
DCC Level 0 and Level 1 are often underestimated in the realm of cyber compliance. On paper, they appear straightforward, showcasing basic controls and entry-level assurance. However, when thoroughly assessed, several issues emerge: the scope is unclear, responsibilities are undefined, controls are inconsistent, and evidence doesn’t align with reality. Furthermore, operational practices often don’t match the documentation. These challenges highlight the need for robust cyber compliance strategies, underscoring the role of a cybersecurity consultancy in enhancing DCC assurance. That’s where organisations often fail.
Our Defence Cyber Certification (DCC) services help UK defence suppliers achieve and maintain the cybersecurity credentials required to bid for and deliver Ministry of Defence (MOD) contracts. We guide organisations through the DCC framework—developed by the MOD in partnership with IASME, the scheme's Certification Authority—ensuring alignment with the Cyber Security Model (CSM) and the controls specified in Defence Standard 05-138 Issue 4.
Whether you need DCC Level 0 (3 controls plus Cyber Essentials), Level 1 (101 controls plus Cyber Essentials), Level 2 (139 controls plus Cyber Essentials Plus), or Level 3 (144 controls plus Cyber Essentials Plus), we support you from initial gap analysis through to point-in-time assessment by an Assured Certification Body. We help you understand your Cyber Risk Profile (CRP), obtain your Risk Assessment Reference (RAR), and navigate MOD contract conditions including DEFCON 658, which mandates Cyber Essentials Plus for most defence contracts.
Our team ensures your controls meet the five core technical requirements—firewalls, secure configuration, access control, malware protection, and patch management—and address the broader organisational, procedural, and governance controls needed for higher CRP levels. We also assist with flow-down obligations to subcontractors, Cyber Improvement Plans (CIP) where full compliance is not yet achieved, Self-Assessment Questionnaires (SAQ), and the handling of OFFICIAL-SENSITIVE information, while advising on ITAR and broader export control requirements affecting UK defence suppliers.
Whether you are a micro, small, medium, or large enterprise, or a prime contractor managing complex supply chains, we help you demonstrate cyber resilience, satisfy MOD procurement teams, and protect both MOD Identifiable Information and national security interests.
Black Kyte 17 delivers assurance-led DCC consultancy focused on ensuring your controls effectively work in practice, all while enhancing your cyber compliance. We don't just prepare you to meet minimum expectations; we equip you to withstand scrutiny in the realm of cybersecurity consultancy.
DCC Level 0 — Foundation
Establishes the baseline of cyber security awareness and control, essential for achieving cyber compliance.
- Clear understanding of risks
- Basic security controls in place, supported by cybersecurity consultancy
- Defined responsibilities
- Initial evidence of control application for DCC assurance
This is your entry point — but it still gets tested.
Moves beyond awareness into demonstrable control implementation for cyber compliance.
Controls are applied consistently, ensuring that responsibilities are embedded within the framework of cybersecurity consultancy.
Evidence is structured and repeatable, reinforcing DCC assurance.
Operational practices align with policy.
This is where weak implementations are exposed.

Organisations that:
- Need to meet DCC assurance requirements for supply chain participation
- Are entering regulated or government-linked ecosystems
- Want to build a solid, defensible cyber foundation through effective cybersecurity consultancy
- Need assurance that their controls actually work to ensure cyber compliance
Our lead auditors possess global recognition and are ex-military specialists with extensive experience in operational environments. They have a deep understanding of regulated and defence ecosystems, ensuring our focus is on DCC assurance — prioritizing assurance over mere compliance.
We don’t just prepare you for cyber compliance on paper; we equip you to withstand scrutiny in the real world.
DCC isn’t just about having controls in place; it emphasizes the importance of demonstrating that these controls are understood, applied, and effective for achieving cyber compliance. For businesses seeking DCC assurance, a thorough evaluation is essential. Start Your DCC Readiness Review with a trusted cybersecurity consultancy.
Black Kyte 17 Limited registered in England, company no. 1715944 at Suite A, Tollmere, Norwich Road, Scoulton, Norfolk, NR9 4NR, England
Copyright © 2026 Black Kyte 17 - All Rights Reserved.