Defence Cyber Certification Level 3
The highest level of Defence Cyber Certification, designed for suppliers where there is a substantial level of assessed cyber risk.
DCC Level 3 is the highest of the four DCC certification levels and is intended for organisations operating at a substantial level of assessed cyber risk. It requires expert cyber security capability and a mature defence-in-depth approach, demonstrating that security is embedded across people, processes, technology and resilience to protect against new and evolving threats. Assessment is undertaken against Def Stan 05-138 Issue 4.
DCC Level 3 at a Glance
Key facts about the highest level of Defence Cyber Certification.
144 Controls
DCC Level 3 assesses 144 security controls across the organisation, covering governance, technology, people, resilience and cyber risk management.
Cyber Essentials Plus
A current Cyber Essentials Plus certification is required for DCC Level 3, providing independently verified assurance that key technical security controls are implemented effectively.
Substantial Risk
Level 3 is intended for organisations and contracts assessed as presenting a substantial level of cyber risk, requiring a significantly more mature security capability.
Defence in Depth
Level 3 expects organisations to apply defence in depth, combining multiple technical, procedural and organisational safeguards to protect against sophisticated and evolving cyber threats.
DCC Level 3 at a Glance
Key facts about the highest level of Defence Cyber Certification.
144 Controls
Comprehensive Cyber Assurance
Expert-level cyber security
Cyber Essentials Plus
Verified Technical Security
Required and Maintained
Substantial Risk
Designed for the Highest Cyber Risk Profile
Highest DCC Cyber RIsk Profile
Defence in Depth
Multiple Layers of Protection
Protection against evolving threats
Certified to Assess at the Highest Level
KEYSIGMA is an authorised DCC Level 3 Certification Body, qualified to independently assess and certify organisations across DCC Levels 0–3.
Authorised under the IASME Defence Cyber Certification scheme
DCC Level 3 - Four Core Assessment Objectives
DCC Level 3 builds upon Cyber Essentials Plus and assesses your cyber security capability across four core objectives defined in Def Stan 05-138 Issue 4.
Managing Security Risk
Understand, Assess & Manage Risk
Governance, risk management, assets and supply-chain dependencies.
Protecting Against Cyber Attack
Prevent & Protect
Preventative controls protecting systems, networks and data.
Detecting Cyber Security Events
Monitor & Detect
Monitoring, logging, alerting and detection.
Minimising Cyber Incident Impact
Respond, Recover & Restore
Incident response, recovery, continuity and restoration.
DCC Level 3 - Four Core Assessment Objectives
Managing Security Risk
Governance, risk management, assets and supply-chain dependencies.
Demonstrate how your organisation identifies, assesses and systematically manages security risks across its networks, systems, data, assets and supply chain. Establish clear governance, policies and processes to maintain visibility of critical dependencies, manage vulnerabilities and risks, and support informed security decisions.
Protecting Against Cyber Attack
Preventative controls protecting systems, networks and data.
Demonstrate proportionate security measures that protect the networks and information systems supporting your organisation’s functions from cyber attack.
Detecting Cyber Security Events
Monitoring, logging, alerting and detection.
Demonstrate monitoring and detection capabilities that identify cyber security events affecting, or with the potential to affect, your functions and data.
Minimising Cyber Incident Impact
Protecting Against Cyber Attack
Demonstrate incident response and recovery capabilities that minimise disruption and support the restoration of functions and data following a cyber security incident.
Cyber Essentials Plus is a prerequisite for DCC Level 3 and must remain current throughout the period of certification.
The Cyber Essentials Plus scope must appropriately align with the DCC scope. All business units included within the DCC scope must be covered by Cyber Essentials Plus for the systems and networks to which the Cyber Essentials scheme applies. DCC may extend further, including systems that fall outside normal Cyber Essentials scoping rules.
As a Cyber Essentials Certification Body, KEYSIGMA can coordinate your Cyber Essentials Plus and DCC scoping from the outset, helping ensure the certifications align properly, reducing duplication and providing a smoother, more efficient assessment process.
Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for.
As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.
Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.
How is DCC Level 3 assessed?
Level 3 requires full compliance, ALL applicable Level 3 control must be fully met.
DCC Level 3 is independently assessed by a qualified DCC Assessor against Def Stan 05-138 Issue 4. It is an evidence-based assessment: your organisation must explain how each applicable control is met and provide evidence demonstrating that the required measures are implemented and operating effectively. Organisations can target Level 3 directly from the outset, Level 2 is not a prerequisite. However, Level 3 is extremely demanding, requiring 100% compliance with every required control.
For this reason, the current scheme uses a Level 2/3 hybrid assessment, with applicants assessed against the combined requirements. KEYSIGMA recommends pursuing both levels in parallel: if Level 3 is achieved, you receive Level 3 certification; if not, but the Level 2 threshold is met, we can still issue a Level 2 certificate and provide a Level 3 non-compliance report showing what remains to be addressed.
1. Theoretical Assessment
Your Assessor reviews your completed assessment responses, explanations and supporting evidence to determine how the Level 3 controls are being met.
Where evidence is incomplete or further context is required, the Assessor may request clarification or additional information before progressing to the Practical Assessment.
2. Practical Assessment
The Practical Assessment verifies that the controls described during the theoretical phase are actually implemented and operating effectively within your organisation.
The Assessor may examine systems, configurations, records, processes and other supporting evidence, as well as conduct walkthroughs or sample areas of the organisation to confirm that the required controls work in practice.
3. Certification
Once the required Level 3 controls have been successfully demonstrated, KEYSIGMA, as an authorised DCC Level 3 Certification Body, can issue your DCC Level 3 certificate.
DCC certification is valid for three years, subject to annual attestation, continued compliance with the applicable controls and maintaining the required Cyber Essentials Plus certification throughout the certification period.
Support or Certification
Keeping the Assessment Independent
To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.
To give you flexibility, KEYSIGMA offers two clear routes:
✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.
✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.
Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.
Support or Certification
Keeping the Assessment Independent
To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.
To give you flexibility, KEYSIGMA offers two clear routes:
✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.
✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.
Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.