Periculo Blog

The Rules of Engagement: What Your Certification Body Can and Cannot Do

Written by Craig Pepper | Aug 25, 2026, 5:30:00 AM

Somewhere in every DCC preparation project, a compliance officer asks a reasonable question: "Can our Certification Body just fix this for us?" The honest answer is no, and understanding exactly where that line sits is one of the more overlooked parts of preparing for Defence Cyber Certification (DCC).

Get the relationship with your Certification Body (CB) wrong, and you risk a conflict of interest that undermines the credibility of the certificate you are working towards.

Why the boundary exists

A DCC certificate only means something if the assessment behind it is impartial. If the same organisation, or worse, the same individuals both built your security controls and then signed off on them, the certificate stops being independent assurance and becomes a self-assessment with extra paperwork.

The scheme protects against that by drawing a firm line between two distinct roles a CB can play: advisory support and assessment. A CB can offer one or the other to a given applicant, but not both at once for the same engagement.

What a CB can do

Within the advisory role, a CB has plenty of latitude to help an applicant prepare:

  • Explain the DCC levels and help an organisation decide which one fits its risk profile and contract pipeline.
  • Clarify individual controls — what evidence a control is actually asking for, and what "good" looks like in practice.
  • Support Cyber Essentials and Cyber Essentials Plus preparation, since these sit as prerequisites underneath every DCC level.
  • Identify gaps in an organisation's current posture relative to the standard, so the applicant knows where to focus effort.

All of this is legitimate, expected, and genuinely useful; a good CB should be able to talk an applicant through the standard in plain English long before any formal submission is made.

What a CB cannot do

The moment a CB is also acting as the assessor for an applicant, it steps back from anything resembling hands-on delivery:

  • It cannot implement controls on the applicant's behalf — writing the actual policy documents, configuring the firewall, deploying the endpoint agent.
  • It cannot manage the applicant's security defences day-to-day.
  • It cannot prepare the evidence package that the applicant submits for assessment — that evidence has to be the applicant's own work, describing its own environment.
  • The same individual or team within the CB cannot both implement and audit the same organisation, even where the CB itself offers both services more broadly.

This is not the CB being unhelpful — it is the CB protecting the value of the certificate it is about to issue.

What this means for compliance teams

For compliance officers and operations teams assembling a submission, the practical takeaway is to plan resourcing with this boundary in mind from the outset. If your organisation needs genuinely hands-on help, someone to actually write the policies, reconfigure the network, or roll out new controls that work needs to sit with a separate, independent technology provider, or with a distinct and separated part of your CB's business that is walled off from the assessment team. Trying to get your assessor to also do the implementation work will not speed up certification; it will disqualify the assessment.

A useful test before engaging any support: ask directly whether the same people (or the same commercially incentivised team) will end up both advising on your controls and assessing them. If the answer is yes, that is the point to bring in a second, independent party, not a point to work around.

Building the right team around your submission

None of this means an applicant is left to figure everything out alone. It means being deliberate about who does what: advisory input from your CB to understand the standard and spot gaps, independent technical delivery where hands-on implementation is needed, and a genuinely arm's-length assessment at the end. Organisations that set this structure up early tend to move through certification with far fewer surprises than those who discover the boundary exists partway through their assessment.

If you are scoping out your DCC submission and want to understand where advisory support ends and independent delivery needs to begin, get in touch with Periculo.

As an official IASME Certification Body, we can talk you through exactly what support we can offer directly and where you will need to look elsewhere.