Framework · UK defence supply chain
Def Stan 05-138
The MOD cyber security standard behind DEFCON 658 and Defence Cyber Certification, grading contracts from Very Low to Very High risk.
What Def Stan 05-138 is
Def Stan 05-138 is the Ministry of Defence standard setting cyber security requirements for the defence supply chain. Issue 4 grades contracts across risk levels from Very Low to Very High and defines the controls expected at each.
It is the technical substance behind two things suppliers meet in practice: the DEFCON 658 contract condition, and Defence Cyber Certification, which assesses suppliers against the standard independently.
How the standard is structured
Proportionate controls, applied by contract risk level and evidenced at assessment.
Risk levels, not company size
Def Stan 05-138 grades contracts from Very Low to Very High. The grade follows the sensitivity of the information handled, not the size or turnover of the supplier.
A cumulative control set
Each risk level inherits the controls of the level below and adds to them, so moving up a level extends an existing baseline rather than replacing it.
Cyber Essentials as the floor
The lower risk levels align closely with Cyber Essentials. Higher levels bring governance, monitoring, incident response, and supplier assurance obligations.
The standard behind DCC
Defence Cyber Certification assesses against Def Stan 05-138 Issue 4. The DCC level you are asked for maps directly to the risk profile of your contracts.
Evidence, not assertion
Controls must be evidenced. Policy documents alone do not satisfy an assessor where operational records, logs, and reviews are expected.
Overlap with ISO 27001
A substantial share of the higher-level controls map to ISO 27001 Annex A, so certified organisations usually face materially less incremental work.
Where Goldline fits
Goldline maps your Def Stan 05-138 risk profile, confirms the Defence Cyber Certification level that follows from it, and closes the control gaps to assessment standard. Delivery is by a senior, SC Cleared practitioner.
Goldline delivers readiness and implementation. Certification is issued by an accredited Certification Body, not by Goldline.
Related reading: DEFCON 658, Defence Cyber Certification, and ISO 27001.
