Skip to main content
Defence Cyber Certification

How should an organisation prepare for DCC?

Bring your commercial requirement, organisational scope and evidence owners into one assessment plan.

1. Confirm the level and context.

Clarify what your MOD or prime-contractor contact expects and who owns that requirement internally. Record your target timeframe and any procurement dependencies. An early discussion can help distinguish a contractual requirement from an assumption.

2. Discuss scope before collecting evidence.

Use the current IASME scoping guidance with your assessor. Consider the systems and services that keep the organisation operating securely and resiliently. Identify shared platforms and supplier dependencies early.

For a large group, prepare a clear view of the legal entity structure and how shared services support the proposed boundary.

3. Assign owners and organise the evidence.

Use the applicant guidance for your target level. Match each requirement to an owner who can explain implementation and provide evidence. Review missing or inconsistent records before assessment.

Policies alone may not explain how controls operate. Prepare the relevant technical and organisational evidence for discussion with the assessor.

IASME applicant and scoping resources ↗

4. Agree the next step.

Bring your current certification status, scope questions and readiness concerns to the initial conversation. Assessment effort and any preparation support should be agreed against those facts.

DCC Level 0

Discuss the foundation-level route.

Explore Level 0 →

DCC Level 1

Plan broader control and evidence preparation.

Explore Level 1 →

← Back to the Knowledge Centre

Discuss your assurance requirements

Tell us about your organisation, scope and target timeframe. Start with a conversation with an experienced assessor.

Discuss your requirements →