Skip to main content
DEFCON 658

DEFCON 658 Explained for UK Tier-2 and Tier-3 Defence Suppliers

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

11 min read

Contents

    UK defence suppliers reading their contracts in 2026 increasingly encounter the same clause. DEFCON 658 appears in the tender documentation, in the prime contract terms, and in the supply chain flow-down clauses to tier-2 and tier-3 sub-contractors. The clause is not new. It has been a standard MOD contractual mechanism since the Cyber Security Model came into operational use, and it sits at the centre of how MOD measures and enforces cyber risk in its supply chain.

    What is new is the depth of evidence primes are now asking sub-contractors to produce against the clause. The pass-through assumption that a prime would interpret DEFCON 658 on behalf of the sub-contract has narrowed. Sub-contractors are being asked to produce their own risk assessment documentation, their own evidence of control implementation, and their own ability to defend the cyber risk treatment if the prime's assessment is challenged by the MOD authority.

    This is a practitioner read on what DEFCON 658 actually requires, the risk profile levels under DEFSTAN 05-138 that the clause references, the documentation that defence supply chain SMEs need to produce, and the most common mistakes in tier-2 and tier-3 implementations.

    What DEFCON 658 is and why it exists

    DEFCON 658 (Cyber Risk) is a standard MOD contractual condition imposed on prime contractors and flowed down through the supply chain to relevant sub-contracts. It is one of a wider set of Defence Conditions (DEFCONs) that the MOD uses to standardise contract terms across procurement. The cyber-specific version of the clause was introduced as the operational mechanism for the Cyber Security Model (CSM), which is the MOD framework for assessing and managing cyber risk across the defence supply chain.

    The clause requires the contractor to perform a cyber risk assessment, identify a cyber risk profile based on the contract's exposure, implement controls appropriate to the profile, and produce evidence of the assessment and the controls in place. The clause flows down through the supply chain: if a prime is bound by DEFCON 658, every sub-contract that touches the same supply chain risk is also bound.

    The purpose of the clause is operational. The MOD cannot directly assess every supplier in its supply chain. It delegates the cyber risk management to the prime, requires the prime to flow down the obligation, and audits the prime on the strength of the supply chain risk treatment it has in place. DEFCON 658 is the contractual lever that gives the prime the authority to require evidence from sub-contractors, and gives the MOD the audit trail back through the supply chain to the original assessment.

    For tier-2 and tier-3 UK defence suppliers, the practical implication is that DEFCON 658 is not a clause the prime handles on the sub-contractor's behalf. It is a clause the sub-contractor produces evidence against, and the prime aggregates that evidence into the prime's own contract compliance.

    Who DEFCON 658 applies to

    DEFCON 658 applies to MOD contracts where cyber risk is identified as a contract-relevant exposure. In practice, the clause is now included in the substantial majority of MOD procurements that touch operational information systems, classified or sensitive information handling, or supply of products or services where cyber compromise could affect MOD operations. The full text of the DEFCON catalogue is held by MOD Defence Commercial and published in summary form on gov.uk.

    The flow-down is where most tier-2 and tier-3 suppliers first encounter the clause. A prime contractor bound by DEFCON 658 will include equivalent terms in its sub-contract with a tier-2 supplier. The tier-2 supplier, if it then sub-contracts work that touches the same risk, will flow the obligation to a tier-3. The chain extends as deep as the supply chain extends.

    This produces a recognisable pattern in the SME defence supply chain. A 35 FTE tier-2 aerospace supplier reading a new bid document from BAE, Babcock, Leonardo, Rolls-Royce Defence, Lockheed Martin UK, Northrop Grumman UK, or Thales UK will find DEFCON 658 referenced in the cyber annex. The supplier is then required to produce a risk assessment against the profile the prime has assigned to the sub-contract, evidence the controls implemented in response to the profile, and produce that evidence at contract award and at periodic review during the contract life.

    Tier-3 suppliers, who are typically sub-contracted to tier-2s rather than directly to primes, encounter the clause at the same operational depth as tier-2s. The reduced visibility to the MOD does not reduce the contractual obligation. A tier-3 reading a sub-contract from a tier-2 will find DEFCON 658 flowed down with the same documentation expectations.

