Skip to content
Compliance

DEFSTAN 05-138 - What does it mean for suppliers?

DEFSTAN 05-138 issue 4 is the UK MOD's published cyber security standard for the defence supply chain - the document that DCC Level 0 to Level 3 assesses against. The MOD has asked all suppliers to achieve DCC Level 0 by 31 December 2026, and DCC is the recognised route to evidence this standard under DEFCON 658. This guide explains the standard, the supplier obligations, who is in scope, and what certification costs.

A woman in military uniform examines document

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

13 min read

Share

Section 01

DEFSTAN 05-138 - What does it mean for suppliers?

DEFSTAN 05-138 (also written Def Stan 05-138, and formally Defence Standard 05-138) is the UK Ministry of Defence's published cyber security standard for the defence supply chain. The current version is issue 4. It defines the four control sets that sit underneath the Defence Cyber Certification (DCC) scheme, operates within the current Cyber Security Model alongside its mandatory Supplier Assurance Questionnaire, and is the document UK MOD contracts now point to when they specify the cyber posture a supplier must hold. The MOD has asked all suppliers to achieve DCC Level 0 - which is assessed against this standard - by 31 December 2026 (MOD Defence Digital blog, 8 May 2026), and where a contract requires DEFSTAN 05-138 compliance under DEFCON 658, DCC at the level matching your Cyber Risk Profile is the recognised way to evidence it. If you supply the MOD, directly or as a subcontractor at any tier, DEFSTAN 05-138 issue 4 is the standard your cyber posture is measured against.

Section 02

What changed in the latest DEFSTAN 05-138

DEFSTAN 05-138 issue 4 sets the current CSMv4 control requirements. DCC adds independently assessed evidence, while suppliers must still complete the full contract-specific SAQ. Read the actual tender, DEFCON 658 terms and transition requirements; certification does not universally replace self-assessment or the annual contract process.

The substantive control changes follow from that audit footing.

The standard defines four control sets, not one. Issue 4 codifies four progressively stringent control sets that map onto the four DCC levels. Level 0 covers three foundational controls. Level 1 covers 101 controls across governance, identity, device, secure configuration, and supply chain. Level 2 covers 139 controls including technical verification. Level 3 covers 144 controls and is the most demanding tier. The total control universe is 148 controls across the four levels.

Levels are pulled by the contract Cyber Risk Profile. Each MOD contract is assigned a Cyber Risk Profile (CRP) by the contracting authority - numeric Level 0, 1, 2 or 3 under CSMv4 - and the CRP determines the applicable control set and corresponding DCC evidence level where certification is required by the contract. Issue 4 makes the CRP the contractual dial that points to the applicable control set. Suppliers do not choose their level; the contract does. See the Cyber Risk Profile reference for the full mapping and the contract-clause language that triggers each level.

Scope is the supplier's overarching corporate or enterprise environment. Issue 4 clause 1.1 sets the scope of the standard as the supplier's overarching corporate or enterprise environment - all systems, processes, procedures, and data necessary for the effective protection of the data and functions in scope of the MOD contract. This is intentionally broad. It goes beyond protecting only the information provided to the supplier in support of the contracted output. Per the IASME Scoping Guide, scope is not just about the data held: if the processes and systems are essential for the organisation to operate as a business in support of the contract, they are within scope. The conservative test the DCC scoping guide sets out: if removing a system would impair the supplier's ability to deliver the contracted output, that system is in scope.

Cyber Essentials is the prerequisite at every level. Issue 4 makes a current Cyber Essentials certificate the floor for every DCC engagement. Levels 0 and 1 require standard Cyber Essentials. Levels 2 and 3 require Cyber Essentials Plus. The certificate must be within its 12-month validity window and can come from any IASME-licensed Certification Body. Early DCC scoping can begin before CE is issued; current CE is required for certification.

Certificates are organisation-wide and run for three years. Under issue 4, a single DCC certificate at the supplier's certified level covers multiple MOD procurements at or below that CRP. The certificate is valid for three years, with annual attestation at the end of years one and two confirming the in-scope controls remain in place. Year three is full re-assessment. The certificate can support evidence reuse, but each contract’s full SAQ and annual maintenance requirements remain.

