DCC Penetration Testing Requirements: A Complete Guide to Control 2403
UK defence procurement no longer assesses cybersecurity contract by contract. The Ministry of Defence (MOD) and IASME have replaced that patchwork approach with the Defence Cyber Certification (DCC), a single, organisation-wide assurance that supports multiple procurements at once, built around Def Stan 05-138.
That shift puts more weight on proving your defences actually hold up under attack. Penetration testing is the mechanism DCC uses to validate perimeter security, but what it demands depends entirely on which of the four DCC levels (0 to 3) you're certifying against. This guide breaks down the exact DCC penetration testing requirements for each level, what assessors expect to see as evidence, and where organisations most often trip up.
1. DCC Levels at a Glance: Where Does Penetration Testing Fit?
DCC's four levels scale with your assessed Cyber Risk Profile (CRP) under Def Stan 05-138:
Level 0 (3 controls) — very low cyber risk. No penetration testing requirement; relies on Cyber Essentials and UK GDPR compliance alone.
Level 1 (101 controls) — established security baselines.
Level 2 (139 controls) — uplifted requirements, mandates Cyber Essentials Plus.
Level 3 (144 controls) — expert "defence in depth" against sophisticated, evolving threats.
Control counts grow with each level, but penetration testing itself is governed by one control that doesn't change:
Control 2403 (Penetration Testing). It applies identically to Levels 1, 2 and 3; if you're certifying at any of those three, you're meeting the same penetration testing bar.
2. DCC Control 2403: The Core Requirements
Control 2403 requires a formal, proactive, recurring penetration testing programme with four mandates:
A. 12-month testing frequency. Penetration testing must run at least once every 12 months, an ongoing annual cycle for the life of your certification, not a one-off exercise.
B. Scope covers all external-facing assets. Testing must target every externally facing system that supports your business functions or protects data.
C. Recognised standards, qualified testers. Methodology must align with recognised industry standards, executed by suitably qualified and experienced personnel (e.g. CREST-certified testers).
D. Timely, risk-based remediation. Findings must be fixed on a timeline proportionate to their risk to the network; identifying vulnerabilities isn't enough on its own.
3. What Your DCC Penetration Test Report Must Include
Assessors don't take completion on trust — Control 2403 requires formal records. Even a redacted report must document:
- Scope and methodology — systems tested and the standard/framework used
- Findings by severity — exact counts of critical, high and medium findings
- Tester identity — the named individual or organisation who ran the test
- Testing date — the exact date the test was executed
- Remedial action plan — timelines and actions for every vulnerability found
4. What Evidence Do DCC Assessors Expect for Penetration Testing?
During assessment, the Certification Body (CB) evaluates implementation evidence, operational effectiveness and policy. Have these ready:
- Tester qualifications — proof of the standard followed and the tester's certifications or expertise
- A documented annual policy — a published company policy mandating annual external penetration testing
- An active 12-month schedule — proof a test ran against external systems within the last 12 months, plus the report or summary
- Vulnerability tracking and mitigation logs — evidence remedial actions were recorded, tracked and closed within risk-based timelines
5. Does an Authenticated Portal Count as "External"? Black-Box vs Grey-Box for DCC
A common question: if a system sits behind a login (a client portal, for example), does it fall in scope and is unauthenticated "black-box" testing enough?
Yes, authenticated systems are external-facing. Under Control 2403, any portal, application or system accessible over the internet is externally facing. If it supports business operations or protects sensitive data, it's in scope for your annual test.
No, black-box testing alone is rarely sufficient. A test that stops at the login screen tends to raise red flags with DCC assessors, for three reasons:
- Scope-restriction risk. Assessor guidance warns that penetration tests often cover a narrower scope than vulnerability scans, and assessors are directed to ask whether the scope is "too restricted to represent the DCC scope." Stopping at the login gate under-represents your real operating environment.
- Control-bypass testing. Assessors must judge whether results show bypassed security controls or weaknesses that shouldn't exist if policies were followed, something a black-box test can't surface once a user is authenticated.
- Account authorisation verification. DCC requires that every identity, account and automated function be properly verified, authenticated and authorised. Proving that requires a tester to log in with test credentials and check whether standard users can escalate privileges or reach data they shouldn't.
Recommended approach: for any system with an authenticated portal, commission grey-box (credentialed) penetration testing and supply test account credentials so access controls and data protection get properly exercised.
6. Avoiding Common DCC Penetration Testing Mistakes
Map pen testing against your vulnerability scanning programme. Don't let an overly narrow pen test scope undercut an otherwise solid vulnerability management programme.
Don't rely on generic, AI-generated policy templates. DCC permits automated tools to help draft policy, but assessors are trained to flag generic procedures that don't reflect how your business actually operates. Tailor penetration testing and remediation policies to your real workflows.
Document remediation timelines against a clear standard. Assessors scrutinise whether past risks were fixed within defined timelines. A vulnerability management process that ties remediation SLAs to CVSS v3 scores gives you a defensible, structured answer.
Get Proactive About Your DCC Penetration Testing Programme
DCC is a point-in-time assessment of ongoing operational resilience. An annual penetration testing programme that's well documented and covers both unauthenticated and authenticated perimeters protects your certification and the wider defence supply chain.
If you're preparing for a Level 1, 2 or 3 DCC assessment, start by checking your last penetration test report against the five mandatory record-keeping elements above, and confirm your remediation tracker is current. Talk to us about CREST-aligned penetration testing for DCC-ready evidence.