    The Cyber Security Model and DEFCON 658

    The Cyber Security Model (CSM) is the MOD framework that operationalises cyber risk management across the defence supply chain. DEFCON 658 is the contractual clause; the CSM is the methodology DEFCON 658 implements.

    The CSM uses Defence Standard 05-138 (DEFSTAN 05-138) as the technical reference for cyber risk profiling. DEFSTAN 05-138 Issue 4 specifies the cyber controls suppliers are required to achieve at each of the four cyber risk profile levels a contract can be assessed at. DEFCON 658 contractually binds the supplier to assess against, implement against, and evidence against the profile assigned to the contract.

    The relationship between DEFCON 658 and the CSM matters because the documentation a supplier produces is judged against the CSM evidence expectations, not against a generic cyber framework. A DEFCON 658 risk assessment that produces output in a generic ISO 27001 or NIST CSF format, without the specific DEFSTAN 05-138 profile mapping, is unlikely to satisfy the prime's contract compliance team.

    The risk profile levels, and which version of the model assigned yours

    Corrected 2 September 2026. An earlier version of this article described five named risk profiles running from Very Low to Very High. That was wrong, and the correction matters because it changes what a supplier prepares against.

    The Cyber Security Model has been through a version change and the two versions do not share a scale.

    Cyber Security Model version 3, now legacy, focused on the protection of electronic MOD Identifiable Information. It used Defence Standard 05-138 Issue 3 and had four Cyber Risk Profiles: Very Low, Low, Moderate and High.

    Cyber Security Model version 4, which is live, moves the focus from MOD Identifiable Information to organisational security and resilience. It uses Defence Standard 05-138 Issue 4 and has four Cyber Risk Profiles: Level 0, Level 1, Level 2 and Level 3. GOV.UK describes Issue 4 as specifying the cyber controls defence suppliers are required to achieve at each of the four cyber risk profile levels a contract can be assessed at.

    There is no Very High profile in either version.

    MOD state that existing and new procurements should now use CSMv4, and warn directly that "CSM v3 Cyber Risk Profiles (N/A – High) are not consistent with CSMv4." The named profiles are not the numbered levels under different labels, and a control mapping built against Moderate is not a control mapping against Level 2.

    The practical consequence for a tier-2 or tier-3 supplier is a question to ask before any preparation work starts: which version of the model produced the profile in front of me, and when. Under CSMv4 the authority issues a Risk Assessment Reference and a required Cyber Risk Profile level, usually in the invitation to tender, and the supplier self-assesses against it in the Supplier Cyber Protection Service. If you hold a named profile from an older contract and no Risk Assessment Reference, you do not yet have what CSMv4 needs, and the guidance advises requesting both from your delivery team or buyer.

    The relationship between the levels and the certification scheme is set out separately in DEFCON 658 versus Def Stan 05-138.

    What a DEFCON 658 risk assessment actually involves

    A DEFCON 658 risk assessment is not a generic cyber risk assessment with DEFCON 658 in the title. It has specific structural requirements aligned to the CSM methodology and the DEFSTAN 05-138 profile.

    The assessment documents the contract scope and the specific cyber risk exposure the contract introduces. This is not a description of the supplier's general cyber posture. It is an assessment of the specific risk associated with the specific contract.

    The assessment maps to the DEFSTAN 05-138 profile assigned by the prime. The mapping makes explicit how the supplier's cyber controls satisfy the evidence expectations of the profile. An assessment that does not specifically address each of the DEFSTAN 05-138 control expectations for the assigned level is incomplete.

    The assessment identifies the threat actors, attack surfaces, and asset classifications relevant to the contract. Threat actor identification is calibrated to the contract context. For a defence supply chain contract, the relevant threat actors include nation-state cyber actors, organised criminal actors targeting defence supply chain for intellectual property exfiltration, and insider threat.

    The assessment documents the controls in place that address the identified risks. Each control is mapped to the risk it mitigates and the evidence that demonstrates the control is operating. A control statement without supporting evidence is incomplete.

