Def Stan 05-138 lists the cyber security controls required for each Cyber Risk Profile. Issue 4 is the current version. You do not have to meet all of it. You have to meet the control set that matches the Cyber Risk Profile assigned to your contract, which is a Level 0 to 3 requirement supplied by the buyer following its risk assessment.
So the practical sequence is: find your Cyber Risk Profile, look up the controls for that level, close the gaps, then evidence it. Everything below is the detail behind those four steps.
Source: the MOD’s current CSMv4 guidance (opens in new tab) identifies Issue 4, explains the buyer’s risk assessment and sets out the SAQ and CIP process. The MOD’s May 2026 DCC statement (opens in new tab) supplies the Level 0 objective date.
Four things that get confused for each other.
The Cyber Security Model has several moving parts with similar names. Getting them straight makes the rest simple.
The Cyber Security Model
The framework. How the MOD manages cyber risk across its supply chain. The current version is CSMv4.
DEFCON 658
The contract clause. It lays out the contractual terms for the Cyber Security Model, and it contains the obligations you must pass down to your own subcontractors. If DEFCON 658 is in your contract, the rest of this applies to you and to your supply chain.
Def Stan 05-138
The control list. It sets out the cyber security controls required at each Cyber Risk Profile. You are contractually required to meet the controls for your assigned profile.
Defence Cyber Certification
The independent certificate. It evidences compliance with the model, at four levels matching the risk profiles, with IASME as the scheme's Certification Authority. See DCC Level 0.
Your Cyber Risk Profile decides the answer.
Not your size, not your turnover. The risk of the specific contract.
MOD Delivery Teams complete an initial Risk Assessment for a contract. That determines its Cyber Risk Profile and generates a Risk Assessment Reference, a RAR number. You should be given the RAR at the earliest market engagement, and it is usually in the invitation to tender. If you have been asked about cyber and cannot find a RAR number, ask for it. It is the thing that tells you which controls you owe.
CSMv3 used Very Low, Low, Moderate and High. CSMv4 uses Levels 0 to 3 and makes a significant change in focus from MOD Identifiable Information to organisational security and resilience. The old labels do not map directly onto the new profiles. Use the version and profile confirmed by your customer.
Familiar ground, assessed more strictly.
If you have done Cyber Essentials, none of this is alien. The difference is depth of evidence and the fact that it is contractual.
Scope and asset knowledge
You cannot protect what you have not written down. Expect to evidence what systems are in scope, what data they hold, and who has access.
Access and configuration
Who can reach what, how accounts are granted and removed, and how systems are hardened from their default state.
Patching and malware
Keeping software current and malicious code out. Keep records that show the required configuration and update routines operate.
Monitoring and logging
Knowing when something has gone wrong, and being able to show what happened afterwards.
Incident management
A plan that exists before you need it, with named people and a route to telling your customer.
Supply chain and governance
The obligations you pass down to your own suppliers, and the governance showing this is maintained rather than done once.
You self-assess, and now you do it online.
Suppliers self-assess against the Cyber Security Model requirements using a Supplier Assurance Questionnaire. The MOD has moved this onto the Supplier Cyber Protection Service, an online platform for completing Risk Assessments and SAQs. A SAQ submitted there is automatically scored against the Cyber Risk Profile, and you are told immediately whether it is compliant.
Establish your actual position before submitting the SAQ. If you cannot meet the required compliance, MOD guidance requires a Cyber Improvement Plan with actions and timescales. The contracting authority considers the proposal; submission of a plan is not a certification or an automatic approval.
One thing to be clear about, because a lot of advice gets it wrong: Defence Cyber Certification does not currently replace the SAQ. MOD guidance states that suppliers holding a valid DCC certificate are not yet exempt from completing elements of the SAQ, and that completion of the full SAQ to the required level remains mandatory. Plan for both.
Cyber Essentials does a lot of this work for you.
Cyber Essentials contributes the technical baseline required at every DCC level. It does not establish the other Def Stan 05-138 controls or settle organisational scope. DCC covers the organisation’s security and resilience, including the processes, systems and business parts needed to function and deliver. The applicant documents the proposed scope and the certification body verifies it. Use the buyer’s Cyber Risk Profile to establish the required level, but do not reduce organisational scope to the files for one contract.
It also matters directly for certification. Every DCC level requires Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus as well. The MOD's own request for Level 0 by 31 December 2026 explicitly includes obtaining Cyber Essentials for all applicable business-critical systems within scope. Our guide to DCC and Cyber Essentials sets out why the two are not alternatives.
We are an appointed Cyber Essentials certification body and an appointed DCC certification body for Level 0, so both parts of that can be assessed by the same team.
Common questions
What is Def Stan 05-138?
Defence Standard 05-138 is the Ministry of Defence standard that lists the cyber security controls required for each Cyber Risk Profile. Suppliers are contractually required to meet the controls matching the profile assigned to their contract. Issue 4 is the current version.
Which issue of Def Stan 05-138 is current?
Issue 4. MOD guidance for the Cyber Security Model refers to Def Stan 05-138 Issue 4 as the document specifying the controls.
How do I find out my Cyber Risk Profile?
An MOD Delivery Team completes an initial Risk Assessment for the contract, which determines the Cyber Risk Profile and produces a Risk Assessment Reference (RAR) number. It is normally provided at the earliest market engagement and found in the invitation to tender. If you cannot find it, ask the contracting authority.
Is Def Stan 05-138 the same as DEFCON 658?
No. DEFCON 658 is the contract condition that brings the Cyber Security Model into your contract and requires you to flow obligations down to subcontractors. Def Stan 05-138 is the standard containing the controls you then have to meet.
Do I need Cyber Essentials to meet Def Stan 05-138?
Cyber Essentials is not a substitute for the standard, but it covers much of the same ground at the lower profiles, and it is required for Defence Cyber Certification at every level, with Cyber Essentials Plus required at Levels 2 and 3.
Does a DCC certificate mean I can skip the SAQ?
No, not currently. MOD guidance is explicit that DCC holders are not yet exempt from completing elements of the SAQ, and that the full SAQ to the required level remains mandatory.
