretical scoring.
  5. Exit if the organisation cannot evidence compliance before practical scoring.
  6. Validate assumptions through practical scoring and site visits.
  7. Issue certification when the assessment outcome supports it.

What affects Level 1 cost

  • Scope arguments. DCC is organisation-level assurance, so support functions and critical operations can matter even when they are not the obvious MOD-facing system.
  • Cyber Essentials mismatch. Cyber Essentials scope and DCC scope are not automatically identical, so the overlap needs to be explained.
  • Weak evidence ownership. Policies without owners, review dates, registers, screenshots, or operational proof rarely land well.
  • Personal data records. Many companies have GDPR policies but no usable record of processing, DPIA screening, or processor register.
  • Resilience evidence. Backups are often configured but not restored, tested, or mapped to business recovery expectations.
  • Level 1 site assumptions. Multiple sites, operational technology, production systems, or inconsistent locations can quickly change practical assessment effort.

What we need to quote or book the assessment

  • The level requested by MOD or your prime, if known.
  • Your current Cyber Essentials certificate and scope statement.
  • A list of key systems, sites, business functions, and suppliers.
  • Any existing policies, registers, risk assessments, DPIAs, backup records, and incident response documents.
  • Site assumptions for practical scoring.
  • A named contact who can answer scope and evidence questions.

Common assessment questions

Do we need Cyber Essentials first?

Yes. Cyber Essentials is the starting point for DCC. If you already hold it, the quote builder keeps that cost out of the total.

Why is Level 1 not a single fixed price?

Level 1 depends on scope, evidence quality, locations, theoretical scoring effort, practical scoring effort, and whether support is needed before formal assessment.

Can we stop after readiness or theoretical scoring?

Yes. The Level 1 route has decision points so you can pause if the organisation is not ready to continue.

What does the Level 1 issuing cost cover?

For Level 1, the certification issuing cost is fixed by organisation size and matches the Level 0 pricing bracket used in the builder.

Do all sites need to be visited?

Not always. If sites are genuinely similar, practical scoring may only need one representative visit, subject to final scope and assessment approach.

Can you help us get ready before assessment?

Yes, but that is a separate offer. See DCC support and implementation if you need readiness, evidence, remediation, templates, or hands-on implementation before the audit.

Useful references



DCC Level 0 and Level 1 Audits

Want to learn more?



WHAT OUR CLIENTS SAY

Townsend Music

Townsend Music

We initially reached out to Punk Security to help us out with our hosting architecture and were impressed with their breadth of knowledge.

With their expertise we were able to implement additional controls into AWS and successfully scale our systems. When we needed to gain more performance insights, their engineers configured our datadog platform end to end.

We’ve found that they really take the time to understand our problem and then put forward a great solution.

Knights

Knights

Our internal IT team were in need of expert consultancy to help us strengthen our cybersecurity measures and protect our sensitive data.

We engaged the services of Punk Security and were thoroughly impressed with the level of professionalism and knowledge they brought to the table.

The team was able to provide valuable insights and recommendations, and their guidance helped us implement effective security protocols that have greatly enhanced our overall security posture.

Parallel

Parallel

We originally sought Punk’s services to support us with a potential cyber-attack. The team responded immediately, out of hours, and calmly and professionally walked us through the necessary steps to determine that our environment hadn’t been compromised.

Since then, we have engaged Punk to carry out a third party audit of our cloud environment and a gap analysis against the Cyber Essentials and ISO270001 criteria. The team provided a thorough report with recommendations and are now working with us to improve our processes and systems.

I feel assured that we are walking towards best practice security operations.

MKM

MKM

Having attended a live hack demo held at C4DI we approached Punk Security to help sure-up our cyber security and DevOps processes. Punk not only completed this audit but passed on valuable gained knowledge to our team to broaden their skills and insight in this area.

We have since continued to work in partnership with Punk to implement a WAF and frequently consult their expertise in DevOps in relation to our application so we can all learn and grow in a collaborative way.

Punk are approachable, knowledgeable and also adept at explaining in layman’s terms for the less technical! We look forward to continuing our fruitful working relationship.

Illumio

Illumio

Our team at Illumio recently participated in a custom CTF event hosted by Punk Security, and it was a great experience! The CTF was not only challenging but also immensely educational, especially in the realm of cloud security principles.

The challenges presented during the CTF were designed to cover a broad spectrum of cloud security topics. This approach allowed our team to dive deep into practical scenarios that tested our skills and pushed us to explore new strategies and technologies. The balance between difficulty and learning outcomes was perfectly struck, ensuring that each team member, regardless of their prior level of expertise, found the event to be rewarding.

Friends of the Earth

Friends of the Earth

Punk Security were happy to perform external scans pro bono due to our status as an NGO.

The team also spent meeting time on two separate occasions to discuss our requirements and provide advice without any commitment or expectation. I’ll certainly be coming to Punk Security again in future should we need further security services

Sage

Sage

Punk Security provided exceptional DevSecOps training for our engineers here at Sage and delivered an outstanding talk at our Securing Sage Summit.

Their expertise and knowledge were evident throughout the sessions.

Not only were they efficient and great to work with, but their presentation was also the highest rated session of the entire event. We highly recommend Punk Security for any security-related needs.