If your contract requires Defence Cyber Certification (DCC) Level 3, there's one thing worth knowing before you go any further: there's no standalone Level 3 assessment. The only sanctioned route to Level 3 is the Level 2/3 Hybrid, a single assessment covering both the Level 2 and Level 3 control sets in one engagement, scored by an IASME Certification Body.
That structure sounds like it adds complexity, but in practice it works in your favour. Meet the Level 3 pass mark, and you're certified at Level 3. Fall short, but still meet the Level 2 pass mark, and you come away with a Level 2 certificate rather than an outright fail. One Assessment Submission Record (ASR), one set of IASME fees, one scoring pass and two possible certification outcomes.
Here's how the process runs, from prerequisites through to certification.
The Level 2/3 Hybrid evaluates a combined total of around 145 controls across the Level 2 and Level 3 control sets, assessed against DEFSTAN 05-138 Issue 4. It's intended for organisations facing a moderate to substantial level of assessed cyber risk, typically those handling more sensitive MOD information, operating critical systems, or forming a significant part of a high-assurance defence programme.
Where Level 1 is a theoretical review of evidence, the Hybrid assessment goes further: it combines theoretical scoring of your ASR with hands-on practical validation of the controls you've described, across people, processes and technology.
Both Level 2 and Level 3 require a valid Cyber Essentials Plus (CE+) certificate. This is a hard prerequisite, not optional, and the assessment cannot begin without it. CE+ goes further than standard Cyber Essentials by requiring independent technical verification, including hands-on vulnerability scanning and configuration review.
You'll also need to maintain CE+ for the duration of your DCC certificate's validity; if it lapses, so does your DCC standing. If you don't currently hold CE+, or it's close to expiry, this needs to be resolved before, or alongside, your Hybrid engagement.
Scope is the single most consequential decision in the whole process. An under-scoped assessment fails automatically, regardless of how well-controlled the systems within scope actually are.
The key thing to understand is that DCC scope is deliberately broader than your CE+ scope:
| Certification | Covers |
|---|---|
| Cyber Essentials / CE+ | Internet-connected devices only — laptops, desktops, servers, cloud services reachable from the internet |
| DCC (Levels 2–3) | The whole organisation — including non-internet-connected systems such as operational technology (OT), industrial control systems (ICS/SCADA), building entry systems, air-gapped networks, or legacy systems without external connectivity, where these are essential to your operations |
If your CE+ scope doesn't sit within, or clearly overlap with, your DCC scope and that gap isn't properly justified the assessment fails automatically. This is worth resolving on paper, in a formal Statement of Scope, before you approach a Certification Body.
As an IASME-accredited Certification Body, Periculo conducts the Hybrid assessment from scoping through to certificate issuance. This stage covers:
Your assessor won't move to scoring until scope has been confirmed and every prerequisite check has passed. This stage-gated approach is designed to protect your chances of a first-time pass, not slow you down for its own sake.
Note: If you'd rather use a different Certification Body for the formal assessment, Periculo can instead act as your implementation partner, helping build out the controls, policies and evidence before handing you to an independent CB. IASME's independence rules mean the same organisation cannot both implement your controls and formally assess them.
With scope agreed, you complete the ASR against the combined control set, referencing evidence for every response and generating hash values for each evidence file, so its integrity can be checked later. As with every DCC level, your Certification Body won't draft responses on your behalf; this is evidence of your own controls.
Given the scale of a Hybrid submission, it's worth starting your evidence folder early, and treating access control on that folder itself as one more thing your assessor may want to see evidenced.
The formal assessment opens with a kickoff call confirming scope, checking your submission is complete, and agreeing the audit timetable. From there, your assessor conducts a detailed remote review of every response across the full control set, applying IASME's marking criteria.
During this stage, IASME may grant clarification rounds as a normal, expected opportunity to strengthen a response or evidence item, not a sign you've failed. Your assessor will also identify any controls at risk of an automatic fail as early as possible, so you have the maximum opportunity to remediate before practical scoring begins. Practical scoring shouldn't start until these critical gaps have been addressed.
Practical scoring verifies that what your evidence describes is genuinely implemented and operating day-to-day. Where theoretical scoring checks what your policies say, practical scoring checks what your controls actually do. Depending on your scope, this may include:
Organisations with complex or multi-site environments should expect on-site elements to be scoped in from the start, with assessors sampling representatively rather than reviewing everything in person.
Once scoring is complete, your assessor signs off the final ASR and the outcome is entered on the IASME platform:
| Outcome | Certificate Issued |
|---|---|
| Meets the Level 3 pass mark | DCC Level 3 |
| Doesn't meet Level 3, but meets Level 2 | DCC Level 2 |
| Doesn't meet the Level 2 pass mark | No certification at this time |
This is the built-in safety net of the Hybrid model: a narrowly missed Level 3 doesn't mean walking away with nothing.
Your obligations don't end at certification. Evidence must remain accessible to your Certification Body for two months after the assessment, and the full evidence set must be retained for 3.5 years after certification. Given the volume of evidence a Hybrid assessment generates, a dedicated, access-controlled repository set up from day one will save considerable pain later.
Assuming CE+ scope is "close enough." It needs to sit within or clearly overlap your DCC scope, with any gap explicitly justified — not just broadly similar.
Overlooking non-internet-connected systems. OT, ICS/SCADA, and similar systems are in scope for DCC even though they'd never appear in a CE+ scope.
Treating clarification rounds as a red flag. They're a normal part of theoretical scoring, built into the process by IASME.
Under-resourcing evidence management. At 145 controls, an unstructured evidence folder becomes unmanageable fast — and hashing needs to happen as you go, not retrospectively.
Periculo is an IASME-authorised Certification Body, authorised to deliver the Level 2/3 Hybrid assessment and issue certificates at both Level 2 and Level 3.
If you're working toward Level 3, or you're not yet sure whether Level 2 or the Hybrid route is right for your contract, get in touch and we'll talk it through.