DCC Levels 0–3 Requirements Explained: When Are In-Person Site Visits Needed?
When preparing for the Defence Cyber Certification (DCC) as an industry partner for the UK Ministry of Defence (MOD), one of the most common questions asked is: "Will an assessor need to visit our physical site?"
Because the DCC framework shifts focus to total organisational security and resilience, physical premises and access controls play an integral role in the assessment. However, misconceptions surround whether an on-site audit is mandatory at any of the DCC Levels 0-3.
Quick answer: No DCC level automatically requires an in-person site visit. Level 0 is portal-only. Levels 1–3 default to a remote meetings for Practical Scoring, and a physical visit is only arranged if the scoping phase flags multi-site operations, complex physical access controls, or specialised OT/critical facilities that can't be verified remotely.
In this blog, we break down the DCC Levels 0-3 requirements for audits, explain the exact scoping triggers that result in an in-person site visit, and detail the commercial travel costs suppliers should anticipate.
1. Audit Requirements Across DCC Levels 0–3
The short answer is no level automatically mandates an in-person site visit by default. Instead, the assessment method depends on the certification level and the findings of your initial scoping phase.
| DCC Level | Default Assessment Method | Site Visit Required? |
|---|---|---|
| Level 0 | Online portal self-assessment only | No |
| Level 1 | Remote meeting (Practical Scoring) | Rarely, only if triggered by scoping |
| Levels 2 & 3 | Remote meeting + multi-site sampling | Conditional, as identified in scoping |
Level 0 Requirements: Online Portal Submission
- Assessment Method: Purely portal-based self-assessment.
- Site Visit Required?: No.
- Details: DCC Level 0 candidates complete core questions directly on the IASME portal. The Certification Body reviews responses for compliance on paper. There is no practical scoring phase, live demonstration, or physical site inspection involved.
Level 1 Requirements: Remote Demonstration Default
- Assessment Method: Two-phase evaluation (Theoretical Scoring followed by Practical Scoring).
- Site Visit Required?: Rarely.
- Details: The standard format for Practical Scoring at DCC Level 1 is a remote meeting. During this session, the Certification Body and Applicant review technical and physical controls in real time using a "show me/demonstrate" approach (e.g., via screen sharing or live video walk-throughs). An in-person site visit is only arranged if physical complexities or specific risks are flagged during the scoping phase.
Level 2 and 3 Requirements: Multi-Site Sampling & On-Site Evaluation
- Assessment Method: Advanced theoretical scoring and enhanced practical validation.
- Site Visit Required?: Conditional / As Identified in Scoping.
- Details: Like Level 1, Practical Scoring for DCC Levels 2 and 3 defaults to a remote meeting demonstration. However, for higher risk profiles, assessors evaluate the organisation's entire footprint, including head offices, manufacturing workshops, and secondary facilities, to determine how many physical locations must be sampled. If multi-site complexity or specialised physical infrastructure cannot be verified remotely, an in-person audit is scheduled.
2. What Scoping Factors Trigger an On-Site Visit?
During the initial scoping phase, the Applicant and Certification Body document the boundary of the DCC assessment. Several operational factors can determine whether a physical site visit is necessary:
1. Multi-Site Operations and Sampling Requirements
Applicants must provide a complete list of all physical operational locations, including head offices, workshops, warehouses, and satellite sites. For Levels 2 and 3, assessors review this facility footprint to determine an appropriate sampling size. Large or geographically dispersed operations are more likely to require physical sampling.
2. Physical Access Control Complexity (1500 Control Family)
DCC controls require organisations to restrict and monitor physical access to facilities where sensitive data is processed or stored. If your facility utilises complex physical security mechanisms that are difficult to validate over video, an on-site audit may be requested. Key physical controls evaluated include:
- Swipe card access technology and photographic access credentials.
- Monitored CCTV and remotely monitored alarm systems.
- On-premises security guards and physical access logs.
- Visitor access management, entry/exit logging, and visitor badge issuance.
- Restricted access lists for high-sensitivity areas (e.g., server rooms or research labs).
3. Operational Technology (OT) and Critical Facilities
If your business operations rely on non-IT physical systems, such as Industrial Control Systems (ICS/SCADA), manufacturing OT, building management systems, or specialised environmental controls (HVAC), these must be included in your DCC scope. Demonstrating operational resilience for these physical assets frequently favours on-site verification.
