UK Defence Cyber Certification Level 0

Defence Cyber Certification

Defence Cyber Certification Level 0 is quickly becoming a priority for organizations across the UK Defence supply chain as the 31 December 2026 deadline approaches. But before you can secure and certify your environment, do you know every device connected to it?

The UK Ministry of Defence has asked Defence industry partners to achieve Level 0 of the Defence Cyber Certification (DCC) by 31 December 2026, including obtaining Cyber Essentials for all applicable business-critical systems within scope.

For organisations operating within the UK Defence supply chain, this creates an important question:
Do you actually know every device and hardware asset that forms part of the environment you are trying to secure and certify?

This is where Sepio can help.

Sepio does not replace Cyber Essentials, Defence Cyber Certification requirements, firewalls, endpoint protection, patch management, or the work of an accredited Defence Cyber Certification Body.

Instead, Sepio addresses an underlying challenge that can affect virtually every security programme:

You cannot effectively protect, assess, or continuously monitor an asset you do not know exists and identifying a device is not necessarily the same thing as knowing what it really is.

What is Defence Cyber Certification Level 0?

The Defence Cyber Certification scheme provides independent assurance of the cyber resilience of organisations participating in the UK Defence ecosystem.

Defence Cyber Certification has four levels, from Level 0 through Level 3. IASME describes Level 0 as the foundation level, normally associated with organisations assessed as presenting a very low level of cyber risk. It consists of three controls and requires organisations to demonstrate basic cyber-security practices.

Cyber Essentials is a prerequisite for DCC, with Cyber Essentials Plus required at higher DCC levels.

The MOD’s current Cyber Security Model is based on Defence Standard 05-138 Issue 4, which defines the cyber controls Defence suppliers are required to meet according to their Cyber Risk Profile. The standard applies to MOD procurements, suppliers, and relevant subcontract suppliers.

Importantly, organisations should confirm the exact DCC obligations applying to them with the MOD, their Prime contractor, and their Certification Body. IASME currently notes that DCC certification itself is not universally mandatory, even though the MOD has publicly asked industry partners to achieve Level 0 by the end of 2026.

Defence Cyber Certification Level 0 Starts with Understanding the Scope

This is where the Defence Cyber Certification discussion becomes particularly relevant to hardware visibility.

IASME’s Defence Cyber Certification guidance states that the scope of an assessment must include the processes, systems, and business parts required for the organisation to function and deliver securely and resiliently. Applicants are expected to establish their scope and provide evidence showing how relevant controls are being met.

Cyber Essentials starts from a similar premise.

The current Cyber Essentials Requirements for IT Infrastructure v3.3 explicitly instruct applicants to first:
establish the boundary of scope and determine what is inside that boundary.

Cyber Essentials defines scope as including the:
networks, hardware and software assets, and cloud services included in the assessment.

This sounds straightforward.

In modern environments, it often isn’t.

The Hardware Visibility Problem

Most organisations already have multiple technologies providing some form of asset visibility.

They may use:

  • CMDB platforms
  • Endpoint management
  • EDR
  • NAC
  • Vulnerability scanners
  • Network monitoring
  • Active discovery tools
  • Switch and router management systems

Yet these technologies frequently see the environment through different lenses.

An endpoint management system might know about managed computers.

A vulnerability scanner might know about IP-addressable systems.

A NAC solution might identify devices based on network attributes and authentication.

A CMDB may contain the assets organisations believe should be present.

But this still leaves an important question:
What about the hardware that does not behave like a conventional managed endpoint?

Examples can include:

  • Unmanaged network equipment.
    A small unmanaged switch or hub can be added somewhere inside an environment without becoming a traditionally managed network asset.
  • Dormant or low-communication devices.
    A device does not necessarily generate enough traffic at the right moment to make traffic-centric discovery complete.
  • Devices whose apparent identity differs from their underlying hardware.
    MAC addresses, IP addresses, protocol characteristics, and device-reported information can provide valuable context but they are not always sufficient to establish what physical device is actually connected.
  • Transparent or difficult-to-inventory hardware.
    Some devices may sit within the connectivity chain while exposing very little conventional network identity.
  • Peripheral and host-connected devices.
    Not every security-relevant hardware component is represented as a traditional network endpoint.

