UK defence procurement no longer assesses cybersecurity contract by contract. The Ministry of Defence (MOD) and IASME have replaced that patchwork approach with the Defence Cyber Certification (DCC), a single, organisation-wide assurance that supports multiple procurements at once, built around Def Stan 05-138.
That shift puts more weight on proving your defences actually hold up under attack. Penetration testing is the mechanism DCC uses to validate perimeter security, but what it demands depends entirely on which of the four DCC levels (0 to 3) you're certifying against. This guide breaks down the exact DCC penetration testing requirements for each level, what assessors expect to see as evidence, and where organisations most often trip up.
DCC's four levels scale with your assessed Cyber Risk Profile (CRP) under Def Stan 05-138:
Level 0 (3 controls) — very low cyber risk. No penetration testing requirement; relies on Cyber Essentials and UK GDPR compliance alone.
Level 1 (101 controls) — established security baselines.
Level 2 (139 controls) — uplifted requirements, mandates Cyber Essentials Plus.
Level 3 (144 controls) — expert "defence in depth" against sophisticated, evolving threats.
Control counts grow with each level, but penetration testing itself is governed by one control that doesn't change:
Control 2403 (Penetration Testing). It applies identically to Levels 1, 2 and 3; if you're certifying at any of those three, you're meeting the same penetration testing bar.
Control 2403 requires a formal, proactive, recurring penetration testing programme with four mandates:
A. 12-month testing frequency. Penetration testing must run at least once every 12 months, an ongoing annual cycle for the life of your certification, not a one-off exercise.
B. Scope covers all external-facing assets. Testing must target every externally facing system that supports your business functions or protects data.
C. Recognised standards, qualified testers. Methodology must align with recognised industry standards, executed by suitably qualified and experienced personnel (e.g. CREST-certified testers).
D. Timely, risk-based remediation. Findings must be fixed on a timeline proportionate to their risk to the network; identifying vulnerabilities isn't enough on its own.
Assessors don't take completion on trust — Control 2403 requires formal records. Even a redacted report must document:
During assessment, the Certification Body (CB) evaluates implementation evidence, operational effectiveness and policy. Have these ready:
A common question: if a system sits behind a login (a client portal, for example), does it fall in scope and is unauthenticated "black-box" testing enough?
Yes, authenticated systems are external-facing. Under Control 2403, any portal, application or system accessible over the internet is externally facing. If it supports business operations or protects sensitive data, it's in scope for your annual test.
No, black-box testing alone is rarely sufficient. A test that stops at the login screen tends to raise red flags with DCC assessors, for three reasons:
Recommended approach: for any system with an authenticated portal, commission grey-box (credentialed) penetration testing and supply test account credentials so access controls and data protection get properly exercised.
Map pen testing against your vulnerability scanning programme. Don't let an overly narrow pen test scope undercut an otherwise solid vulnerability management programme.
Don't rely on generic, AI-generated policy templates. DCC permits automated tools to help draft policy, but assessors are trained to flag generic procedures that don't reflect how your business actually operates. Tailor penetration testing and remediation policies to your real workflows.
Document remediation timelines against a clear standard. Assessors scrutinise whether past risks were fixed within defined timelines. A vulnerability management process that ties remediation SLAs to CVSS v3 scores gives you a defensible, structured answer.
DCC is a point-in-time assessment of ongoing operational resilience. An annual penetration testing programme that's well documented and covers both unauthenticated and authenticated perimeters protects your certification and the wider defence supply chain.
If you're preparing for a Level 1, 2 or 3 DCC assessment, start by checking your last penetration test report against the five mandatory record-keeping elements above, and confirm your remediation tracker is current. Talk to us about CREST-aligned penetration testing for DCC-ready evidence.