Chartered Cyber Security Professional and NCSC Head Consultant, Sam Stait breaks down how to pass DCC first time.
There is a common assumption that passing Defence Cyber Certification comes down to how mature your security environment is. In practice, that is not what the evidence shows. Organisations with relatively straightforward environments pass first time regularly. Organisations with sophisticated security functions fail. The difference, in almost every case, comes down to how well they prepared.
Start With Scope
Everything begins with scope. Organisations that define it accurately at the outset know what needs to be assessed, what controls apply, what evidence is required, and who needs to be involved. That clarity runs through the entire submission and makes every subsequent step more manageable.
Organisations that treat scope as an administrative task to complete before the real work begins tend to find themselves revisiting decisions, reworking documentation, and in some cases restarting the process entirely. Define scope first. Define it carefully. Everything that follows depends on it.
Know Where You Stand Before You Commit
Before applying for an assessment, conduct a structured and deep gap analysis against the DefStan 05-138 controls that apply to your scope and desired DCC level. This gives a clear and honest picture of where your organisation currently stands and what needs to be addressed.
Organisations that skip this step are more likely to encounter findings during assessment that could have been identified and resolved in advance. A gap analysis is not additional overhead. It is the tool that sets you up for a predictable, well-managed assessment.
Fix What Matters
Remediation should be proportionate, focused, and directed at the right level. A common mistake is addressing the symptom rather than the underlying cause. A missing patch, for example, is rarely just a missing patch. It may indicate that the patch management programme is ineffective, that responsibility for patching is unclear, or that there is no process in place to identify and track what needs to be applied. Fixing the single known issue satisfies the immediate finding but leaves the condition that created it firmly in place.
Assessors are looking at control effectiveness across the scope. Where a gap is identified, the question they will be asking is not simply whether it has been resolved, but whether the organisation has understood why it existed and what has been done to prevent recurrence. A one-off fix with no supporting process, policy, or governance is unlikely to satisfy that question.
Before remediating any gap, take the time to understand what caused it. Where the root cause points to a process weakness, a governance gap, or an ownership issue, that is what needs to be addressed. The fix to the individual issue follows from that.
Organisations that address root causes also tend to find that a single change resolves multiple gaps simultaneously. Organisations that fix issues in isolation often find themselves returning to the same areas repeatedly.
Tell a Coherent Story
Evidence is not just about having the right documentation. It is about presenting it in a way that makes the assessor’s job straightforward. Each piece of evidence should be clearly mapped to the control it is intended to satisfy, current, and reflective of how the organisation actually operates.
Assessors are not there to piece the picture together. Where the link between evidence and a control requirement is not explicit, it creates doubt. Where evidence is outdated or does not reflect current practice, it undermines the submission.
A useful test before assessment is to ask yourself whether you could clearly explain, for every control, exactly what your evidence is and why it demonstrates compliance. If the answer is uncertain, or if the instinct is to ask the assessor what they want to see, the submission is not ready. These are your controls, implemented across your environment. You should know exactly how to evidence them and who is best placed to do so.
Prepare Your People
The assessment does not begin and end with documentation. Assessors will speak to people across the organisation, and what those people say matters. Inconsistent or inaccurate responses from staff can undermine a submission that looks strong on paper.
Preparation here does not mean scripting answers. It means ensuring that the people who will speak to the assessor understand what has been documented, can explain how controls operate in practice, and are comfortable doing so. Control owners and asset owners in particular should be briefed before assessment day and given the opportunity to ask questions.
Internal walkthroughs, where the submission is talked through with relevant staff in advance, are one of the most effective ways to surface gaps between what has been documented and what people will actually say. Where those gaps exist, it is far better to find them internally than to have an assessor find them first.
Validate Before You Apply
A mock assessment or independent readiness review before submitting is one of the most reliable ways to reduce assessment risk. It creates an opportunity to test the submission against the same criteria an assessor will apply, identify any remaining gaps, and address them before they become formal findings.
Organisations that go through this step consistently report a smoother assessment experience. It removes uncertainty, builds confidence across the team, and ensures that the submission presented to the assessor is as strong as it can be.
The Common Thread
Passing DCC first time is as much about approach as it is about effort. Organisations that structure their preparation well, start with scope, understand their gaps, focus their remediation, present their evidence clearly, and prepare their people, give themselves every opportunity to achieve certification without unnecessary cost, delay, or rework.
The assessment is designed to establish whether an organisation has appropriate controls in place and can demonstrate that clearly. Organisations that prepare with that in mind will find the process significantly more straightforward.
If you’re working through the Defence Cyber Certification at the moment and are encountering some of these common DCC challenges, we can help. Join our upcoming webinar on Wednesday 13th May 2026 to get started. Register your interest here.