Skip to main content
Defence

DCC versus Cyber Essentials

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

8 min read

Contents

    This is one of the most common questions from UK defence suppliers, and the honest answer is that it is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification. You do not pick one. You hold Cyber Essentials in order to be assessed for DCC at all.

    The question is entirely reasonable. Both schemes are run by IASME, both are UK government backed, both arrive in procurement documents, and nobody explains the relationship in the covering email. Here is the relationship.

    What IASME actually states

    From IASME's own DCC scheme pages, read on 1 September 2026:

    "All levels start with Cyber Essentials certification, with Levels 2 and 3 requiring Cyber Essentials Plus."

    And on prerequisites:

    "Other than Cyber Essentials or Cyber Essentials Plus, there are not."

    So the dependency runs one way and it is absolute. Level 0 and Level 1 need Cyber Essentials. Levels 2 and 3 need Cyber Essentials Plus.

    They are not measuring the same thing

    Once you stop treating them as alternatives, the more useful question is what each one actually looks at, because the scopes are genuinely different and this catches people out at assessment.

    Cyber EssentialsDefence Cyber Certification
    OwnerIASME, on behalf of NCSCThe Ministry of Defence, managed by IASME
    Assessed againstThe five technical controlsDefStan 05-138 Issue 4
    ScopeInternet-connected networks and systemsThe whole organisation, and the functions essential for it to operate
    LevelsOne, plus the audited Plus variantFour: Level 0, 1, 2 and 3
    Self-assessmentCyber Essentials is a self-assessed questionnaire, verifiedNone. No DCC level is self-assessment
    RenewalAnnuallyRecertify every three years, with an annual attestation
    SectorAny organisationUK defence supply chain, though anyone may apply

    The scope difference is the one that costs time. Cyber Essentials looks at internet-connected devices and systems. DCC looks at your whole organisation and everything essential to it operating securely and resiliently, which pulls in operational technology, cloud services essential to your business, and the policies by which you manage your own suppliers.

    IASME are explicit that the two scopes have to be reconciled rather than assumed to match: any internet-connected device or network inside your DCC scope must be covered by your Cyber Essentials or Cyber Essentials Plus certification, and the DCC assessor reviews both scopes to check they align.

    The four levels, and where Cyber Essentials Plus starts to bite

    Each level corresponds to the degree of cyber risk associated with a supplier's role in the MOD supply chain, and the control counts are published:

    • Level 0, 3 controls. Very low assessed risk. Basic practices, and the foundation for everything above it.
    • Level 1, 101 controls. Low to moderate assessed risk. A comprehensive programme with good practices.
    • Level 2, 139 controls. High assessed risk. Advanced oversight and planning. Cyber Essentials Plus required.
    • Level 3, 144 controls. Substantial assessed risk. Expert capability using defence in depth. Cyber Essentials Plus required.

    The jump from Cyber Essentials to Cyber Essentials Plus is not paperwork. Plus is technically audited by an assessor rather than self-assessed and verified, so if a Level 2 requirement is heading your way, that audit is on the critical path and it is often the longest lead item.

    The four levels are set out in more detail here, and what Level 2 adds over Level 1 has its own article, because the answer is not the thirty eight extra controls people expect.

    Does holding Cyber Essentials get you any of the DCC controls?

    Some evidence, yes. Compliance, no.

    IASME's position is direct: you can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls. So Cyber Essentials will furnish evidence for parts of a DCC submission. It will not discharge them, and no other certificate does either.

    Is any of this mandatory?

    No, and it is worth being precise about this, because the market is not.

    IASME's own FAQ states plainly that DCC is currently not mandatory, and separately that applicants may still tender for MOD contracts via the normal MOD process. Which contracts will require it is a matter for the MOD, and the level you need is decided by the MOD or by your prime rather than by you.

    Nobody is legally required to hold DCC. The belief that they are is an easy one to arrive at, because the MOD has asked industry to move and a request from your largest customer feels a great deal like an obligation. It is still worth separating the two, because a supplier who buys on the belief that it is compulsory has bought it for the wrong reason, even if they turn out to need it later for the right one.

    What to do, in order

    1. Get Cyber Essentials if you do not hold it. It is the gate to everything else and it is the cheapest thing on this list.
    2. Ask your prime or contracting authority which DCC level applies to you. They decide it, and the answer changes what you need to do next by a very large margin.
    3. If the answer is Level 2 or 3, start Cyber Essentials Plus now, because it is audited and it is a prerequisite.
    4. Scope before you buy anything else. DCC scope is your whole organisation, and it is where most of the cost variation sits.

    Goldline's DCC requirement and scope review exists for step 2 and step 4. Goldline is not a certification body and cannot certify DCC, which is a separate role held by assessors working for IASME-licensed certification bodies.

    Sources

    • IASME, Defence Cyber Certification scheme page, read 1 September 2026. Four levels with control counts of 3, 101, 139 and 144. "All levels start with Cyber Essentials certification, with Levels Two and Three requiring Cyber Essentials Plus." Point-in-time assessment against a UK Defence standard, organisation-level assurance, annual attestation and recertification every three years.
    • IASME, Defence Cyber Certification Frequently Asked Questions, read 1 September 2026. "Is DCC mandatory? DCC is currently not mandatory." "Applicants may still tender for MOD contracts via the normal MOD process, DCC is not mandatory at this stage." "Other than Cyber Essentials or Cyber Essentials Plus, there are not." "You can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls." "Are any levels self-assessment? No." Scope guidance on the alignment of Cyber Essentials and DCC scopes, and on the level being decided by the MOD or your prime.
    • DefStan 05-138 Issue 4 was first published as an advance, informational publication in May 2024, per the same IASME FAQ.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    Defence

    7 min read

    What DCC Level 2 Requires That Level 1 Does Not

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The obvious answer is thirty eight controls. The expensive answer is that you cannot upgrade, Cyber Essentials Plus becomes a prerequisite, and the assessor starts looking for governance.

    • Defence
    • DCC
    • DEFSTAN 05-138
    • Cyber Essentials
    Defence

    8 min read

    DCC versus JOSCAR

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One is a certification against a defence standard, owned by the MOD. The other is a commercially operated supplier data platform. Neither substitutes for the other, and different people decide whether you need each.

    • Defence
    • DCC
    • JOSCAR
    • Supply Chain
    Defence

    8 min read

    Choosing a DCC Certification Body

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.

    • Defence
    • DCC
    • Certification
    • DEFSTAN 05-138
    Defence

    9 min read

    Defence Cyber Certification: the four levels, and what each one actually asks

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The four levels, the control counts, and the three things that catch suppliers out.

    • Defence
    • DCC
    • DEFCON 658
    • DEFSTAN 05-138
    Defence Supply Chain

    11 min read

    DEFCON 658 Explained for UK Tier-2 and Tier-3 Defence Suppliers

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    DEFCON 658 explained for UK defence supply chain SMEs. What the clause requires, the five risk profiles, and the most common documentation mistakes.

    • DEFCON 658
    • Defence
    • DEFSTAN 05-138
    • MOD
    Defence Supply Chain

    12 min read

    DEFSTAN 05-138 Risk Profiling Explained: Very Low to Very High and What Each Means in Evidence

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    DEFSTAN 05-138 risk profiling explained. The five profiles from Very Low to Very High, evidence at each level, and the DCC relationship for UK defence SMEs.

    • DEFSTAN 05-138
    • Defence
    • DCC
    • ISO 27001

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.