Scope and asset knowledge
You cannot protect what you have not written down. Expect to evidence what systems are in scope, what data they hold, and who has access.
Defence Standard 05-138 is where the Ministry of Defence writes down the cyber security controls its suppliers have to meet. If DEFCON 658 has appeared in your contract, or a prime has sent you a Risk Assessment Reference number, this standard is what you are being measured against. Here is what it asks for, and how to work out which parts apply to you.
Def Stan 05-138 lists the cyber security controls required for each Cyber Risk Profile. Issue 4 is the current version. You do not have to meet all of it. You have to meet the control set that matches the Cyber Risk Profile assigned to your contract, which is a number from 0 to 3 that the MOD works out and gives you.
So the practical sequence is: find your Cyber Risk Profile, look up the controls for that level, close the gaps, then evidence it. Everything below is the detail behind those four steps.
The Cyber Security Model has several moving parts with similar names. Getting them straight makes the rest simple.
The framework. How the MOD manages cyber risk across its supply chain. The current version is CSMv4.
The contract clause. It lays out the contractual terms for the Cyber Security Model, and it contains the obligations you must pass down to your own subcontractors. If DEFCON 658 is in your contract, the rest of this applies to you and to your supply chain.
The control list. It sets out the cyber security controls required at each Cyber Risk Profile. You are contractually required to meet the controls for your assigned profile.
The independent certificate. It evidences compliance with the model, at four levels matching the risk profiles, with IASME as the scheme's Certification Authority. See DCC Level 0.
Not your size, not your turnover. The risk of the specific contract.
MOD Delivery Teams complete an initial Risk Assessment for a contract. That determines its Cyber Risk Profile and generates a Risk Assessment Reference, a RAR number. You should be given the RAR at the earliest market engagement, and it is usually in the invitation to tender. If you have been asked about cyber and cannot find a RAR number, ask for it. It is the thing that tells you which controls you owe.
An accuracy point worth making, because a lot of published advice is out of date. If you find guidance describing the profiles as Very Low, Low, Moderate and High, it is describing CSMv3. Those designations were replaced in CSMv4 by Level 0 to Level 3. The substance is similar, the labels are not, and mixing the two is a quick way to answer a questionnaire against the wrong control set.
If you have done Cyber Essentials, none of this is alien. The difference is depth of evidence and the fact that it is contractual.
You cannot protect what you have not written down. Expect to evidence what systems are in scope, what data they hold, and who has access.
Who can reach what, how accounts are granted and removed, and how systems are hardened from their default state.
Keeping software current and malicious code out. The controls most often met in practice but least often evidenced properly.
Knowing when something has gone wrong, and being able to show what happened afterwards.
A plan that exists before you need it, with named people and a route to telling your customer.
The obligations you pass down to your own suppliers, and the governance showing this is maintained rather than done once.
Suppliers self-assess against the Cyber Security Model requirements using a Supplier Assurance Questionnaire. The MOD has moved this onto the Supplier Cyber Protection Service, an online platform for completing Risk Assessments and SAQs. A SAQ submitted there is automatically scored against the Cyber Risk Profile, and you are told immediately whether it is compliant.
That immediacy is useful and slightly unforgiving: there is no window in which to tidy up an answer after submission. It is worth working out your real position against the control set before you fill it in, not during.
One thing to be clear about, because a lot of advice gets it wrong: Defence Cyber Certification does not currently replace the SAQ. MOD guidance states that suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
The controls in Def Stan 05-138 at the lower profiles cover much the same ground as Cyber Essentials: firewalls, secure configuration, access control, malware protection, patching. If you already hold Cyber Essentials, you are further along than you think, the usual gap is scope rather than capability, because Cyber Essentials scope and contract scope are not always the same thing.
It also matters directly for certification. Every DCC level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. The MOD's own request for Level 0 by 31 December 2026 explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope. Our guide to DCC and Cyber Essentials sets out why the two are not alternatives.
We are an appointed Cyber Essentials certification body and an appointed DCC certification body for Level 0, so both parts of that can be assessed by the same team.
Defence Standard 05-138 is the Ministry of Defence standard that lists the cyber security controls required for each Cyber Risk Profile. Suppliers are contractually required to meet the controls matching the profile assigned to their contract. Issue 4 is the current version.
Issue 4. MOD guidance for the Cyber Security Model refers to Def Stan 05-138 Issue 4 as the document specifying the controls.
An MOD Delivery Team completes an initial Risk Assessment for the contract, which determines the Cyber Risk Profile and produces a Risk Assessment Reference (RAR) number. It is normally provided at the earliest market engagement and found in the invitation to tender. If you cannot find it, ask the contracting authority.
No. DEFCON 658 is the contract condition that brings the Cyber Security Model into your contract and requires you to flow obligations down to subcontractors. Def Stan 05-138 is the standard containing the controls you then have to meet.
Cyber Essentials is not a substitute for the standard, but it covers much of the same ground at the lower profiles, and it is required for Defence Cyber Certification at every level, with Cyber Essentials Plus required at Levels 2 and 3.
No, not currently. MOD guidance is explicit that DCC holders are not yet exempt from completing elements of the SAQ, and that the full SAQ to the required level remains mandatory.
Send us your RAR number, or just tell us who you supply. We will tell you which control set you are being measured against and where your real gaps are. We are an appointed certification body for Cyber Essentials and for DCC Level 0, so we can certify what we assess.
Hello, I am Ainsley, the assistant here at Dead Simple Computing, and a governed AI assistant we built ourselves. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Ainsley is an assistant and can be wrong. For anything that matters you will speak to an engineer.