Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Preparing

What good evidence actually looks like

The difference between a smooth Level 0 assessment and a slow one is almost entirely whether the evidence already exists in a form somebody else can read.

DCC Level 0 › The evidence pack

Defence Cyber Certification Level 0 is assessed on evidence. Not on a conversation about your intentions, and not on a self-declaration. That is the whole point of it, and it is why it carries more weight with buyers than a questionnaire.

The practical consequence is that preparation is mostly an exercise in assembling things that already exist, in a form an assessor can verify without taking your word for it.

The hierarchy of evidence

Not all evidence is equal, and the difference is consistently underestimated.

The same fact, evidenced three ways
StrengthExample, for patchingWhy
StrongAn exported report from your management tooling showing patch status across every device on a stated dateGenerated by a system, covers the whole estate, timestamped, hard to curate.
AdequateScreenshots of the patching policy and of the compliance dashboardShows configuration and a summary, but is a point in time and easy to select favourably.
WeakA written statement that patches are applied within fourteen daysAn assertion. It may well be true and it is not evidence.

Aim for strong wherever the tooling can produce it, which for most of Level 0 it can.

What to assemble

Asset inventory

Every device and system in scope: what it is, what it runs, who uses it, where it lives. Exported from your management tooling rather than typed up, and with a revision history if you have one. An inventory assembled the week of the assessment is visibly different from one that has been maintained, and assessors notice.

Scope definition

A short written statement of which systems handle the defence information and therefore fall in scope, with the reasoning. This is the document everything else is judged against, so it is worth more care than its length suggests.

Patching evidence

The policy, and a report showing actual patch status across the estate. Both. The policy alone proves intent; the report proves practice.

Access control evidence

Your joiners, movers and leavers process, plus a current list of accounts with administrative privilege and who holds them. The second one is the one that gets scrutinised, because it is where the gap between policy and reality usually sits.

Malware protection evidence

Central console output showing protection enabled and updating across every device in scope, not a screenshot of one machine.

Boundary protection evidence

Firewall configuration, rule review records, and evidence that inbound rules have a documented business reason. Rule reviews are the thing most often absent, and a review record dated eighteen months ago is a finding in itself.

Cyber Essentials certificate

Required at every DCC level including Level 0, so it is part of the pack rather than an alternative to it. Make sure it is current and that its scope covers the systems in your DCC scope, which is a mismatch that catches people out.

Supplier register

Which of your own suppliers handle the covered information, what they are required to hold, and what they currently hold.

Four things that slow an assessment down

The two-week assembly plan

  1. Days one and two. Write the scope statement. Everything else follows from it.
  2. Days three to five. Export the inventory and reconcile it against what you believe you own. Investigate every discrepancy.
  3. Week two, first half. Pull the patching, access control and malware reports. Fix what they reveal, because they will reveal something.
  4. Week two, second half. Gather the policies, date and version them, and assemble the supplier register.
  5. Before submission. Read the pack as though you were the assessor. Anything you would question, they will.

What this buys you beyond the certificate

The pack is close to what you need for Cyber Essentials, for most customer security questionnaires, and for an insurance application. Assembling it once and keeping it current turns a recurring scramble into a file you update quarterly, which is a better position than certification alone.

Who should own the pack

The pack fails in the same way documents always fail: it is assembled by whoever was available, for a deadline, and then nobody owns it. Twelve months later it is out of date and the next assessment starts from scratch.

Give it a named owner, and make the owner somebody who will still be doing the same job in a year. In a small organisation this is usually whoever owns IT, or the operations lead. The specific person matters less than that there is one.

Their job is not to produce the evidence, which comes out of the tooling. It is to run a quarterly refresh: re-export the reports, check what changed, and note anything that would now fail. An hour, four times a year.

Storing it sensibly

The pack describes your security posture in some detail, which makes it useful to an attacker as well as to an assessor. It should not sit in a shared folder everybody can read.

Restricted access, version control so you can see what changed and when, and a retention position so you keep last year's pack for comparison but are not keeping seven years of it. If your storage is itself in the certified scope, worth confirming it meets the controls it describes.

What the pack is worth beyond the certificate

This is the part suppliers usually discover afterwards and wish they had known. The same pack, with very little modification, answers:

Those things arrive unpredictably and usually with a short deadline. An organisation with a current evidence pack answers them in an afternoon. An organisation without one spends a fortnight assembling the same material under time pressure, and does it again next time.

Which is the argument for treating the pack as an asset you maintain rather than a submission you produce.

Do we need formal written policies?

You need documented processes. They do not have to be long or formally styled. A one-page starters and leavers process that is actually followed is worth more than a twenty-page policy nobody has read, and assessors can tell the difference.

Can screenshots be used as evidence?

Yes, and they are adequate rather than strong. Where your tooling can export a report covering the whole estate, that is considerably better. Always make sure anything you submit is dated.

How current does the evidence need to be?

Recent enough to reflect the estate as it is now. Reports generated within the last month are comfortable. Anything older than a quarter will be questioned, and reasonably so.

What if we find a gap while assembling the pack?

Fix it and evidence the fix. Finding gaps is what the exercise is for. What causes difficulty is submitting evidence that shows a gap without addressing it, which turns a preparation task into an assessment finding.

Want the pack reviewed before you submit?

Send us what you have assembled and we will tell you where an assessor will push back, and what to strengthen.