Alignment with the NCSC Cyber Assessment Framework. Issue 4 aligns the DCC control sets with the NCSC Cyber Assessment Framework (CAF), which means suppliers already working against CAF principles - including suppliers in other regulated sectors - find substantial control overlap. The standard is also consistent with the IASME DCC Overview Document v1.2, the canonical IASME-published companion that explains how the controls are assessed.

The transition from DCPP self-attestation to independently audited DCC certification is the change suppliers feel hardest. The control universe is larger, the evidence depth is greater, and the verification is external. Suppliers carrying historical SAQ documentation should not assume that material translates directly - the assessor will review it against issue 4 and call out where it does not meet the audit threshold. Current MOD CSMv4 guidance points to issue 4; verify the latest authority guidance and contract version.

Section 03

What this means for UK MOD suppliers

DEFSTAN 05-138 issue 4 changes how a UK MOD supplier proves cyber posture, what evidence they need to hold, and how often they need to demonstrate it. Treating the standard as paperwork is the principal failure mode Fig Group sees at scoping conversations. Treating it as a contract requirement that gates revenue is the right framing.

A Level 0 Cyber Risk Profile sets the applicable control requirements; where the contract requires DCC, Level 0 or a qualifying higher-level certificate provides the corresponding evidence. That means a documentation-led IASME assessment of three foundational controls: appropriately scoped Cyber Essentials, board-level cyber responsibility and an organisation-wide cyber risk assessment, with a current Cyber Essentials certificate as a prerequisite. Fig Group published delivery for L0 is 2-3 weeks for prepared organisations. See DCC Level 0 for the full scope.

A Level 1 Cyber Risk Profile sets the applicable control requirements; where the contract requires DCC, Level 1 or a qualifying higher-level certificate provides the corresponding evidence. That means a consultant-led IASME assessment of 101 controls across governance, identity, device, secure configuration, and supply chain, with current Cyber Essentials and structured remediation rounds before formal assessment. Fig Group published delivery for L1 is 6-10 weeks for prepared organisations. See DCC Level 1 for the full scope.

A Level 2 Cyber Risk Profile sets the applicable control requirements; where the contract requires DCC, Level 2 or a qualifying higher-level certificate provides the corresponding evidence. L2 requires Cyber Essentials Plus as the prerequisite (not standard Cyber Essentials), 139 controls, and hands-on technical verification including multi-tier supply-chain assessment. Fig Group refers L2 engagements to IASME-licensed Certification Bodies that hold Level 2 scope - see the IASME directory for accredited bodies.

A Level 3 Cyber Risk Profile sets the applicable control requirements; where the contract requires DCC, Level 3 or a qualifying higher-level certificate provides the corresponding evidence. L3 covers 144 controls, requires Cyber Essentials Plus, and is currently delivered as a Level 2 / Level 3 hybrid pilot. Fig Group refers L3 engagements.

The supplier obligations that follow from issue 4 are concrete, not abstract.

Read the CRP in your contract clause - do not infer it. Three patterns appear in MOD and prime-contractor flow-down clauses: the clause names the CRP explicitly, the clause names a DCC level explicitly, or the clause uses vague language like "industry-standard cyber security" or "compliance with Defence Standards" without naming the level. The third case is the trap. Ask the contracting authority in writing before incurring assessment cost. Choosing the wrong level is materially more expensive than confirming it.

Maintain Cyber Essentials where the scheme and actual contract require it. CE is a prerequisite for every DCC certificate; MOD supply obligations depend on the applicable contract and assessed scope. CE validity is 12 months; a lapsed certificate must be renewed before certification, while early scoping can proceed. Fig Group issues Cyber Essentials within six working hours of a compliant submission from £299.99 + VAT for Micro organisations.

The Fig Group six-working-hour service applies to complete compliant submissions received before midday on a UK business day; readiness work, remediation and Plus scheduling are separate.

Scope the certified organisation’s essential operations and dependencies. Include services necessary for secure and resilient operation, whether they support MOD or non-MOD work; document legal-entity boundaries and justify exclusions with the assessor. Over-scoping multiplies evidence work; under-scoping fails certification. The IASME Scoping Guide is explicit: failure to adequately and accurately define the scope, including under-scoping, will result in a failure to achieve certification even if all required controls have been met. Use the DCC scoping guide to bound the engagement before any fee is incurred.

