Defence cyber
DEFCON 658, Def Stan 05-138 and Defence Cyber Certification
Three names come up whenever a UK defence supplier is asked about cyber security. DEFCON 658 is the contract condition. Def Stan 05-138 lists the controls. Defence Cyber Certification is how a supplier can show, with independent evidence, that it meets them. This guide explains how they fit together.
Not legal advice. The MOD's Cyber Security Model guidance on GOV.UK, the Industry Security Notices it publishes and your own contract are the authoritative sources. If a contract's Security Aspects Letter conflicts with general guidance, the MOD says to refer to your delivery team.
The short version
| Name | What it is | Who owns it |
|---|---|---|
| DEFCON 658 | The MOD contract condition that imposes cyber requirements on a supplier and its supply chain | MOD |
| Cyber Security Model (CSM) | The process that assesses a contract's cyber risk and records the supplier's response | MOD |
| Cyber Risk Profile | The risk level assigned to a contract: Level 0, 1, 2 or 3 under CSM version 4 | Set by the MOD buyer's risk assessment |
| Def Stan 05-138 (Issue 4) | The Defence Standard listing the controls required at each Cyber Risk Profile level | MOD, published May 2024 |
| Supplier Assurance Questionnaire (SAQ) | The supplier's statement of how it meets the controls | Completed by the supplier |
| Defence Cyber Certification (DCC) | An independently assessed certification against those control levels | Delivered with IASME and its certification bodies; launched May 2025 |
| Cyber Essentials / Cyber Essentials Plus | The government-backed baseline cyber scheme; part of the DCC requirements | National Cyber Security Centre, delivered by IASME |
How the process runs on a contract
- The buyer assesses the risk. Before advertising a requirement, the MOD buying team completes a risk assessment. The result is a Cyber Risk Profile and a Risk Assessment Reference (RAR), which appears in the tender documents.
- The supplier completes the SAQ. Using the RAR, bidders complete a Supplier Assurance Questionnaire through the Supplier Cyber Protection Service linked from the MOD's Cyber Security Model page on GOV.UK. Since 3 December 2025, new risk assessments and SAQs must go through that tooling (Industry Security Notice 2025/07).
- Gaps become a plan. Where a supplier does not yet meet every control, the MOD's process allows a Cyber Improvement Plan setting out how and when gaps will be closed. The buyer decides whether that is acceptable for the contract.
- The contract carries DEFCON 658. The supplier must apply the controls for the profile level and flow the requirements down to subcontractors whose work involves the relevant MOD information.
- The SAQ is reviewed every year. ISN 2025/07 reinstated the annual review, on the contract's anniversary date. Suppliers on older contracts are notified of their updated profile level under CSM version 4 ahead of that date.
The four Cyber Risk Profile levels
CSM version 4 uses four levels, Level 0 to Level 3, replacing the older names (Very Low, Low, Moderate, High). Def Stan 05-138 Issue 4 sets out the controls for each level, and each level includes everything below it. Level 0 is the baseline expected of suppliers handling little or no sensitive MOD information; higher levels add controls across governance, identity and access, data protection, monitoring, incident response and resilience. Obtain the standard itself (it is published on GOV.UK) rather than relying on a summary of how many controls each level contains.
Where Defence Cyber Certification fits
An SAQ is a self-declaration. Defence Cyber Certification adds independent assessment. Industry Security Notice 2026/02 (30 March 2026) instructs MOD buyers to accept a current, valid DCC certificate as meeting the Def Stan 05-138 control requirement where the certificate's level is equal to or higher than the level the contract requires:
| DCC held | Level 0 required | Level 1 required | Level 2 required | Level 3 required |
|---|---|---|---|---|
| DCC Level 0 | Compliant | Not compliant | Not compliant | Not compliant |
| DCC Level 1 | Compliant | Compliant | Not compliant | Not compliant |
| DCC Level 2 | Compliant | Compliant | Compliant | Not compliant |
| DCC Level 3 | Compliant | Compliant | Compliant | Compliant |
Source: ISN 2026/02, paragraph 7.
The 31 December 2026 Level 0 request
Writing on the MOD's Defence Digital blog in May 2026, the MOD's Director of Cyber Defence and Risk said she had asked all industry partners to achieve DCC Level 0 by 31 December 2026, including Cyber Essentials for all applicable business-critical systems in scope. IASME, which delivers the scheme, has said DCC is not currently a universal mandatory requirement, but a request from the customer with a date attached is one most suppliers will plan around. If you are unsure whether it applies to you, ask your MOD delivery team or your prime.
Cyber Essentials and Cyber Essentials Plus
- Cyber Essentials covers five technical control themes: firewalls, secure configuration, user access control, malware protection and security update management. It is verified through a self-assessment questionnaire reviewed by a certification body.
- Cyber Essentials Plus covers the same controls, with hands-on technical testing by an assessor.
- Both are renewed annually. An expired certificate is one of the most common reasons a supplier's evidence is rejected.
- Scope matters. A certificate that covers only part of your organisation may not cover the systems that will hold MOD information.
A practical preparation checklist
- Get a copy of Def Stan 05-138 Issue 4 and read the controls for Level 0 and Level 1.
- Map where MOD or prime-contractor information would sit: email, file storage, engineering tools, shop-floor systems, laptops and phones.
- Achieve Cyber Essentials for that scope, then decide whether Plus is needed.
- Write down the policies the controls expect, such as access control, incident response and supplier security, and make sure they are followed.
- List your own suppliers and IT providers who would touch MOD information; the requirements flow down to them too.
- Choose a DCC certification body and book the assessment with enough time to fix findings.
- Record your certificate dates and SAQ anniversary dates in one place.
Common questions
Is DEFCON 658 in every MOD contract?
No. It is used where the contract involves the transfer or generation of MOD identifiable information. Where it applies, the tender documents give the Risk Assessment Reference.
We are a subcontractor. Does this apply to us?
Often, yes. DEFCON 658 requirements flow down to subcontractors whose work involves the relevant information, and primes commonly ask for Cyber Essentials and, increasingly, DCC as a condition of supply.
Does DCC replace the Supplier Assurance Questionnaire?
ISN 2026/02 says a DCC certificate at the right level may be submitted as evidence that the Def Stan 05-138 controls are met, and buyers should accept it as such. The contract's process still applies, so follow the instructions in the tender.
How long does DCC take?
It depends on how far your current controls are from the level required. Suppliers starting from Cyber Essentials and documented policies move faster than those building both at once. Allow time for remediation after the first assessment.
Where else do these requirements show up?
In prime contractors' pre-qualification, including the cyber section of JOSCAR, and in the wider steps to becoming an MOD supplier.
Last reviewed 2026-09-17