IT built for the demands of the defence supply chain.

Primes and their suppliers carry obligations ordinary IT cannot satisfy: flow down cyber clauses, a JOSCAR registration to keep current, OFFICIAL-SENSITIVE material to handle, and evidence that survives a supplier assurance review. We run, secure, build, and prove the technology behind all of it, so a contract is never lost on a control nobody owned. UK based, BPSS cleared staff, UK data residency, and a working knowledge of the standards most providers have never read.

A precision aerospace engineer inspecting a machined component in a clean UK machine shop
Verified
ISO 27001 & 9001UKAS accredited Cyber Essentials PlusCertified Cyber EssentialsCertification body CISSPIn house 5.0Google rating
Defence and Aerospace / 01 · The context

Most MSPs have never heard of Def Stan 05-138. We work to it.

Prime contractors are flowing down cyber security requirements harder than ever, and the MOD now expects specific, evidenced controls from the businesses in its supply chain. The consequence of getting it wrong is not just a failed audit. It is a lost contract and a damaged relationship with a prime. We understand the framework that governs this work, and we build the posture and the evidence to satisfy it.

Def Stan 05-138 DEFCON 658 and 659 MOD Cyber Security Model JOSCAR Cyber Essentials Plus AS9100 ITAR and EAR aware
658DEFCON 658 and 659The MOD contract clauses for cyber risk management, and the flow down to subcontractors. If they sit in your contract, your IT has to answer them.
CSMMOD Cyber Security ModelA risk profile from Very Low to Very High, set by the sensitivity of what you handle, with a baseline of controls to match.
JOSCARSupplier assuranceThe pre qualification register the major primes use. We help complete the cyber sections honestly and with evidence behind them.
Defence and Aerospace / 02 · The framework

The Cyber Security Model, in plain English.

The MOD assigns each contract a risk profile based on the information and systems involved, and each profile sets a minimum security baseline. Knowing where a contract sits, and what it therefore demands, is the difference between a clean supplier assurance review and an awkward one. The grades below are the model's own.

01
Very Low and Low
No access, or OFFICIAL information with no MOD system access. Basic cyber hygiene, rising to Cyber Essentials as the floor.
02
Moderate
OFFICIAL-SENSITIVE information and limited MOD connectivity. Cyber Essentials Plus as the minimum baseline.
03
High and Very High
Critical systems and significant integration, up to national security implications. Cyber Essentials Plus with additional controls, through to a bespoke security regime.
01Def Stan 05-138The MOD standard for supplier cyber security, across people, process, and technology.
02DEFCON 658/659Cyber risk clauses, and the flow down to your subcontractors.
03JOSCARPre qualification and annual renewal for the major primes.
04AS9100Aerospace quality management, underpinned by compliant IT and traceability.
Defence and Aerospace / 03 · The pressures

What we hear from suppliers and primes.

The pressures are specific to this sector, and so is the cost of failing them. These are the problems we are most often brought in to solve.

01Win and keep work

The contract is at stake

A prime's questionnaire lands with cyber clauses you have to evidence, and the next stage of the contract depends on the answers. Getting it wrong does not mean a warning. It means the work goes elsewhere.

02Handle it correctly

Sensitive material, sensitive data

OFFICIAL and OFFICIAL-SENSITIVE information has to be encrypted, access controlled on a need to know basis, logged, disposed of securely, and kept in the UK. Ordinary cloud defaults do not get you there.

03Protect the IP

Designs people want to steal

Test data, flight systems, and design files are exactly what a capable adversary is after. The work has to be defended, monitored, and recoverable, and you need to be able to show that it is.

Defence and Aerospace / 04 · How we help

One accountable partner, across all four pillars.

We do not sell defence a different product. We point the same four disciplines at the obligations and risks that are specific to it, and link you to the service that does the work. One partner, no gaps between suppliers for a failure to hide in.

01Run it

Managed IT and infrastructure

UK based support, UK hosted infrastructure, and no offshore centre touching your environment. A service desk and proactive management that keep a demanding operation online, with MDR included as standard.

