Do I need DCC if I already have ISO 27001?
Yes. ISO 27001 certification does not exempt you from Defence Cyber Certification. If your MOD contract specifies a Cyber Risk Profile, the way to evidence it is DCC at the corresponding level, underpinned by Cyber Essentials. ISO 27001 is neither a prerequisite nor a substitute; it is a different certification answering a different question.
The good news: if you genuinely operate an ISO 27001 information security management system, much of the work transfers. You will find the DCC journey shorter than a company starting cold.
Why does ISO 27001 not count?
Because the MOD's assurance chain is specific. CSM v4 assigns your contract a Cyber Risk Profile, DefStan 05-138 defines the controls at that profile, and DCC certifies you against exactly those controls. The MOD gets like-for-like assurance across every supplier, assessed by IASME-approved certification bodies against its own standard.
ISO 27001 certifies that you operate a risk-based management system of your own design and scope. Two ISO-certified companies can have very different actual control coverage depending on their Statement of Applicability. That flexibility is ISO's strength commercially and its weakness as defence assurance: it does not tell the MOD that the specific DefStan controls are in place.
Where ISO 27001 genuinely helps
Plenty of overlap exists, and it is worth exploiting.
- Governance and risk management. DCC Levels 1 and above require documented risk management, defined responsibilities, and policy frameworks. A living ISMS gives you most of this evidence off the shelf.
- Evidence culture. ISO's audit discipline of records, reviews, internal audit and management review is precisely the muscle DefStan Issue 4 assessments exercise. Companies used to external audit find DCC assessment familiar rather than frightening.
- Cross-mapping. A competent gap analysis maps your existing ISO controls to the DefStan control set, so you only build what is genuinely missing rather than starting again.
One honest caveat from experience: an ISO certificate maintained as a paperwork exercise, renewed annually and lived never, transfers almost nothing. Independent DCC assessment will find the gap between your documentation and your reality, because that is what it is designed to do.
Which should I get first?
If defence is your market, the sequence is Cyber Essentials, then DCC at the level your contracts demand, then ISO 27001 only when a customer or commercial situation genuinely requires it.
DCC opens MOD doors. ISO 27001 opens certain commercial and international ones. Certifying to ISO speculatively, before any customer has asked, is a five-figure decision that deserves more scrutiny than it usually gets.
Making your ISO work harder
If you already hold ISO 27001, do not resent the extra certification. You have built the governance muscle that most companies approaching DCC lack entirely.
The fastest route from here is a cross-mapping exercise rather than a fresh compliance programme: identify what your Statement of Applicability already covers, close the specific DefStan gaps, certify. Weeks, not months.
How much of your existing programme counts?
We map ISO 27001, NIST and CMMC controls into UK DefStan and CSM requirements, so you build only what is genuinely missing. Ask us what your Statement of Applicability already covers.