Framework · UK defence supply chain
DEFCON 658
The MOD contract condition that turns cyber security into a contractual obligation and cascades it through the defence supply chain.
What DEFCON 658 is
DEFCON 658 is the Ministry of Defence contract condition covering cyber security. Where a contract carries it, the supplier accepts obligations to assess cyber risk, evidence controls proportionate to that risk, and flow the same obligations down to subcontractors handling MOD identifiable information.
It is the mechanism through which defence cyber requirements reach organisations that never contract with the MOD directly. Most Tier 2 and Tier 3 suppliers meet it as a clause in a prime contractor agreement.
How the obligation works
Risk assessment, supplier assurance, and flowdown, applied proportionately to the assessed risk level.
The contract condition
DEFCON 658 is the standard MOD contract condition covering cyber security. Where it appears, cyber risk assessment and supplier assurance become contractual obligations rather than good practice.
Cyber Risk Assessment
The contracting authority completes a Cyber Risk Assessment producing a risk level from Very Low to Very High, drawn from the Def Stan 05-138 control framework.
Supplier Assurance Questionnaire
Suppliers respond through the Defence Cyber Protection Partnership Supplier Assurance Questionnaire, evidencing the controls applicable at the assessed risk level.
Flowdown to subcontractors
The obligation cascades. Prime contractors must flow DEFCON 658 and the associated risk level down through the supply chain to any subcontractor handling identifiable MOD information.
Cyber Implementation Plan
Where controls are not yet in place, suppliers agree a Cyber Implementation Plan with the authority, setting out remediation and timescales.
The route to DCC
Defence Cyber Certification is the independently assessed assurance layer replacing self-declared questionnaire responses across the defence industry base.
Where Goldline fits
Goldline prepares defence suppliers to answer DEFCON 658 obligations credibly: mapping the assessed risk level, closing the Def Stan 05-138 control gaps, and building the evidence pack that supports both the Supplier Assurance Questionnaire and Defence Cyber Certification.
Goldline delivers readiness and implementation. Certification is issued by an accredited Certification Body, not by Goldline.
Related reading: Def Stan 05-138, Defence Cyber Certification, and Cyber Essentials.
