EngineeringBritain

Defence cyber

DEFCON 658, Def Stan 05-138 and Defence Cyber Certification

Three names come up whenever a UK defence supplier is asked about cyber security. DEFCON 658 is the contract condition. Def Stan 05-138 lists the controls. Defence Cyber Certification is how a supplier can show, with independent evidence, that it meets them. This guide explains how they fit together.

Not legal advice. The MOD's Cyber Security Model guidance on GOV.UK, the Industry Security Notices it publishes and your own contract are the authoritative sources. If a contract's Security Aspects Letter conflicts with general guidance, the MOD says to refer to your delivery team.

The short version

NameWhat it isWho owns it
DEFCON 658The MOD contract condition that imposes cyber requirements on a supplier and its supply chainMOD
Cyber Security Model (CSM)The process that assesses a contract's cyber risk and records the supplier's responseMOD
Cyber Risk ProfileThe risk level assigned to a contract: Level 0, 1, 2 or 3 under CSM version 4Set by the MOD buyer's risk assessment
Def Stan 05-138 (Issue 4)The Defence Standard listing the controls required at each Cyber Risk Profile levelMOD, published May 2024
Supplier Assurance Questionnaire (SAQ)The supplier's statement of how it meets the controlsCompleted by the supplier
Defence Cyber Certification (DCC)An independently assessed certification against those control levelsDelivered with IASME and its certification bodies; launched May 2025
Cyber Essentials / Cyber Essentials PlusThe government-backed baseline cyber scheme; part of the DCC requirementsNational Cyber Security Centre, delivered by IASME

How the process runs on a contract

  1. The buyer assesses the risk. Before advertising a requirement, the MOD buying team completes a risk assessment. The result is a Cyber Risk Profile and a Risk Assessment Reference (RAR), which appears in the tender documents.
  2. The supplier completes the SAQ. Using the RAR, bidders complete a Supplier Assurance Questionnaire through the Supplier Cyber Protection Service linked from the MOD's Cyber Security Model page on GOV.UK. Since 3 December 2025, new risk assessments and SAQs must go through that tooling (Industry Security Notice 2025/07).
  3. Gaps become a plan. Where a supplier does not yet meet every control, the MOD's process allows a Cyber Improvement Plan setting out how and when gaps will be closed. The buyer decides whether that is acceptable for the contract.
  4. The contract carries DEFCON 658. The supplier must apply the controls for the profile level and flow the requirements down to subcontractors whose work involves the relevant MOD information.
  5. The SAQ is reviewed every year. ISN 2025/07 reinstated the annual review, on the contract's anniversary date. Suppliers on older contracts are notified of their updated profile level under CSM version 4 ahead of that date.

The four Cyber Risk Profile levels

CSM version 4 uses four levels, Level 0 to Level 3, replacing the older names (Very Low, Low, Moderate, High). Def Stan 05-138 Issue 4 sets out the controls for each level, and each level includes everything below it. Level 0 is the baseline expected of suppliers handling little or no sensitive MOD information; higher levels add controls across governance, identity and access, data protection, monitoring, incident response and resilience. Obtain the standard itself (it is published on GOV.UK) rather than relying on a summary of how many controls each level contains.

Where Defence Cyber Certification fits

An SAQ is a self-declaration. Defence Cyber Certification adds independent assessment. Industry Security Notice 2026/02 (30 March 2026) instructs MOD buyers to accept a current, valid DCC certificate as meeting the Def Stan 05-138 control requirement where the certificate's level is equal to or higher than the level the contract requires:

DCC heldLevel 0 requiredLevel 1 requiredLevel 2 requiredLevel 3 required
DCC Level 0CompliantNot compliantNot compliantNot compliant
DCC Level 1CompliantCompliantNot compliantNot compliant
DCC Level 2CompliantCompliantCompliantNot compliant
DCC Level 3CompliantCompliantCompliantCompliant

Source: ISN 2026/02, paragraph 7.

The 31 December 2026 Level 0 request

Writing on the MOD's Defence Digital blog in May 2026, the MOD's Director of Cyber Defence and Risk said she had asked all industry partners to achieve DCC Level 0 by 31 December 2026, including Cyber Essentials for all applicable business-critical systems in scope. IASME, which delivers the scheme, has said DCC is not currently a universal mandatory requirement, but a request from the customer with a date attached is one most suppliers will plan around. If you are unsure whether it applies to you, ask your MOD delivery team or your prime.

Cyber Essentials and Cyber Essentials Plus

A practical preparation checklist

Common questions

Is DEFCON 658 in every MOD contract?

No. It is used where the contract involves the transfer or generation of MOD identifiable information. Where it applies, the tender documents give the Risk Assessment Reference.

We are a subcontractor. Does this apply to us?

Often, yes. DEFCON 658 requirements flow down to subcontractors whose work involves the relevant information, and primes commonly ask for Cyber Essentials and, increasingly, DCC as a condition of supply.

Does DCC replace the Supplier Assurance Questionnaire?

ISN 2026/02 says a DCC certificate at the right level may be submitted as evidence that the Def Stan 05-138 controls are met, and buyers should accept it as such. The contract's process still applies, so follow the instructions in the tender.

How long does DCC take?

It depends on how far your current controls are from the level required. Suppliers starting from Cyber Essentials and documented policies move faster than those building both at once. Allow time for remediation after the first assessment.

Where else do these requirements show up?

In prime contractors' pre-qualification, including the cyber section of JOSCAR, and in the wider steps to becoming an MOD supplier.

Last reviewed 2026-09-17