DCC Level 0 by 31 December. Ready, not just registered.
The MoD has asked its defence industry partners to reach Defence Cyber Certification Level 0 by 31 December 2026. Goldline gets your evidence ready so an independent certification body can pass you first time.
- A free 45 minute diagnostic, not a sales call
- Your scope agreed before any evidence work starts
- A written readiness plan with owners and dates
- Run by a senior practitioner, not a coordinator
Loading the calendar
Open the booking pageCalendar not loading? Open Calendly directly
CISSP, ISO/IEC 27001 Senior Lead Implementer and Lead Auditor, ISO/IEC 42001 Lead Implementer and Lead Auditor, PMP.
The three Level 0 controls
Cyber Essentials
A current certificate covering the applicable internet-connected devices in your DCC scope, kept in place for as long as the certification or the contract runs.
UK GDPR
Documented data protection policies and procedures, and data protection impact assessments on the data you hold.
Resilience
An assessment of how resilient your systems need to be against attack and failure, with measures in place, such as backups and power protection.
All three must be fully met. There is no partial pass.
Scope is where most fail
DCC scope is the organisation's essential functions. Payroll, stock systems and any machinery the business depends on sit inside it, not only the systems that touch the defence contract.
A scope drawn too narrowly fails certification even when every control is met. Agreeing the scope is the first thing the diagnostic does.
How Goldline helps
Free 45 minute diagnostic
We agree your scope and establish where you stand against the three Level 0 controls.
Written readiness plan
Every gap written up as an action, with an owner and a date against it.
Producing what is missing
The GDPR policies and procedures, the data protection impact assessments and the resilience assessment.
Pre-submission check
A last read of the evidence pack before it goes to the certification body.
Goldline prepares you. An independent DCC-licensed certification body assesses and certifies, so nobody marks their own work. If a prime asks how your certificate was earned, that answer holds.
What comes next
Level 1 is the next step for suppliers handling sensitive information. It carries 101 controls, assessed objective by objective, and it builds on the same foundation you put in place for Level 0.
For suppliers heading further, read the ISO 27001 overview.
The diagnostic is free
Readiness support is scoped and priced at the diagnostic, by what your evidence needs, and fixed once agreed. Certification body fees are separate and paid to the body.