These aren’t necessarily malicious devices.

That distinction matters.

The issue is visibility and assurance. Before an organisation can make an informed risk decision about a device, it first needs to know the device exists.

Sepio hardware visibility overview dashboard
Sepio Visibility Overview

Cyber Essentials Itself Recognises the Importance of Asset Management

One particularly relevant point in the current Cyber Essentials guidance is that asset management is not itself one of the five Cyber Essentials technical controls.

However, the NCSC states that effective asset management can help organisations meet all five controls and should therefore be considered a core security function.

The five Cyber Essentials technical control areas remain:

  1. Firewalls
  2. Secure Configuration
  3. Security Update Management
  4. User Access Control
  5. Malware Protection

Sepio should therefore not be considered a substitute for the technologies that implement these controls.

Instead, Sepio can help organisations answer something fundamental beneath them:
What hardware are those controls expected to protect?

How Sepio Supports Defence Cyber Certification Level 0 Initiatives

Sepio provides hardware asset visibility and device identity intelligence across connected environments.

Rather than relying solely on network traffic analysis or what a device reports about itself, Sepio uses physical-layer characteristics and AssetDNA™ to help organisations understand the hardware connected to their infrastructure.

For organisations preparing for DCC and Cyber Essentials, Sepio can support several practical objectives.

1. Discover the Hardware Estate

Sepio can help identify connected assets across IT, OT, IoT, and other connected environments.

This can complement existing CMDB, NAC, vulnerability-management, EDR, and network-management systems by providing an additional hardware-centric view of the environment.

The objective is simple:
reduce the difference between the assets an organisation thinks it has and the assets that are actually connected.

2. Help Validate Device Identity

Discovery answers:
“Something is connected here.”

Identity verification asks a more difficult question:
“Is it really the device we believe it to be?”

Sepio’s AssetDNA™ technology uses physical-layer information to provide additional intelligence about device identity.

This can help organisations identify anomalies between expected and observed hardware characteristics rather than relying exclusively on logical identifiers such as a MAC address.

For Defence organisations adopting Zero Trust principles, this distinction can be important.

Trusting a device simply because it presents an expected identifier is fundamentally different from independently validating characteristics of the hardware itself.

3. Find Assets That Traditional Approaches May Overlook

Sepio can provide visibility into categories that can be difficult for traditional endpoint- or traffic-centric security tools to identify consistently, including certain:

  • unmanaged network devices
  • dormant devices
  • transparent hardware
  • unexpected infrastructure components
  • host-connected hardware and peripherals

This makes Sepio particularly useful as a complementary visibility layer, rather than another replacement inventory system.

4. Continuously Monitor Changes

Certification is performed at a point in time.

Infrastructure changes continuously.

Employees connect equipment.

Teams deploy new systems.

Devices are replaced.

Temporary equipment becomes permanent.

Network topology changes.

An organisation therefore needs more than an initial inventory exercise.

Sepio continuously observes the hardware environment and can identify when unexpected devices or hardware characteristics appear.

This can help organisations maintain awareness of changes to the estate after an initial DCC or Cyber Essentials assessment.

This is particularly relevant because IASME requires DCC-certified organisations to maintain their controls and scope between certification cycles, including annual attestation and Cyber Essentials recertification.

Sepio's Discovered Assets
Sepio’s Discovered Assets

From “Asset Inventory” to “Hardware Assurance”

There is an important distinction between maintaining a list of assets and having confidence in the hardware environment.

Consider these three questions:

What devices should be connected?
Your CMDB and inventory systems may answer this.

What devices are actually connected?
Continuous hardware discovery helps answer this.

Are those devices actually what we believe them to be?
Hardware identity validation adds another level of assurance.

Sepio’s value sits primarily around questions two and three.

This is why Sepio should be viewed as complementary to existing cybersecurity infrastructure rather than as a replacement for NAC, EDR, vulnerability management, SIEM, CMDB, or Cyber Essentials controls.

Supporting the Evidence Process

Defence Cyber Certification applicants are required to answer assessment questions, explain how controls are being met, and provide supporting evidence to their Certification Body. IASME specifically advises organisations to ensure evidence is readily available and clearly demonstrates implementation in practice.

