Defence supplier cyber assurance: DCC, DEFCON 658 and Def Stan 05-138

What DEFCON 658, Def Stan 05-138 and Defence Cyber Certification (DCC) actually require of MOD suppliers and their supply chains, and how to evidence compliance.

Informational, not legal advice. Not an endorsement by, or statement on behalf of, the Ministry of Defence. Regulatory detail verified 22 September 2026.

DCC Level 0: the MOD's 31 December 2026 request

The MOD has asked all defence industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026. DCC launched in May 2025 and is delivered through IASME's network of assured certification bodies. It is available at four levels, 0 to 3, matching the CSM v4 Cyber Risk Profile Levels.

Level 0 is the entry point. If a contract is assigned a higher Cyber Risk Profile Level, the certification you need is at that level or above.

DEFCON 658 and Def Stan 05-138: how they fit together

DEFCON 658

The contract condition. It makes the controls in Def Stan 05-138 contractually binding and flows the requirement down the supply chain: sub-contractors as well as prime contractors.

Def Stan 05-138

The technical standard. Issue 4 (published May 2024) sets out which controls are required at each risk level: network security, access management, encryption, incident response, vulnerability management, and staff training among them.

What changed under CSM v4

Since 3 December 2025, all new and existing MOD contracts containing DEFCON 658 must comply with Cyber Security Model version 4 and Def Stan 05-138 Issue 4. Two changes worth knowing: risk levels moved from descriptive labels (Very Low, Low, Moderate, High under the previous version) to four numbered Cyber Risk Profile Levels (0 to 3); and the requirement now applies across the whole supply chain, not only to the organisation directly contracting with the MOD. ISN 2025/07 also reinstated the annual review of the Supplier Assurance Questionnaire (SAQ) under DEFCON 658.

Evidencing compliance: ISN 2026/02 and Defence Cyber Certification

Industry Security Notice 2026/02 (30 March 2026) confirms that suppliers who hold a current, valid Defence Cyber Certification can submit it as assured evidence of compliance with the relevant Def Stan 05-138 control requirement, where the certification level is equal to or higher than the control level specified. A DCC Level 3 certificate, for example, covers Levels 0, 1 and 2.

DCC levels at a glance

  • Level 0: the baseline the MOD has asked every industry partner to reach by 31 December 2026.
  • Levels 1 to 3: required where a contract carries a higher Cyber Risk Profile Level. Each adds controls from Def Stan 05-138 Issue 4.
  • A certificate at a higher level satisfies every level below it.

How to prepare

  • Identify the Cyber Risk Profile Level assigned to the contract, or the Risk Assessment Reference (RAR) provided by the buyer or prime
  • Map current controls against the Def Stan 05-138 Issue 4 requirements for that level
  • Complete or renew the Supplier Assurance Questionnaire, now reviewed annually
  • Where a control is not yet met, agree a Cyber Implementation Plan with the delivery team
  • Decide whether to pursue DCC certification as assurance evidence, or a direct assessment route
  • Build the evidence base as an ongoing record, not a one-time exercise. The requirement extends across the contract lifecycle, not just at bid stage

How STREAM® Classic supports defence supplier assurance

STREAM® Classic gives you one configurable workspace to manage the evidence behind DEFCON 658, from bid to contract close. It does not certify you: DCC certificates are issued only by IASME's assured certification bodies.

Risk profile mapping

Map each contract's Cyber Risk Profile Level to the Def Stan 05-138 Issue 4 controls it requires, and see where you stand against each one.

Framework inheritance

Evidence a control once and reuse it across Def Stan 05-138, Cyber Essentials, ISO 27001 and your other frameworks.

Milestone reporting

Track Cyber Implementation Plan actions and report progress against dates to your delivery team or prime.

Supply chain questionnaires

Send assurance questionnaires to your own sub-contractors and hold their responses in the same place, so the flow-down is evidenced too.

Deployment for defence

Runs on-premises or air-gapped where your contracts demand it.

Defence Supplier Cyber Assurance FAQ

Common questions about DCC Level 0, DEFCON 658, Def Stan 05-138, and evidencing compliance.

See how STREAM Classic supports defence supplier assurance

Map risk profile levels, evidence controls, and maintain assurance across the contract lifecycle in one configurable workspace.

Sources

  • Industry Security Notice 2026/02, 30 March 2026 (assets.publishing.service.gov.uk)
  • Industry Security Notice 2025/07, Implementation of CSM v4 (assets.publishing.service.gov.uk)
  • Defence Standard 05-138, Issue 4, May 2024 (assets.publishing.service.gov.uk)
  • MOD Defence Digital blog, "One Year of Defence Cyber Certification", 8 May 2026 (defencedigital.blog.gov.uk)

Solve Your Challenges with STREAM®

Discover how STREAM®, our Cyber GRC platform, can help you address these challenges and streamline your compliance and risk management processes.