Logo Transparent
DCC FAQ

Defence Cyber Certification FAQs

Answers to common questions about Defence Cyber Certification, DefStan 05-138 Issue 4, assessment, scope and certification. KEYSIGMA provides independent DCC assessment and certification across Levels 0, 1, 2 and 3.

About Defence Cyber Certification

DCC Defence Cyber Certification DefStan 05-138 Issue 4

DCC was developed by the Ministry of Defence (MOD) and IASME to provide independent assessment and certification against DefStan 05-138 Issue 4. The standard was first published in May 2024 and introduced a broader, organisation-wide approach to cyber security and resilience for defence suppliers.

The DCC scheme launched in May 2025, giving suppliers a formal way to demonstrate that they meet the cyber security controls required at the relevant level.

DCC Defence Cyber Certification Contracts

This will be decided by the MOD. However, any organisation can apply for certification, whether they are a current defence contractor or not.

DCC Defence Cyber Certification Mandatory

Defence Cyber Certification (DCC) is currently not mandatory across the defence supply chain. IASME confirms that organisations can still tender for MOD contracts through the normal procurement process without holding DCC certification.

However, the Ministry of Defence has asked all industry partners to achieve DCC Level 0 certification by 31 December 2026, including obtaining Cyber Essentials for all applicable business-critical systems within scope.

While this is not currently a universal mandatory requirement, it represents a clear direction of travel from the MOD. Individual contracts and Prime Contractors may also specify a particular DCC level as a requirement, depending on the cyber risk associated with the work.

DCC Defence Cyber Certification BenefitsDCC certification can cover multiple defence contracts within the certified scope, reducing the need for separate assessments for each contract.

It also introduces practical security controls that help strengthen your cyber security, improve resilience and provide greater assurance to customers and partners.

Cyber Essentials Ring
There are no prerequisites beyond Cyber Essentials. For DCC Levels 0 and 1, you must hold and commit to maintaining Cyber Essentials certification for the duration of the DCC certificate. For Levels 2 and 3, you must hold and maintain Cyber Essentials Plus certification for the duration of the DCC certificate.

 Each DCC level reflects the degree of cyber risk associated with a supplier’s role in the MOD supply chain. Organisations can apply for certification at any level, even where they are not currently delivering an MOD contract.

  • Level 0 – 3 controls: Very low risk. Covers foundational cyber security and resilience requirements.
  • Level 1 – 101 controls: Low to moderate risk. Requires a broader and more comprehensive cyber security programme.
  • Level 2 – 139 controls: High risk. Requires advanced security governance, planning and organisational controls.
  • Level 3 – 144 controls: Substantial risk. Requires mature, expert-level cyber security capabilities and a strong defence-in-depth approach.

Levels 0 and 1 require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus.

 Defence Cyber Certification DCC Sequential Certification

No. You can apply for certification at any DCC level without first completing the lower levels.

Yes. DCC certification is available to organisations based outside the UK, provided they can meet the requirements of the scheme and complete the relevant assessment process.

Defence Cyber Certification DCC Classified Data

DefStan 05-138 Issue 4 no longer addresses data classification, as its primary focus is now on whole organisation security and resilience. DCC holders may be subject to further requirements, such as a Security Aspects Letter, depending on the specific needs of the MOD contract.

DCC Assessment & Certification

DCC Certification ProcessOnce you know the DCC level you need, KEYSIGMA can guide you through the certification process from scoping to assessment.

This typically involves:

  • Reviewing your organisation and agreeing the correct assessment scope.
  • Completing your Statement of Scope.
  • Preparing for the assessment and gathering the required evidence.
  • Completing the independent DCC assessment with KEYSIGMA.
  • Addressing any findings before certification is issued.

If you are unsure which level applies or how to define your scope, speak to us and we can help you understand the next steps.

Defence Cyber Certification DCC Recertification

You must re-certify annually to Cyber Essentials/Cyber Essentials Plus and every three years to DCC. You must also complete an annual attestation that you are meeting and maintaining the controls and your scope has not significantly changed.

Defence Cyber Certification DCC Level Upgrade

No. If you wish to move to a higher DCC level, you will need to complete an assessment against the full requirements of the new level. The assessment cannot be limited to only the additional or changed controls between your current and desired level.

However, assessments at multiple levels can be run in parallel. For example, an organisation may be assessed against Levels 1, 2 and 3 at the same time.

Defence Cyber Certification DCC MOD SAQ

Yes, although there may be small differences due to the syncing of different updates and versions.

Defence Cyber Certification DCC Scoring PhasesDCC assessments have two phases: Theoretical and Practical.

The Theoretical phase allows you to explain how you meet each control and provide supporting evidence, with an opportunity to clarify any issues identified by the Assessor.

The Practical phase verifies that the controls are actually implemented and operating as described, and determines the final assessment outcome.

Defence Cyber Certification DCC Guidance

KEYSIGMA can provide guidance throughout the assessment process to help you understand the intent of individual questions and controls. The DCC Applicant Guides also include detailed explanations and example responses to support you.

The Theoretical Scoring phase is designed to identify any questions that may have been misunderstood or answered incorrectly. Where appropriate, you may be given the opportunity to clarify or update your response before progressing to the Practical Scoring phase.

Defence Cyber Certification DCC TimescaleThere is no fixed timescale for DCC certification, as the duration will depend mainly on:

  • How well prepared you are for assessment.
  • Whether any gaps need to be addressed before the Practical Scoring phase.
  • The complexity and scope of your organisation.

KEYSIGMA will agree a clear assessment plan with you at the outset and work with you to keep the process moving efficiently.