    The assessment identifies residual risk after controls are applied, and records the supplier's acceptance of the residual risk through a named risk owner at appropriate seniority. Risk owners for DEFCON 658 assessments are typically at director level in tier-2 SME suppliers.

    The assessment is reviewed at defined intervals during the contract life, and re-performed when contract scope, threat landscape, or control posture changes materially.

    The output is a working document that the prime's contract compliance team can review against its own DEFCON 658 obligations and that the MOD can audit through the prime if required.

    The five most common mistakes UK SMEs make in DEFCON 658 documentation

    From engagement experience across UK defence supply chain SMEs in the 25 to 200 FTE band, five mistakes appear consistently in DEFCON 658 documentation that primes return for rework.

    1. Generic cyber risk assessments labelled as DEFCON 658 assessments. The most common pattern. A supplier produces a generic risk assessment (often output from a GRC platform or a consultancy template) and labels it as the DEFCON 658 assessment. The assessment does not reference the contract specifically, does not map to the assigned cyber risk profile level, and does not document the supply-chain-specific risk. Primes increasingly reject these on first review.

    2. Self-assessed profiles that do not match the prime's assignment. Some suppliers attempt to self-assess the cyber risk profile level, typically at a lower level than the prime has actually assigned. The misalignment is caught at first review. The supplier then has to redo the assessment against the correct profile, which is materially more demanding than the level the supplier originally chose.

    3. Control statements without supporting evidence. "Multi-factor authentication is enforced." Statement made, no evidence attached. The prime's contract compliance team needs to see the configuration screenshot, the audit log, or the policy document referenced. A control statement is not evidence in itself.

    4. Missing residual risk acceptance. The risk assessment identifies risks, maps controls, and stops. The residual risk that remains after controls are applied is not documented, and there is no named acceptance of the residual risk by an appropriately senior risk owner. DEFSTAN 05-138 expects residual risk to be acknowledged and accepted at named seniority.

    5. No review cadence documented. The assessment is treated as a one-off document produced at contract award. There is no documented cadence for review, no trigger for re-assessment when contract scope changes, and no evidence that the assessment has been kept current. DEFCON 658 is a continuing obligation through the contract life. A static assessment fails this requirement.

    These five mistakes account for the majority of DEFCON 658 documentation rework in the UK defence supply chain. Closing them is methodology, not technology. The technical controls are usually adequate. The documentation that evidences the technical controls is where the gap sits.

    How DEFCON 658 interacts with Cyber Essentials Plus and ISO 27001

    DEFCON 658 is the contractual clause. Cyber Essentials Plus and ISO 27001 are evidence frameworks that contribute to satisfying the clause. The relationship between the three depends on the DEFSTAN 05-138 profile.

    For Level 0 and Level 1 contracts, Cyber Essentials Plus is typically sufficient cyber control evidence for the DEFCON 658 documentation. The supplier produces the risk assessment, references the CE Plus certificate as the principal control evidence, and adds incident response and policy documentation as supporting evidence.

    For Level 2 contracts and above, Cyber Essentials Plus is the floor and ISO 27001 is typically the expected reference framework for the information security management system evidence. ISO 27001 controls map across the substantial majority of DEFSTAN 05-138 evidence expectations at Level 2, with some additional defence-specific controls layered on top. The ISO 27001 certificate, scope statement, Statement of Applicability, and risk register all become DEFCON 658 evidence inputs.

    For Level 3 contracts, ISO 27001 is the baseline expectation and additional MOD-approved or defence-specific controls layer above it. JOSCAR Stage 2 with the cyber security module validated, DCC certification where applicable, and specific security aspects implementation become part of the evidence pack.

    The integrated answer for UK defence supply chain SMEs is to build the information security management system to ISO 27001 standard, certify with a UKAS-accredited certification body, and then map the ISO 27001 evidence into DEFCON 658 documentation rather than producing two parallel evidence sets.

