DCF Cymru Digital competence for Wales

← All qualifications

GCSE Computer Science

Both units are sat on screen. Unit 1 tests theory (algorithms, data representation, networks, cybersecurity, logic, the systems development life cycle) and Unit 2 asks learners to design, write, test and refine Python 3 programs with a Tkinter interface in IDLE against a pre-released scenario. The single biggest thing KS3 should build is confident algorithm design and debugging: pupils who can decompose a problem, write it as a flowchart or pseudocode, then code, test and fix it arrive ready for Unit 2.

Awarding body
WJEC
Level
Level 1 and Level 2
First taught
September 2025
Amount of digital work
High
Specification
Open the specification
How this qualification is assessed
  • Unit 1: Understanding Computer Science: Digital examination 1 hour 30 minutes, 50%, 80 marks
  • Unit 2: Computer Programming: On-screen examination based on a pre-released brief, 2 hours, 50%, 80 marks, set and marked by WJEC

Skills that use Identity, image and reputation

  1. Recognising cyber threats and protecting personal data

    Assessed: In the exam

    Learners know threats such as malware, phishing and other social engineering, brute force and data interception, and the purpose of protections such as passwords, multifactor authentication, backups, firewalls and encryption.

    DCF: Identity, image and reputation, Storing and sharing, Online behaviour and online bullying

    Getting pupils ready

    Year 7
    Pupils sort a set of real and fake emails into 'safe' and 'phishing' and highlight the clues that gave each fake away.
    Year 8
    Pupils test sample passwords against a strength checklist, then set up multifactor authentication on their school Microsoft 365 account.
    Year 9
    Pupils encrypt and decrypt messages with a Caesar cipher by hand, then discuss why brute force breaks it and why modern encryption does not.
    Show the specification wording and the DCF statements

    Where it is in the specification: Unit 1, Section 1.3.2 Cybersecurity and personal privacy, pages 15 to 16

    “social engineering such as phishing, pretexting, baiting, quid pro quo and impersonation”
    Progression step 3
    • I can understand how to protect myself from online identity theft, e.g. identifying secure sites, phishing, scam websites.

    • I can identify the benefits and risks of giving personal information and device access to different software.

    Progression step 4
    • I can use strategies for guarding myself against identity theft and online scams that try to access my personal information.

    • I can show an awareness of simple encryption and its purpose, e.g. to send sensitive data more securely.

    • I can act appropriately online, keeping myself safe and behaving in a responsible manner.

    Progression step 5
    • I can continuously evaluate online behaviour, taking into consideration the consequences of actions; take action to minimise risk to safety and security; consider global and cultural perspectives and adapt behaviour accordingly.

    • I can explain the ethical issues of corporate encryption, e.g. building in a bypass system.

    • I can recognise the risks and the uses of data/services on personal devices, within the terms and conditions of a range of software and web services, and identify how organisations become data compliant when using multi-national products.

Good to know

Links with other qualifications

GCSE Digital Technology shares the binary data representation, compression calculation, cyber threats (phishing, social engineering, man-in-the-middle attacks), data validation and legal and ethical content, and its practical work also involves coding (JavaScript arrays, string methods and form validation), so Years 7 to 9 work on these skills serves both GCSEs; the binary, logic and storage calculations also draw on Mathematics number skills.

Source: WJEC GCSE Computer Science specification, teaching from 2025, for award from 2027, Version 3, September 2025.