DCC: what DISX customers need to know

DCC for DISX Customers

If your organisation already uses DISX Secure Collaboration, one of the most important DCC questions is understanding how the service contributes to your overall certification position.

Defence Cyber Certification (DCC) is an organisation-level certification, so no single platform, network or collaboration service can make an organisation DCC-certified on its own. It assesses the supplier and the business-critical operations within its agreed scope.

For DISX customers, the service can make a meaningful contribution to that position. Within the service boundary it provides, DISX combines secure collaboration with managed endpoints, identity and access controls, security configuration, monitoring, logging, patching, vulnerability management and operational governance. Those capabilities can support relevant DCC requirements and provide evidence for controls operated within the DISX environment.

The key is understanding where DISX already contributes, how that fits with the wider organisational scope, and what needs to happen before an independent Certification Body can assess the complete position.

The simplest way to think about it: DISX supports relevant controls and evidence within its service boundary. DCC brings that contribution together with the rest of your organisation’s certification scope.

How DISX fits within organisation-wide DCC certification

DCC is designed to give UK Defence independent assurance that a supplier meets the controls associated with its assigned Cyber Risk Profile. The applicable level is set by the MOD or relevant Prime contractor, and the certification boundary is built around the supplier’s business-critical operations.

Depending on the organisation and the agreed certification boundary, the scope may extend beyond the environment used for a single MOD contract. It can include corporate IT, identity services, finance and payroll platforms, operational technology, physical premises, outsourced IT, cloud services and other third parties where those services are important to the organisation’s ability to operate securely and resiliently.

A managed service does not sit outside DCC simply because another provider operates it. Where a DCC control depends on a managed platform or service, the supplier still needs to explain how that control is met and may need supporting evidence from the provider.

Where DISX can support your DCC position

DISX Secure Collaboration provides a defined and operated collaboration boundary. Logiq manages the service through-life, including configuration control, monitoring, patch management, governance, structured reporting and audit-ready logging. This means DISX can support relevant DCC requirements where the organisation relies on the service for secure collaboration and associated technical controls.

Area within the DISX boundaryHow DISX can contribute
Secure collaboration and data handlingA governed Microsoft 365 collaboration environment with controlled and auditable sharing paths.
Identity and accessManaged identity, access control and MFA within the service boundary.
Endpoint and security configurationManaged endpoints, agreed security posture, configuration and change control.
Monitoring and logging24/7 managed detection and response, security operations, SIEM logging and reporting.
Patching and vulnerability managementManaged patching, vulnerability management and platform integrity controls.
Assurance and evidenceCompliance monitoring, audit-ready logging, reporting and evidence/posture reviews that can support relevant assessment responses.
Backups and recoveryBackup and recovery capabilities where included in the selected DISX deployment profile.

Important: the DISX contribution still needs to be considered against your assigned DCC level, agreed scope and how your organisation uses the service. Relevant capabilities can support DCC controls and evidence, but they do not automatically map to every requirement.

What remains within your organisation’s DCC scope

DISX provides a strong technical and operational foundation within its service boundary. DCC also reaches across governance, risk, people, technology, physical security, supply-chain management, incident response and business continuity, so there will usually be requirements that sit elsewhere in the organisation.

  • Board and senior management direction, governance and risk ownership
  • Policies, processes and responsibilities across the wider organisation
  • People, training, joiner/mover/leaver processes and personnel-related controls
  • Physical security and premises controls
  • Supplier and third-party assurance beyond the DISX service
  • Business continuity, incident response and recovery arrangements across the organisation
  • Other corporate systems, networks, cloud services and operational technology within the DCC boundary

For existing DISX customers, this means some technical and evidential foundations may already be supported within the managed environment. DISX can reduce the work that needs to be built from scratch, while the wider organisation focuses on evidencing the remaining DCC requirements.

What about evidence from DISX?

DCC requires applicable controls to be documented, implemented and supported by auditable evidence. A policy can explain what should happen, but the assessment also needs evidence that the control actually operates across the agreed scope.

For controls delivered within DISX, the managed service model can provide useful supporting material through structured reporting, audit-ready logging, configuration and change records, security monitoring outputs, vulnerability and patching records, and other evidence generated through service operation. The exact evidence needed will depend on the control, your DCC level and the scope agreed for certification.

The practical task is therefore to map the DCC requirement to the control owner, identify which parts are delivered through DISX, establish what evidence can be supplied from the service, and then identify any remaining evidence or remediation required elsewhere in the organisation.

What should DISX customers do now?

If DCC is beginning to appear in your contracts, tenders or conversations with the MOD or a Prime, start with the requirement rather than the technology.

  1. Confirm the level that applies – Your DCC level is determined by the MOD or relevant Prime through the Cyber Security Model. Level 0 is the common baseline requested across Defence industry, but individual contracts may require Level 1, 2 or 3.
  2. Define a defensible scope – Identify the business-critical operations, systems, assets, processes and dependencies that need to sit inside the certification boundary. The boundary may extend beyond the DISX environment or the network used for one contract, depending on the agreed scope.
  3. Confirm the Cyber Essentials prerequisite – The DCC scope needs to align with the relevant Cyber Essentials or Cyber Essentials Plus requirement for the applicable level.
  4. Map where DISX contributes – Identify which DCC requirements are supported by the DISX service and what supporting evidence is available from the managed environment.
  5. Find and close the remaining gaps – Assess the wider organisation across governance, risk, people, suppliers, physical security, other systems and operational processes. Turn gaps into owned remediation actions and build the evidence while the controls are being fixed.
  6. Test readiness before formal assessment – Before engaging a Certification Body, make sure the scope is stable, responses are accurate, evidence is current and control owners can explain how the arrangements work in practice.

A few common DISX and DCC questions

Does using DISX mean our organisation is DCC compliant?

Not on its own. DCC certification applies to the supplier organisation and the defined business-critical scope. DISX can support relevant controls and evidence within the service boundary, giving customers a useful foundation for the wider DCC requirements that apply to the organisation.

Is DISX itself DCC-certified?

DCC is an organisation-level certification rather than a product certification. DISX is positioned to support relevant DCC requirements; independent certification is awarded to the supplier organisation by an IASME-assured DCC Certification Body.

Can DISX form part of our DCC scope?

Yes. Where DISX supports business-critical operations or delivers controls that your DCC responses rely on, it may form part of the wider scope and evidence position.

Does DCC replace our other Defence cyber obligations?

No. DCC does not replace every contractual requirement. The Supplier Assurance Questionnaire may still be required, and separate obligations can apply for classified information, specific systems, operational technology, Secure by Design and other Defence requirements.

How Logiq can help

For existing DISX customers, the most useful starting point is to establish what DCC requires of your organisation, then identify the requirements already supported by DISX and the additional areas that need to be addressed elsewhere.

Logiq’s Managed DCC Readiness service takes organisations from interpretation and scope through gap assessment, remediation planning, evidence preparation and readiness review. Where DISX supports relevant technical requirements, Logiq can help map that contribution into the wider DCC position. Where additional requirements sit outside DISX, the same readiness programme can coordinate the governance, risk, supplier, architecture, technical and operational work needed before independent assessment.