Skip to main content

Framework · UK defence supply chain

Def Stan 05-138

The MOD cyber security standard behind DEFCON 658 and Defence Cyber Certification, grading contracts from Very Low to Very High risk.

What Def Stan 05-138 is

Def Stan 05-138 is the Ministry of Defence standard setting cyber security requirements for the defence supply chain. Issue 4 grades contracts across risk levels from Very Low to Very High and defines the controls expected at each.

It is the technical substance behind two things suppliers meet in practice: the DEFCON 658 contract condition, and Defence Cyber Certification, which assesses suppliers against the standard independently.

How the standard is structured

Proportionate controls, applied by contract risk level and evidenced at assessment.

Risk levels, not company size

Def Stan 05-138 grades contracts from Very Low to Very High. The grade follows the sensitivity of the information handled, not the size or turnover of the supplier.

A cumulative control set

Each risk level inherits the controls of the level below and adds to them, so moving up a level extends an existing baseline rather than replacing it.

Cyber Essentials as the floor

The lower risk levels align closely with Cyber Essentials. Higher levels bring governance, monitoring, incident response, and supplier assurance obligations.

The standard behind DCC

Defence Cyber Certification assesses against Def Stan 05-138 Issue 4. The DCC level you are asked for maps directly to the risk profile of your contracts.

Evidence, not assertion

Controls must be evidenced. Policy documents alone do not satisfy an assessor where operational records, logs, and reviews are expected.

Overlap with ISO 27001

A substantial share of the higher-level controls map to ISO 27001 Annex A, so certified organisations usually face materially less incremental work.

Where Goldline fits

Goldline maps your Def Stan 05-138 risk profile, confirms the Defence Cyber Certification level that follows from it, and closes the control gaps to assessment standard. Delivery is by a senior, SC Cleared practitioner.

Goldline delivers readiness and implementation. Certification is issued by an accredited Certification Body, not by Goldline.

Related reading: DEFCON 658, Defence Cyber Certification, and ISO 27001.

Frequently asked

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.