iso27001partnersUK certification, costed Get a cost estimate

DEFCON 658 and Def Stan 05-138: the cyber requirements for MOD suppliers

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 11 min read
5 primary sources cited on this page. How we check what is on this site
Required at every level Cyber Essentials — and Plus from Level 2

Def Stan 05-138 Issue 4 makes Cyber Essentials the first control at all four Cyber Risk Profiles, and Cyber Essentials Plus the second at Levels 2 and 3. It does not mention ISO/IEC 27001 at all.

If you supply the Ministry of Defence, or supply someone who does, the cyber requirement arrives as two documents: a contract condition, DEFCON 658, and the standard it points to, Def Stan 05-138. Both are published on GOV.UK. This page sets out what they require, quoted from the documents, and answers the question an ISO 27001 certificate holder needs answered: does our certificate cover it?

The four Cyber Risk Profiles

Cyber Risk Profiles in Def Stan 05-138 Issue 4 (descriptions verbatim)
ProfileControlsCyber EssentialsCyber Essentials PlusNormally assigned where…
Level 0 (‘Basic’)3YesNo“…normally assigned where there is a very low level of assessed cyber risk to a Supplier delivering an output. It requires Supplier organisations to demonstrate basic cyber security practices.”
Level 1 (‘Foundational’)101YesNo“…normally assigned where there is a low to moderate level of assessed cyber risk to a Supplier delivering an output. It requires Supplier organisations to demonstrate a comprehensive cyber security programme with good practices.”
Level 2 (‘Advanced’)139YesYes“…normally assigned where there is a high level of assessed cyber risk to a Supplier delivering a contracted output. It requires Supplier organisations to demonstrate advanced cyber security oversight and planning which drives robust organisational and cyber practices.”
Level 3 (‘Expert’)144YesYes“…normally assigned where there is a substantial level of assessed cyber risk from a Supplier delivering a contracted output. It requires Supplier organisations to demonstrate expert cyber security capabilities that fully take advantage of the ‘defence in depth’ methodology to appropriately protect the organisation against new and evolving threats.”

The profile is set per contract, not per company. “A Risk Assessment Reference (RAR) number and required Cyber Risk Profile (CRP) Level (Levels 0-3) relevant to a new or existing MOD activity will be provided by the authority at the earliest market engagement, and will usually be found in the invitation to tender.” So the same supplier can hold a Level 1 contract and bid for a Level 2 one — and the control count rises from 101 to 139, with a Cyber Essentials Plus certificate among the additions.

Issue 4 replaced the old profiles

“This substantive update details the move from five Cyber Risk Profiles of “N/A, Very Low, Low, Moderate and High” to four Cyber Risk Profiles of “Level 0, Level 1, Level 2 and Level 3” and introduces new cyber security control requirements at each level.” The MOD's guidance is explicit that the two systems do not map onto each other: “CSM v3 Cyber Risk Profiles (N/A – High) are not consistent with CSMv4.” A supplier that was “Low” under the old model cannot assume it is Level 1 under the new one.

It covers the whole organisation

“The scope of this standard is the Supplier’s overarching corporate or enterprise environment.” The MOD describes version 4 as changing “the CSM focus from ‘MOD Identifiable Information’ to organisational security and resilience”. And the controls are a floor: “These requirements are intended to be considered as a ‘minimum’. Individual contracts may specify greater levels of controls/protection (such as where specified within a Security Aspects Letter).”

What the controls cover

The 148 controls in Table 1 are grouped under four objectives, plus the two certification controls. We counted them from the published table; the totals match the numbers the standard gives for each level.

Def Stan 05-138 Issue 4 controls by objective and level (our count of Table 1)
ObjectiveLevel 0Level 1Level 2Level 3
Certification (Cyber Essentials, Cyber Essentials Plus)1122
A — Managing security risk0121819
B — Protecting against cyber attack2759598
C — Detecting cyber security events091515
D — Minimising the impact of cyber security incidents04910

Level 0 in full

Level 0 is short enough to quote entirely:

The three Level 0 controls, verbatim
ControlNameRequirement
0001Cyber EssentialsThe Supplier shall have Cyber Essentials certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract.
2314Ensure UK GDPR complianceThe Supplier shall ensure that the processing of personal data is conducted in compliance with the General Data Protection Regulation.
2500Resilient networks and systemsThe Supplier shall build resilience against cyber-attack and system failure into their design, implementation, operation and management of systems that support the operation of business Functions and protection of Data.