Treat supply-chain evidence as a four-to-six-week workstream, not an attachment. L1 supply-chain controls require documented flow-down (security clauses in supplier contracts), Supplier Capability Assessments (SCAs) against direct suppliers, and visibility on whether suppliers handle in-scope MOD data. Send SCAs to direct suppliers in week one of the engagement, not week five - suppliers respond on their own timelines, and the engagement stalls waiting for them.

Plan for the three-year cycle, not the certificate. The certificate is valid for three years, but annual attestation at the end of years one and two is a contractual requirement, and year three is a full re-assessment. Build the annual attestation cadence into the same calendar that holds your Cyber Essentials renewal so neither lapses mid-engagement.

Consider certificate reuse against confirmed requirements. A single certificate may support several contracts where entity, scope, level and dates fit. Two Level 0 contracts do not automatically require two paid certifications. Each contract still requires its full SAQ and applicable annual maintenance.

Pre-DCPP evidence transfers selectively, not wholesale. Suppliers transitioning from the prior DCPP regime should expect their Cyber Essentials evidence to map directly into Level 0. The wider SAQ documentation - governance narratives, risk registers, supplier lists - is reviewed against issue 4 at scoping and updated where it does not meet the audit threshold. Do not assume historical SAQ artefacts satisfy issue 4 without an assessor sign-off.

Section 04

Who needs to get Defence Cyber Certified

The population covered by DEFSTAN 05-138 issue 4 is wide and gets wider in 2026. The principal trigger is a contract with the UK MOD or a flow-down clause from a prime that holds an MOD contract. The standard does not distinguish between size, sector, or contract value at the level of who needs to comply - it distinguishes by Cyber Risk Profile.

Prime contractors to the MOD. Primes holding direct MOD contracts are within scope of DEFSTAN 05-138 at the CRP named in their contract. Primes typically certify at Level 1 or above, and cascade DCC requirements as flow-down to their tier-1 subcontractors.

Tier-1, tier-2 and tier-3 subcontractors. Subcontractors in the MOD supply chain inherit DEFSTAN 05-138 obligations through flow-down. Each subcontract needs its own assigned risk profile and RAR. Tier alone does not establish its profile or a DCC certificate requirement; read the actual flowed-down terms. The CRP is set by the contracting authority - the MOD or the prime in a subcontract scenario - and is named in the contract clause or DCPP requirements section.

Framework suppliers. Suppliers on MOD frameworks (DE&S, DIO, DSTL, Defence Sourcing Portal call-offs, Crown Commercial Service routes that feed MOD spend) are within scope when individual call-offs name a CRP. Holding DCC at the highest CRP the framework triggers is the practical default for framework participants.

Direct MOD procurements. Suppliers responding to direct MOD procurements, including small-value contracts under departmental thresholds, are within scope when the contract clause names DCC or a CRP. The standard does not exempt small contracts.

Professional services and technology vendors. Read the buyer’s current numeric CRP and RAR for the actual contract. Supplier type, tier and absence of classified data do not independently determine the level; confirm legacy verbal wording with the authority.

Operational technology and infrastructure suppliers. For operational technology, ICS and infrastructure services, obtain the buyer’s numeric profile, RAR and certificate requirements. Service type, tier and data classification alone do not assign Level 2 or Level 3.

MOD-adjacent regulated supply chains. Suppliers into defence-adjacent procurement routes (defence-aligned NHS, defence-aligned critical national infrastructure programmes, defence research consortia) inherit DCC obligations where the parent contract flows down DEFSTAN 05-138 requirements.

Cyber Essentials is a prerequisite for the whole population. Issue 4 requires a current Cyber Essentials certificate at every DCC level. CE Plus is required at L2 and L3. Suppliers without current CE can prepare it alongside early DCC scoping; CE must be current before DCC certification. Arrange CE certification and annual renewal separately if needed. See Cyber Essentials for the CE prerequisite detail.

If you are unsure whether your contract triggers DCC, the practical test is the contract clause. If the clause names a CRP, names a DCC level, or references DEFSTAN 05-138, you are in scope. If the clause is vague, ask the contracting authority in writing before incurring assessment cost. Use the DCC scoping guide or book a scoping call to confirm the level your contract requires before any fee is incurred.

