Def Stan 05-138, explained.

Defence Standard 05-138 is where the Ministry of Defence writes down the cyber security controls its suppliers have to meet. If DEFCON 658 has appeared in your contract, or a prime has sent you a Risk Assessment Reference number, this standard is what you are being measured against. Here is what it asks for, and how to work out which parts apply to you.

Def Stan 05-138 lists the cyber security controls required for each Cyber Risk Profile. Issue 4 is the current version. You do not have to meet all of it. You have to meet the control set that matches the Cyber Risk Profile assigned to your contract, which is a number from 0 to 3 that the MOD works out and gives you.

So the practical sequence is: find your Cyber Risk Profile, look up the controls for that level, close the gaps, then evidence it. Everything below is the detail behind those four steps.

05-138 / 01 · How the pieces fit

Four things that get confused for each other.

The Cyber Security Model has several moving parts with similar names. Getting them straight makes the rest simple.

01

The Cyber Security Model

The framework. How the MOD manages cyber risk across its supply chain. The current version is CSMv4.

02

DEFCON 658

The contract clause. It lays out the contractual terms for the Cyber Security Model, and it contains the obligations you must pass down to your own subcontractors. If DEFCON 658 is in your contract, the rest of this applies to you and to your supply chain.

03

Def Stan 05-138

The control list. It sets out the cyber security controls required at each Cyber Risk Profile. You are contractually required to meet the controls for your assigned profile.

04

Defence Cyber Certification

The independent certificate. It evidences compliance with the model, at four levels matching the risk profiles, with IASME as the scheme's Certification Authority. See DCC Level 0.

05-138 / 02 · Which controls apply to you

Your Cyber Risk Profile decides the answer.

Not your size, not your turnover. The risk of the specific contract.

MOD Delivery Teams complete an initial Risk Assessment for a contract. That determines its Cyber Risk Profile and generates a Risk Assessment Reference, a RAR number. You should be given the RAR at the earliest market engagement, and it is usually in the invitation to tender. If you have been asked about cyber and cannot find a RAR number, ask for it. It is the thing that tells you which controls you owe.

0Level 0The baseline set. Where most of the supply chain sits, and the level the MOD has asked all industry partners to certify by 31 December 2026.
1Level 1More controls, and more evidence expected of how you operate them rather than just that you have them.
2Level 2Higher assurance again. At DCC Levels 2 and 3, Cyber Essentials Plus is required as well as Cyber Essentials.
3Level 3The most demanding profile, for the contracts where a compromise would matter most.

An accuracy point worth making, because a lot of published advice is out of date. If you find guidance describing the profiles as Very Low, Low, Moderate and High, it is describing CSMv3. Those designations were replaced in CSMv4 by Level 0 to Level 3. The substance is similar, the labels are not, and mixing the two is a quick way to answer a questionnaire against the wrong control set.

05-138 / 03 · The shape of the controls

Familiar ground, assessed more strictly.

If you have done Cyber Essentials, none of this is alien. The difference is depth of evidence and the fact that it is contractual.

01Know

Scope and asset knowledge

You cannot protect what you have not written down. Expect to evidence what systems are in scope, what data they hold, and who has access.

Asset registerData flowsScope boundary
02Control

Access and configuration

Who can reach what, how accounts are granted and removed, and how systems are hardened from their default state.

Access controlSecure configPrivilege
03Defend

Patching and malware

Keeping software current and malicious code out. The controls most often met in practice but least often evidenced properly.

PatchingMalware protectionFirewalls
04Detect

Monitoring and logging

Knowing when something has gone wrong, and being able to show what happened afterwards.

LoggingMonitoringAlerting
05Respond

Incident management

A plan that exists before you need it, with named people and a route to telling your customer.

Incident planReportingRecovery
06Sustain

Supply chain and governance

The obligations you pass down to your own suppliers, and the governance showing this is maintained rather than done once.

Flow-downReviewOwnership
05-138 / 04 · How you evidence it

You self-assess, and now you do it online.

Suppliers self-assess against the Cyber Security Model requirements using a Supplier Assurance Questionnaire. The MOD has moved this onto the Supplier Cyber Protection Service, an online platform for completing Risk Assessments and SAQs. A SAQ submitted there is automatically scored against the Cyber Risk Profile, and you are told immediately whether it is compliant.

That immediacy is useful and slightly unforgiving: there is no window in which to tidy up an answer after submission. It is worth working out your real position against the control set before you fill it in, not during.

One thing to be clear about, because a lot of advice gets it wrong: Defence Cyber Certification does not currently replace the SAQ. MOD guidance states that suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.

05-138 / 05 · The overlap worth using

Cyber Essentials does a lot of this work for you.

The controls in Def Stan 05-138 at the lower profiles cover much the same ground as Cyber Essentials: firewalls, secure configuration, access control, malware protection, patching. If you already hold Cyber Essentials, you are further along than you think, the usual gap is scope rather than capability, because Cyber Essentials scope and contract scope are not always the same thing.

It also matters directly for certification. Every DCC level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. The MOD's own request for Level 0 by 31 December 2026 explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope. Our guide to DCC and Cyber Essentials sets out why the two are not alternatives.

We are an appointed Cyber Essentials certification body and an appointed DCC certification body for Level 0, so both parts of that can be assessed by the same team.

FAQ

Common questions

What is Def Stan 05-138?

Defence Standard 05-138 is the Ministry of Defence standard that lists the cyber security controls required for each Cyber Risk Profile. Suppliers are contractually required to meet the controls matching the profile assigned to their contract. Issue 4 is the current version.

Which issue of Def Stan 05-138 is current?

Issue 4. MOD guidance for the Cyber Security Model refers to Def Stan 05-138 Issue 4 as the document specifying the controls.

How do I find out my Cyber Risk Profile?

An MOD Delivery Team completes an initial Risk Assessment for the contract, which determines the Cyber Risk Profile and produces a Risk Assessment Reference (RAR) number. It is normally provided at the earliest market engagement and found in the invitation to tender. If you cannot find it, ask the contracting authority.

Is Def Stan 05-138 the same as DEFCON 658?

No. DEFCON 658 is the contract condition that brings the Cyber Security Model into your contract and requires you to flow obligations down to subcontractors. Def Stan 05-138 is the standard containing the controls you then have to meet.

Do I need Cyber Essentials to meet Def Stan 05-138?

Cyber Essentials is not a substitute for the standard, but it covers much of the same ground at the lower profiles, and it is required for Defence Cyber Certification at every level, with Cyber Essentials Plus required at Levels 2 and 3.

Does a DCC certificate mean I can skip the SAQ?

No, not currently. MOD guidance is explicit that DCC holders are not yet exempt from completing elements of the SAQ, and that the full SAQ to the required level remains mandatory.

Not sure which controls apply to you?

Send us your RAR number, or just tell us who you supply. We will tell you which control set you are being measured against and where your real gaps are. We are an appointed certification body for Cyber Essentials and for DCC Level 0, so we can certify what we assess.

Reading, Berkshire  /  reply within one working day