Skip to content

DCC scoping guide, guidance from Fig Group.

Agree what your DCC assessment covers before you commit to a quote. This guide helps you prepare questions about organisational scope, existing evidence, suppliers and Cyber Essentials prerequisites for a conversation with your assessor.

What scoping decides

Scoping establishes the assessment boundary, preparation work and commercial terms. For contractual certification, first confirm the CSM version and level required by your customer.

Plan for the assessment fee, the internal work to prepare evidence and the time needed to resolve any gaps. Agree responsibilities and a realistic timetable with your assessor; preparation needs vary between organisations.

Scoping decides four things in concrete terms: which legal entity is being certified, which estate is in scope, which supply-chain depth is being evidenced, and which prerequisite position you are starting from. The CRP your contract carries determines the level (see the CRP glossary); scoping determines the size and shape of the engagement at that level.

Suppliers seeking the same level can need different amounts of preparation. Existing evidence, shared systems and supplier dependencies help determine the work involved. Confirm the scope before relying on a price or completion estimate.

Six scoping issues to resolve early

Use these questions to agree the scope and preparation work with your assessor.

Using only the MOD contract boundary

DCC considers organisational security and resilience. Functions and services essential to the organisation can be in scope even when they do not directly handle MOD information. A contract-only boundary can omit important dependencies.

How Fig Group approaches this

Map the essential functions, services, people, sites, systems and suppliers with your assessor. Agree the scope using the IASME applicant guidance rather than assuming every non-MOD activity is excluded.

Missing shared systems and dependencies

Shared identity services, backups, cloud platforms and supplier access can support several business functions. Looking only at one project or data flow can miss systems that the organisation depends on.

How Fig Group approaches this

Trace the dependencies of essential services as well as MOD information. Document shared systems and third-party responsibilities, then agree how they are covered by the assessment scope.

Treating CE as a shortcut to DCC

Holding a current Cyber Essentials certificate is a prerequisite for DCC L0 and L1, but it is not a substitute for the DCC control set. Fig regularly sees suppliers assume that because CE evidence is in place, DCC evidence is essentially done. The L1 control set covers 101 controls; CE covers five. The overlap on technical controls is partial, and the governance, supply-chain, and risk-management evidence required for L1 is not in the CE evidence pack at all.

How Fig Group approaches this

Treat CE as a foundation, not a passport. Use the Fig platform (or your own gap analysis) to map what CE evidence already covers, then identify what L0 or L1 still requires. Plan the gap, not the headline.

Underestimating supply-chain depth

Supplier responsibilities can affect essential services and the evidence available for assessment. The evidence needed depends on the assigned DCC level, applicable controls and contractual requirements; a supplier checklist is not an additional universal Level 0 control.

How Fig Group approaches this

Identify the suppliers supporting in-scope functions and agree the evidence needed with your assessor. Request applicable records early, including contract-specific assurance where required. Distinguish certification evidence from procurement flow-down obligations.

Retained legacy systems with no migration plan

Unsupported or difficult-to-maintain systems need early review where they support in-scope services. Their condition may affect preparation and remediation work, but does not determine a fixed position within the Level 1 price band.

How Fig Group approaches this

Discuss legacy systems with your assessor before assessment. Identify the applicable requirements, plan necessary upgrades or replacements and agree the evidence needed. A migration plan or internal risk acceptance does not itself establish compliance.

Late evidence collection

Missing or outdated records can delay assessment. Gather relevant evidence as preparation progresses, and identify records that will need updating after remediation.

How Fig Group approaches this

Agree the required evidence with your assessor. Keep records of the controls actually in place, refresh them after relevant changes and confirm they support the scope being assessed.

The four boundary tests

The questions a Fig consultant will ask in the first scoping call. Run these against your own estate before the call to compress it.

The data-path test

Map the systems supporting essential organisational services as well as MOD information flows. Data paths help identify dependencies; they do not, on their own, define the complete DCC scope.

The organisational-resilience test

Which functions and services are essential to the organisation? Which entities, sites, staff and suppliers support them? Agree these boundaries with your assessor and record how the assessment scope meets IASME guidance.

The MFA-coverage test

Multi-factor authentication enforced across admin and remote access is required for L1, and MFA gaps are a frequent assessment failure. At scoping, list every identity surface that grants access to in-scope data: corporate IdP, secondary IdPs, vendor admin portals, support tooling. Check the access controls and evidence required for your assigned DCC level.

The evidence-currency test

Evidence must reflect the controls in place for assessment. Agree evidence dates and formats with your assessor, and refresh records after relevant infrastructure or supplier changes before submission.

The readiness kit

The evidence Fig Group asks for, grouped by control family. This is preparation guidance, not an extra scheme control set; agree the applicable items with your assessor. Level 0 fees remain fixed by organisation size, and Level 1 pricing depends on the agreed scope and support required.

Governance and risk

  • Current information security policy or policy framework reflecting actual controls; agree evidence dates with your assessor
  • Documented RACI or named ownership for cyber security responsibilities
  • Risk register with named risks, owners, and treatment status (L1; lighter for L0)
  • Incident response plan and contact tree, including notification routes for MOD-handling incidents

Identity and access

  • Joiner / mover / leaver process documentation with example evidence (tickets, IdP audit logs)
  • Privileged access list, with review cadence
  • Multi-factor authentication enforced across all admin and remote access (L1 mandatory)
  • Service-account inventory with documented isolation where MFA cannot apply

Device and configuration

  • Device inventory aligned to the in-scope estate (a maintained list is acceptable; real-time tooling not required at L0)
  • Patch management cadence: SLA for high / critical updates, with evidence of last cycle
  • Endpoint protection coverage report across in-scope devices
  • Documented baseline configuration for OS, cloud, and network components (L1)

Supply chain

  • Supplier list covering dependencies of in-scope organisational functions and services
  • Standard supplier security clauses or DPA template, with signed copies where applicable
  • Cyber Essentials evidence from suppliers where contractually required
  • Supplier assurance records relevant to the assigned level and agreed scope

The readiness kit is Fig’s evidence framework, not a verbatim copy of any source-pack document. For the canonical scoping rules of Def Stan 05-138 issue 4 and the IASME-delivered DCC scheme, see the IASME directory and the published IASME guidance at iasme.co.uk/defence-cyber-certification.

Two scoping decisions worth pre-deciding

Prepare these points for discussion with your assessor before the scoping call.

Decision one: are you certifying the legal entity, or a subset of it? DCC is organisation-wide and focuses on the business-critical systems within the agreed organisational scope. Do not exclude a division simply because it does not directly handle the MOD contract. Confirm the legal entity, business-critical systems and any justified boundary with your assessor. The scoping call is faster and the boundary is cleaner.

Decision two: what is the prerequisite position? L0 and L1 require Cyber Essentials. L2 and L3 require Cyber Essentials Plus. If you do not currently hold a current CE certificate, arrange certification separately before formal Level 0 or Level 1 assessment. If you hold one but it expires within the engagement window, plan renewal before formal assessment. If you hold CE but the in-scope estate has changed materially since issue, the assessor will want the renewed CE evidence to reflect the current estate.

Changes to scope or prerequisite certification can require more preparation and affect the timetable. Raise uncertainties before formal assessment so the next steps can be agreed.

For the buyer-facing FAQ on scope, prerequisites, timelines and pricing structure, see the DCC FAQ. Each question has its own deep-link URL for citation and reference.

Open the full DCC FAQ

Scope it once, scope it right.

Send Fig Group your contract requirements and scope questions. Review the published Level 0 fee for your organisation size, or agree a scoped Level 1 quote and timetable before committing to the engagement.