DEFCON 658, explained.
DEFCON 658 is the contract condition that brings the Ministry of Defence's Cyber Security Model into your contract. If it appears in your terms, you have cyber obligations to meet, and obligations you have to pass down to your own subcontractors. That second part is the one people miss.
DEFCON 658 lays out the contractual terms for the Cyber Security Model. It does not itself list any technical controls. That is Defence Standard 05-138. What DEFCON 658 does is make the model contractually binding on you, and require you to place the same obligations on your subcontractors.
So if you are looking for "what do I actually have to implement", DEFCON 658 is not the document that tells you. It is the document that tells you that you have to, and points at the standard that does. The control set you owe depends on the Cyber Risk Profile assigned to your contract.
Four documents, four different jobs.
These get used interchangeably and they should not be. Once the distinction is clear the rest is straightforward.
Four steps, and most people stop after three.
Find your Cyber Risk Profile
An MOD Delivery Team completes an initial Risk Assessment for the contract. That determines its Cyber Risk Profile and produces a Risk Assessment Reference, a RAR number. It should be given to you at the earliest market engagement and is usually in the invitation to tender. If you cannot find it, ask.
Meet the Def Stan 05-138 controls for that profile
You are contractually required to meet the controls matching your assigned profile. Not the whole standard, the set for your level.
Complete the Supplier Assurance Questionnaire
You self-assess against the model's requirements. This now happens on the Supplier Cyber Protection Service, the MOD's online platform, where a submitted SAQ is automatically scored against your risk profile and you are told immediately whether it is compliant.
Flow the obligations down to your subcontractors
DEFCON 658 explicitly contains the obligations you must place on your own suppliers. This is a contractual requirement on you, not a courtesy.
Your compliance is not just about you.
Most suppliers read DEFCON 658, work out their own position, meet their controls, submit their SAQ, and consider it handled. Then a prime asks what obligations they have placed on their own supply chain, and there is nothing to show.
DEFCON 658 contains the obligations that suppliers must place upon subcontractors. If you subcontract any part of the work, or if a supplier of yours touches contract data or the systems that hold it, this applies to you as well as to them.
Three practical things, in order. Work out who is actually in scope, not every supplier, but the ones who handle contract data, have access to the systems that process it, or provide something the contract depends on. A cleaning contractor is not in scope. A managed IT provider almost certainly is. So is anyone hosting your files. Get the condition into their contracts, not a covering email: the obligation is contractual and needs to be reflected in the agreement, at renewal if not sooner. Keep the evidence that you did it, because when you are asked, and on a contract of any size you will be, the answer needs to be a document rather than a recollection.
If your own IT is outsourced, this is worth a direct conversation with your provider. It is reasonable to ask whether they can evidence the controls your contract requires of them, and a provider who cannot answer clearly is a risk you are carrying on their behalf. Our managed IT work is built for organisations that have to answer that question.
DEFCON 658 is one of many.
Defence Conditions are the MOD's standard contract clauses, and there are a lot of them, covering everything from intellectual property to packaging. DEFCON 658 is the cyber one: it is where the Cyber Security Model enters your contract.
"DEFCON 659" also draws searches, and if you have seen it referenced alongside 658 it is worth checking the specific clause list in your own contract rather than relying on a summary. Defence Conditions are amended and reissued, so the version that matters is the one your contract cites, with its issue date.
DCC is how you evidence the model.
Meeting the controls and self-assessing is the baseline. Defence Cyber Certification is the independent certificate that evidences compliance with the model, and it is where the MOD is heading.
In May 2026 the MOD's Director of Cyber Defence and Risk asked all industry partners to achieve DCC Level 0 certification by 31 December 2026, a request that includes obtaining Cyber Essentials for all applicable business-critical systems within scope. If DEFCON 658 is in your contract, Level 0 is the floor you should be working toward.
One thing to be clear on, because a good deal of published advice has it wrong: a DCC certificate does not currently exempt you from the SAQ. MOD guidance states that holders are not yet exempt from completing elements of it, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
We are an appointed certification body for DCC Level 0 and for the Cyber Essentials it requires, so both parts can be assessed by the same team. For anyone earlier in the journey, Cyber Essentials for defence suppliers covers the ground, and our defence and aerospace work sets out the wider picture.
Common questions
What is DEFCON 658?
DEFCON 658 is the Ministry of Defence contract condition that lays out the contractual terms for the Cyber Security Model. It makes the model binding on the supplier and contains the obligations that suppliers must place upon their subcontractors.
Does DEFCON 658 apply to subcontractors?
Yes. DEFCON 658 contains the obligations suppliers must place upon subcontractors, so if you subcontract work or use suppliers who touch contract data or systems, the requirements flow down to them and evidencing that flow-down is your responsibility.
Is DEFCON 658 the same as Def Stan 05-138?
No. DEFCON 658 is the contract condition that brings the Cyber Security Model into your contract. Def Stan 05-138 is the standard listing the cyber security controls required at each Cyber Risk Profile. One obliges, the other specifies.
What is a RAR number?
A Risk Assessment Reference number. An MOD Delivery Team completes an initial Risk Assessment for a contract, which determines its Cyber Risk Profile and generates the RAR. It is normally provided at the earliest market engagement and found in the invitation to tender.
Do I need Cyber Essentials to satisfy DEFCON 658?
DEFCON 658 itself points at the Def Stan 05-138 controls for your risk profile rather than naming Cyber Essentials. But Cyber Essentials covers much of the same ground at the lower profiles, and it is required for Defence Cyber Certification at every level, with Cyber Essentials Plus required at Levels 2 and 3.
What happens if I cannot meet the controls for my risk profile?
Talk to the contracting authority early rather than submitting a non-compliant SAQ and hoping. There is usually a route involving an agreed plan with timescales, and it is a far better position than being found short after award.
DEFCON 658 in your contract? Start here.
Send us your RAR number, or just tell us who you supply. We will tell you which control set applies, where your real gaps are, and what your subcontractors need from you. We are an appointed certification body for Cyber Essentials and for DCC Level 0.