Prime questionnaires
A prime's questionnaire lands with cyber clauses you have to evidence, and the next stage of the contract depends on the answers. Get it wrong and the work is at risk.
Primes and their suppliers carry demanding obligations: flow down cyber clauses, a JOSCAR registration, OFFICIAL-SENSITIVE material, and evidence that survives a supplier assurance review. We run, secure, build, and prove the technology behind it, so the controls a prime asks about are already in place and evidenced. UK-based, with UK-hosted infrastructure for the systems we manage, and working to Def Stan 05-138, DEFCON 658 and 659, and the MOD Cyber Security Model.
Prime contractors are increasingly flowing down cyber security requirements, and the MOD expects specific, evidenced controls from its supply chain. Getting it wrong does not just fail an audit; it can put the contract at risk.
The MOD assigns each contract a risk profile based on the information and systems involved, and each profile sets a minimum security baseline. Knowing where your contract sits is the difference between a clean supplier assurance review and an awkward one.
A prime's questionnaire lands with cyber clauses you have to evidence, and the next stage of the contract depends on the answers. Get it wrong and the work is at risk.
OFFICIAL and OFFICIAL-SENSITIVE information has to be encrypted, access controlled on a need to know basis, logged, disposed of securely, and kept in the UK. Default cloud configuration does not get you there.
Test data, flight systems, and design files are exactly what a capable adversary is after. The work has to be defended, monitored, recoverable, and evidenced as such.
UK-based support and UK-hosted infrastructure for the systems we manage, with Managed Detection and Response (MDR) included as standard and a service desk staffed by engineers.
We are an appointed Cyber Essentials certification body, so we know what the standard requires. We prepare you for Cyber Essentials Plus, the baseline most supply chain work now expects; formal assessment is scoped separately. Monitoring and incident response sit behind it.
Custom software, integration, and applied AI, with UK-hosted deployment available and an audit trail behind it, built by the team that also runs and secures it.
We build and maintain the evidence packs, policies, and audit trails primes and assessors ask for, and help you complete JOSCAR and prime specific questionnaires, with the controls mapped to the Cyber Assessment Framework (CAF).
We do not hold SC or DV clearance, and we will not pretend otherwise. Where a contract requires cleared personnel, we work with you through the sponsorship process. Our team is UK-based, with UK-hosted infrastructure for the systems we manage.
For most supply chain work it is the floor. Under the MOD Cyber Security Model, a Low risk profile generally expects Cyber Essentials, and a Moderate profile, where OFFICIAL-SENSITIVE information is involved, expects Cyber Essentials Plus. Which applies depends on your contract's risk profile, which we can read with you. As an appointed certification body we know what the standard asks for and prepare you for it; formal assessment is scoped as its own piece of work.
They are MOD contract clauses for cyber security. 658 sets out the cyber risk management requirements that apply to you under the contract; 659 covers flowing those requirements down to your own subcontractors. If either appears in your contract, your IT and your suppliers both have to answer it, and we help you build and evidence that.
We do not hold SC or DV clearance, and we do not claim clearances we do not have. Where your contract requires cleared personnel, we work with you through the sponsorship process. Our team is UK-based, and we will tell you what we can and cannot cover on a given contract.
With encryption at rest and in transit, access controlled on a need to know basis, audit logging, secure disposal, and UK-hosted storage for the systems we manage. The controls match the risk profile of the contract rather than a generic template, and the evidence is produced as a matter of course rather than reconstructed before a review.
Yes. We help clients complete JOSCAR registrations and annual renewals, including the detailed cyber security sections, and the prime specific supplier assurance questionnaires alongside them. The aim is accurate, evidenced answers backed by controls that are in place, because that is what stands up when a prime checks.
We build and run the IT environment and the access controls designed to keep restricted material away from unauthorised foreign access, with a UK-based team and UK-hosted infrastructure for the systems we manage. ITAR and EAR compliance is a legal and procedural matter, so we work alongside your export control advisers rather than replacing them; the legal interpretation stays with the specialists.
Send us the clauses in your contract, or the questionnaire from your prime. We will tell you where you stand and what it takes to close the gap.
Hello, I am Ainsley, the AI assistant here at Dead Simple Computing. Ask me anything about managed IT, cyber security, software and AI, or governance and audit. I can also put you in touch with a person.
Replies are AI generated and can be wrong. Your messages are sent to a third-party AI service to produce them, and a member of our team can read this chat and may join it. Do not type anything confidential. See our privacy notice.