Cyber Security

DEFCON 658, Def Stan 05-138 and CSMv4 in Plain English for Subcontractors

Printed defence contract documents fanned out on a desk
On this page

You have had the letter, or the clause has turned up in a contract renewal, and it names things you have never had to think about before. DEFCON 658. Def Stan 05-138. The Cyber Security Model. Defence Cyber Certification. Four names, sometimes a fifth if someone mentions the Supplier Assurance Questionnaire, and a contact at the other end who can tell you the date but not much else.

This article does one job: which document does what, how each one reaches a subcontractor two or three tiers below the Ministry of Defence, and why your prime cannot quietly make the requirement go away. If you want the practical steps instead, start with our explainer on what MOD has asked suppliers to do by 31 December 2026.

Four documents, one requirement

The simplest way to hold this in your head is that there is one requirement, expressed through four documents that each do a different job.

  • DEFCON 658 is the contract clause. It is the mechanism that puts cyber security obligations into an MOD contract and pushes them down to subcontractors.
  • Def Stan 05-138 is the control standard. It lists the security controls a supplier has to have in place, organised by risk level.
  • The Cyber Security Model, now at version 4, is the process MOD uses to decide how risky a contract is and therefore which level of Def Stan 05-138 applies.
  • Defence Cyber Certification is how you prove you meet the controls. It is an independent certification, developed by MOD with IASME and launched on 8 May 2025, delivered through licensed certification bodies.

Clause, standard, risk process, proof. Once you see the four in that order, most of the confusion goes.

DEFCON 658: the contract clause

DEFCONs are MOD's standard contract conditions. DEFCON 658 is the one that deals with cyber security. When it appears in a contract, it obliges the contractor to meet the cyber security controls set out in Def Stan 05-138 at the level the contract specifies, and it is the route by which those obligations travel down the supply chain to subcontractors.

Two things follow from this for a subcontractor.

First, the requirement is contractual, not a preference of the company that sent it. If DEFCON 658 sits in your prime's contract with MOD, or with the tier above you, the controls are part of the deal your prime has signed and agreed to flow down. It cannot decide that you are a special case.

Second, the wording matters. The clause points to a standard and a level. If the letter does not name the level, ask for it in writing. We come back to how below.

Def Stan 05-138 Issue 4: the control standard

Def Stan 05-138 is the Defence Standard that sets out the cyber security controls for suppliers. Issue 4, the current version, was published in May 2024. Everything in Defence Cyber Certification traces back to it: when an assessor checks a control, it is a Def Stan 05-138 control.

The standard is organised around four Cyber Risk Profiles: very low, low, moderate and high. Each profile carries its own set of controls, and each profile maps to a Defence Cyber Certification level. Very low sits with Level 0, low with Level 1, moderate with Level 2 and high with Level 3.

Across the four levels there are 148 controls in total, grouped into control domains covering governance, identity, device, secure configuration and supply chain. The higher the profile, the more of the 148 you must meet and the more rigorously you must evidence them.

In plain terms:

  • Level 0 asks for three controls: Cyber Essentials, UK GDPR and data protection, and business resilience. We cover what each asks for and the evidence that passes separately.
  • Level 1 asks for 101 controls, with Cyber Essentials as the prerequisite.
  • Level 2 asks for 139 controls and requires Cyber Essentials Plus.
  • Level 3 asks for 144 controls, also on Cyber Essentials Plus.

One change in Issue 4 matters more than any other for a small supplier. Earlier issues relied on suppliers attesting to their own compliance. Issue 4 moved to independent assessment. You no longer tell MOD you meet the controls; a certification body checks that you do. That shift is why a letter that would once have meant "fill in a form" now means "get certified".

The Cyber Security Model v4: how MOD decides your level

The Cyber Security Model is the process side: the method MOD uses to assess the cyber risk attached to a contract and assign the Cyber Risk Profile that goes with it. Version 4 is the current one, and Defence Cyber Certification is its assurance route, the recognised way of demonstrating that the controls for a given profile are in place.

The point to take from this is that the level is not yours to choose. The contracting authority assigns the Cyber Risk Profile based on what the contract involves: the information handled, the systems touched, the consequences of a compromise. The profile determines the level, and the level determines the controls.

Subcontractors sometimes assume they can pick the lightest level and work upwards if pressed. It does not work that way. Your prime has been given a profile for the work you do on its behalf, and that is what it will ask you to meet. If you believe the profile is wrong for what you actually do, raise it with the prime; it is not something you settle on a certification body's order form.

Defence Cyber Certification: how you prove it

Defence Cyber Certification is the proof, and it is organisation-wide. The scope is your business's essential functions, including corporate IT, identities, endpoints, connectivity, cloud, backup and continuity. You cannot certify only the team that does the defence work, and a standalone software product cannot satisfy the scope on its own.

At every level a certification body does the checking. Level 0 is a documentation-led review. Level 1 adds interviews, demonstrations and review of operational evidence. Level 2 adds hands-on technical testing. A certificate is valid for three years, with an annual attestation in years one and two, and Cyber Essentials has to be renewed every year throughout.

