Defence Cyber Certification FAQs
Answers to common questions about Defence Cyber Certification, DefStan 05-138 Issue 4, assessment, scope and certification. KEYSIGMA provides independent DCC assessment and certification across Levels 0, 1, 2 and 3.
About Defence Cyber Certification
DCC was developed by the Ministry of Defence (MOD) and IASME to provide independent assessment and certification against DefStan 05-138 Issue 4. The standard was first published in May 2024 and introduced a broader, organisation-wide approach to cyber security and resilience for defence suppliers.
The DCC scheme launched in May 2025, giving suppliers a formal way to demonstrate that they meet the cyber security controls required at the relevant level.
This will be decided by the MOD. However, any organisation can apply for certification, whether they are a current defence contractor or not.
Defence Cyber Certification (DCC) is currently not mandatory across the defence supply chain. IASME confirms that organisations can still tender for MOD contracts through the normal procurement process without holding DCC certification.
However, the Ministry of Defence has asked all industry partners to achieve DCC Level 0 certification by 31 December 2026, including obtaining Cyber Essentials for all applicable business-critical systems within scope.
While this is not currently a universal mandatory requirement, it represents a clear direction of travel from the MOD. Individual contracts and Prime Contractors may also specify a particular DCC level as a requirement, depending on the cyber risk associated with the work.

It also introduces practical security controls that help strengthen your cyber security, improve resilience and provide greater assurance to customers and partners.
There are no prerequisites beyond Cyber Essentials. For DCC Levels 0 and 1, you must hold and commit to maintaining Cyber Essentials certification for the duration of the DCC certificate. For Levels 2 and 3, you must hold and maintain Cyber Essentials Plus certification for the duration of the DCC certificate.

- Level 0 – 3 controls: Very low risk. Covers foundational cyber security and resilience requirements.
- Level 1 – 101 controls: Low to moderate risk. Requires a broader and more comprehensive cyber security programme.
- Level 2 – 139 controls: High risk. Requires advanced security governance, planning and organisational controls.
- Level 3 – 144 controls: Substantial risk. Requires mature, expert-level cyber security capabilities and a strong defence-in-depth approach.
Levels 0 and 1 require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus.
No. You can apply for certification at any DCC level without first completing the lower levels.
Yes. DCC certification is available to organisations based outside the UK, provided they can meet the requirements of the scheme and complete the relevant assessment process.
DefStan 05-138 Issue 4 no longer addresses data classification, as its primary focus is now on whole organisation security and resilience. DCC holders may be subject to further requirements, such as a Security Aspects Letter, depending on the specific needs of the MOD contract.
DCC Assessment & Certification

This typically involves:
- Reviewing your organisation and agreeing the correct assessment scope.
- Completing your Statement of Scope.
- Preparing for the assessment and gathering the required evidence.
- Completing the independent DCC assessment with KEYSIGMA.
- Addressing any findings before certification is issued.
If you are unsure which level applies or how to define your scope, speak to us and we can help you understand the next steps.
You must re-certify annually to Cyber Essentials/Cyber Essentials Plus and every three years to DCC. You must also complete an annual attestation that you are meeting and maintaining the controls and your scope has not significantly changed.
No. If you wish to move to a higher DCC level, you will need to complete an assessment against the full requirements of the new level. The assessment cannot be limited to only the additional or changed controls between your current and desired level.
However, assessments at multiple levels can be run in parallel. For example, an organisation may be assessed against Levels 1, 2 and 3 at the same time.
Yes, although there may be small differences due to the syncing of different updates and versions.

The Theoretical phase allows you to explain how you meet each control and provide supporting evidence, with an opportunity to clarify any issues identified by the Assessor.
The Practical phase verifies that the controls are actually implemented and operating as described, and determines the final assessment outcome.
KEYSIGMA can provide guidance throughout the assessment process to help you understand the intent of individual questions and controls. The DCC Applicant Guides also include detailed explanations and example responses to support you.
The Theoretical Scoring phase is designed to identify any questions that may have been misunderstood or answered incorrectly. Where appropriate, you may be given the opportunity to clarify or update your response before progressing to the Practical Scoring phase.

