JOSCAR reassessment cycles have become one of the most reliable forcing functions driving UK defence supply chain organisations toward ISO 27001. The scoring has tightened, the evidence requirements have become more specific, and the ongoing review burden has increased. Suppliers who treated JOSCAR as a once-every-three-years administrative exercise are finding their scores moving in unwelcome directions.
This piece covers what JOSCAR assessors actually look for in ISO 27001 evidence, how the scoring works in practice, what distinguishes a well-scored submission from a poorly-scored one, and the common mistakes defence suppliers make on reassessment.
What JOSCAR is and why it matters
JOSCAR, the Joint Supply Chain Accreditation Register, is the pre-qualification system used by UK defence, aerospace, and civil nuclear industries. It is operated by Hellios Information Limited on behalf of a consortium of buying organisations including BAE Systems, MBDA, Thales, Leonardo, Babcock, Rolls-Royce, Airbus, and the UK MOD directly. Around nine thousand suppliers hold JOSCAR registration at any given time.
The premise of JOSCAR is straightforward: rather than each prime running separate pre-qualification processes for the same suppliers, suppliers submit once to Hellios and their profile is accessible to all participating buyers. This reduces cost and duplication across the supply chain. For suppliers, JOSCAR is a gate. Organisations not on JOSCAR, or holding weak JOSCAR profiles, are excluded from a meaningful share of defence sector bid opportunities before the bid starts.
Reassessment is required every two years. Between reassessments, suppliers are expected to keep their profile current as circumstances change, with new certifications, insurance renewals, and material changes to the business reflected promptly. In practice, many suppliers update their profile only at reassessment and discover at that point how much has drifted.
How ISO 27001 fits into the JOSCAR assessment
JOSCAR assesses suppliers across multiple dimensions: finance, insurance, quality, environment, health and safety, modern slavery, cyber. The cyber section is where ISO 27001 evidence primarily feeds, though the standard also supports quality and governance scoring in secondary ways.
The cyber section is scored against a documented rubric. Suppliers can achieve scoring credit through Cyber Essentials, Cyber Essentials Plus, ISO 27001 certification, or equivalent management system standards. The scoring is not cumulative in a simple additive way (a CE Plus certificate plus an ISO 27001 certificate does not double the score) but the two together tell a stronger story than either alone, because they evidence both technical hygiene and management system maturity.
The highest cyber scores go to suppliers holding ISO 27001 certification with clean audit history, scope matching their defence work, and evidence of active ISMS operation. Lower but still passing scores go to suppliers holding CE Plus only. Suppliers holding no cyber certification fail the cyber section and typically fail the overall JOSCAR assessment.
This scoring has tightened over the last three years. The threshold for a passing cyber score has moved up. The weighting of ISO 27001 relative to CE Plus has increased. Primes participating in JOSCAR have pushed for this. They want their supply chain risk posture to strengthen, and they are using JOSCAR scoring to achieve that.
What assessors actually look at
JOSCAR assessors reviewing ISO 27001 evidence examine five things specifically.
They look at the certificate. They verify it against the UKAS-accredited certification body that issued it. They check the expiry date. They check whether the certificate is within surveillance or suspension status. A certificate technically valid but with a suspended surveillance audit is scored differently from a certificate with a clean surveillance record.
They look at the scope statement on the certificate. This is the single most important piece of evidence. A scope statement that reads "the provision of IT consultancy services from the head office" while the supplier's defence work is carried out at an engineering facility two hundred miles away is a scope that does not cover the relevant work. Assessors flag this. A scope that reads "all information security activities supporting the design, manufacture, and supply of [defence-relevant products] at all UK sites" is a scope that clearly covers the work. Assessors score this positively.
They look at the Statement of Applicability. Not every assessor reads every SoA in full, but scope ambiguity in the certificate triggers a closer SoA read. An SoA that excludes A.5.19 (supplier information security) while the supplier runs a subcontracting-heavy model raises questions. An SoA with clearly reasoned inclusion and exclusion decisions, and implementation status recorded per control, reads as a mature ISMS document.
They look at audit evidence. Specifically, they look at the last surveillance audit report. A clean surveillance audit with no major non-conformities, or with minor non-conformities that have been addressed, scores well. Major non-conformities, or a gap of more than thirteen months since the last surveillance audit, scores poorly and may trigger a fail.
They look at management engagement. This is harder to evidence at JOSCAR level because JOSCAR does not typically require management review minutes. But where a supplier submits supplementary material (board-level security reporting, executive security updates, evidence that the ISMS is a management-layer concern rather than a technical-layer one) it strengthens the submission.
