Thousands of defence SMEs are heading into DCC assessment. Snubnose is how Certification Bodies meet that demand at scale, without drowning your team in paperwork. Efficient, consistent, defensible.
Certification Bodies delivering DCC through Snubnose
DCC is about to put thousands of SMEs through assessment. We're making sure the ones who land on your desk arrive ready.
You're in from the start. The SME builds their scope inside Snubnose and you verify each step (sites, systems, data, people, target level) before a single piece of evidence is collected.
No more audit-day scope surprises. No email chains to reconcile.
Every artifact is tagged to the controls it satisfies, versioned, and annotated. Our AI pre-validates against the standard so junk evidence doesn't reach your reviewers.
Audit effort per engagement drops materially.
Alliance members sit on the preferred-CB list we draw from when an SME asks us to introduce them to a Certification Body. You choose the sectors, sizes and regions you want to see.
Grow your book without growing your BD team.
Quarterly working sessions with our product team. Your interpretations shape the control library, the evidence rules, and the assessor workspace itself.
The tool fits the way you actually audit.
Your team is trained on the Snubnose platform before your first engagement. You then assess inside the same workspace the SME prepared in (reviewing evidence, raising clarifications, and issuing findings, all in-app) as we build towards a seamless, guided assessor experience focused on the controls that matter most to a supplier's cyber resilience.
Audit day stops being a surprise. For both sides.
We keep the alliance small on purpose. Every member goes through the same onboarding.
Tell us about your firm, your DCC readiness, and the sectors you serve. We review applications weekly and run a 30-minute intro call with every qualifying firm. We can also help with your DCC certification.
Your assessors get hands-on training on the Snubnose platform, the DefStan 05-138 control library, and the evidence review workflow. Certification is completed in a single afternoon.
We add your firm to the preferred-CB list we draw from when SMEs ask us to introduce them to a Certification Body. SMEs in your chosen sectors are matched to you based on scope fit, capacity, and sector expertise.
We pair alliance members with SMEs at the start; you verify the scope in-app, then review evidence as it's submitted. No hand-off, no audit-day surprises, and every engagement feeds back into the platform, making the next one cleaner.
A longer-form explainer: who the Alliance is for, what Certification Bodies receive, why no referral fees change hands under ISO/IEC 17021-1, and how the Alliance sits inside the DCC scheme alongside IASME and UKAS.
Read the full explainerThe alliance isn't open to everyone. We're looking for CBs who meet all of the following.
You're an established Certification Body with a track record in information-security standards (ISO 27001, Cyber Essentials Plus, or similar).
You've already audited defence-sector SMEs, or you're credentialed to assess against DefStan 05-138 / DCC.
You have assessor capacity to take on referrals. The programme is built for CBs who can absorb real pipeline, not a logo-only partnership.
You'll join quarterly working sessions and give direct feedback on the control library, evidence rules, and assessor workspace.
We give preference to firms with a strong defence focus (veteran-founded, veteran-led, or with demonstrable ties to UK defence primes and MOD supply chains). The SMEs going through DCC are building the capability our armed forces depend on. We want assessors who get that.
Applications are reviewed weekly. If you're a CB working in UK defence, we'd like to hear from you.