- How well prepared you are for assessment.
- Whether any gaps need to be addressed before the Practical Scoring phase.
- The complexity and scope of your organisation.
KEYSIGMA will agree a clear assessment plan with you at the outset and work with you to keep the process moving efficiently.
During the Practical Assessment, KEYSIGMA will select a sample of relevant users, systems, devices or other evidence to verify that controls are operating effectively across the organisation.
Sample sizes follow the DCC assessment methodology and GovAssure principles. Samples are selected by the Assessor, and additional samples may be requested where further assurance is required.
KEYSIGMA provides DCC certification across Levels 0, 1, 2 and 3, giving you a single Certification Body as your requirements develop.
Our experienced cyber security assessors focus on making the certification process clear, efficient and straightforward, with practical communication throughout your assessment.
As specialists in Cyber Essentials, Cyber Essentials Plus and defence cyber security, we understand both the technical requirements of DCC and the pressures faced by organisations working within the defence supply chain.
We aim to provide a professional, responsive assessment experience while maintaining the independence and impartiality required by the scheme.
KEYSIGMA will provide you with the relevant DCC guidance and documentation throughout your certification journey.
Official scheme documentation includes:
- An overview of the DCC scheme
- Scoping guidance
- Process guidance
- Applicant guidance
Where required, we will also direct you to the relevant official IASME guidance.
Reach out to KEYSIGMA, who will initiate the process by setting you up on the assessment portal.
info@keysigma.co.uk.
Routine organisational, personnel or network changes would not normally require recertification. However, if you make a significant change that could materially affect your certified scope, you should contact your Certification Body so they can confirm whether any further assessment is required.
DCC Certification Scope
DefStan 05-138 Issue 3 and CSMv3 focused primarily on protecting MOD Identifiable Information.
DefStan 05-138 Issue 4 and CSMv4 take a much broader approach, focusing on the security and resilience of the organisation as a whole. This means DCC assesses wider organisational, technical and operational controls rather than only those directly associated with specific MOD information.
Your DCC scope should include the essential functions, systems and services your organisation relies on to operate securely and resiliently. Non-essential areas can generally be excluded.
You will need to document clearly what is included and excluded, how the scope aligns with your Cyber Essentials or Cyber Essentials Plus certification, and the reasons behind your scoping decisions.
As part of the assessment, KEYSIGMA will review and challenge the proposed scope to make sure it is logical, clearly defined and appropriate for certification.
No. Your DCC scope should remain consistent across all certification levels. The systems, services and functions considered essential to your organisation’s secure and resilient operation do not change simply because you are being assessed at a different level.
No. DCC takes a broader organisational approach. Your scope should include the systems, services and functions essential to your organisation’s secure and resilient operation, whether they support MOD or non-MOD work.
This will depend on how your organisation is structured. You may choose to certify the wider organisation or define a smaller legal entity, such as the UK arm of the business.
For large or complex organisations, we recommend discussing the proposed scope with KEYSIGMA before starting the assessment.
Not exactly. Cyber Essentials and Cyber Essentials Plus focus specifically on internet-connected systems and networks, whereas DCC considers the broader security and resilience of the organisation.
However, any internet-connected systems within your DCC scope that fall within Cyber Essentials requirements must be covered by the relevant Cyber Essentials or Cyber Essentials Plus certification.
KEYSIGMA will review both scopes during the assessment to confirm they align appropriately.
Your suppliers themselves do not necessarily become part of your certification scope. However, the policies, processes and controls you use to manage and oversee supplier risk must be included where relevant.
There are two possible approaches.The wider organisation can be included within the DCC scope, or the services it provides can be treated in the same way as an external supplier service.
Whichever approach is taken, any DCC controls delivered through those services must still be demonstrated as effective, and supporting evidence from the parent organisation may be required.
Using a third party does not remove the requirement to meet the control. Where an MSP or other supplier delivers part of a control on your behalf, you must still demonstrate that the requirement is being met.
The Assessor may therefore need supporting evidence from the third party as part of the assessment.
Yes. If a cloud service is essential to your organisation’s operation, security or resilience, it should be included within the DCC scope.
This can include services such as cloud infrastructure, SaaS platforms, identity services, backup platforms and other critical hosted services.

This can be useful for groups that share infrastructure, systems or services. Where separate certifications are required, multiple assessments may also be able to make use of shared evidence where appropriate.
If operational technology is essential to your organisation’s operation, it should be included within the DCC scope.
It is recognised that some DCC controls may not be directly applicable to OT environments. In these circumstances, appropriate compensating controls may be considered by the Assessor.
Routine organisational, personnel or network changes would not normally require recertification. However, if you make a significant change that could materially affect your certified scope, you should contact your Certification Body so they can confirm whether any further assessment is required.
Cost

Other factors can include your current security posture, how prepared you are for assessment and the amount of work required to complete the assessment.
KEYSIGMA will review your requirements with you and provide a clear, tailored quotation for the appropriate DCC level.






















