Skip to main content
Defence

What DCC Level 2 Requires That Level 1 Does Not

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

7 min read

Contents

    The obvious answer is thirty eight controls, because Level 1 carries 101 and Level 2 carries 139. That answer is arithmetically correct and it is the least useful thing about the difference.

    Three other things change, and two of them cost far more than the extra controls.

    1. Cyber Essentials Plus becomes a prerequisite

    Levels 0 and 1 start with Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus.

    Plus is not a longer questionnaire. It is technically audited by an assessor, on your systems, which means a booked assessor, a sample of devices that actually pass, and remediation time if they do not. Where an organisation is moving from Level 1 to Level 2, this is frequently the longest lead item on the whole plan and it is the one people discover last.

    If a Level 2 requirement is anywhere on your horizon, Cyber Essentials Plus is the thing to start now rather than the thing to schedule after the DCC work.

    2. You cannot upgrade. You reassess.

    This is the finding worth the whole article, and IASME state it plainly in their own FAQ.

    Asked whether it is possible to upgrade a certificate level by assessing only the additional or updated controls between a current level and a desired level, IASME's answer is a single word: No.

    So moving from Level 1 to Level 2 is not an assessment of thirty eight new controls on top of work already accepted. It is a full assessment against all 139. Everything you evidenced for Level 1 is evidenced again.

    Two consequences follow, and they point in opposite directions.

    If you already know Level 2 is coming, certify at Level 2. There is no requirement to work up through the levels, and IASME confirm you can apply for any level without completing the lower ones first. Certifying at Level 1 first and Level 2 six months later means paying for two full assessments to reach one position.

    If you genuinely do not know, Level 1 is not wasted. The evidence, the scope statement and the practices are all reusable, even though the assessment is not. What you lose is assessment fees, not the underlying work.

    3. The risk framing changes, and so does what "good" looks like

    The levels are not a difficulty ladder for its own sake. Each corresponds to the degree of cyber risk associated with a supplier's role in the MOD supply chain, in IASME's published descriptions:

    • Level 1, low to moderate assessed risk. Requires a supplier to demonstrate a comprehensive cyber security programme with good practices.
    • Level 2, high assessed risk. Requires a supplier to demonstrate advanced cyber security oversight and planning which drives robust organisational and cyber practices.

    Read those two descriptions next to each other. Level 1 asks whether you are doing the right things. Level 2 asks whether somebody is steering. Oversight and planning are governance words, and the extra controls cluster accordingly: the assessor is looking for evidence that decisions are made, reviewed and driven from somewhere, not simply that controls exist.

    That is a different kind of gap to close. Buying a tool closes a control gap. It does not close a governance gap, and this is the point at which organisations that have been running security as a technical function rather than a managed one find the work harder than the control count suggested.

    What does not change between the levels

    The scope. IASME are explicit that scope must remain the same across all levels, because what is essential for your organisation to operate securely and resiliently does not depend on which level you are assessed at. Your whole organisation, and the functions essential to it, in both cases.

    The absence of self-assessment. No DCC level is self-assessed. Both are assessed by a certification body.

    The two scoring phases. Theoretical first, which does not contribute to the final score but lets you supply context and evidence and may include a clarification round, then Practical, which IASME describe as the critical component, where the assessor verifies that controls are implemented as described.

    Who decides. The level required is decided by the MOD or by your prime. It is not a choice you make on ambition, and asking them is free.

    The practical sequence

    1. Ask your prime or contracting authority what level applies. Everything else depends on the answer and the answer costs nothing.
    2. If the answer is Level 2, book Cyber Essentials Plus. Longest lead item, hard prerequisite.
    3. Do not certify at Level 1 as a stepping stone to a known Level 2. There is no partial credit at reassessment.
    4. Scope once, properly. It does not change between levels, so scoping work carries forward even when assessment fees do not.

    Goldline's DCC requirement and scope review answers steps 1 and 4, and the Level 1 readiness diagnostic covers the control set with a remediation roadmap. Goldline is not a certification body and cannot certify DCC at any level. Assessment is carried out by an assessor working for an IASME-licensed certification body, and choosing that body has its own considerations.

    Sources

    • IASME, Defence Cyber Certification Frequently Asked Questions, read 1 September 2026. Control counts and level descriptions for Levels 0 to 3. "All levels start with Cyber Essentials certification, with Levels 2 and 3 requiring Cyber Essentials Plus." "Do I need to work up through the levels? No, you can apply for any level without completing lower levels first." "Is it possible to upgrade my certificate level by assessing the additional or updated controls between a current level and desired levels? No." "Are any levels self-assessment? No." "Does the scope vary between levels? No, the scope must remain the same across all levels." Description of the Theoretical and Practical scoring phases. "How do I know the level I require for a contract? This will be decided by the MOD or your Prime."
    • IASME, Defence Cyber Certification scheme page, read 1 September 2026, for the control counts and the recertification cycle.
    • DCC is currently not mandatory, per the same IASME FAQ. Nothing in this article should be read as saying a supplier is required to hold it.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    Defence

    8 min read

    DCC versus Cyber Essentials

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    It is not a choice. Cyber Essentials is a prerequisite for every level of Defence Cyber Certification, and Cyber Essentials Plus for Levels 2 and 3. What each one actually measures.

    • Defence
    • DCC
    • Cyber Essentials
    • DEFSTAN 05-138
    Defence

    8 min read

    DCC versus JOSCAR

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One is a certification against a defence standard, owned by the MOD. The other is a commercially operated supplier data platform. Neither substitutes for the other, and different people decide whether you need each.

    • Defence
    • DCC
    • JOSCAR
    • Supply Chain
    Defence

    8 min read

    Choosing a DCC Certification Body

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    One rule matters more than price or availability. Your certification body can advise you or assess you, not both, and IASME write that separation into the scheme rather than leaving it to conscience.

    • Defence
    • DCC
    • Certification
    • DEFSTAN 05-138
    Defence

    9 min read

    Defence Cyber Certification: the four levels, and what each one actually asks

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The four levels, the control counts, and the three things that catch suppliers out.

    • Defence
    • DCC
    • DEFCON 658
    • DEFSTAN 05-138

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.