The single most important piece of ISO 27001 evidence in a JOSCAR submission is the scope statement on the certificate. A scope that covers the defence work scores well. A scope that does not cover the defence work fails regardless of how good the underlying ISMS is.
The three most common reassessment failures
Three failure modes appear repeatedly in JOSCAR reassessment.
The first is scope drift. The business has changed since the certificate was first issued. New work is being done at new sites, by new teams, under contracts the certificate scope does not cover. The supplier did not update the scope at surveillance audit, because they did not want to trigger additional assessor attention. JOSCAR assessors spot this. They compare the supplier's stated commercial activity against the certificate scope and flag the mismatch. This is the single most common reason a previously-passing JOSCAR submission scores lower at reassessment.
The second is dormant ISMS. The certificate is technically current. Surveillance audits happen, get passed, and are never thought about in between. Internal audits happen because the auditor asks for them but do not drive meaningful change. Management reviews happen briefly once a year, documented lightly, and influence nothing. This can produce a certificate that passes its audit cycle but feels thin when assessor attention lands on it: the SoA has not been updated in three years, the risk register has three stale entries, the incident management process has no test evidence since 2023. JOSCAR scoring penalises this.
The third is poor supplementary evidence. The supplier submits only the certificate and scope statement. They do not provide the Statement of Applicability, the last surveillance audit report, or any indication that the ISMS is operational. This is a missed opportunity. The scoring rubric rewards evidence depth, and a supplier who provides thin evidence is scored on thin evidence. Providing more does not trigger deeper scrutiny; it demonstrates maturity.
What high-scoring submissions look like
Suppliers who score well at JOSCAR reassessment share common characteristics.
Their ISO 27001 scope matches their current business. Where the business has changed since the last certification cycle, scope extension has been handled at the next surveillance audit rather than deferred. The certificate in the submission is the certificate that covers the work.
Their Statement of Applicability is a living document. Control decisions are reviewed at least annually. The SoA includes implementation status per control, not just applicability status. Changes are dated. A reviewer can see the document is being maintained.
Their audit history is clean. Where minor non-conformities have been raised, they are visible in the audit report with documented corrective action. Where surveillance audits have been held, they are on cycle: thirteen months apart, not eighteen.
Their governance is visible. The JOSCAR submission includes evidence beyond the certificate: management review meeting records, board-level security reporting, risk register summaries. This is not always required, but it is always rewarded.
Their CE Plus is current and layered. Holding both CE Plus and ISO 27001 evidences both technical hygiene and management system maturity. Assessors treat this combination as materially stronger than either alone. The distinction between the two is worth understanding in its own right; ISO 27001 vs Cyber Essentials Plus: What Really Differs covers the practical comparison.
Preparing for reassessment
Reassessment happens every two years on a known schedule. The preparation window should be at least twelve weeks, ideally longer.
In the twelve weeks before reassessment, the minimum effective preparation is: a scope review against current business activities, with any scope extension triggered at the next surveillance audit if needed; a Statement of Applicability review, with the SoA refreshed to reflect current reality; a governance evidence package prepared, including recent management review records and any material security decisions; and a supplementary evidence package prepared, including the last surveillance audit report and documentation of any material improvements made in the review period.
For suppliers with ISMS rigour below this standard, the twelve-week window is not enough. Sustained rebuild of ISMS operational rhythm takes closer to six to nine months. This is why the most effective preparation for JOSCAR reassessment is not a pre-reassessment sprint but an ongoing ISMS cadence: the reassessment finds the ISMS in good order because the ISMS was already in good order.
Many defence suppliers use the period immediately after their first ISO 27001 certification to establish this cadence. Monthly security governance meetings. Quarterly risk register reviews. Annual full internal audits and management reviews. Staff awareness refreshed annually. The ISO 27001 Implementation service we run deliberately extends into an Ongoing Support phase for this reason: certification without operational rhythm is a certificate that struggles at first reassessment.
Closing
JOSCAR reassessment is not a binary pass-or-fail event. It is a scored evaluation where the scoring rubric rewards evidence depth, scope fidelity, and demonstrated ISMS maturity. Suppliers who treat ISO 27001 as a management discipline (scope calibrated to actual work, SoA maintained as a living document, governance rhythm visible in the evidence) score well. Suppliers who treat ISO 27001 as an annual administrative exercise score progressively worse as the rubric tightens.
The most effective preparation for JOSCAR reassessment is ongoing ISMS operation, not pre-reassessment sprint. Where sustained operation has not happened, reassessment will surface the gap.
If you are approaching JOSCAR reassessment and want a practitioner-led review of your ISO 27001 evidence before you submit, we offer scoped pre-reassessment reviews designed for defence suppliers in this position.
