Both turn up in UK defence procurement, both are often described as things a supplier "needs", and they are not comparable. One is a certification against a defence standard. The other is a shared supplier data platform. Neither substitutes for the other, and a supplier who assumes otherwise discovers it late.
What each one actually is
Defence Cyber Certification is a certification scheme owned by the Ministry of Defence and managed for the MOD by IASME through a network of licensed certification bodies. It assesses an organisation against DefStan 05-138 Issue 4, at one of four levels, and produces a certificate. IASME describe it as a point-in-time assessment against a UK Defence standard, giving a single organisation-level assurance that can be presented in support of UK Defence procurements.
JOSCAR is a supplier data and pre-qualification platform operated commercially by Hellios for the defence, aerospace and security sector. Hellios describe it as a community of buying organisations working together to manage supply chain data, with a supplier questionnaire whose content the buyer members control. The published figures on their site are more than thirty buying organisations and more than six thousand suppliers.
The difference in one line: DCC assesses your cyber security against a standard. JOSCAR collects and shares your supplier information with buyers who subscribe to it.
Set against each other
| Defence Cyber Certification | JOSCAR | |
|---|---|---|
| Owner | The Ministry of Defence | Hellios, commercially |
| What it is | A certification | A supplier data platform and registration |
| Assessed against | DefStan 05-138 Issue 4 | A questionnaire whose content the buyer members set |
| Covers | Cyber security and organisational resilience | Cyber, but also financial, quality, health and safety, ESG and carbon |
| Who assesses | An assessor at an IASME-licensed certification body | Hellios validate submitted data |
| Output | A certificate at Level 0, 1, 2 or 3 | Registration and a supplier record visible to buyer members |
| Who asks for it | The MOD or your prime, contract by contract | The individual buying organisations who are members |
| Renewal | Recertify every three years, annual attestation, annual Cyber Essentials | Ongoing, as a maintained record |
Does one get you the other?
No, in both directions, and IASME say so directly for the DCC side: you can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls. A JOSCAR registration is not a certification at all, so it cannot.
Going the other way, holding DCC does not register you on JOSCAR. It may well answer a good portion of the cyber section of the questionnaire, and a certificate is strong evidence in a data platform built to reduce duplication. That is a real efficiency and it is worth using.
Which one do you need?
The honest answer is that neither is decided by you, and they are decided by different people.
JOSCAR is asked for by a specific buyer. If a prime you are bidding to is a JOSCAR member and their process requires registration, you need it for that relationship. If none of your buyers use it, it does nothing for you. Ask.
The DCC level is decided by the MOD or by your prime. IASME's own FAQ says which contracts will require DCC is a matter for the MOD, and that the level required is decided by the MOD or your prime.
So the same question answers both: ask the organisation actually asking you for something what they require. It is free, it takes one email, and it is the single most useful thing a supplier can do before spending money on either.
Is either one mandatory?
DCC is currently not mandatory, in IASME's own words, and applicants may still tender for MOD contracts via the normal MOD process. That is a customer instruction where it appears, not a legal requirement, and it is worth holding the distinction firmly because the market does not always.
JOSCAR is a commercial platform. It is mandatory only in the sense that a particular buyer's process makes it a condition of doing business with that buyer.
What they have in common, and why it matters commercially
Both exist to solve the same underlying problem: a supply chain in which every buyer asks every supplier the same questions separately, and everybody pays for the duplication.
JOSCAR solves it by pooling the answers across a buyer community. DCC solves it by producing a single organisation-level certificate that IASME state will cover all your contracts to the certified level, so one assessment covers multiple contracts rather than one per contract.
That framing is useful when you are deciding whether either is worth the money. The value is not the badge. It is the assessments you stop repeating. If you are answering the same cyber questionnaire for four primes a year, the arithmetic is different from a supplier answering one.
Where Goldline sits
Goldline prepares organisations for DCC and helps establish which level a contract actually requires. Goldline is not a certification body, cannot certify DCC, and has no role in JOSCAR, which is Hellios's platform. Assessment for DCC is carried out by an assessor working for an IASME-licensed certification body, and choosing one has its own considerations.
If you are earlier than this and working out which schemes apply at all, DCC and Cyber Essentials are related in a way that surprises people.
Sources
- IASME, Defence Cyber Certification scheme page and Frequently Asked Questions, both read 1 September 2026. DCC ownership by the MOD and management by IASME. Assessment against DefStan 05-138 Issue 4. Four levels. "Is DCC mandatory? DCC is currently not mandatory." "Applicants may still tender for MOD contracts via the normal MOD process." "You can use other schemes to support or provide evidence required for DCC, but there are currently no certifications that give direct compliance with DefStan controls." "Which contracts require the Defence Cyber Certification? This will be decided by the MOD." "How do I know the level I require for a contract? This will be decided by the MOD or your Prime." The single-assessment benefit: "This certificate will cover all of your contracts to the certified level, streamlining the process by requiring only one assessment to cover multiple contracts, rather than conducting separate assessments for each contract."
- Hellios, JOSCAR product page, read 1 September 2026. Described as a platform for managing supply chain data for the defence, aerospace and security industry, with a buyer community whose members control the content of the supplier questionnaire. Published figures of more than thirty buyers and more than six thousand suppliers. Sustainability and carbon reporting modules are part of the same platform.
- Individual buyer members are not listed here. The current membership is published by Hellios and is the authoritative source.
