Chartered Cyber Security Professional and NCSC Head Consultant, Sam Stait, dives into what we’ve learnt about the Defence Cyber Certification as we approach the scheme’s one year anniversary.
One of the most common issues we see with organisations preparing for DCC is not capability, tooling, or maturity, so much as how they approach their application. Too often, we see that DCC is treated as another compliance exercise, with the instinct being to focus on implementing controls, producing documentation, and working through each requirement in detail. While that approach seems logical, in practice it often leads to unnecessary effort, increased cost, and rework later on and what we are seeing is that organisations are frequently doing far more than is actually required.
Resetting Expectations
Before getting into the detail, it is worth resetting expectations. There is a common assumption that passing DCC requires the best tools and highly mature environment but in reality, that is not what assessors are looking for. From a Defence Cyber Certification Assessor’s perspective, what we want to see is clear evidence of the things you are doing to meet a control requirement. In practical terms, an organisation must be able to describe how controls are applied across its scope and demonstrate that they are operating as intended.
So, as assessor, what am I looking for?
Clarity of Scope
Firstly, I need to understand the scope of the certification. This means that you must be able to clearly identify the aspects of your organisation that you wish to be in scope and those that you feel can be suitably justified as being out of scope.
If you are unsure how to approach this, it is recommended that you use the NCSC’s Five Lens model. This starts by establishing the context of your organisation, focusing on your objectives and what you are trying to achieve in the short, medium, and long term. Once that context is understood, you then move on to identifying your services and the functions that support those services. These are the day-to-day activities your organisation carries out in order to achieve those objectives. From there, you identify the supporting assets, infrastructure, and physical locations required to deliver those services.
It is important to note that you do not need to provide a comprehensive list of every application, service, or network subnet. What assessors are looking for is enough detail to understand how your organisation operates, and what exists to support that. For example, you may include that you have on-premises systems delivering specific functions, that you use third-party SaaS applications to support parts of the business, and that you operate across one or more physical locations.
There are a few common areas where organisations struggle. The first is focusing too narrowly on MOD delivery. DCC takes an organisational view. It considers not just the systems directly involved in delivering MOD contracts, but also the wider business functions that support continuity. A good example to illustrate this point would be to consider how long it would be before your delivery to the MOD was impacted if you couldn’t pay your suppliers. Or if you lost an entire revenue stream due to reputational damage resulting from a cyber incident.
The second is understanding the boundary between a UK entity and a wider group or global organisation. Where the UK relies on global services (perhaps with a Corporate IT network or Finance system), assessors will expect to see how you understand those services are processing or storing your data with the appropriate level of security. This does not mean however, that everything in global is now in scope, it is just the bits you rely on.
The third area is criticality. This is often misunderstood. It is possible to exclude elements that are not critical dependencies, but this is sometimes interpreted too broadly. A common example is office locations and remote working, where you wish to descope your physical sites because you allow for remote working and so the physical offices are not critical. This might seem logical, while remote working may reduce the impact of losing an office, it does not remove the need to provide a secure working environment. Therefore, both need to be considered within scope.
Ultimately, defining scope is the organisation’s responsibility. If it is unclear or does not reflect reality, it will create issues during assessment.
Application of Controls
The next area assessors focus on likely to be the application of controls. It is very common to see organisations where controls are in place and are working effectively, but they are not properly governed through policies, procedures, or standards.
It is important to remember that the assessment is essentially a comparison between three things. What you say you do, what you actually do, and whether what you actually do is sufficient to meet the requirements of the DCC. Where those things do not align, that is where issues arise which may result in an unfavourable result at assessment time.
Another common misconception is that all controls must be applied uniformly across the entire scope. That is not the case. Controls must be applied appropriately, based on the systems, services, and risks within your scope. There will be situations where a control cannot be applied in the same way everywhere. In those cases, assessors are looking for two things. Firstly, a clear understanding of why the control cannot be applied. Secondly, what has been done to mitigate that gap.
A good example of this is multi-factor authentication. In most environments, MFA is expected to be applied broadly and governed through policy and standards. However, there may be areas, such as industrial control systems or operational technology, where MFA is not technically feasible.
In those cases, the expectation is not that you force the control, but that you understand the limitation, clearly explain it, and implement appropriate compensating controls.
If you can demonstrate that the control is applied appropriately across your environment, and that any exceptions are understood and managed, then you are in a strong position from an assessment perspective.
Evidence
Next, and often the biggest challenge we see, is evidence. DCC is not just about what you say you do. It is about what you can demonstrate. From an assessment perspective, evidence is critical. An Assessor is looking to understand whether the controls you have described are actually operating in practice. Specifically, Assessors will be looking for:
- Evidence that supports your narrative
- Evidence that is current and relevant
This is where many organisations encounter difficulties, and time and time again we get asked the same question by our clients, “can you provide us with a list of what evidence you want to see”.
The short answer to this question is no. Seems unhelpful yes, but it is important to the credibility and objectivity of the assessment that we do not do this. Ultimately, there is no defined correct way to present evidence as it depends on your context and set up. IASME do provide guidance to both Applicants and Assessors but this is guidance, it is there to guide not prescribe. Additionally, by the time you get to the assessment you should know exactly how you are going to evidence each control requirement. If this is not the case, I’d suggest you are not ready for the assessment yet.
From an assessment perspective, if you cannot clearly demonstrate that your controls are operating as described, it becomes difficult to assess if what you are doing satisfies the control requirements. So, the key point here is not just to have evidence, but to ensure that it is clearly mapped, relevant, and aligned to how your organisation actually operates. Tell your story to the Assessor, do not expect them to find it out for themselves.
Understanding
The final point, which is often overlooked, is understanding. Assessors will speak to people across the organisation to understand how controls operate in practice. This is done to validate both the claims made in the ASR and what was found during the documentation review. Specifically, assessors are looking to confirm whether the appropriate individuals:
Understand what has been documented in the ASR
Can clearly explain how a process or control is applied in practice
A common issue we see is that the ASR is developed by a single individual or a small group, who naturally present the strongest possible case for compliance. However, that narrative does not always reflect how things actually operate day to day. When assessors then speak to control owners, asset owners, or other stakeholders, there can be a disconnect between what is documented and what is described in practice.
Where that misalignment exists, it creates a clear inconsistency between what you say you do and what you actually do. From an assessment perspective, that will typically result in a non-conformity. So, the key point here is that controls must not only be documented but also understood and owned by the people responsible for implementing them.
Looking Ahead
Over the coming weeks, we will be sharing further insight into common DCC challenges, why scope is critical, and how to approach DCC in a structured way.
We will also be bringing this together in an upcoming webinar for organisations currently preparing for DCC. Register your interest here.