DCC Level 2/3 Hybrid: The Assessment Process, Step by Step
If your contract requires Defence Cyber Certification (DCC) Level 3, there's one thing worth knowing before you go any further: there's no standalone Level 3 assessment. The only sanctioned route to Level 3 is the Level 2/3 Hybrid, a single assessment covering both the Level 2 and Level 3 control sets in one engagement, scored by an IASME Certification Body.
That structure sounds like it adds complexity, but in practice it works in your favour. Meet the Level 3 pass mark, and you're certified at Level 3. Fall short, but still meet the Level 2 pass mark, and you come away with a Level 2 certificate rather than an outright fail. One Assessment Submission Record (ASR), one set of IASME fees, one scoring pass and two possible certification outcomes.
Here's how the process runs, from prerequisites through to certification.
Understanding the Hybrid Assessment
The Level 2/3 Hybrid evaluates a combined total of around 145 controls across the Level 2 and Level 3 control sets, assessed against DEFSTAN 05-138 Issue 4. It's intended for organisations facing a moderate to substantial level of assessed cyber risk, typically those handling more sensitive MOD information, operating critical systems, or forming a significant part of a high-assurance defence programme.
Where Level 1 is a theoretical review of evidence, the Hybrid assessment goes further: it combines theoretical scoring of your ASR with hands-on practical validation of the controls you've described, across people, processes and technology.
Prerequisite: Cyber Essentials Plus
Both Level 2 and Level 3 require a valid Cyber Essentials Plus (CE+) certificate. This is a hard prerequisite, not optional, and the assessment cannot begin without it. CE+ goes further than standard Cyber Essentials by requiring independent technical verification, including hands-on vulnerability scanning and configuration review.
You'll also need to maintain CE+ for the duration of your DCC certificate's validity; if it lapses, so does your DCC standing. If you don't currently hold CE+, or it's close to expiry, this needs to be resolved before, or alongside, your Hybrid engagement.
Step 1: Get Your Scope Right — Including What CE+ Doesn't Cover
Scope is the single most consequential decision in the whole process. An under-scoped assessment fails automatically, regardless of how well-controlled the systems within scope actually are.
The key thing to understand is that DCC scope is deliberately broader than your CE+ scope:
| Certification | Covers |
|---|---|
| Cyber Essentials / CE+ | Internet-connected devices only — laptops, desktops, servers, cloud services reachable from the internet |
| DCC (Levels 2–3) | The whole organisation — including non-internet-connected systems such as operational technology (OT), industrial control systems (ICS/SCADA), building entry systems, air-gapped networks, or legacy systems without external connectivity, where these are essential to your operations |
If your CE+ scope doesn't sit within, or clearly overlap with, your DCC scope and that gap isn't properly justified the assessment fails automatically. This is worth resolving on paper, in a formal Statement of Scope, before you approach a Certification Body.
Step 2: Engage Your Certification Body
As an IASME-accredited Certification Body, Periculo conducts the Hybrid assessment from scoping through to certificate issuance. This stage covers:
- Validating your CE+ certificate and confirming scope overlap with your DCC scope
- Reviewing your Statement of Scope and challenging any under-scoping before anything is committed
- Issuing the Assessment Submission Record covering the full combined control set
- Confirming evidence submission requirements and access to your evidence folder
- Setting audit dates, communication channels and the assessment timetable
Your assessor won't move to scoring until scope has been confirmed and every prerequisite check has passed. This stage-gated approach is designed to protect your chances of a first-time pass, not slow you down for its own sake.
Note: If you'd rather use a different Certification Body for the formal assessment, Periculo can instead act as your implementation partner, helping build out the controls, policies and evidence before handing you to an independent CB. IASME's independence rules mean the same organisation cannot both implement your controls and formally assess them.
