MANAGED DCC READINESS
/ PART 3 OF 3
Looking at the journey from understanding a DCC requirement to being ready for independent certification
Reaching the end of a remediation plan does not automatically mean an organisation is ready for Defence Cyber Certification. Readiness depends on whether the supplier can present a stable scope, answer the assessment questions accurately, produce supporting evidence and show that the controls work across the organisation.
That is a higher bar than having security products in place or approving a new set of policies. DCC has no self-assessment level. The Certification Body reviews the supplier’s descriptions and evidence, then verifies the implementation through the practical phase of the assessment.
Understand how the assessment tests the organisation
IASME describes two scoring phases. The theoretical phase allows the supplier to explain what it does, how it meets each control and what evidence supports the answer. The assessor can use this stage to seek clarification and identify issues before the practical assessment.
The practical phase verifies that the supplier implements the controls as described and judges whether those measures are sufficient. The Certification Body selects samples and may request additional evidence. A confident theoretical response will therefore unravel if control owners, system records or working practices tell a different story.
What useful DCC evidence looks like
Useful evidence is relevant to the control, current enough to describe the organisation’s present position and clearly connected to the agreed scope. It also shows operation. A policy may establish governance, while minutes, system records, completed reviews and test outputs show that the stated process is being followed.
Depending on the control, the evidence set could include board or security committee minutes, risk registers, asset inventories, network diagrams, supplier assurance records, access reviews, configuration reports, vulnerability and patching records, monitoring outputs, incident records, exercise reports, business continuity tests, staff training records, joiner and leaver evidence, physical access logs and approved policies. The exact set depends on the control and the organisation’s implementation.
Volume is a poor substitute for traceability. A large document repository can make assessment harder if files are duplicated, outdated or disconnected from the answers. Each evidence item should have a clear owner, date, scope and relationship to the relevant control. Sensitive material should be handled carefully, with the Certification Body consulted where evidence access needs special arrangements.
Can the people responsible explain the control?
The evidence pack is only one part of the position. The people who own and operate the controls need to understand their responsibilities and describe what happens. This is particularly important where a written process spans several teams or depends on an external provider.
A readiness review should test the likely assessment path. Ask the access-management owner to walk through a recent review. Follow a leaver from HR notification to account removal and asset return. Trace a critical supplier from due diligence to ongoing monitoring. Take a security alert through triage, escalation and closure. Confirm that the records support each account.
These walkthroughs reveal inconsistencies that desk-based checking can miss. They also prepare control owners for the practical phase without coaching them to recite artificial answers. The strongest response is an accurate explanation of a process the organisation already uses.
Seven questions for the readiness decision
The final readiness review should reach a defensible answer to seven questions. Does the organisation understand what DCC requires? Is the applicable level confirmed? Is the scope complete and justified? Have the gaps been closed? Can every remaining action be tied to a named owner? Is the evidence current, accessible and aligned to each response? Would the organisation be comfortable placing this position in front of an independent Certification Body now?
A ‘yes’ needs support. The readiness team should be able to show the assessment record, control status, evidence index, closed-action verification and any residual issues already discussed with the appropriate party. If a material gap remains, the correct outcome is a managed delay with a clear completion plan. Entering assessment prematurely can consume assessor time, create avoidable clarification rounds and weaken internal confidence.
Certification is followed by maintenance
DCC provides point-in-time assurance, supported by ongoing obligations. Organisations must renew Cyber Essentials or Cyber Essentials Plus annually, complete an annual attestation that the controls and scope are being maintained, and recertify to DCC every three years. Significant scope changes should be reviewed with the assessing Certification Body.
Evidence management should therefore continue after certification. New systems, acquisitions, supplier changes, office moves and operating-model changes can all affect the certified position. The owners, review cycles and evidence routines created during readiness work become part of maintaining assurance.
How Logiq can help
Logiq provides a managed route through DCC readiness, from the initial requirement and scope through control assessment, remediation, evidence preparation and the final readiness decision. Logiq can coordinate the programme and support technical and operational changes while preserving the independent role of the chosen Certification Body.




