DEFCON 658 lays out the contractual terms for the Cyber Security Model. It does not itself list any technical controls. That is Defence Standard 05-138. What DEFCON 658 does is make the model contractually binding on you, and require you to place the same obligations on your subcontractors.
So if you are looking for "what do I have to implement", DEFCON 658 is not the document that tells you. It is the document that tells you that you have to, and points at the standard that does. The control set you owe depends on the Cyber Risk Profile assigned to your contract.
The MOD’s current Cyber Security Model guidance (opens in new tab) sets out the RAR, SAQ, flow-down and CIP sequence. CSMv4 focuses on organisational security and resilience. Check the version and conditions incorporated into your contract.
Four documents, four different jobs.
These get used interchangeably and they should not be. Once the distinction is clear the rest is straightforward.
Four steps, and most people stop after three.
Find your Cyber Risk Profile
An MOD Delivery Team completes an initial Risk Assessment for the contract. That determines its Cyber Risk Profile and produces a Risk Assessment Reference, a RAR number. It should be given to you at the earliest market engagement and is usually in the invitation to tender. If you cannot find it, ask.
Meet the Def Stan 05-138 controls for that profile
You are contractually required to meet the controls matching your assigned profile. Not the whole standard, the set for your level.
Complete the Supplier Assurance Questionnaire
You self-assess against the model's requirements. This now happens on the Supplier Cyber Protection Service, the MOD's online platform, where a submitted SAQ is automatically scored against your risk profile and you are told immediately whether it is compliant.
Flow the obligations down to your subcontractors
DEFCON 658 explicitly contains the obligations you must place on your own suppliers. This is a contractual requirement on you, not a courtesy.
Your compliance is not just about you.
A supplier can complete its own assessment and still leave a gap in its subcontracting arrangements. Keep a record of the downstream risk assessments, the requirements passed to each relevant subcontractor and their responses. This makes the flow-down visible when your customer asks for evidence.
DEFCON 658 contains the obligations that suppliers must place upon subcontractors. If you subcontract any part of the work, or if a supplier of yours touches contract data or the systems that hold it, this applies to you as well as to them.
Confirm the relevant subcontracted activity. Follow the contract and the MOD flow-down process; supplier category alone does not determine whether it is in scope. Assess the risk. Once you have your own CSMv4 profile and RAR, complete the required risk assessment for the subcontractor and pass on its resulting profile and RAR. Record the response. Retain the contractual condition, SAQ position and any agreed Cyber Improvement Plan. An IT provider, hosting service or other business dependency needs a considered scope decision, not an assumption.
If your own IT is outsourced, this is worth a direct conversation with your provider. It is reasonable to ask whether they can evidence the controls your contract requires of them, and a provider who cannot answer clearly is a risk you are carrying on their behalf. Our managed IT work is built for organisations that have to answer that question.
DEFCON 658 is one of many.
Defence Conditions are the MOD's standard contract clauses, and there are a lot of them, covering everything from intellectual property to packaging. DEFCON 658 is the cyber one: it is where the Cyber Security Model enters your contract.
"DEFCON 659" also draws searches, and if you have seen it referenced alongside 658 it is worth checking the specific clause list in your own contract rather than relying on a summary. Defence Conditions are amended and reissued, so the version that matters is the one your contract cites, with its issue date.
DCC is how you evidence the model.
Meeting the controls and self-assessing is the baseline. Defence Cyber Certification is the independent certificate that evidences compliance with the model, and it is where the MOD is heading.
In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve DCC Level 0 certification by 31 December 2026, a request that includes obtaining Cyber Essentials for all applicable business-critical systems within scope. That request does not replace the profile or deadline set by your contracting authority; a particular procurement may require a higher level.
The date comes from the MOD’s 8 May 2026 statement (opens in new tab). Plan the DCC assessment and any annual Cyber Essentials renewal alongside your customer’s requirements.
One thing to be clear on, because a good deal of published advice has it wrong: a DCC certificate does not currently exempt you from the SAQ. MOD guidance states that holders are not yet exempt from completing elements of it, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
We are an appointed certification body for DCC Level 0 and for the Cyber Essentials it requires, so both parts can be assessed by the same team. For anyone earlier in the journey, Cyber Essentials for defence suppliers covers the ground, and our defence and aerospace work sets out the wider picture.
Common questions
What is DEFCON 658?
DEFCON 658 is the Ministry of Defence contract condition that lays out the contractual terms for the Cyber Security Model. It makes the model binding on the supplier and contains the obligations that suppliers must place upon their subcontractors.
Does DEFCON 658 apply to subcontractors?
Yes. DEFCON 658 contains the obligations suppliers must place upon subcontractors, so if you subcontract work or use suppliers who touch contract data or systems, the requirements flow down to them and evidencing that flow-down is your responsibility.
Is DEFCON 658 the same as Def Stan 05-138?
No. DEFCON 658 is the contract condition that brings the Cyber Security Model into your contract. Def Stan 05-138 is the standard listing the cyber security controls required at each Cyber Risk Profile. One obliges, the other specifies.
What is a RAR number?
A Risk Assessment Reference number. An MOD Delivery Team completes an initial Risk Assessment for a contract, which determines its Cyber Risk Profile and generates the RAR. It is normally provided at the earliest market engagement and found in the invitation to tender.
Do I need Cyber Essentials to satisfy DEFCON 658?
DEFCON 658 itself points at the Def Stan 05-138 controls for your risk profile rather than naming Cyber Essentials. But Cyber Essentials covers much of the same ground at the lower profiles, and it is required for Defence Cyber Certification at every level, with Cyber Essentials Plus required at Levels 2 and 3.
What happens if I cannot meet the controls for my risk profile?
MOD guidance requires a Cyber Improvement Plan (CIP) if you cannot meet the required compliance, including the relevant DCC position. Submit the plan with realistic actions and timescales as part of the tender. The authority decides whether to accept it; a plan does not guarantee contract award or certification.
