Defence Supplier Cyber Assurance
What DEFCON 658 and Def Stan 05-138 actually require of MOD suppliers and their supply chains — and how to evidence compliance.
Informational, not legal advice. Not an endorsement by, or statement on behalf of, the Ministry of Defence. Regulatory detail verified 31 August 2026.
DEFCON 658 and Def Stan 05-138 — how they fit together
DEFCON 658
The contract condition. It makes the controls in Def Stan 05-138 contractually binding and flows the requirement down the supply chain — sub-contractors as well as prime contractors.
Def Stan 05-138
The technical standard. Issue 4 (published May 2024) sets out which controls are required at each risk level — network security, access management, encryption, incident response, vulnerability management, and staff training among them.
What changed under CSM v4
Since 3 December 2025, all new and existing MOD contracts containing DEFCON 658 must comply with Cyber Security Model version 4 and Def Stan 05-138 Issue 4. Two changes worth knowing: risk levels moved from descriptive labels (Very Low, Low, Moderate, High under the previous version) to four numbered Cyber Risk Profile Levels (0–3); and the requirement now applies across the whole supply chain, not only to the organisation directly contracting with the MOD.
Evidencing compliance: ISN 2026/02 and Defence Cyber Certification
Industry Security Notice 2026/02 (30 March 2026) confirms that a valid Defence Cyber Certification (DCC) — an organisation-wide certification scheme delivered for the MOD by IASME, aligned to the four CSM v4 levels — can be submitted as assurance evidence that a supplier has satisfied the relevant Def Stan 05-138 control requirement, at the same level or higher, without a separate assessment.
How to prepare
- Identify the Cyber Risk Profile Level assigned to the contract, or the Risk Assessment Reference provided by the buyer or prime
- Map current controls against the Def Stan 05-138 Issue 4 requirements for that level
- Decide whether to pursue DCC certification as assurance evidence, or a direct assessment route
- Build the evidence base as an ongoing record, not a one-time exercise — the requirement extends across the contract lifecycle, not just at bid stage
Defence Supplier Cyber Assurance FAQ
Common questions about DEFCON 658, Def Stan 05-138, and evidencing compliance.
See how STREAM Classic supports defence supplier assurance
Map risk profile levels, evidence controls, and maintain assurance across the contract lifecycle in one configurable workspace.
Sources
- Industry Security Notice 2026/02, 30 March 2026 (assets.publishing.service.gov.uk)
- Defence Standard 05-138, Issue 4, May 2024 (assets.publishing.service.gov.uk)
- MOD Defence Digital blog — DCC Level 0 deadline (verified elsewhere in this engagement; re-check before publish)
- Logiq, "What is DEFCON 658?" and "Defence Supply Chain Cyber Security Guide"
Solve Your Challenges with STREAM®
Discover how STREAM®, our Cyber GRC platform, can help you address these challenges and streamline your compliance and risk management processes.