A supplier receives a Ministry of Defence (MoD) contract, finds a clause called DEFCON 658, and asks whether Cyber Essentials covers it.
No. Cyber Essentials does not cover DEFCON 658, and it never has. Not partially, not for small contracts, not if you also hold Cyber Essentials Plus. The two answer different questions, and anyone telling a supplier that a certificate satisfies the clause is setting them up to fail an assurance check.
What Cyber Essentials does is sit underneath the framework as a prerequisite, and that is a genuinely useful position to be in. But the obligation itself involves four things rather than one, and they are frequently confused with each other. DEFCON 658 creates the contractual obligation. The Cyber Security Model decides how much security the contract demands. Def Stan 05-138 sets out the controls at each level. Defence Cyber Certification is the newest piece: an independently assessed way of evidencing those controls.
There is now a date attached to the last of those, which is why this has become urgent rather than theoretical.
The four pieces, and how they fit
| Piece | What it does |
|---|---|
| DEFCON 658 | The contract condition. Where it appears, cyber obligations apply and flow down to subcontractors |
| Cyber Security Model | The MoD’s framework for assessing supply chain cyber risk. Assigns a Cyber Risk Profile to each contract |
| Def Stan 05-138 | The defence standard listing the controls required at each risk level |
| Defence Cyber Certification | Independently assessed certification that those controls are in place |
The distinction that trips people up: the Cyber Security Model is the overall risk and procurement model, Def Stan 05-138 is the control standard that model uses, DEFCON 658 creates the contractual obligations, and Defence Cyber Certification provides independently assessed evidence against the control level. Four different jobs, four different documents.
DEFCON 658
DEFCON 658 is a standard MoD contract condition applied where a contract involves MoD identifiable information. It is not itself a set of controls; it is the hook that pulls the rest of the framework into your contract.
This is why no certificate satisfies it on its own. The clause obliges you to complete a process, and holding certifications makes that process easier to complete truthfully. It does not remove it.
Where it appears, three obligations follow.
A cyber risk profile is assigned. The contracting authority assesses the risk associated with that specific contract and issues a Risk Assessment Reference. Two contracts with the same customer can carry different profiles, because the assessment is about the information involved rather than the size of your business.
You complete a Supplier Assurance Questionnaire. Submitted through the Supplier Cyber Protection Service, against the controls required at your assigned profile. The outcome is compliance, or a Cyber Implementation Plan setting out what you will do and by when. A plan is a legitimate outcome, not a failure, provided it is honest and you deliver against it.
It flows down. The condition passes to your own subcontractors where they handle relevant information. Assuring your supply chain becomes your responsibility rather than the department’s, and this is the obligation most commonly missed by organisations meeting DEFCON 658 for the first time.
The Cyber Security Model: version 3 to version 4
The Cyber Security Model is the MoD’s framework for assessing and managing cyber risk across its supply chain, and the current version changes what suppliers are asked to do.
Under version 3, assurance was essentially self-assessment driven. A contract received a risk profile, the supplier answered the questionnaire against the corresponding Def Stan 05-138 controls, and the assurance rested on that declaration. It functioned, but it produced inconsistent evidence: two suppliers answering the same question could mean quite different things by the same answer, and nobody independent had looked.
Version 4 keeps the risk profile approach and adds an independently assessed route. It updated the requirements and introduced the Defence Cyber Certification scheme, with Def Stan 05-138 Issue 4 as the control standard underneath it.
The practical shift is from “tell us you have the controls” toward “show us that somebody independent checked”.
And this matters now, because version 3 has in part been deprecated. New contracts are being let under version 4, which means a Defence Cyber Certification level assigned by the MoD rather than a self-assessment against the older model. If your experience of the Cyber Security Model is a questionnaire you filled in a couple of years ago, that is not the process your next contract will follow.
You do not have to wait to be told
The level is assigned by the MoD for a given contract, but nothing stops you certifying ahead of that.
Suppliers can pursue whichever level they judge appropriate, in advance of a contract requiring it. If you already know the kind of work you do, you can plan accordingly: an organisation whose work routinely handles more sensitive information can reasonably expect to land at Level 3 and prepare for that, rather than certifying at Level 0 and repeating the exercise when a contract arrives demanding more.
That is worth thinking about commercially as well as practically. Certification held in advance is evidence you can put in front of a prime contractor during a bid, rather than a gap you promise to close afterwards.
Def Stan 05-138
Def Stan 05-138 is the defence standard listing the actual cyber security controls, organised by risk level. It is the technical content behind everything above, and Issue 4 is the version used by the current model.
Two things are worth knowing before you start reading it.
It scales. A contract assessed at a low risk profile asks considerably less than one assessed high. Reading the standard at your assigned level, rather than the whole document, is usually the difference between a manageable piece of work and an imagined one.
The levels are cumulative. Each higher profile includes the controls from the levels beneath it, so preparation for a higher level never wastes the work done for a lower one.
Defence Cyber Certification
Defence Cyber Certification is the newest and most consequential piece: an organisation-wide cyber security certification framework for UK defence suppliers, developed by the MoD with IASME. It provides a single organisation-level assurance that can be presented in support of defence procurements, subject to annual attestation and recertification every three years.
Two features distinguish it from what came before.