Sepio-generated hardware intelligence can potentially contribute supporting information such as:

  • discovered device inventories
  • hardware classification
  • device identity information
  • hardware risk indicators
  • unexpected asset identification
  • changes in connected assets
  • network infrastructure observations
  • reporting around hardware anomalies

Whether particular Sepio output constitutes acceptable evidence for a specific DCC control remains a matter for the organisation and its accredited Certification Body.

That distinction is important.

Sepio provides data and technical visibility that can support compliance and assurance activities. It does not determine whether an organisation passes DCC certification.

Defence Cyber Certification Level 0 Is the Beginning, Not the End

There is another reason Defence suppliers should look beyond achieving the immediate Level 0 requirement.

DCC is risk based.

IASME currently describes the levels as progressing from:

  • Level 0 — 3 controls
  • Level 1 — 101 controls
  • Level 2 — 139 controls
  • Level 3 — 144 controls

As organisations progress into environments with higher Cyber Risk Profiles, the expectations around cyber-security governance, risk, resilience, and technical controls increase considerably.

Building an authoritative understanding of the technology estate early therefore has value beyond simply preparing for Level 0.

It establishes a foundation upon which stronger security controls can operate.

A Simple Question for Defence Suppliers

As organisations prepare for the 31 December 2026 Level 0 target, there will understandably be significant attention on assessment questions, Cyber Essentials certification, documentation, and evidence.

But there is a simpler question worth asking first:
Can you confidently identify every relevant device connected to the environment you are putting into scope?

And then:

Can you verify that those devices are actually what you believe them to be?
If the answer isn’t completely clear, there may be a hardware visibility gap.

That is where Sepio can help.

How Sepio Fits

Sepio is not a DCC Certification Body.

It does not certify organisations against DCC or Cyber Essentials.

Nor does it replace the five Cyber Essentials technical controls.

What Sepio does provide is a hardware-centric security layer that can help organisations:

  • Discover what is connected.
  • Understand what it is.
  • Validate its identity.
  • Identify unexpected hardware.
  • Continuously monitor the hardware estate.
  • Provide additional evidence and context for security and assurance teams.

In an environment where security increasingly depends on verified identity and continuous assurance, knowing that a device exists is only the beginning.

Don’t just trust what a device tells you.

Verify what it really is.

Sepio, extending Zero Trust to the hardware layer.

Talk to an expert. See What You’ve Been Missing.

Frequently Asked Questions

Defence Cyber Certification (DCC) Level 0 is the entry level of the DCC framework, designed to provide assurance that organizations meet foundational cybersecurity requirements. It is intended for organizations assessed as presenting a very low cyber risk and includes three core controls. Cyber Essentials is a prerequisite for DCC certification.

Yes. Cyber Essentials is a prerequisite for organizations seeking to achieve DCC Level 0. Higher DCC levels may require Cyber Essentials Plus.

Before an organization can protect and assess its environment, it must understand what assets are connected and within scope. Hardware visibility helps identify connected devices, including assets that may not appear in traditional inventory systems.

Examples include unmanaged network devices, dormant assets, transparent hardware, host-connected peripherals, and devices whose reported identity may not accurately reflect the underlying hardware.

Sepio helps organizations discover connected hardware, validate device identity, identify unexpected assets, and continuously monitor the hardware environment. It complements existing security and asset management solutions rather than replacing them.

No. Sepio is not a DCC Certification Body and does not certify organizations against DCC or Cyber Essentials. Sepio provides hardware visibility and device identity intelligence that can support security, compliance, and assurance efforts.

Yes. Sepio is designed to help identify connected hardware that may be difficult for traditional endpoint, network, or traffic-based discovery tools to consistently detect.

AssetDNA™ is Sepio’s technology that uses physical-layer characteristics to provide additional intelligence about device identity, helping organizations validate that connected hardware is what it claims to be.

Zero Trust relies on verifying trust rather than assuming it. Hardware visibility and device identity validation help organizations gain greater confidence in the devices connected to their environment.

Sepio can generate information such as device inventories, hardware classifications, device identity data, and hardware risk indicators that may support evidence-gathering activities. Whether specific evidence is acceptable remains a decision for the organization’s accredited Certification Body.

August 31st, 2026