Section 05

DCC Level 0 by end of 2026: what the MOD has asked of suppliers

The single most consequential development for the UK defence supplier base in 2026 is the MOD's request that all suppliers achieve DCC Level 0 by 31 December 2026. In the MOD's 8 May 2026 Defence Digital blog, Eleanor Fairford, Director of Cyber Defence and Risk, asked all industry partners to achieve Level 0 DCC certification - including Cyber Essentials for business-critical systems - by that date. Separately, ISN 2026/02 makes DCC the recognised route to evidence DEFSTAN 05-138 compliance under DEFCON 658, at the level set by the contract's Cyber Risk Profile. Fig Group's assessment is that DCC Level 0 is becoming the effective baseline for the supply chain and will increasingly gate the ability to bid for and hold MOD work. The full detail is in our companion guide: Do I need DCC for MOD contracts? DCC Level 0 by end of 2026.

The request gives suppliers a dated target to plan against. It does not remove contractual triggers or establish automatic exclusion from every procurement. Ask the buyer for the actual numeric CRP, RAR and DCC conditions, including any transition or agreed CIP.

What suppliers should do now:

1. Check CE scope and expiry; prepare CE in parallel with early DCC scoping if necessary.

2. Obtain the current numeric profile/RAR and written evidence requirements from the buyer.

3. Book assessment against a confirmed deadline and availability, allowing remediation buffer.

4. Calendar annual CE renewal, DCC attestations and the separate annual contract SAQ.

5. Read the step-by-step DCC guide.

Section 06

DCC pricing: what certification costs

Fig Group publishes DCC pricing openly so suppliers can budget before scoping. The pricing structure follows the level - L0 is flat-priced by organisation size and L1 is range-priced by variance drivers.

DCC Level 0 is flat-priced by organisation size, delivered in 2-3 weeks for prepared organisations:

  • Micro (1-9 employees): £499.99 + VAT
  • Small (10-49 employees): £599.99 + VAT
  • Medium (50-249 employees): £699.99 + VAT
  • Large (250+ employees): £799.99 + VAT

DCC Level 1 is range-priced according to supplier complexity, delivered in 6-10 weeks for prepared organisations:

  • From £9,999 + VAT (Micro, simple scope, clean estate)
  • Up to £49,999 + VAT (Large, complex scope, multi-cloud, large supply chain)

The variance drivers Fig Group prices against are site count, cloud footprint, legacy system presence, supply-chain depth, staff population, and existing maturity. Existing ISO 27001 evidence may reduce preparation work where it covers the DCC scope. Site count, cloud services, legacy systems and suppliers can affect the work required, but no single factor fixes a position within the price band. The accepted scope and support requirements determine the quote. Confirm any Cyber Essentials assessment inclusion in the accepted Level 1 Order Form; the standalone Level 1 price does not establish universal inclusion.

Cyber Essentials prerequisite. Arrange CE certification and annual renewal separately if needed; confirm the DCC scope in writing. CE must be current for every DCC certificate, with Plus at Levels 2 and 3. Early scoping is permitted before issue.

DCC Level 2 and Level 3 are not within Fig Group's licensed scope. Fig Group refers L2 and L3 engagements to IASME-licensed Certification Bodies that hold those scopes. L2 engagements are typically £40,000 to £90,000 + VAT scoped against the contract. L3 engagements are typically priced bespoke, often six figures.

Hidden costs to budget for separately: internal time (one to two FTEs across six to ten weeks at L1), legacy decommissioning where applicable, and supplier SCA response wait time. For the full pricing detail, including the variance-driver breakdown, see the DCC pricing detail on the hub.

Section 07

Frequently asked questions

Is DEFSTAN 05-138 mandatory?

In the contexts where it applies, yes. The MOD has asked all suppliers to achieve DCC Level 0 - the IASME-assessed control set drawn from DEFSTAN 05-138 issue 4 - by 31 December 2026, and where a contract requires DEFSTAN 05-138 compliance under DEFCON 658, DCC is the recognised evidence route. Where the contract requires DCC, the certificate must meet its required level and scope; the full SAQ and any agreed CIP remain separate. A higher numeric profile alone is not proof of a universal certification condition.

When does DEFSTAN 05-138 become mandatory for all MOD suppliers?

The MOD has set 31 December 2026 as the date by which it has asked all suppliers to achieve DCC Level 0. The contract’s numeric CRP determines the required control set. Check the actual DCC condition, timing, transition instructions and any agreed CIP before assuming certification is required at award. The full detail is in our DCC Level 0 by end of 2026 guide.

What is the difference between DEFSTAN 05-138 and DCC?