It is organisation-wide rather than contract-specific. One certification presented across procurements, rather than assembling the same evidence contract by contract.
It is independently assessed. IASME manages delivery through its network of assured certification bodies, so the assurance comes from an assessor rather than a self-declaration.
Its status under DEFCON 658 is formally recognised. An Industry Security Notice published in March 2026 confirms that a supplier holding and maintaining valid certification at the appropriate level under the scheme may submit that certification as evidence of having satisfied the requirement to apply the relevant Def Stan 05-138 controls.
The levels
Certification runs from Level 0 upward, mapped to the Cyber Risk Profile assigned to your contracts. Certification at a higher level satisfies the requirement for lower levels; the reverse does not apply. Level 0 establishes a baseline but will not satisfy a contract requiring a higher level, so a supplier working across several contracts should plan around the highest level any of them demands rather than the one currently in front of them.
Where Cyber Essentials fits
Directly, and as a prerequisite rather than an alternative. Cyber Essentials is a mandatory prerequisite for Level 0: you must hold a valid certificate whose scope aligns to your Defence Cyber Certification scope before applying. Level 0 is then assessed against Def Stan 05-138 Issue 4, with MoD-specific requirements for the defence supply chain.
At Level 2 and above, Cyber Essentials alone is not enough: you need Cyber Essentials Plus as well. That is a meaningful step up in effort and lead time, because Plus involves an independent technical audit of a sample of your systems rather than a verified self-assessment, and it depends on holding the base certificate first. If you expect to sit at Level 2 or Level 3, plan both certifications together from the outset rather than discovering the requirement partway through. We set out the difference between the two levels in Cyber Essentials vs Cyber Essentials Plus.
The phrase doing the work there is scope alignment. A Cyber Essentials certificate covering a subset of your organisation will not support a certification scope covering more than that subset, which makes scoping a decision to take deliberately at the start rather than discover late. Our scope guide covers how the boundary is defined and where whole organisation status survives.
The date
The MoD has asked all defence industry partners to achieve Level 0 by 31 December 2026, including Cyber Essentials for the applicable business-critical systems within scope.
Read that alongside the caveat, because both are true: IASME’s published scheme information still describes the certification as not currently mandatory in every case, so the deadline is not yet a universal contractual requirement.
My reading, for what it is worth: a request from the department to its entire supply chain, with a date attached, tends to become a contractual expectation faster than the formal position suggests. If you supply defence and do not hold Cyber Essentials, that is the work to start now. It is the prerequisite, and it is the part with the longest lead time if something in your estate turns out to need replacing.
DEFCON 658 is the obligation. The Cyber Security Model sets your level, and new contracts run under version 4. Def Stan 05-138 lists the controls. Defence Cyber Certification is how you evidence them independently. Cyber Essentials is the prerequisite for Level 0, and Cyber Essentials Plus is required from Level 2 upward. Work out the level your business is likely to need, then certify for that rather than the minimum.
What to do if DEFCON 658 has appeared in a contract
- Find the Risk Assessment Reference and Cyber Risk Profile for that contract. Without it you are guessing at the level, and guessing high wastes money while guessing low fails the assurance.
- Read Def Stan 05-138 Issue 4 at your assigned level, not at every level.
- Complete the Supplier Assurance Questionnaire honestly. An accurate Cyber Implementation Plan is a stronger position than an optimistic claim of compliance, because the plan is a commitment you control.
- Get Cyber Essentials in place, scoped correctly. It is the Level 0 prerequisite and it answers a meaningful share of the questionnaire.
- Decide your target level on the highest profile across your contracts and the work you expect to win, not the nearest one. If that is Level 2 or above, budget for Cyber Essentials Plus as well as Cyber Essentials.
- Deal with flow down early. Identify which subcontractors handle relevant information before the contract does it for you.
- Keep the evidence. Defence assurance is periodic, and the organisation that kept its records finds the next round trivial.
One caution
Certification does not replace everything else. Current MoD guidance is that suppliers must still complete the full Supplier Assurance Questionnaire through the Supplier Cyber Protection Service where required, and the scheme is separate from additional requirements covering classified information, specific systems, operational technology and Secure by Design. Those may appear in procurement notices, other Defence Standards, other DEFCONs or a Security Aspects Letter.
Readiness starts with the whole contractual picture rather than one certificate.
Where we come in
Wiltshire and the surrounding counties hold an unusual concentration of defence activity, and around every establishment and prime contractor sits a long tail of smaller suppliers who have never been asked a security question until a contract arrives with a clause in it.
We are a licensed IASME Certification Body, so we assess and issue Cyber Essentials and Cyber Essentials Plus directly, including getting the scope right first time so it aligns with where your defence certification scope needs to be. Where a higher risk profile asks for more than the five controls, an independent security audit establishes where you actually stand against them rather than where you assume you do.
If DEFCON 658 has landed in a contract and you are not sure what it means for you, get in touch or call 01722 445972.
Sources: Industry Security Notice 2026/02, Use of Defence Cyber Certification as assurance of control requirements under DEFCON 658, Ministry of Defence, March 2026; IASME Defence Cyber Certification scheme information. Contains public sector information licensed under the Open Government Licence v3.0. Defence requirements change; confirm the current position against MoD and IASME sources before relying on this.