    A reasonable working position

    UK defence supply chain SMEs facing DEFCON 658 in their prime contracts in 2026 have three operational priorities. Establish the cyber risk management capability to ISO 27001 standard, hold Cyber Essentials Plus as the technical control baseline, and produce DEFCON 658 documentation that maps to the DEFSTAN 05-138 profile the prime has assigned.

    For 25 to 200 FTE suppliers building this capability for the first time, the work is structured but demanding. It requires senior practitioner input on the methodology, hands-on implementation of the technical controls, and discipline in producing documentation that satisfies prime contract compliance teams rather than generic cyber frameworks.

    Book a 30-minute strategy call to scope your DEFCON 658 readiness.

    Frequently asked questions

    Is DEFCON 658 mandatory for all MOD suppliers? DEFCON 658 applies where the MOD has identified cyber risk as relevant to the contract. It is not universal across every MOD procurement, but it is now included in the substantial majority of contracts that touch operational information, sensitive information handling, or supply chain risk. Flow-down to tier-2 and tier-3 sub-contractors is determined by the prime contract terms.

    What is the difference between DEFCON 658 and Cyber Essentials Plus? DEFCON 658 is a contractual clause that requires the supplier to perform a cyber risk assessment and implement controls appropriate to the assigned DEFSTAN 05-138 profile. Cyber Essentials Plus is a UK government-backed certification that evidences specific technical controls. CE Plus is typically a component of the evidence pack for DEFCON 658, particularly at the lower profile levels, but does not in itself satisfy DEFCON 658 because the clause requires a risk assessment and broader documentation beyond CE Plus.

    Do I need DEFCON 658 if I am only a tier-3 supplier? If the tier-3 sub-contract flows down DEFCON 658 obligations from the tier-2 above, then yes, the tier-3 supplier is contractually bound. Flow-down depth depends on the prime contract terms and the nature of the work sub-contracted. Tier-3 suppliers should read sub-contract terms carefully and clarify obligations with the tier-2 if DEFCON 658 is referenced.

    How is DEFCON 658 enforced? DEFCON 658 is enforced through the contract chain. The MOD audits the prime against its DEFCON 658 obligations. The prime audits its sub-contractors against the flowed-down obligations. Non-compliance can result in contract termination, exclusion from future bids, or remediation requirements imposed by the prime. The MOD does not directly audit tier-2 and tier-3 suppliers in most cases, but the prime's audit findings carry the same commercial consequence.

    What happens if our DEFCON 658 risk assessment is rejected by the prime? The prime will identify the gaps and require resubmission. Common rejection reasons include profile misalignment, missing evidence, generic assessments that do not reference the specific contract, and missing residual risk acceptance. Rework typically takes between two and six weeks depending on the depth of the gaps. Repeated rejection can affect the bid timeline and, in some cases, the bid eligibility.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    Defence

    9 min read

    Defence Cyber Certification: the four levels, and what each one actually asks

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The four levels, the control counts, and the three things that catch suppliers out.

    • Defence
    • DCC
    • DEFCON 658
    • DEFSTAN 05-138
    Defence Supply Chain

    6 min read

    Tier 2 UK Aerospace Supplier Achieves Cyber Essentials Plus and JOSCAR Submission in Fourteen Weeks

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Composite case study. A 35 FTE tier-2 UK aerospace supplier closes the JOSCAR gap and lands CE Plus in fourteen weeks. Defence Cyber Foundation engagement.

    • Defence
    • JOSCAR
    • Cyber Essentials Plus
    • Case Study
    Defence Supply Chain

    11 min read

    JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    JOSCAR Stage 2 explained for UK tier-2 defence SMEs. The cyber security module, the evidence gaps, and the seven-question readiness checklist.

    • JOSCAR
    • Defence
    • ISO 27001
    • Cyber Essentials Plus
    Defence Supply Chain

    12 min read

    DEFSTAN 05-138 Risk Profiling Explained: Very Low to Very High and What Each Means in Evidence

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    DEFSTAN 05-138 risk profiling explained. The five profiles from Very Low to Very High, evidence at each level, and the DCC relationship for UK defence SMEs.

    • DEFSTAN 05-138
    • Defence
    • DCC
    • ISO 27001

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.