Protos Networks Achieves Defence Cyber Certification (DCC) Level 1

Darren Kewley
Darren Kewley
Technical Director
Published
4 August 2026
Share
LinkedIn logo X logo

Protos Networks is pleased to announce that we have achieved Defence Cyber Certification (DCC) Level 1. The certification recognises the security controls we have in place across the business and gives our customers, and the wider defence supply chain, confidence that we meet the standard the Ministry of Defence expects of its suppliers.

What is Defence Cyber Certification?

Defence Cyber Certification is the MOD’s cyber assurance scheme, delivered by IASME through its network of certification bodies. It was developed jointly by the Ministry of Defence and IASME to provide the defence sector with a consistent way to measure the cyber resilience of the organisations it works with. Increasingly, DCC is being written into defence contracts, so for many suppliers it is becoming a requirement rather than a nice-to-have.

The scheme is built on Defence Standard 05-138 and runs across four levels. Level 0 covers three controls, Level 1 covers 101 controls, Level 2 covers 139 controls, and Level 3 covers 144 controls. Every level starts with Cyber Essentials as the technical foundation, with Levels 2 and 3 also requiring Cyber Essentials Plus. Unlike many technical certifications, DCC assesses the resilience of the organisation as a whole, not just a single system or product.

The level you need is usually determined by the MOD risk level attached to your contracts, or set by your prime as a condition of working with them. You can also decide to achieve a particular level in your own right, for example, to demonstrate your security maturity and position yourself ahead of upcoming bids.

Stone government building facade with tall columns, seated statues and a plaque reading Ministry of Defence.

What Level 1 involves

Level 1 assesses the business against 101 controls, answered through 236 questions, covering areas such as governance, risk management, asset management, data protection, secure configuration, access control, and how you prepare for and respond to incidents. The important point is that Level 1 is not a paper exercise. You are expected to demonstrate that the controls are in place and working, not merely that a policy exists.

Protos already holds ISO 27001, and as a result, we met a good number of the DCC controls from day one. Our existing information security management system, policies and risk processes carried a lot of the weight. That said, ISO 27001 does not cover everything DCC asks for, and there were still a number of elements we needed to implement or evidence specifically for the scheme.

Those included implementing application allowlisting across our estate, so that software is blocked by default and only approved applications are permitted to run, carrying out reviews of the information about Protos that is publicly available and could be useful to an attacker, and documenting how government and MOD business flows through our organisation, including where that data sits and who has access to it. We also tightened areas such as asset inventories, secure configuration baselines and our incident response arrangements so that everything could be demonstrated in practice rather than just described. It was a useful exercise in its own right, and a good example of how a scheme like DCC can add real value on top of an existing standard.

We can help you achieve DCC

Protos Networks is a DCC Level 1 Certification Body, which means we can support customers across the whole journey. We can act as the assessor and certify your organisation against the standard, or we can work as the implementer and help you put the controls in place, ready for assessment by a Certification Body. Having just been through the process ourselves, we understand both sides of it and can help you implement many of the required controls, from application allowlisting and secure configuration through to the governance and documentation the scheme expects.

How the assessment works

The assessment is evidence-led. The applicant hosts the Assessment Submission Record (ASR) on their own infrastructure, for example, in SharePoint, and gives the Certification Body access to it. For each control, you provide an answer with evidence to support it. That evidence might be a screenshot, a PDF of a policy or procedure, a spreadsheet or a similar artefact, and for each piece, you also record the file hash so that the Certification Body can be confident the evidence has not been changed.

The assessment then runs in stages. You work through rounds of theoretical marking first, during which the Certification Body reviews your answers and evidence and provides feedback until the submission meets the standard. Only once that is complete do you move on to the practical assessment. For Level 1, this can be carried out fully remotely, whereas Levels 2 and 3 require on-site visits as part of the process.

You can read more about how we support Defence Cyber Certification on our Defence Cyber Certification service page.

If you supply the defence sector and want to understand what DCC means for your organisation, or you need help getting ready for assessment, we would be happy to help.

With thanks to C3IA, our Certification Body, for their support throughout the process.

Need Advice?

If you need any advice on this issue or any other cyber security subjects, please contact Protos Networks.

Email: [email protected]
Tel: 0333 370 1353