Why Scope is the Most Important Decision You Will Make in Your DCC Journey

Why Scope is the Most Important Decision You Will Make in Your DCC Journey

Chartered Cyber Security Professional and NCSC Head Consultant, Sam Stait breaks down why scope is the most important decision you will make in your DCC journey.

DCC takes an organisational view. Unlike previous frameworks that focused primarily on MOD Identifiable Information, DCC looks at whole organisation security and resilience. That means scope extends beyond the systems or services directly involved in delivering MOD contracts to include all functions, processes, and infrastructure essential to keeping your organisation operating. The bottom line is, if a system, process, or function is required for the organisation to operate, it needs to be within scope of DCC.

That is a broader remit than many organisations expect, and it is one of the reasons scoping catches people out.

The Business Case for Getting Scope Right

Scoping a DCC certification will have a direct and measurable impact on your organisation, so it is worth thinking about it in those terms before anything else. Scoping affects: 

  • Financial cost. Every element within scope requires controls to be implemented, evidence to be gathered, and ongoing attestation to be maintained. A scope that is broader than necessary generates disproportionate costs through assessment, remediation, and the annual attestation process that follows.
  • Operational impact. Preparing for assessment draws on time and attention across the organisation. Where scope pulls in functions or teams that did not need to be included, it creates disruption that could have been avoided with more precise scoping at the outset.
  • Resource demand. The wider the scope, the greater the demand on IT teams, security functions, operational staff, and senior leadership. For smaller suppliers in particular, that resource has to come from somewhere.
  • Remediation effort. Gap analysis and remediation is scoped to what falls within the certification boundary. An unnecessarily large scope means more gaps to identify, more controls to implement, and more evidence to produce.
  • Long-term maintenance. The scope defined today is the scope that will need to be actively managed and attested against on an ongoing basis. Getting it right at the start creates a sustainable compliance posture. Getting it wrong creates an ongoing burden.

What Good Scope Looks Like

A good scope is a clear scope; a documented picture of your organisation that gives an assessor enough context to understand what is being certified. It covers:

  • Defined boundaries. What is in scope, what is out of scope, and a clear justification for any exclusions. Where the organisation is part of a wider group or relies on global services, those boundaries need to be clearly explained.
  • Business functions. The day-to-day activities that deliver services and support continuity across the organisation, not just those directly tied to MOD contracts.
  • Business processes. The operational and administrative processes that underpin how those functions are carried out, including finance, procurement, and HR workflows.
  • Systems and data. The technology, infrastructure, and data that support those functions. The IASME scoping attestation requires a brief list of IT and OT networks and systems, along with a description of devices and data storage.
  • Physical locations. All sites, offices, offsite workspaces, and assets in transit. Remote working capability does not remove physical locations from scope. It reduces the impact of losing a site; it does not remove the need to operate that site securely.
  • People and teams. All staff, third parties, and visitors whose activities touch systems or data within scope, across technical, operational, and administrative functions.

Alignment with Cyber Essentials. All DCC certification levels require either Cyber Essentials or Cyber Essentials Plus, and the DCC scope must encompass or overlap with the CE or CE+ scope. These should be planned together, not treated as separate exercises.

The Risks of Getting It Wrong

Poor scoping has consequences that extend well beyond the assessment. A poorly developed or written scope could lead to: 

  • Failing certification. Under-scoping can result in failure even where all controls have been met. IASME is explicit on this point. An inaccurate or insufficient scope cannot be rescued by strong control implementation.
  • Increased operating costs. Over-scoping generates disproportionate and ongoing costs across assessment, remediation, and the full certification cycle.
  • Inability to access MOD contracts. DCC is an increasing requirement across the defence supply chain. Organisations that fail or cannot achieve certification within a reasonable timeframe may be at risk of being unable to bid for or retain MOD contracts.
  • Reputational risk. A failed assessment or prolonged delay sends a signal to MOD and wider industry about how cyber security is being managed. In a supply chain environment where trust and assurance matter, that perception can be difficult to recover from.

Where to Start

Before implementing a single control or writing a single policy, define your scope. The IASME Scoping Guide is publicly available and sets out clearly what is required. The NCSC Five Lens model provides a practical framework for working through it in a structured way.

Scope is your organisation’s responsibility. Assessors will review it, challenge it, and base the entire assessment against it. Organisations that invest the time to get it right at the start will find everything that follows significantly more straightforward.

If you’re working through the Defence Cyber Certification at the moment and are encountering some of these common DCC challenges, we can help. Join our upcoming webinar on Wednesday 13th May 2026 to get started. Register your interest here.