Evidence, not intentions

“The supplier shall, for each control requirement referenced in Clause 3, ensure they have a documented and implemented control in place with auditable evidence.” And where a control does not fit your circumstances: “Where specified controls are deemed inappropriate/impractical for specific circumstances this shall be documented by the Supplier and flagged to the Authority at the time of bidding or immediately to such if identified during the period of any contracted activity.”

What DEFCON 658 obliges you to do

DEFCON 658 is the contract condition that makes all of this binding. Suppliers are contractually required to meet Def Stan 05-138 controls. The contractor obligations include:

DEFCON 658 contractor obligations (extract, verbatim)
ClauseThe Contractor shall
3.1.1comply with DEFSTAN 05-138 or, where applicable, the Cyber Implementation Plan attached to this Contract
3.1.3re-perform the CSM Supplier Assurance Questionnaire no less than once in each year of this Contract commencing on the first anniversary of completion of the CSM Supplier Assurance Questionnaire to demonstrate continued compliance with the Cyber Security Instructions
3.1.6notify the JSyCC WARP in accordance with ISN 2017/03 as amended or updated from time to time and the Contractors NSA/DSA, and in the case of a Sub-contractor also notify the Contractor, immediately in writing as soon as they know or believe that a Cyber Security Incident has or may have taken place
3.1.9include provisions equivalent to those set out in the Annex to this Condition (the “equivalent provisions”) in all relevant Sub-contracts

Records and audits

Records must be kept for 6 years after the contract ends, including “copies of all documents required to demonstrate compliance with DEFSTAN 05-138 and this Condition, including but not limited to any information used to inform the CSM Risk Assessment Process and to carry out the CSM Supplier Assurance Questionnaire, together with any certificates issued to the Contractor and/or Sub-contractor”. The MOD may audit after an incident and, while you still hold MOD Identifiable Information, at any time during the contract and for six years after — “but not more than once in any calendar year”. “The Authority shall endeavour to (but is not obliged to) provide at least 15 calendar days' notice of its intention to conduct an audit.”

On costs: “The Parties agree that they shall bear their own respective costs and expenses incurred in respect of compliance with their obligations under this Condition, unless the audit identifies a material breach of the terms of this Condition by the Contractor” — in which case the contractor reimburses the authority's reasonable audit costs.

Incidents

The reporting duty in clause 3.1.6 is “immediately in writing”, to the MOD's warning, advice and reporting point and to your security authority, with further information in phases as it becomes available. There is no grace period written into the condition.

How the Cyber Security Model works, step by step

“The Cyber Security Model (CSM) is how Defence builds cyber security into its supply chain.” Under version 4 the process runs:

  1. The requirement is in the tender. The authority gives a Risk Assessment Reference and the required Cyber Risk Profile level.
  2. You self-assess. Through the Supplier Cyber Protection Service, using the Supplier Assurance Questionnaire. “A SAQ will be automatically scored against the CRP, and the supplier immediately informed if it is compliant.”
  3. If you fall short, you plan. “If the supplier is non-compliant, they must complete a CIP. The CIP will form part of the contract document itself.”
  4. The authority selects. Compliance, or the improvement plan, is taken into account.
  5. You repeat it every year. “Annually, the supplier will complete a new SAQ on the anniversary of the contract award date, with a window of 1 month after that anniversary for timely completion.”

Flow down to sub-contractors

“Flow down is required from the prime contractor to their sub-contractors and onwards down the sub-contracting tiers to the end of the supply chain.” Each tier runs its own risk assessment for the tier below, and the sub-contractor completes the questionnaire at the level that produces. DEFCON 658 lets the tier above rely on the answer: “Provided that it is reasonable in all the circumstances to do so, the Authority agrees that the Contractor shall be entitled to rely on the self-certification by the Sub-contractor of their compliance with this Condition in accordance with 3.1.1 above.”

Defence Cyber Certification

“The Defence Cyber Certification (DCC) has been created in partnership with industry and IASME, the scheme’s Certification Authority, as a way of independently evidencing compliance with the Cyber Security Model.” The MOD says suppliers should expect it to be required increasingly as a tender condition. For now it does not remove the questionnaire: “Whilst it is hoped that DCC will be recognised within online tooling in due course, completion of the full SAQ to the required level remains mandatory as part of contractual risk assessment and procurement processes at this point in time.”

Where ISO 27001 fits — and where it does not

Def Stan 05-138 Issue 4 does not mention ISO/IEC 27001, ISO/IEC 27002, or any ISO standard by name. Its only named certifications are Cyber Essentials and Cyber Essentials Plus. So an ISO 27001 certificate does not, on its own, meet any control in the table.