4. Security Clearances and Onboarding Restrictions
If an assessor must visit your site, any special access constraints must be declared during scoping:
- Assessor security clearance requirements (e.g., Security Check / SC).
- Non-Disclosure Agreements (NDAs) or client-specific access restrictions.
- Site safety briefings or specialised PPE onboarding protocols.
3. How Home Offices and Remote Work Impact Physical Audits
Many defence suppliers operate remote or hybrid working models. The DCC framework handles remote working with clear, pragmatic guidelines:
- Sole Traders & Home Offices: If you work from a home office, that location constitutes your physical premises. Residential properties are not expected to install security guards, swipe cards, or photo ID systems. Assessors look for proportionate mechanisms (e.g., physical door locks and clear desk practices) appropriate for a domestic setting.
- Authorised Working Locations (Control 2311): Organisations must maintain an approved list of non-company working locations (such as client sites or home offices) and communicate these to staff.
- Third-Party Data Centres: Applicants are not required to control physical access to commercial data centres; these are covered under supply chain management controls.
4. Supplier Action Checklist: Preparing for Practical Demonstration
To ensure a smooth assessment and avoid unnecessary on-site audit costs, follow these steps during your preparation:
4.1 Accurate Scoping Attestation: Clearly document all physical premises, IT networks, OT systems, and working locations in your Statement of Scope.
4.2 Align Cyber Essentials Scope: Verify that your Cyber Essentials (or CE+) scope covers all internet-connected devices in your DCC boundary.
4.3 Compile Physical Evidence Early: Gather electronic evidence of physical security controls (e.g., sample visitor access logs, photos of keycard locks, and visitor badge templates).
4.4 Disclose Site Requirements Upfront: Inform your Certification Body during scoping if your sites require security clearances, NDAs, or safety briefings.
4.5 Prepare for Remote Demonstration: Test remote meeting tools and ensure staff are ready to walk through security controls virtually.
While physical security is a core pillar of the Defence Cyber Certification scheme, an in-person site visit is not standard for every audit across DCC Levels 0-3. By thoroughly documenting your scope and preparing digital evidence of your physical controls, most Level 1–3 suppliers can complete their practical scoring via a remote meeting.
FAQs
Does DCC Level 0 require an in-person site visit?
No. DCC Level 0 is assessed entirely through the IASME online portal. Applicants complete self-assessment questions and the Certification Body reviews responses on paper — there's no practical scoring phase, live demonstration, or physical site inspection at this level.
Is a site visit required for DCC Level 1?
Rarely. Level 1's Practical Scoring defaults to a remote meeting, where the Certification Body reviews technical and physical controls via screen share or live video walk-through. An in-person visit is only arranged if the scoping phase flags physical complexities or specific risks.
Are site visits mandatory for DCC Levels 2 and 3?
Not automatically. Like Level 1, Practical Scoring for Levels 2 and 3 defaults to a remote meeting. However, assessors review your full facility footprint during scoping, and an in-person audit is scheduled if multi-site complexity or specialised physical infrastructure can't be verified remotely.
What factors during scoping can trigger an on-site DCC audit?
Four main factors: multi-site operations requiring physical sampling, complex physical access controls (e.g. swipe cards, CCTV, security guards) that are hard to validate on video, Operational Technology or critical facilities like ICS/SCADA systems, and site-specific requirements such as security clearances or NDAs.
Who pays for travel costs when a DCC site visit is required?
Travel costs are passed through to the customer's quote. Typical charges include 45p per mile for car travel, the actual cost of train tickets for rail travel, hotel and subsistence for multi-day or long-distance audits, and scaled day rates for larger facility footprints.
Do home offices need swipe card access or CCTV for DCC certification?
No. If you work from a home office, that location counts as your physical premises, but residential properties aren't expected to install security guards, swipe cards, or photo ID systems. Assessors look for proportionate measures instead, such as door locks and clear desk practices.
Do I need to control physical access to third-party data centres for DCC?
No. Applicants aren't required to control physical access to commercial data centres they use. These are assessed under supply chain management controls rather than the organisation's own physical security controls.
How can I avoid an unnecessary on-site visit during my DCC audit?
Document all physical premises, IT networks, OT systems and working locations accurately in your Statement of Scope, align your Cyber Essentials scope, gather physical evidence early (access logs, keycard photos), disclose any site access restrictions upfront, and test your remote meeting setup in advance.