Logo Transparent

Defence Cyber Certification Level 3

The highest level of Defence Cyber Certification, designed for suppliers where there is a substantial level of assessed cyber risk.

DCC Level 3

The highest level of Defence Cyber Certification, requiring full compliance across all applicable Level 3 controls.

DCC Level 3 is the highest of the four DCC certification levels and is intended for organisations operating at a substantial level of assessed cyber risk. It requires expert cyber security capability and a mature defence-in-depth approach, demonstrating that security is embedded across people, processes, technology and resilience to protect against new and evolving threats. Assessment is undertaken against Def Stan 05-138 Issue 4.

DCC Level 3 at a Glance

Key facts about the highest level of Defence Cyber Certification.

144 Controls

DCC Level 3 assesses 144 security controls across the organisation, covering governance, technology, people, resilience and cyber risk management.

Cyber Essentials Plus

A current Cyber Essentials Plus certification is required for DCC Level 3, providing independently verified assurance that key technical security controls are implemented effectively.

Substantial Risk​

Level 3 is intended for organisations and contracts assessed as presenting a substantial level of cyber risk, requiring a significantly more mature security capability.

Defence in Depth

Level 3 expects organisations to apply defence in depth, combining multiple technical, procedural and organisational safeguards to protect against sophisticated and evolving cyber threats.

DCC Level 3 at a Glance

Key facts about the highest level of Defence Cyber Certification.

144 Controls

Comprehensive Cyber Assurance

DCC Level 3 assesses 144 security controls across the organisation, covering governance, technology, people, resilience and cyber risk management.

Expert-level cyber security

Cyber Essentials Plus

Verified Technical Security

A current Cyber Essentials Plus certification is required for DCC Level 3, providing independently verified assurance that key technical security controls are implemented effectively.
Learn More

Required and Maintained

Substantial Risk

Designed for the Highest Cyber Risk Profile

Level 3 is intended for organisations and contracts assessed as presenting a substantial level of cyber risk, requiring a significantly more mature security capability.
Highest DCC Cyber RIsk Profile

Defence in Depth

Multiple Layers of Protection

Level 3 expects organisations to apply defence in depth, combining multiple technical, procedural and organisational safeguards to protect against sophisticated and evolving cyber threats.
Protection against evolving threats

Certified to Assess at the Highest Level

KEYSIGMA is an authorised DCC Level 3 Certification Body, qualified to independently assess and certify organisations across DCC Levels 0–3.
DCC Defence Cyber Certification Level 3 Certification Body

Authorised under the IASME Defence Cyber Certification scheme

DCC Level 3 - Four Core Assessment Objectives

DCC Level 3 builds upon Cyber Essentials Plus and assesses your cyber security capability across four core objectives defined in Def Stan 05-138 Issue 4.

Managing Security Risk

Understand, Assess & Manage Risk

Demonstrate the governance, policies and processes used to understand, assess and systematically manage security risks across your networks, systems and data.

Governance, risk management, assets and supply-chain dependencies.

Protecting Against Cyber Attack

Prevent & Protect

Demonstrate proportionate security measures that protect the networks and information systems supporting your organisation's functions from cyber attack.

Preventative controls protecting systems, networks and data.

Detecting Cyber Security Events

Monitor & Detect

Demonstrate monitoring and detection capabilities that identify cyber security events affecting, or with the potential to affect, your functions and data.
Monitoring, logging, alerting and detection.

Minimising Cyber Incident Impact

Respond, Recover & Restore

Demonstrate incident response and recovery capabilities that minimise disruption and support the restoration of functions and data following a cyber security incident.
Incident response, recovery, continuity and restoration.

DCC Level 3 - Four Core Assessment Objectives

Managing Security Risk

Governance, risk management, assets and supply-chain dependencies.

Demonstrate how your organisation identifies, assesses and systematically manages security risks across its networks, systems, data, assets and supply chain. Establish clear governance, policies and processes to maintain visibility of critical dependencies, manage vulnerabilities and risks, and support informed security decisions.

Protecting Against Cyber Attack

Preventative controls protecting systems, networks and data.​

Demonstrate proportionate security measures that protect the networks and information systems supporting your organisation’s functions from cyber attack.

Detecting Cyber Security Events​​

Monitoring, logging, alerting and detection.

