Skip to main content

Framework · UK defence supply chain

DEFCON 658

The MOD contract condition that turns cyber security into a contractual obligation and cascades it through the defence supply chain.

What DEFCON 658 is

DEFCON 658 is the Ministry of Defence contract condition covering cyber security. Where a contract carries it, the supplier accepts obligations to assess cyber risk, evidence controls proportionate to that risk, and flow the same obligations down to subcontractors handling MOD identifiable information.

It is the mechanism through which defence cyber requirements reach organisations that never contract with the MOD directly. Most Tier 2 and Tier 3 suppliers meet it as a clause in a prime contractor agreement.

How the obligation works

Risk assessment, supplier assurance, and flowdown, applied proportionately to the assessed risk level.

The contract condition

DEFCON 658 is the standard MOD contract condition covering cyber security. Where it appears, cyber risk assessment and supplier assurance become contractual obligations rather than good practice.

Cyber Risk Assessment

The contracting authority completes a Cyber Risk Assessment producing a risk level from Very Low to Very High, drawn from the Def Stan 05-138 control framework.

Supplier Assurance Questionnaire

Suppliers respond through the Defence Cyber Protection Partnership Supplier Assurance Questionnaire, evidencing the controls applicable at the assessed risk level.

Flowdown to subcontractors

The obligation cascades. Prime contractors must flow DEFCON 658 and the associated risk level down through the supply chain to any subcontractor handling identifiable MOD information.

Cyber Implementation Plan

Where controls are not yet in place, suppliers agree a Cyber Implementation Plan with the authority, setting out remediation and timescales.

The route to DCC

Defence Cyber Certification is the independently assessed assurance layer replacing self-declared questionnaire responses across the defence industry base.

Where Goldline fits

Goldline prepares defence suppliers to answer DEFCON 658 obligations credibly: mapping the assessed risk level, closing the Def Stan 05-138 control gaps, and building the evidence pack that supports both the Supplier Assurance Questionnaire and Defence Cyber Certification.

Goldline delivers readiness and implementation. Certification is issued by an accredited Certification Body, not by Goldline.

Related reading: Def Stan 05-138, Defence Cyber Certification, and Cyber Essentials.

Frequently asked

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.