Defence Cyber Certification Scope
Define the right assessment boundary from the outset and ensure your DCC certification reflects the essential functions, systems and services your organisation relies upon
Defining the DCC Scope
Your DCC scope defines which parts of your organisation will be covered by the certification. Unlike previous versions of the Cyber Security Model, DCC is not limited solely to systems handling MOD information or supporting a particular defence contract. It considers the functions, systems and services your organisation relies upon to operate securely and resiliently.
Getting the scope right is therefore fundamental to the certification process. It should accurately reflect your organisation and the activities relevant to the DCC assessment. Senior leadership, such as the CEO or CISO, should be aware of and understand the proposed scope to ensure it is appropriate and accurate.
Whilst KEYSIGMA will assist you with the scoping process, the applicant remains responsible for:
- Defining the scope of the assessment.
- Documenting the scope clearly and thoroughly.
- Responding to scheme questions and providing the required supporting evidence.
An incomplete or incorrectly defined scope may delay certification and require the scope or supporting evidence to be revisited.
What Should be in Scope?
The first step is to identify the organisation or legal entity, or entities, that will be covered by the certification.
However, this does not mean that every system, department or business activity must automatically be included. The scope should cover the services, functions, processes and systems that the organisation relies upon to operate securely and resiliently.
This will commonly include areas such as IT, identity and access management, communications, HR, finance, supply chain or stock management, backup and recovery, and other functions that are necessary to support continued business operations.
Conversely, systems or activities that are genuinely non-essential to the organisation’s ability to operate or deliver its services may fall outside the assessment scope. For example, a separately hosted public marketing website that is not used to deliver services, process sensitive information or support business operations may not need to be included.
The scope must include all processes, systems and parts of the business that are necessary for the organisation to function and deliver its services in a secure and resilient manner.
The Five Key Scoping Elements
People with access to in-scope systems, information or locations.
Operational Technology (OT)
If your organisation relies on Operational Technology (OT) as an essential part of its operations, those systems should be included within the DCC scope. For example, CNC machinery used continuously as part of a core production process would normally be in scope, whereas equipment used only occasionally for non-essential activities may be excluded.
The key consideration is whether the system is necessary for the organisation to operate securely and resiliently. If the business depends on it to deliver an essential function or service, it should form part of the DCC scope.
Where OT is included, some controls may not be capable of being applied directly because of technical or operational constraints. Organisations should implement the required controls wherever possible, but where a particular measure cannot be applied, the reason must be clearly explained.
For example, if anti-malware software cannot be installed on a CNC machine because of compatibility or operational limitations, the organisation should provide evidence of the alternative or compensating measures used to manage the associated risk. The Assessor will then determine whether those measures provide sufficient assurance against the relevant DCC requirement.
Cyber Essentials and DCC
Cyber Essentials is a prerequisite for every Defence Cyber Certification (DCC) level. Levels 0 and 1 require Cyber Essentials, while Levels 2 and 3 require Cyber Essentials Plus.
DCC and Cyber Essentials have different scoping principles. DCC considers the essential functions, services, systems and dependencies needed for an organisation to operate securely and resiliently, while Cyber Essentials focuses on internet-connected IT infrastructure.
Where practical, KEYSIGMA recommends using a whole-organisation Cyber Essentials or Cyber Essentials Plus scope, as this provides the clearest alignment between the two certifications. Where the scopes differ, all internet-connected devices and networks within the DCC scope must still be appropriately covered by the relevant Cyber Essentials certification.
Where multiple Cyber Essentials certificates are held, these can be considered collectively. The DCC Assessor will review both scopes and confirm that the relationship between them is appropriate and clearly documented.
Example DCC Company
How to Define Your DCC Scope
Start by identifying the functions and services your organisation relies on to operate securely and resiliently. For each one, consider whether it is essential and what systems, people, locations and dependencies support it.
These supporting elements should then be considered for inclusion within the DCC scope. Where something is excluded, the organisation should be able to clearly explain and document why it is not essential to its secure and resilient operation.
Worked Example: Defining a DCC Scope
to evaluate each function or service and assess its criticality to your organisation.
Technology (OT) into scope.
Statement of Scope
Your Statement of Scope should clearly document:
- The systems, services and functions that are included within and excluded from the DCC scope.
- The systems, services and functions covered by your Cyber Essentials or Cyber Essentials Plus certification.
- The rationale for significant inclusions and exclusions, including why any excluded areas are not essential to the organisation’s secure and resilient operation.
- Diagrams showing the relevant scope boundaries and how the DCC and Cyber Essentials scopes align.
- The sites and locations included within the scope and the functions performed at each.
DCC scope is not determined solely by where MOD data is held or processed. If processes, systems or services are essential for the organisation to operate securely and resiliently, they must be considered as part of the Defence Cyber Certification scope.
How KEYSIGMA Supports You
It is imperative that organisations consider their intended Defence Cyber Certification scope when preparing for, or applying for, Cyber Essentials or CE+.
KEYSIGMA will support your organisation throughout the Cyber Essentials process, ensuring your chosen scope is properly defined and aligned to your Defence Cyber Certification requirements.