The document that ties certification back to the contract clause is Industry Security Notice 2026/02, issued on 30 March 2026. It tells MOD buyers that a supplier holding current, valid Defence Cyber Certification at a level equal to or above the contract's required level "is to be considered in satisfaction of the control requirement to DEFSTAN 05-138 (Issue 4, onwards), as specified under DEFCON 658" (Industry Security Notice 2026/02, 30 March 2026).

That sentence does two useful things for you. It closes the loop: DEFCON 658 imposes the controls, Def Stan 05-138 defines them, and the certificate is formally accepted as evidence that you meet them. And it confirms that a higher level satisfies all lower levels, so if you hold Level 1 and a contract asks for Level 0, you are covered.

Two cautions. Defence Cyber Certification does not remove the Supplier Assurance Questionnaire. Suppliers still complete the questionnaire through the Supplier Cyber Protection Service, and a valid certificate sits alongside it as assured evidence. And the certificate does not change your contract: it is proof that you meet the DEFCON 658 obligations, not a substitute for the clause.

What "or equivalent" and "flow-down" mean for you

Two phrases turn up in supplier letters and cause more trouble than the rest of the document combined.

"Or equivalent"

Some requirements read "Defence Cyber Certification or equivalent". Do not assume that ISO 27001, Cyber Essentials Plus or a quality accreditation counts. Whether an alternative is accepted is your customer's decision, and since ISN 2026/02 told MOD buyers to accept the certificate, primes have little reason to accept anything else. If you hold something you believe should qualify, put it to the prime and get the answer in writing before you rely on it.

"Flow-down"

Flow-down is how the obligation travels. MOD puts DEFCON 658 in its contract with the prime. The prime passes the obligation into its contracts with its suppliers, who do the same with theirs. By the time it reaches a small machining firm or a software house, the letter may have come from a company that has never spoken to MOD.

This is why your prime cannot waive it. It has not chosen the requirement; it has inherited it and is bound to pass it on. What you can do is establish exactly what has been passed to you.

Get the level and the Cyber Risk Profile in writing. A reply along these lines usually gets a straight answer:

"Thank you for the notification. To scope this correctly, please confirm the Defence Cyber Certification level you require from us, the Cyber Risk Profile assigned to the work we perform for you, and the date by which you need the certificate in place. We will respond with a plan and a target date once we have those three details."

Three sentences, no commitment beyond a plan, and it puts the level on the record.

What changed in 2026

The scheme launched in May 2025, but 2026 is the year it acquired weight. Three dates explain why the letters started arriving.

On 30 March 2026, MOD issued Industry Security Notice 2026/02, quoted above. It is the notice that made the certificate the recognised evidence of the Def Stan 05-138 controls under DEFCON 658.

On 8 May 2026, marking one year of the scheme, Eleanor Fairford, MOD's Director of Cyber Defence and Risk, wrote on the Defence Digital blog: "I have also recently asked all industry partners to achieve Level 0 DCC certification by 31st December 2026, which includes a requirement for obtaining Cyber Essentials for all applicable business-critical systems within scope." (Defence Digital blog, 8 May 2026.)

Note the word. MOD has asked. Where DEFCON 658 is in your contract the controls are contractual; the December date is what MOD has asked industry to achieve for Level 0. Primes are treating the two together, and the letters reflect that.

On 13 July 2026, the same blog addressed the supply chain directly. Primes should push Level 0 down the chain and set timescales for their subcontractors, and "where higher levels of certification are required at lower tiers in the supply chain, these should be scheduled for delivery after 31 December 2026." To subcontractors: "If you are a subcontractor to a Prime, engage with your Prime and discuss what level you should be looking to achieve." (Defence Digital blog, 13 July 2026.)

Put those together and the shape of the next twelve months is clear. Level 0 is the December priority for the whole chain, including the smallest suppliers. Level 1 and above at lower tiers is a 2027 conversation, and IT support providers, software houses, training and consultancy firms and logistics suppliers with some access to MOD systems or OFFICIAL data are the ones most likely to be asked for Level 1 next.

Where to start

The next step is not to read the standard cover to cover. It is to find out which parts apply to you and get moving on Level 0, because certification body capacity is expected to tighten towards the end of the year.

  • Get the requirement in writing, with the level and the Cyber Risk Profile named, using the reply above.
  • Check that your Cyber Essentials certificate covers the whole business. One that covers part of it will not satisfy the first Level 0 control.
  • Name the person in your business who owns cyber security. The scheme expects one.
  • Read our explainer on what MOD has asked suppliers to do by 31 December 2026 for this month's steps, and the Level 0 controls post for what an assessor actually wants to see.

Where we fit

HGC IT Solutions is a UK managed service provider. We do not issue, assess or certify Defence Cyber Certification. We prepare suppliers for it: scoping, remediation, evidence, and managing the assessment through CyberSmart, an IASME-accredited DCC certification body for Levels 0 and 1, then keeping you current through the three-year certificate. If you have a DEFCON 658 requirement in front of you, start with our Defence Cyber Certification page.

More on Cyber Security

Talk to a real IT team

Plain-English advice from a UK team that picks up the phone. Call 01305 310006 or email [email protected].