When an aircraft maintenance manual is amended, the new pages arrive with change bars in the margin. A thin black line next to every altered paragraph. Nobody expects the engineers to re-read 400 pages to find out that step 14b subsection 2 of the maintenance procedure has been updated - you flag what changed.
IASME have just released version 2.2 of the DCC Applicant Guide. It's 383 pages, up from 363 in June. The revision history describes it as "additional guidance as per DCPP IWG request". There are no change bars, so pulled the text out of both versions and compared them, control by control and question by question.
The good news first. Not a single control or question has been added or removed. All 351 question IDs, MOD references and level applicabilities are identical. Only four questions have changed wording: 2202.1 (now "choose all that apply"), 2321.3 and 2321.4 (now tied to your own classification scheme) and 2322.1 (MDM "or equivalent").
The other 20 pages are guidance. Most of it is genuinely helpful. Some of it quietly moves the goalposts.
The introduction of judgement
The most important change isn't in a control at all. It's a new section called Assessor Judgement, and it formalises the way assessors can apply their professional experience to the scoring.
Assessors can now add or remove a point on any control using professional judgement. If you meet three of five requirements because the other two simply don't apply to how you operate, the Assessor can score you fully met. The guide is explicit that you shouldn't roll back passkeys to satisfy a password question, or install a VPN you have no use for, just to tick a box. Finally, someone has written down what practitioners have been saying for years: don't make yourself less secure to look more compliant.
However, it cuts both ways. If you have a beautifully written policy and no evidence anyone follows it, the Assessor can drop you from partially met to not met. At Levels 1 and 2, a single not met fails the whole objective. The policy-in-a-drawer approach just became a liability.
The "Updates to Controls and Guidance" section has also been rewritten around intent. DefStan 05-138 Issue 4 was finalised in May 2024, and some of its examples have aged like milk. The new text says plainly that examples are not the requirement. Show how you achieve the intent, using current NCSC and NPSA good practice, and the Assessor should score accordingly. It also says Applicants aren't expected to plan for every theoretical future threat, which is a mercy.
Two smaller housekeeping changes are worth knowing:
- Cyber Essentials. The old "CE/CE+" shorthand caused genuine confusion. It now reads CE for all levels, and CE+ only where applicable (Levels 2 and 3).
- Your ASR. If you plan to reuse a completed Assessment Submission Record for renewal or uplift, copy it first. The original must stay intact. Learn that one before you overwrite it, not after.
And for those who relied on it: the contents page has gone. Navigating 383 pages with Ctrl+F is now part of the assessment experience.
Common sense, officially sanctioned
A lot of the new control guidance is IASME giving smaller organisations permission to be proportionate.
Asset management (1300 and 1301). You don't need to inventory every keyboard and pair of headphones. At Level 2, "automation" no longer implies an enterprise platform. Exports from tools you already run, a discovery scan and a well-kept spreadsheet can do the job.
MFA and passwords (2201, 2213). Passkeys and passwordless methods are explicitly acceptable. Human passwords shouldn't be routinely rotated. OT and safety-critical systems where interactive MFA would be dangerous now have a documented route: explain why, then show what stops access relying on a single check.
Remote access (2305). This was rewritten almost from scratch. Remote access now explicitly includes webmail and other cloud services you don't host. And the guide says, in black and white, don't install a VPN just to pass the control. An incorrectly configured VPN is a new hole with a padlock painted on it.
Device trust (2202). Zero Trust and Conditional Access are now named as acceptable modern approaches. If your setup beats the control but doesn't map neatly to the questions, explain it to your Assessor.
Where the bar quietly went up
This is where I'd push back on the "clarification" label. Several changes raise expectations, and they are buried in the Jargon Busters.
Patching (2402). Most people treat Cyber Essentials' 14 days as the target. v2.2 says remediate as soon as practicable, not routinely at day 14, and adds the NCSC rollout table: 5 days for internet-facing services, 7 for operating systems and applications. Fourteen days was always the bus timetable. Now it's officially just the last bus.
Data loss prevention (2320). At Level 2, policy alone isn't enough. You need tooling that monitors and enforces across removable media, external websites and external email. AI tools are now named as a potential exfiltration channel. If your staff are pasting draft bids into a public chatbot, that is now squarely an assessment question.
Continuous monitoring (3102). At Level 3, 24/7/365 monitoring and correlation is stated outright. The welcome nuance: it doesn't have to be a staffed SOC. Automated alerting and quarantine, with investigation the next working day, can be enough where the risk supports it.
Backup transport (2506). You now need a documented policy even if you never physically move backup media.
Visitors (1503). "We don't have visitors" used to be a note. Now it's a conversation with your Assessor.
What to do this week
If you're mid-assessment, don't panic and don't rewrite everything. Do three things:
- Re-check your answers to 2202.1, 2321.3, 2321.4 and 2322.1 against the new wording.
- Walk through 2402, 2320, 3102, 2506 and 1503 and ask honestly whether your evidence still clears the bar.
- Find every policy you've cited and make sure you can prove someone actually follows it. Under Assessor Judgement, that's where the points will be lost.
If you're just starting out, v2.2 is good news. It's a more honest, more proportionate guide than the one it replaces, as long as you read it properly.
We'll be digging into specific controls over the next few days. If you'd like a second pair of eyes on where v2.2 leaves your organisation, our free Readiness Assessment will show you where you stand, with no cost and no hard sell. Drop us a line at defence@nova-blue.com, or try the instant CSMv4 readiness check at https://defence.nova-blue.com/assess.