What an ISMS does give you (our reading)

The standard asks for every control to be documented, implemented and evidenced, and its first objective is “Managing security risk”. That is the ground an ISO 27001 management system covers: a risk assessment, documented controls, internal audit and management review. An organisation that already runs one will usually find the questionnaire easier to answer, because the evidence already exists. That is our reading of the two documents side by side, not something either document says.

What it does not give you

  • Cyber Essentials, and Plus from Level 2. Separate certifications, required by name. See ISO 27001 vs Cyber Essentials.
  • The questionnaire. Completed per contract, repeated every year.
  • Whole-organisation scope. An ISO 27001 certificate covers the scope written on it. Def Stan 05-138 covers the supplier's “overarching corporate or enterprise environment”. If your ISMS scope is one product or site, the gap is the rest of the company.

Check this before bidding

The required level is in the invitation to tender. Level 2 and above means Cyber Essentials Plus as well as Cyber Essentials. Find out the level first, then work out whether you can hold both certificates by the time the contract needs them.

We do not assess, certify or consult, and we are paid the same fixed fee per enquiry whichever firm you use. Nothing on this page is legal advice about a specific contract; the documents quoted are the ones the MOD publishes, and your contract may add to them.

Where this fits

Common questions

What is DEFCON 658?

The Ministry of Defence's cyber contract condition. It makes the Cyber Security Model part of the contract: comply with Def Stan 05-138 (or an agreed Cyber Implementation Plan), complete the risk assessment and Supplier Assurance Questionnaire, re-perform the questionnaire every year, report cyber security incidents immediately, keep records, allow audits, and pass equivalent terms down to sub-contractors. The current document on GOV.UK is Edition 10/22.

What is Def Stan 05-138?

The defence standard that lists the cyber controls a supplier must have at each Cyber Risk Profile. Issue 4, published 23 May 2024, has four levels, from Level 0 with 3 controls to Level 3 with 144. “This defence standard (Def Stan 05-138, Issue 4) is applicable to all Ministry of Defence (MOD) procurements, MOD suppliers and their subcontract suppliers, which have a relationship to one or more MOD contracts.”

Does ISO 27001 satisfy DEFCON 658?

Not by itself. Def Stan 05-138 Issue 4 does not mention ISO/IEC 27001 anywhere. It requires Cyber Essentials at every level and Cyber Essentials Plus at Levels 2 and 3, and it requires each control to be “documented and implemented” with “auditable evidence”. An ISO 27001 management system can supply much of that evidence, but the certificate is not a substitute for the certifications or the questionnaire.

Do I need Cyber Essentials Plus for MOD contracts?

At Level 2 and Level 3, yes: “The Supplier shall have Cyber Essentials Plus certification that covers the scope required for all aspects of the contract and commit to maintaining this for the duration of the contract.” At Levels 0 and 1 the requirement is Cyber Essentials.

Who decides my Cyber Risk Profile?

The contracting authority, through the CSM risk assessment. “A Risk Assessment Reference (RAR) number and required Cyber Risk Profile (CRP) Level (Levels 0-3) relevant to a new or existing MOD activity will be provided by the authority at the earliest market engagement, and will usually be found in the invitation to tender.” Where you sub-contract, you run the risk assessment for your sub-contractor.

What happens if we cannot meet the controls?

You complete a Cyber Improvement Plan. “If the supplier is non-compliant, they must complete a CIP. The CIP will form part of the contract document itself.” The authority takes compliance, or the plan, into account in supplier selection.

Does DEFCON 658 apply to sub-contractors?

Yes. “Flow down is required from the prime contractor to their sub-contractors and onwards down the sub-contracting tiers to the end of the supply chain.” DEFCON 658 requires equivalent provisions in all relevant sub-contracts, and a contractor may rely on a sub-contractor's self-certification where that is reasonable.

Does Defence Cyber Certification replace the questionnaire?

Not yet. “Whilst it is hoped that DCC will be recognised within online tooling in due course, completion of the full SAQ to the required level remains mandatory as part of contractual risk assessment and procurement processes at this point in time.”

Sources cited on this page

  1. Ministry of Defence, Def Stan 05-138 Issue 4, Cyber security for defence suppliers (published 23 May 2024), GOV.UK
  2. Ministry of Defence, DEFCON 658 Cyber (Edition 10/22), GOV.UK
  3. Ministry of Defence, Cyber Security Model guidance, GOV.UK (last updated 6 March 2026)
  4. NCSC, Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026)
  5. ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Bidding for an MOD contract?

Say which Cyber Risk Profile level the tender asks for, and what you already hold. That decides what needs doing first.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to contact@iso27001partners.co.uk. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now