Suppliers ask which one they need. It is the wrong question, because they are not alternatives and you do not choose between them. DEFCON 658 is the contract condition. Def Stan 05-138 is the control set that condition points at. You get both or neither, and which one you are looking at changes entirely what you are supposed to do next.
The reason this matters commercially is that the confusion has a predictable and expensive shape. A supplier reads DEFCON 658 in a tender, understands correctly that cyber security is now a contractual matter, and goes shopping for a certificate. Meanwhile the thing the contract obliges them to do sits undone, in an online service they have not registered for.
What each one is
DEFCON 658 is a Defence Condition, a standard contractual clause the Ministry of Defence inserts into contracts. MOD's Cyber Security Model guidance puts its role in one sentence: DEFCON 658 "lays out the contractual terms for the Cyber Security Model". It is the legal mechanism, not the technical content. GOV.UK publishes the clause as an ODT document under reference Edition 10/17 12/22, first published on 17 October 2017 and last updated on 13 December 2022, and lists its structure as seven sections covering definitions, authority obligations, contractor obligations, management of sub-contractors, records, audit and general terms, plus an annex addressed to sub-contractors.
Def Stan 05-138 is the Defence Standard. GOV.UK describes Issue 4 as the standard that "specifies the cyber controls that defence suppliers are required to achieve at each of the 4 cyber risk profile levels that a contract can be assessed at". It was published on 23 May 2024, was last updated on 3 December 2025, and runs to 37 pages. It is applicable, in MOD's words, to all MOD procurements, MOD suppliers and their subcontract suppliers which have a relationship to one or more MOD contracts.
The Cyber Security Model guidance states the obligation plainly: "Suppliers are contractually required to meet Def Stan 05-138 controls." DEFCON 658 is how that requirement reaches you and reaches everyone below you.
Set against each other
| DEFCON 658 | Def Stan 05-138 | |
|---|---|---|
| What it is | A contract condition | A defence standard |
| What it does | Binds you, and obliges you to bind your sub-contractors | Lists the controls to be met |
| Where it lives | Your contract and your sub-contracts | The MOD standards catalogue |
| Current version | Edition 10/17 12/22 | Issue 4, published 23 May 2024 |
| Who applies it | MOD commercial, and then you, downwards | You, against the profile level you were given |
| What it produces | Obligations, records and audit rights | A control set and a compliance position |
The part suppliers skip
DEFCON 658 does not ask you for a certificate. It puts you inside a process, and MOD publishes each step of it.
The Cyber Security Model version 4 process, as set out in the guidance, runs like this. The authority gives you a Risk Assessment Reference number and a required Cyber Risk Profile level, usually in the invitation to tender. You then complete a Supplier Assurance Questionnaire against that level in the Supplier Cyber Protection Service, which scores it automatically and tells you at once whether you are compliant. If you are not compliant, you complete a Cyber Improvement Plan, and MOD state that the plan "will form part of the contract document itself". The authority weighs your compliance, or your improvement plan, in supplier selection. After award you complete a new questionnaire on each anniversary of the contract award date, inside a one month window.
The questionnaires are not a formality. MOD published the blank question sets on 10 March 2026. The Level 0 questionnaire is 7 pages. The Level 1 questionnaire is 56 pages. Level 2 is 73 pages and Level 3 is 72. The flow down risk assessment is a further 11 pages. The step from Level 0 to Level 1 is where the work appears, and a supplier planning for it on the basis of the Level 0 experience will be surprised.
And the mechanism is compulsory. The question sets page states that suppliers of the Ministry of Defence, including as a subcontractor, "must use the Supplier Cyber Protection Service to complete a SAQ or Flow Down RA".
The claim worth reading twice
There is a widely held assumption that Defence Cyber Certification is how you satisfy this, and that a certificate takes the questionnaire off your desk. MOD's own guidance says otherwise, in terms:
Suppliers with a valid DCC certificate are not yet exempt from completing elements of the SAQ through the Supplier Cyber Protection Service (SCPS) ... Whilst it is hoped that DCC will be recognised within online tooling in due course, completion of the full SAQ to the required level remains mandatory as part of contractual risk assessment and procurement processes at this point in time.
That is the position on the MOD page as it stands. Read alongside the same page's description of DCC as a way of independently evidencing compliance with the Cyber Security Model, and alongside IASME's statement that DCC is currently not mandatory, it produces an uncomfortable conclusion for anyone selling certification, this practice included.
Certification is not the first purchase. The questionnaire is compulsory and the certificate currently is not, and holding the certificate does not, today, remove the questionnaire. A supplier who buys certification first has bought the optional artefact and left the contractual one outstanding.
The honest counter-argument, and it is a real one: MOD also state that suppliers "should expect to see increasing requirement to hold valid DCC certification for the duration of their contract with the MOD", specified as a condition under tender. Level 2 carries 139 controls against Level 1's 101, and control sets of that size are not built in a quarter. A supplier with a credible view of where its contracts are heading may reasonably start the certification work early and accept the duplication in the meantime. That is a defensible plan. What is not defensible is starting it by accident, in place of the questionnaire, because the tender mentioned cyber security and a certificate felt like the answer.
Flow down is your obligation, not your prime's
The second thing DEFCON 658 does is push the requirement downwards, and MOD are direct about where responsibility sits: "Suppliers are responsible for flow down. DEFCON 658 contains the contractual obligations that suppliers must place upon subcontractors."
