I’ve been involved with Defence Cyber Certification since before the scheme went live in May 2025. Since then, a few issues have kept appearing in assessment preparation and assurance discussions.
Most are ordinary operating problems. Organisations need to explain their scope, produce evidence showing that controls operate in practice, and establish who owns issues that cross several parts of the business. DCC gives those questions an independent test.
DCC is not yet universally mandatory across every MOD contract. There is, however, a clear direction of travel. In May 2026, MOD said it had asked all industry partners to achieve Level 0 DCC certification by 31 December 2026. This is an MOD-wide objective rather than a statement that every supplier is contractually required to hold Level 0 by that date. Individual tender and contractual requirements still determine what a supplier must hold for a particular requirement.
For organisations considering DCC, I would spend at least as much time looking at how the business operates as I would looking at the assessment requirements. These are the five areas I would concentrate on.
1. Start with how the organisation actually operates
One of the quickest ways to make DCC difficult is to draw the scope around the obvious MOD-facing systems and assume the job is largely done.
The organisation may rely on shared identity services, common infrastructure, cloud platforms, facilities, finance processes, suppliers or people sitting elsewhere in the business. Those dependencies matter when they are necessary for the organisation to operate securely and resiliently.
That does not automatically pull everything into scope. Non-essential elements can be excluded where the reasoning is logical, documented and defensible. The work is in understanding the dependencies well enough to make those decisions deliberately.
A useful scope exercise tells you more than which systems will be assessed. It gives you a clearer picture of the services the business depends on, what supports them and where somebody has consciously accepted a boundary.
2. Evidence needs to exist because the control operates
This is one of the issues I encounter most often. An organisation can be doing sensible things and still find independent assessment uncomfortable because there is very little reliable evidence left behind.
Access may be reviewed, backups tested, staff briefed and suppliers reviewed throughout the year. When an assessor asks for evidence, somebody can then end up searching email, finding screenshots, working out when a review happened and reconstructing what was done with the result.
“If I asked you to prove this tomorrow, what would you show me?”
Where controls are operating well, the evidence tends to appear naturally. Reviews leave records, testing produces results, remediation can be followed through, and decisions or exceptions have owners attached to them. Where that evidence has to be recreated shortly before assessment, the organisation is relying heavily on people’s recollection.
That creates work for the assessment and leaves leadership with a weaker view of whether the organisation is operating as intended.
3. Cyber Essentials has to be managed as part of the DCC lifecycle
Cyber Essentials sits underneath DCC. The relevant Cyber Essentials baseline is required across the scheme, with Cyber Essentials Plus required at Levels 2 and 3.
The certification needs to be current, its scope needs to make sense alongside the DCC scope and renewal needs to be considered as part of the wider timetable. Changes elsewhere in the organisation can also affect whether the two scopes continue to line up sensibly.
Somebody needs to know the expiry date, understand the dependency and make sure scope changes are considered before they become an assessment issue. I would check the CE or CE+ scope, its validity and the DCC timetable together.
4. You can prepare before a contract forces the issue
An organisation does not need to wait until it has a particular MOD contract before applying for DCC certification, and it does not need to work sequentially through every lower level before seeking a higher one.
For a live requirement, MOD or the relevant Prime determines the level required. Organisations preparing ahead can choose the level they want to pursue. The MOD request that industry partners achieve Level 0 by 31 December 2026 adds a baseline objective, while requirements above Level 0 continue to depend on the relevant procurement and the assurance position the supplier chooses to build proactively.
MOD ISN 2026/02 states that DCC certification at a level equal to, or greater than, the requirement satisfies that requirement, subject to individual procurement requirements, validity and appropriate scope.
This gives suppliers a practical choice about how far ahead of individual procurements they want to prepare. Certification alone does not make a supplier eligible for every opportunity; individual procurements can contain additional contractual, security or technical requirements.
5. Independent assessment changes the quality of the assurance conversation
DCC sits within a wider Cyber Security Model assurance architecture. The Supplier Assurance Questionnaire still has a role in the wider contractual process.
DCC adds independent examination of controls and the evidence supporting them. Showing an assessor how a control operates, producing current evidence and explaining how exceptions or remediation are handled requires a more developed operating discipline than completing a questionnaire alone.
An organisation with a clear scope, usable evidence and named owners can explain its assurance position more easily to customers and leadership. When circumstances change, it also has less work to do reconstructing what happened and who made the decision.
The certificate matters commercially, and the operating discipline required to support it remains useful when an assessor is not present.
Five questions before starting
- Can we explain the DCC scope and defend the material inclusions and exclusions?
- Can we produce current evidence showing that the controls we claim are actually operating?
- Is the relevant Cyber Essentials or Cyber Essentials Plus certification current and sensibly aligned with the DCC scope?
- Do we understand the MOD Level 0 objective and know which DCC level is required for our live contracts or deliberately chosen for future opportunities?
- Is one senior owner responsible for bringing the evidence, remediation, dependencies and certification activity together?
Clear answers do not guarantee an easy assessment, but they give you a much better starting point. If the answers are spread across several owners, different spreadsheets and evidence that has to be rebuilt from memory, I would want to understand that before setting an assessment date.
DCC Readiness / Evidence Check
I’ve put the five questions into a one-page readiness check you can use before independent assessment.
About the author
Paul Maxwell is an IASME Defence Cyber Certification Level 3 Assessor and has been involved with DCC since before the scheme launched.