02Secure it

Cyber Essentials and monitoring

We are a Cyber Essentials certification body, so we know exactly what the standard requires and get you cleanly through Plus, the baseline most supply chain work now expects. Monitoring and incident response sit behind it, watching the systems an adversary would target.

03Build it

Software, secure by design

Bespoke software, integration, and applied AI built by the same team that runs and secures it, on UK hosted infrastructure with a full audit trail. The thing we build is the thing we can stand behind and account for.

04Prove it

Evidence and supplier assurance

We build and maintain the evidence packs, policies, and audit trails that primes and assessors ask for, and help you complete JOSCAR and prime specific questionnaires with accurate, evidenced answers. CAF aligned, so the controls map to a recognised framework.

We are loud about the work, never about the client. In defence and aerospace especially, we describe the sector and the capability and keep the rest confidential. The detail that would identify a client, or help an attacker, stays behind closed doors.
Defence and Aerospace / 05 · Clearance and residency

British owned, UK based, and honest about clearance.

Our UK based staff hold BPSS clearance, which is sufficient for most supply chain work handling OFFICIAL information. We do not currently hold SC or DV clearance, and we will not pretend otherwise. Where a contract requires a higher level, we work with you through the sponsorship process rather than overstating what we have. Your data stays in UK jurisdiction throughout: UK cloud, UK backups, and no offshore support.

01StaffUK based, BPSS cleared. Higher clearances via sponsorship.
02DataUK cloud and UK backups. UK jurisdiction throughout.
03SupportNo offshore centre accessing your environment.
04ITAR and EARWe build the access controls; export control law stays with your specialist advisers.
FAQ

Common questions

Do we definitely need Cyber Essentials for MOD work?

For most supply chain work it is the floor. Under the MOD Cyber Security Model, a Low risk profile generally expects Cyber Essentials, and a Moderate profile, where OFFICIAL-SENSITIVE information is involved, expects Cyber Essentials Plus. The honest answer depends on the risk profile of your specific contract, which we can read with you. As a certification body, we take you through it cleanly.

What is the difference between DEFCON 658 and 659?

They are MOD contract clauses for cyber security. In practice, 658 sets out the cyber risk management requirements that apply to you under the contract, and 659 deals with flowing those requirements down to your own subcontractors. If either appears in your contract, your IT and your suppliers both need to be able to answer it, and we help you build and evidence that.

What security clearances do your staff hold?

Our UK based staff hold BPSS, the Baseline Personnel Security Standard, which is sufficient for most supply chain work handling OFFICIAL information. We do not currently hold SC or DV clearance. Where your contract requires a higher level, we work with you through the sponsorship process rather than claiming clearances we do not have.

How do you handle OFFICIAL-SENSITIVE material?

With encryption at rest and in transit, access controlled on a need to know basis, audit logging, secure disposal, and UK only data residency. The controls are designed to match the risk profile of the contract rather than applied as a generic template, and the evidence that they are in place is produced as a matter of course, not reconstructed under pressure before a review.

Can you help us complete a JOSCAR registration?

Yes. We help clients complete JOSCAR registrations and annual renewals, including the detailed cyber security sections, and the prime specific supplier assurance questionnaires that sit alongside them. The aim is accurate, evidenced answers backed by controls that are genuinely in place, because that is what stands up when a prime checks.

We handle ITAR controlled data. Can you support us?

We can build and run the IT environment that prevents unauthorised foreign access, with UK based staff and UK data residency. ITAR and EAR compliance itself is primarily a legal and procedural matter, so we work alongside your export control advisers rather than replacing them. The technology controls are ours; the legal interpretation stays with the specialists.

The stakes are real. So is the rigour.

Send us the clauses in your contract, or the questionnaire from your prime. We will tell you plainly where you stand and what it takes to close the gap. We reply within one working day, and you will speak to an engineer, not a salesperson.

Reading, Berkshire  /  BPSS cleared, UK data residency  /  reply within one working day