Skip to main content
Defence

DCC versus JOSCAR

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

8 min read

Contents

    Both turn up in UK defence procurement, both are often described as things a supplier "needs", and they are not comparable. One is a certification against a defence standard. The other is a shared supplier data platform. Neither substitutes for the other, and a supplier who assumes otherwise discovers it late.

    What each one actually is

    Defence Cyber Certification is a certification scheme owned by the Ministry of Defence and managed for the MOD by IASME through a network of licensed certification bodies. It assesses an organisation against DefStan 05-138 Issue 4, at one of four levels, and produces a certificate. IASME describe it as a point-in-time assessment against a UK Defence standard, giving a single organisation-level assurance that can be presented in support of UK Defence procurements.

    JOSCAR is a supplier data and pre-qualification platform operated commercially by Hellios for the defence, aerospace and security sector. Hellios describe it as a community of buying organisations working together to manage supply chain data, with a supplier questionnaire whose content the buyer members control. The published figures on their site are more than thirty buying organisations and more than six thousand suppliers.

    The difference in one line: DCC assesses your cyber security against a standard. JOSCAR collects and shares your supplier information with buyers who subscribe to it.

    Set against each other

    Defence Cyber CertificationJOSCAR
    OwnerThe Ministry of DefenceHellios, commercially
    What it isA certificationA supplier data platform and registration
    Assessed againstDefStan 05-138 Issue 4A questionnaire whose content the buyer members set
    CoversCyber security and organisational resilienceCyber, but also financial, quality, health and safety, ESG and carbon
    Who assessesAn assessor at an IASME-licensed certification bodyHellios validate submitted data
    OutputA certificate at Level 0, 1, 2 or 3Registration and a supplier record visible to buyer members
    Who asks for itThe MOD or your prime, contract by contractThe individual buying organisations who are members
    RenewalRecertify every three years, annual attestation, annual Cyber EssentialsOngoing, as a maintained record

    Does one get you the other?

    No, in both directions, and IASME say so directly for the DCC side: you can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls. A JOSCAR registration is not a certification at all, so it cannot.

    Going the other way, holding DCC does not register you on JOSCAR. It may well answer a good portion of the cyber section of the questionnaire, and a certificate is strong evidence in a data platform built to reduce duplication. That is a real efficiency and it is worth using.

    Which one do you need?

    The honest answer is that neither is decided by you, and they are decided by different people.

    JOSCAR is asked for by a specific buyer. If a prime you are bidding to is a JOSCAR member and their process requires registration, you need it for that relationship. If none of your buyers use it, it does nothing for you. Ask.

    The DCC level is decided by the MOD or by your prime. IASME's own FAQ says which contracts will require DCC is a matter for the MOD, and that the level required is decided by the MOD or your prime.

    So the same question answers both: ask the organisation actually asking you for something what they require. It is free, it takes one email, and it is the single most useful thing a supplier can do before spending money on either.

    Is either one mandatory?

    DCC is currently not mandatory, in IASME's own words, and applicants may still tender for MOD contracts via the normal MOD process. That is a customer instruction where it appears, not a legal requirement, and it is worth holding the distinction firmly because the market does not always.

    JOSCAR is a commercial platform. It is mandatory only in the sense that a particular buyer's process makes it a condition of doing business with that buyer.

    What they have in common, and why it matters commercially

    Both exist to solve the same underlying problem: a supply chain in which every buyer asks every supplier the same questions separately, and everybody pays for the duplication.

    JOSCAR solves it by pooling the answers across a buyer community. DCC solves it by producing a single organisation-level certificate that IASME state will cover all your contracts to the certified level, so one assessment covers multiple contracts rather than one per contract.

    That framing is useful when you are deciding whether either is worth the money. The value is not the badge. It is the assessments you stop repeating. If you are answering the same cyber questionnaire for four primes a year, the arithmetic is different from a supplier answering one.

    Where Goldline sits

    Goldline prepares organisations for DCC and helps establish which level a contract actually requires. Goldline is not a certification body, cannot certify DCC, and has no role in JOSCAR, which is Hellios's platform. Assessment for DCC is carried out by an assessor working for an IASME-licensed certification body, and choosing one has its own considerations.

    If you are earlier than this and working out which schemes apply at all, DCC and Cyber Essentials are related in a way that surprises people.

    Sources

    • IASME, Defence Cyber Certification scheme page and Frequently Asked Questions, both read 1 September 2026. DCC ownership by the MOD and management by IASME. Assessment against DefStan 05-138 Issue 4. Four levels. "Is DCC mandatory? DCC is currently not mandatory." "Applicants may still tender for MOD contracts via the normal MOD process." "You can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls." "Which contracts require the Defence Cyber Certification? This will be decided by the MOD." "How do I know the level I require for a contract? This will be decided by the MOD or your Prime." The single-assessment benefit: "This certificate will cover all of your contracts to the certified level, streamlining the process by requiring only one assessment to cover multiple contracts, rather than conducting separate assessments for each contract."
    • Hellios, JOSCAR product page, read 1 September 2026. Described as a platform for managing supply chain data for the defence, aerospace and security industry, with a buyer community whose members control the content of the supplier questionnaire. Published figures of more than thirty buyers and more than six thousand suppliers. Sustainability and carbon reporting modules are part of the same platform.
    • Individual buyer members are not listed here. The current membership is published by Hellios and is the authoritative source.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    Defence

    8 min read

    DCC versus Cyber Essentials

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    It is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification, and Cyber Essentials Plus for Levels 2 and 3. What each one actually measures.

    • Defence
    • DCC
    • Cyber Essentials
    • DEFSTAN 05-138
    Defence

    7 min read

    What DCC Level 2 Requires That Level 1 Does Not

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The obvious answer is thirty eight controls. The expensive answer is that you cannot upgrade, Cyber Essentials Plus becomes a prerequisite, and the assessor starts looking for governance.

    • Defence
    • DCC
    • DEFSTAN 05-138
    • Cyber Essentials
    Defence

    8 min read

    Choosing a DCC Certification Body

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.

    • Defence
    • DCC
    • Certification
    • DEFSTAN 05-138
    Defence

    9 min read

    Defence Cyber Certification: the four levels, and what each one actually asks

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The four levels, the control counts, and the three things that catch suppliers out.

    • Defence
    • DCC
    • DEFCON 658
    • DEFSTAN 05-138
    Defence Supply Chain

    11 min read

    JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    JOSCAR Stage 2 explained for UK tier-2 defence SMEs. The cyber security module, the evidence gaps, and the seven-question readiness checklist.

    • JOSCAR
    • Defence
    • ISO 27001
    • Cyber Essentials Plus

    9 min read

    JOSCAR ISO 27001 Requirements Explained

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    How JOSCAR assessors evaluate ISO 27001 evidence and what that means for defence supply chain bidders preparing for reassessment.

    • JOSCAR
    • ISO 27001
    • Defence

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.