Demonstrate monitoring and detection capabilities that identify cyber security events affecting, or with the potential to affect, your functions and data.

Minimising Cyber Incident Impact

Protecting Against Cyber Attack

Demonstrate incident response and recovery capabilities that minimise disruption and support the restoration of functions and data following a cyber security incident.

Cyber Essentials Plus is a prerequisite for DCC Level 3 and must remain current throughout the period of certification.

The Cyber Essentials Plus scope must appropriately align with the DCC scope. All business units included within the DCC scope must be covered by Cyber Essentials Plus for the systems and networks to which the Cyber Essentials scheme applies. DCC may extend further, including systems that fall outside normal Cyber Essentials scoping rules.

As a Cyber Essentials Certification Body, KEYSIGMA can coordinate your Cyber Essentials Plus and DCC scoping from the outset, helping ensure the certifications align properly, reducing duplication and providing a smoother, more efficient assessment process.

Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. 

As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.

Getting the scope right is a critical part of DCC certification. Your scope should include the systems, services and business functions needed for your organisation to operate securely and resiliently. Defining this correctly at the outset helps avoid gaps, delays and the need to revisit the assessment later, and is crucial to ensuring your DCC certificate is suitable for, and accepted against, the MOD contracts your organisation is bidding for. As part of the assessment, your KEYSIGMA Assessor will review the proposed scope thoroughly to confirm it is appropriate and sufficiently covers the organisation being certified.

How is DCC Level 3 assessed?

Level 3 requires full compliance, ALL applicable Level 3 control must be fully met.

DCC Level 3 is independently assessed by a qualified DCC Assessor against Def Stan 05-138 Issue 4. It is an evidence-based assessment: your organisation must explain how each applicable control is met and provide evidence demonstrating that the required measures are implemented and operating effectively. Organisations can target Level 3 directly from the outset, Level 2 is not a prerequisite. However, Level 3 is extremely demanding, requiring 100% compliance with every required control.

For this reason, the current scheme uses a Level 2/3 hybrid assessment, with applicants assessed against the combined requirements. KEYSIGMA recommends pursuing both levels in parallel: if Level 3 is achieved, you receive Level 3 certification; if not, but the Level 2 threshold is met, we can still issue a Level 2 certificate and provide a Level 3 non-compliance report showing what remains to be addressed.

DCC Process

1. Theoretical Assessment

Your Assessor reviews your completed assessment responses, explanations and supporting evidence to determine how the Level 3 controls are being met.

Where evidence is incomplete or further context is required, the Assessor may request clarification or additional information before progressing to the Practical Assessment.

2. Practical Assessment

The Practical Assessment verifies that the controls described during the theoretical phase are actually implemented and operating effectively within your organisation.

The Assessor may examine systems, configurations, records, processes and other supporting evidence, as well as conduct walkthroughs or sample areas of the organisation to confirm that the required controls work in practice.

3. Certification

Once the required Level 3 controls have been successfully demonstrated, KEYSIGMA, as an authorised DCC Level 3 Certification Body, can issue your DCC Level 3 certificate.

DCC certification is valid for three years, subject to annual attestation, continued compliance with the applicable controls and maintaining the required Cyber Essentials Plus certification throughout the certification period.

Support or Certification

Keeping the Assessment Independent

To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.

To give you flexibility, KEYSIGMA offers two clear routes:

✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.

✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.

Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.

Support or Certification

Keeping the Assessment Independent

To protect the integrity of the scheme, DCC rules allow Certification Bodies to provide advice and identify gaps, but they cannot implement controls or carry out work that they will later assess.

To give you flexibility, KEYSIGMA offers two clear routes:

✔ Implementation Support – We can help you understand the requirements, identify gaps and implement the controls needed to meet the DCC standard. Your assessment would then be carried out independently by a trusted partner Certification Body.

✔ Independent Certification – If your organisation is ready for assessment, KEYSIGMA can independently assess you against the DCC requirements and, where successful, issue your certification.

Whether you need implementation support, independent certification, or both, KEYSIGMA can ensure the right expertise is in place while maintaining the impartiality required by the scheme.

Ready to Discuss DCC Level 3?

Schedule a free 30 minute consultation with a KEYSIGMA Defence Cyber Certification Specialist

Defence Cyber Certification FAQs

Defence Cyber Certification FAQs