The sequence has a constraint that catches people. Under CSMv4 you must first receive your own Cyber Risk Profile level and Risk Assessment Reference from your customer before you can start flowing down to anybody. MOD state that flow down activities under CSMv4 are not possible before that point, and that a supplier cannot complete new flow down activities under the older CSMv3 interim process. If you have not been given a profile level and a reference, the guidance advises requesting them.
So a supplier holding sub-contracts has two obligations, not one, and the second is invisible until you go looking for it.
Check which model your profile came from
One detail is worth a specific look, because it is the kind of thing that quietly invalidates a plan.
Cyber Security Model version 3, now legacy, focused on protection of electronic MOD Identifiable Information, used Def Stan 05-138 Issue 3, and had four Cyber Risk Profiles named Very Low, Low, Moderate and High. Version 4, which is live, moves the focus from MOD Identifiable Information to organisational security and resilience, uses Def Stan 05-138 Issue 4, and has four profiles named Level 0, Level 1, Level 2 and Level 3.
MOD state that existing and new procurements should now use CSMv4, and add a warning that deserves more attention than it gets: "CSM v3 Cyber Risk Profiles (N/A – High) are not consistent with CSMv4."
They are not the same scale under different names. A supplier carrying a Moderate profile from an older contract, or a consultant's report that maps controls to the named profiles, is working against a superseded issue of the standard. If your paperwork says Moderate, the useful next question is not what Moderate requires. It is who assigned it, under which version, and when.
What to do with this
Four things, in order, and none of them cost anything.
- Find the clause. If DEFCON 658 is in your contract or your tender, the Cyber Security Model applies to you and Def Stan 05-138 controls are a contractual requirement.
- Find your profile level and your Risk Assessment Reference. If you have not been given them, ask your delivery team or your buyer. You cannot complete the questionnaire without them and you cannot flow down without them.
- Complete the questionnaire in the Supplier Cyber Protection Service, at the level assigned. If you fall short, the Cyber Improvement Plan is the designed route, not a failure state, and it becomes part of the contract.
- Then, and only then, decide whether certification is worth buying, on the basis of where your contracts are going rather than on the basis of the tender that prompted the question.
If you are working out which scheme applies at all, Cyber Essentials and DCC relate in a way that surprises people, and the four DCC levels are set out separately. If you already know you are heading past Level 1, what Level 2 adds is the next thing to read.
Goldline prepares organisations for the Cyber Security Model and for DCC, including Level 0 readiness. Goldline is not a certification body and cannot certify DCC. Assessment is carried out by an assessor working for an IASME-licensed certification body.
Sources
- Ministry of Defence, Cyber Security Model guidance, GOV.UK, published 9 September 2024, last updated 6 March 2026, read 2 September 2026. Source for: DEFCON 658 laying out the contractual terms for the CSM; "Suppliers are contractually required to meet Def Stan 05-138 controls"; the seven-step CSMv4 process including the RAR, the SAQ, automatic scoring, the Cyber Improvement Plan forming part of the contract document, and the annual questionnaire with its one month window; "Suppliers are responsible for flow down. DEFCON 658 contains the contractual obligations that suppliers must place upon subcontractors"; the requirement to hold a CSMv4 profile and RAR before flowing down; the CSMv3 and CSMv4 comparison including profile names, standard issues and the statement that "CSM v3 Cyber Risk Profiles (N/A – High) are not consistent with CSMv4"; the DCC and SAQ exemption position quoted above; and "Suppliers should expect to see increasing requirement to hold valid DCC certification for the duration of their contract with the MOD, this will be specified as a condition under tender following launch of the CSM."
- Ministry of Defence, Cyber Security Model Question Sets, GOV.UK, published 10 March 2026, read 2 September 2026. Source for: the page counts of the blank Level 0 to Level 3 Supplier Assurance Questionnaires and the Flow Down Risk Assessment, and for suppliers, including subcontractors, being required to use the Supplier Cyber Protection Service to complete them.
- Ministry of Defence, Defence condition 658: cyber (flow-down), GOV.UK, published 17 October 2017, last updated 13 December 2022, read 2 September 2026. Source for: the edition reference 10/17 12/22 and the published section structure of the clause and its annex.
- Ministry of Defence, Cyber security for defence suppliers (Def Stan 05-138, Issue 4), GOV.UK, published 23 May 2024, last updated 3 December 2025, read 2 September 2026. Source for: the standard specifying controls at each of the four cyber risk profile levels, its applicability to MOD procurements, suppliers and their subcontract suppliers, and its length of 37 pages.
- IASME, Defence Cyber Certification scheme page, read 2 September 2026. Source for: IASME as the MOD's official cyber certification partner, the four levels, and the control counts of 3, 101, 139 and 144. The statement that DCC is currently not mandatory is IASME's, from the scheme's published Frequently Asked Questions.
Not read, and therefore not claimed. The text of DEFCON 658 itself has not been quoted here. GOV.UK publishes the clause as a downloadable document and this article relies only on the section structure GOV.UK sets out on the publication page and on MOD's own description of the clause's role. Nothing above should be read as a quotation from, or an interpretation of, the clause wording. The same applies to Def Stan 05-138 Issue 4: the controls themselves are in the standard, and the statements here come from MOD's published description of it rather than from the control text. Where your contract is concerned, the clause in your contract governs, not this page.
