There is one rule in this process that matters more than price, availability or reputation, and it is written into how the scheme works rather than into anybody's marketing.
The rule: your certification body can advise you or assess you, not both
IASME state it directly. A certification body can assist with identifying gaps in your compliance, however, if they are also acting as your DCC Assessor, they cannot be involved in implementing or managing your security defences. IASME describe their certification bodies as trained to support applicants in two distinct roles, providing implementation consultancy or assessing your DCC submission, and as fully aware of the boundaries between them.
Read that carefully, because it does two useful things.
It tells you the boundary is real, and that the people on the other side of it know exactly where it sits. You are not going to catch anyone out by asking about it.
It tells you the decision is yours to make early. A certification body that has helped you implement is a body that has spent its usefulness on the advisory side of the line. If you want their assessor, do not spend them on the build.
This is the same structural point that runs through independence in management system auditing: the party that built the thing is not the party best placed to judge it, and schemes that take assurance seriously write that separation into their rules rather than leaving it to conscience.
Where to find them
IASME publish a certification body search on the DCC scheme site. That is the authoritative list and it is the one to use. Certification bodies are licensed by IASME to offer assessment to the scheme, so a body that is not on the list cannot assess you for DCC, whatever else it can do for you.
IASME also state that there are enough certification bodies trained and available to offer all levels, and that they continue to train new assessors. If you are being told there is a shortage and you must commit today, check that against the search.
Six questions worth asking before you choose
1. Are you licensed for the level I need? Levels 0 to 3 exist and bodies are trained across them, but confirm rather than assume for Level 2 and Level 3 work.
2. Are you assessing me or advising me? The one question this whole article exists for. Decide which you want from them, and make sure you both know the answer before any work starts.
3. Do you have assessors with security clearance? IASME state that some certification bodies have assessors with security clearance and not all do. In most cases applicants are not expected to share sensitive material, because DefStan 05-138 Issue 4 focuses on overall security and resilience rather than data classification. Where you do need it, IASME say you can request an assessor with the appropriate clearance. So ask, but ask because your material requires it rather than as a proxy for quality.
4. How do you handle the two scoring phases? DCC has a Theoretical phase and a Practical phase. The Theoretical phase does not contribute to the final score, but it is where you supply context and evidence, and where the assessor may grant a clarification round to let you update responses or address gaps. A body that treats the Theoretical phase as a formality is wasting the most useful part of the process for you.
5. What is your availability? IASME are explicit that there is no defined timescale for certification, and that it depends on your preparedness, whether you need to remediate gaps before the Practical phase, and the availability of the certification body to carry out the assessment. That third one is entirely outside your control, so ask about it before you plan around a date.
6. How will you price this, and against what? IASME do not publish standardised costs, and say so: pricing varies with the size and complexity of your organisation, your current security posture, your proposed scope, your preparedness and the level you are seeking. Certification bodies work with applicants to determine pricing. So a quote should reference your scope. One that does not has been produced without knowing what it covers.
Scope is the variable you can influence before you call anybody
DCC scope is your whole organisation and the services and functions essential for it to operate, whether those functions serve MOD contracts or not. It does not change between levels. You must provide a scoping statement setting out what is in, what is out, how it aligns with your Cyber Essentials scope, and the reasoning, and IASME say the assessor will review and challenge your scope.
Two practical consequences. First, a scope you cannot explain is a scope that will cost you time in assessment. Second, this is the work with the largest effect on price, and it is the work you can do before choosing anybody.
For large or complex organisations, IASME recommend discussing scope with a certification body before starting. That is advisory work, so it is worth deciding first whether you want that body as your assessor.
What Goldline can and cannot do here
Goldline is not an IASME-licensed certification body, cannot assess DCC and cannot certify it at any level. That role belongs to assessors working for licensed certification bodies, and it is not a gap Goldline is quietly working around.
What Goldline does is the part that sits before the assessment: establishing which level your contracts actually require, getting the scope defensible, and closing gaps against the control set. The DCC requirement and scope review is the entry point, and published prices are on the pricing page.
If you are still working out whether any of this applies to you, DCC and Cyber Essentials are more closely related than the comparison suggests, and JOSCAR is a different thing again.
Sources
- IASME, Defence Cyber Certification Frequently Asked Questions, read 1 September 2026. "Can my Certification Body (CB) help me prepare for the assessment? Your CB can assist with identifying gaps in your compliance; however, if they are also acting as your DCC Assessor, they cannot be involved in implementing or managing your security defences. DCC CBs are trained to support Applicants in two distinct roles: providing implementation consultancy or assessing your DCC submission." Availability of certification bodies, security clearance of assessors, the Theoretical and Practical scoring phases and the clarification round, the absence of a defined certification timescale, the absence of standardised costs, and the scoping requirements including the assessor reviewing and challenging scope.
- IASME, Defence Cyber Certification scheme page, read 1 September 2026, for the delivery model through a network of assured certification bodies.
- DCC is currently not mandatory, per the same IASME FAQ.