Step 3: Complete the ASR and Build Your Evidence Pack
With scope agreed, you complete the ASR against the combined control set, referencing evidence for every response and generating hash values for each evidence file, so its integrity can be checked later. As with every DCC level, your Certification Body won't draft responses on your behalf; this is evidence of your own controls.
Given the scale of a Hybrid submission, it's worth starting your evidence folder early, and treating access control on that folder itself as one more thing your assessor may want to see evidenced.
Step 4: Kickoff Call and Theoretical Scoring
The formal assessment opens with a kickoff call confirming scope, checking your submission is complete, and agreeing the audit timetable. From there, your assessor conducts a detailed remote review of every response across the full control set, applying IASME's marking criteria.
During this stage, IASME may grant clarification rounds as a normal, expected opportunity to strengthen a response or evidence item, not a sign you've failed. Your assessor will also identify any controls at risk of an automatic fail as early as possible, so you have the maximum opportunity to remediate before practical scoring begins. Practical scoring shouldn't start until these critical gaps have been addressed.
Step 5: Practical Scoring
Practical scoring verifies that what your evidence describes is genuinely implemented and operating day-to-day. Where theoretical scoring checks what your policies say, practical scoring checks what your controls actually do. Depending on your scope, this may include:
- Screenshare demonstrations of key controls and configurations
- Interviews with control owners and security personnel
- Sampling of endpoint encryption, patching status and boundary device configuration
- Review of incident response execution evidence and testing outputs
- Network boundary and segmentation validation
- A physical site visit, where OT, ICS/SCADA, air-gapped systems, or restricted areas can't be adequately assessed remotely
Organisations with complex or multi-site environments should expect on-site elements to be scoped in from the start, with assessors sampling representatively rather than reviewing everything in person.
Step 6: The Dual-Certification Outcome
Once scoring is complete, your assessor signs off the final ASR and the outcome is entered on the IASME platform:
| Outcome | Certificate Issued |
|---|---|
| Meets the Level 3 pass mark | DCC Level 3 |
| Doesn't meet Level 3, but meets Level 2 | DCC Level 2 |
| Doesn't meet the Level 2 pass mark | No certification at this time |
This is the built-in safety net of the Hybrid model: a narrowly missed Level 3 doesn't mean walking away with nothing.
Step 7: Retain Your Evidence
Your obligations don't end at certification. Evidence must remain accessible to your Certification Body for two months after the assessment, and the full evidence set must be retained for 3.5 years after certification. Given the volume of evidence a Hybrid assessment generates, a dedicated, access-controlled repository set up from day one will save considerable pain later.
Common Pitfalls to Avoid
Assuming CE+ scope is "close enough." It needs to sit within or clearly overlap your DCC scope, with any gap explicitly justified — not just broadly similar.
Overlooking non-internet-connected systems. OT, ICS/SCADA, and similar systems are in scope for DCC even though they'd never appear in a CE+ scope.
Treating clarification rounds as a red flag. They're a normal part of theoretical scoring, built into the process by IASME.
Under-resourcing evidence management. At 145 controls, an unstructured evidence folder becomes unmanageable fast — and hashing needs to happen as you go, not retrospectively.
Level 2/3 Hybrid Assessment Checklist
- Valid Cyber Essentials Plus certificate in place, with scope overlapping your DCC scope
- Formal Statement of Scope documented, including non-internet-connected systems
- Certification Body engaged and ASR issued for the combined control set
- Evidence pack built, hashed, and access-controlled
- Audit dates confirmed and kickoff call attended
- Any automatic-fail risks or clarification actions resolved before practical scoring
- On-site elements scoped in advance, where relevant
- Evidence retention plan in place for 3.5 years
Get in Touch
Periculo is an IASME-authorised Certification Body, authorised to deliver the Level 2/3 Hybrid assessment and issue certificates at both Level 2 and Level 3.
If you're working toward Level 3, or you're not yet sure whether Level 2 or the Hybrid route is right for your contract, get in touch and we'll talk it through.