Defence Cyber Certification DCC Sample Sizes

During the Practical Assessment, KEYSIGMA will select a sample of relevant users, systems, devices or other evidence to verify that controls are operating effectively across the organisation.

Sample sizes follow the DCC assessment methodology and GovAssure principles. Samples are selected by the Assessor, and additional samples may be requested where further assurance is required.

KEYSIGMA provides DCC certification across Levels 0, 1, 2 and 3, giving you a single Certification Body as your requirements develop.

Our experienced cyber security assessors focus on making the certification process clear, efficient and straightforward, with practical communication throughout your assessment.

As specialists in Cyber Essentials, Cyber Essentials Plus and defence cyber security, we understand both the technical requirements of DCC and the pressures faced by organisations working within the defence supply chain.

We aim to provide a professional, responsive assessment experience while maintaining the independence and impartiality required by the scheme.

Defence Cyber Certification DCC Documentation

KEYSIGMA will provide you with the relevant DCC guidance and documentation throughout your certification journey.

Official scheme documentation includes:

  • An overview of the DCC scheme
  • Scoping guidance
  • Process guidance
  • Applicant guidance

Where required, we will also direct you to the relevant official IASME guidance.

Reach out to KEYSIGMA, who will initiate the process by setting you up on the assessment portal.

info@keysigma.co.uk. 

Defence Cyber Certification DCC Scope Change

Routine organisational, personnel or network changes would not normally require recertification. However, if you make a significant change that could materially affect your certified scope, you should contact your Certification Body so they can confirm whether any further assessment is required.

DCC Certification Scope

DefStan 05-138 Issue 3 vs DefStan 05-138 Issue 4.

DefStan 05-138 Issue 3 and CSMv3 focused primarily on protecting MOD Identifiable Information.

DefStan 05-138 Issue 4 and CSMv4 take a much broader approach, focusing on the security and resilience of the organisation as a whole. This means DCC assesses wider organisational, technical and operational controls rather than only those directly associated with specific MOD information.

Defence Cyber Certification DCC ScopeYour DCC scope should include the essential functions, systems and services your organisation relies on to operate securely and resiliently. Non-essential areas can generally be excluded.

You will need to document clearly what is included and excluded, how the scope aligns with your Cyber Essentials or Cyber Essentials Plus certification, and the reasons behind your scoping decisions.

As part of the assessment, KEYSIGMA will review and challenge the proposed scope to make sure it is logical, clearly defined and appropriate for certification.

Defence Cyber Certification DCC Levels Scope

No. Your DCC scope should remain consistent across all certification levels. The systems, services and functions considered essential to your organisation’s secure and resilient operation do not change simply because you are being assessed at a different level.

Defence Cyber Certification DCC Sensitive Data Networks

No. DCC takes a broader organisational approach. Your scope should include the systems, services and functions essential to your organisation’s secure and resilient operation, whether they support MOD or non-MOD work.

Defence Cyber Certification DCC Large PLC

This will depend on how your organisation is structured. You may choose to certify the wider organisation or define a smaller legal entity, such as the UK arm of the business.

For large or complex organisations, we recommend discussing the proposed scope with KEYSIGMA before starting the assessment.

Defence Cyber Certification DCC and Cyber Essentials

Not exactly. Cyber Essentials and Cyber Essentials Plus focus specifically on internet-connected systems and networks, whereas DCC considers the broader security and resilience of the organisation.

However, any internet-connected systems within your DCC scope that fall within Cyber Essentials requirements must be covered by the relevant Cyber Essentials or Cyber Essentials Plus certification.

KEYSIGMA will review both scopes during the assessment to confirm they align appropriately.

Defence Cyber Certification DCC Suppliers

Your suppliers themselves do not necessarily become part of your certification scope. However, the policies, processes and controls you use to manage and oversee supplier risk must be included where relevant.

Defence Cyber Certification DCC Subsidiary

There are two possible approaches.The wider organisation can be included within the DCC scope, or the services it provides can be treated in the same way as an external supplier service.

Whichever approach is taken, any DCC controls delivered through those services must still be demonstrated as effective, and supporting evidence from the parent organisation may be required.

Using a third party does not remove the requirement to meet the control. Where an MSP or other supplier delivers part of a control on your behalf, you must still demonstrate that the requirement is being met.

The Assessor may therefore need supporting evidence from the third party as part of the assessment.

Defence Cyber Certification DCC Cloud Services

Yes. If a cloud service is essential to your organisation’s operation, security or resilience, it should be included within the DCC scope.

This can include services such as cloud infrastructure, SaaS platforms, identity services, backup platforms and other critical hosted services.

Defence Cyber Certification DCC Multiple EntitiesYes. Multiple legal entities can be included within a single DCC certification, provided the entities and overall scope are clearly defined.

This can be useful for groups that share infrastructure, systems or services. Where separate certifications are required, multiple assessments may also be able to make use of shared evidence where appropriate.

Defence Cyber Certification DCC OT

If operational technology is essential to your organisation’s operation, it should be included within the DCC scope.

It is recognised that some DCC controls may not be directly applicable to OT environments. In these circumstances, appropriate compensating controls may be considered by the Assessor.

Defence Cyber Certification DCC Scope Change

Routine organisational, personnel or network changes would not normally require recertification. However, if you make a significant change that could materially affect your certified scope, you should contact your Certification Body so they can confirm whether any further assessment is required.

Cost

DCC CostThere are no standardised DCC assessment fees, as the cost will depend on the level required and the size, complexity and scope of your organisation.

Other factors can include your current security posture, how prepared you are for assessment and the amount of work required to complete the assessment.

KEYSIGMA will review your requirements with you and provide a clear, tailored quotation for the appropriate DCC level.