Skip to content
All posts

Why Cyber Essentials and DCC Scope Rarely Match

CE scope and DCC scope are not the same thing, and treating them as interchangeable is the single most common reason Defence Cyber Certification (DCC) submissions stall before they even reach assessment.

Most IT Directors default to their Cyber Essentials boundary when asked to define scope: the laptops, servers, and cloud services that touch the internet. That boundary has served organisations well for years, but it is far narrower than what DCC actually asks for.

Two different questions, two different boundaries

Cyber Essentials asks a narrow, well-defined question: which internet-connected devices, networks and cloud services does this organisation use? DCC asks something much broader: which systems, processes, procedures and data does this organisation depend on to operate and to deliver its contracted outputs, connected to the internet or not?

In practice, DCC scope is presumed to cover the whole organisation unless there is a clearly documented justification for excluding a part of it. That means systems many IT teams have never thought to include in a compliance boundary are squarely in scope:

  • Air-gapped or isolated networks running production, test, or legacy systems with no internet connection.
  • Payroll and HR systems, whether hosted on-premises or by a third party.
  • Stock management and logistics platforms underpinning delivery of contracted work.
  • Physical entry controls — door access systems, visitor management, and the sites they protect.

None of these would ordinarily fall inside a Cyber Essentials boundary. All of them can fall inside a DCC one.

Why the mismatch puts your assessment at risk

This is not a minor inconsistency to tidy up later. Applicants are required to provide a clear scoping statement showing how their DCC scope aligns with their Cyber Essentials (or Cyber Essentials Plus) scope, together with the rationale behind any exclusions, and the DCC assessor is entitled to challenge any exclusion that leaves an essential system or service outside the assurance boundary.

If the internet-connected devices, networks and cloud services inside your DCC scope are not adequately covered by your Cyber Essentials certificate, that gap is exactly the kind of thing an assessor will push back on, and if left unresolved, it can be grounds for the submission being rejected before the assessor has even reached the substance of your controls.

For CISOs and compliance managers, this makes scope alignment a gating step, not a formality. Get it wrong, and every hour spent gathering evidence for the controls themselves has been spent against the wrong boundary.

A practical way to map scope: the Five Lens approach

Government assessors facing this same challenge under GovAssure use a structured method worth borrowing directly: the Five Lens approach. Rather than trying to describe an entire organisation's scope in one pass, it breaks the exercise into five progressively narrower views:

  1. Essential service — what does this part of the organisation actually deliver, and to whom?
  2. Organisational function — what sub-functions and teams make that delivery possible?
  3. Core underlying infrastructure — what networks, hosting and authentication systems support those functions?
  4. Systems and applications — which specific platforms and tools are relied on to deliver the service?
  5. Sites and locations — where physically does all of the above sit, and how are those sites connected?

Applying all five lenses to each essential service an organisation delivers and repeating the exercise across every service produces a scope map that is far harder to poke holes in than a one-line statement of "everything the business does." It also surfaces dependencies teams often forget: a stock system that looks self-contained but actually authenticates against a domain controller inside the CE boundary, for instance, or a physical entry system tied into the same network as production servers.

Make the overlap visible, not implicit

Once the DCC scope is mapped, the next step is making the overlap with Cyber Essentials explicit rather than assumed. A clear scoping diagram showing where the CE boundary sits inside, alongside, or (problematically) outside the DCC boundary does more to reassure an assessor than paragraphs of narrative ever will. It also gives internal stakeholders, from finance to facilities, a shared picture of what "in scope" actually means before evidence-gathering begins.

Getting scope right the first time saves months. Organisations that start control implementation before scope is agreed routinely have to redo evidence once the assessor pushes back on boundary exclusions a costly rework cycle that a half-day scoping workshop at the outset would have avoided.

If your organisation is preparing for DCC and is not yet confident its Cyber Essentials and DCC scopes line up, talk to Periculo. As an official IASME Certification Body, we can help map your scope using the Five Lens approach before you commit resources to the wrong boundary.