Somewhere in every DCC preparation project, a compliance officer asks a reasonable question: "Can our Certification Body just fix this for us?" The honest answer is no, and understanding exactly where that line sits is one of the more overlooked parts of preparing for Defence Cyber Certification (DCC).
Get the relationship with your Certification Body (CB) wrong, and you risk a conflict of interest that undermines the credibility of the certificate you are working towards.
A DCC certificate only means something if the assessment behind it is impartial. If the same organisation, or worse, the same individuals both built your security controls and then signed off on them, the certificate stops being independent assurance and becomes a self-assessment with extra paperwork.
The scheme protects against that by drawing a firm line between two distinct roles a CB can play: advisory support and assessment. A CB can offer one or the other to a given applicant, but not both at once for the same engagement.
Within the advisory role, a CB has plenty of latitude to help an applicant prepare:
All of this is legitimate, expected, and genuinely useful; a good CB should be able to talk an applicant through the standard in plain English long before any formal submission is made.
The moment a CB is also acting as the assessor for an applicant, it steps back from anything resembling hands-on delivery:
This is not the CB being unhelpful — it is the CB protecting the value of the certificate it is about to issue.
For compliance officers and operations teams assembling a submission, the practical takeaway is to plan resourcing with this boundary in mind from the outset. If your organisation needs genuinely hands-on help, someone to actually write the policies, reconfigure the network, or roll out new controls that work needs to sit with a separate, independent technology provider, or with a distinct and separated part of your CB's business that is walled off from the assessment team. Trying to get your assessor to also do the implementation work will not speed up certification; it will disqualify the assessment.
A useful test before engaging any support: ask directly whether the same people (or the same commercially incentivised team) will end up both advising on your controls and assessing them. If the answer is yes, that is the point to bring in a second, independent party, not a point to work around.
None of this means an applicant is left to figure everything out alone. It means being deliberate about who does what: advisory input from your CB to understand the standard and spot gaps, independent technical delivery where hands-on implementation is needed, and a genuinely arm's-length assessment at the end. Organisations that set this structure up early tend to move through certification with far fewer surprises than those who discover the boundary exists partway through their assessment.
If you are scoping out your DCC submission and want to understand where advisory support ends and independent delivery needs to begin, get in touch with Periculo.
As an official IASME Certification Body, we can talk you through exactly what support we can offer directly and where you will need to look elsewhere.