DEFSTAN 05-138 issue 4 is the published Defence Standard - the document defining the four control sets. DCC (Defence Cyber Certification) is the IASME-delivered scheme that assesses suppliers against those control sets and issues certificates. Suppliers do not certify against DEFSTAN 05-138 directly; they certify at a DCC level (L0, L1, L2, or L3) that draws its control set from DEFSTAN 05-138 issue 4.

How does DEFSTAN 05-138 relate to Cyber Essentials?

Cyber Essentials is a prerequisite at every DCC level under DEFSTAN 05-138 issue 4. Levels 0 and 1 require a current Cyber Essentials certificate. Levels 2 and 3 require Cyber Essentials Plus. CE proves the endpoint and network baseline; DEFSTAN 05-138 covers the organisation-level governance, supply-chain, and resilience controls that sit on top.

What evidence does DEFSTAN 05-138 require?

At Level 0, prepare evidence for current appropriately scoped CE, board-level cyber responsibility and an organisation-wide cyber risk assessment. Level 1 requires evidence against its applicable controls. Policies, inventories and supplier material can support that evidence without becoming a universal additional Level 0 checklist.

Who has to comply with DEFSTAN 05-138?

The MOD’s 8 May request asks all industry partners to achieve Level 0 by 31 December 2026. Direct contractual duties follow the applicable tender, DEFCON 658, current numeric profile, transition instructions and subcontract flow-down. Do not infer a universal exclusion rule or convert legacy verbal profiles yourself.

What is the latest issue of DEFSTAN 05-138?

Current MOD CSMv4 guidance points to Def Stan 05-138 issue 4. Confirm the version named by the current authority guidance and your contract; this article does not establish that no later issue can exist.

How much does DEFSTAN 05-138 compliance cost?

Compliance cost is the DCC fee at the level your contract requires. Fig Group publishes Level 0 from £499.99 + VAT (Micro) to £799.99 + VAT (Large), and Level 1 from £9,999 + VAT to £49,999 + VAT scoped to supplier complexity. L2 and L3 are out of Fig Group's licensed scope.

How long does DEFSTAN 05-138 certification take?

Fig Group published DCC Level 0 delivery is 2-3 weeks for prepared organisations. Level 1 is 6-10 weeks. The variance lives in the remediation cycles - clean evidence packs run through L1 in around six weeks; packs with legacy decommissioning or widespread gaps stretch to sixteen weeks or more.

Can a single DEFSTAN 05-138 certificate cover multiple MOD contracts?

Yes. DCC certificates are organisation-wide, not contract-specific. A single certificate at the supplier's certified level covers multiple MOD procurements at or below that CRP, valid for three years with annual attestation at the end of years one and two.

Section 08

Where to start

The three practical entry points for suppliers facing DEFSTAN 05-138 obligations are the same regardless of where the trigger came from.

1. Read the DCC scoping guide for the scope boundaries and the IASME-published scoping principles.

2. Read the Cyber Risk Profile reference for the contract-clause language that determines your level.

3. Book a 15-minute scoping call with an IASME-licensed assessor. We will confirm your CRP, review your existing Cyber Essentials evidence, and give you a realistic deadline-aware timeline before any fee is incurred.

Section 09

Scheme sources and contract checks

Use the MOD Cyber Security Model guidance to obtain the current CSMv4 numeric profile (Levels 0–3) and Risk Assessment Reference from your buyer. Legacy verbal profiles are not directly equivalent; ask the authority to confirm transition requirements. DCC is independent evidence of compliance, while the full contract-specific SAQ remains mandatory, including for DCC holders. Annual contract SAQs and applicable subcontract flow-down remain separate from DCC annual attestations. A non-compliant SAQ requires a Cyber Improvement Plan for the authority to consider; acceptance is not automatic.

IASME’s DCC FAQ explains certificate prerequisites: Cyber Essentials at every level, and Cyber Essentials Plus at Levels 2 and 3. Early scoping and preparation can proceed before these certificates are issued. Arrange Cyber Essentials certification and annual renewal separately if needed; confirm the DCC scope in writing. Planning durations and illustrative scenarios in this guide are provider estimates, not scheme deadlines or guarantees.

The assessing Certification Body must remain independent: it may explain requirements and review scope, but must not prepare answers, documents or evidence it later assesses. Confirm any separate preparation service and technology-provider boundary in writing; the applicant owns and approves its evidence.

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.