UK defence supply chain SMEs reading prime contract bid documents in 2026 increasingly encounter the same reference. Defence Standard 05-138 is named in the cyber annex, a risk profile from Very Low to Very High is assigned to the sub-contract, and the supplier is required to evidence cyber controls proportionate to the profile. The framework is not new. DEFSTAN 05-138 has been the operational reference for cyber risk profiling in the UK defence supply chain since the Cyber Security Model came into operational use, and it sits at the centre of how MOD primes flow cyber risk obligations to tier-2 and tier-3 suppliers.
What is new is the depth at which primes are now applying the framework. A profile assigned at Moderate or above now triggers evidence expectations that go materially beyond Cyber Essentials Plus. A profile assigned at Low or below carries a different set of evidence expectations that some suppliers over-comply against, wasting time on controls the contract does not require. Reading the profile correctly is the front-gate decision for the entire cyber compliance work that follows.
This is a practitioner read on what DEFSTAN 05-138 actually requires, the five risk profiles and what determines which applies, how the prime assigns the profile, the evidence at each profile level, the relationship to DCC (Defence Cyber Certification) Levels 0 to 4, the relationship to Cyber Essentials Plus and ISO 27001, and practical examples by sector for UK defence supply chain SMEs.
What DEFSTAN 05-138 is
DEFSTAN 05-138 is the Defence Standard that specifies the MOD framework for cyber risk profiling and control expectations across the defence supply chain. The standard is published by MOD Defence Standardization and held on the gov.uk DEFSTAN catalogue. Issue 4 is the current Issue as of mid-2024 on the catalogue, with Issue 5 in advanced consultation as of the date of publication of this guide.
DEFSTAN 05-138 functions as the technical reference behind DEFCON 658. Where DEFCON 658 is the contractual clause that obliges the supplier to perform cyber risk assessment and implement controls, DEFSTAN 05-138 specifies the methodology, the risk profile structure, and the evidence expectations the supplier must satisfy. The two work together. DEFCON 658 is the mechanism. DEFSTAN 05-138 is the method.
The standard is structured around five cyber risk profiles, with each profile carrying a defined set of control and evidence expectations. The profile assigned to a specific sub-contract is determined by the prime, derived from the prime's own DEFCON 658 obligations and the prime's assessment of the cyber risk associated with the sub-contract scope.
For UK defence supply chain SMEs, the practical implication is that DEFSTAN 05-138 is the technical reference the supplier needs to satisfy through documentation, not merely a reference the prime applies internally.
The five risk profiles and what determines which applies
DEFSTAN 05-138 Issue 4 defines five cyber risk profiles, from Very Low to Very High. The profile assigned to a contract is determined by an assessment of the cyber risk associated with the contract scope, which depends on three principal factors.
The classification and sensitivity of information handled. Contracts handling OFFICIAL information at the lowest end progress through OFFICIAL-SENSITIVE to SECRET and above. The classification level is one of the strongest determinants of profile assignment.
The operational impact of cyber compromise. Contracts where cyber compromise could materially affect MOD operations, capability, or supply chain integrity carry higher profile assignment than contracts where compromise would have limited operational consequence.
The supply chain exposure introduced by the contract. Contracts that introduce significant supply chain exposure, particularly where the supplier's own sub-processors handle MOD-relevant information or systems, carry higher profile assignment than contracts contained within the supplier's own operations.
The profile assignment is the prime's responsibility, derived from the prime contract's own DEFSTAN 05-138 obligations and the prime's assessment of the sub-contract risk. The sub-contractor does not self-assess the profile. The sub-contractor implements against the profile assigned.
Very Low
The cyber risk associated with the contract is minimal. The contract typically handles OFFICIAL information at the lowest classification, does not involve operationally significant systems or services, and the supplier's own information systems are not materially exposed to contract-specific cyber risk. Evidence expectations are minimal. Cyber Essentials (basic) is typically sufficient to demonstrate the baseline expected at Very Low. The supplier is expected to maintain a baseline cyber posture but is not required to evidence the depth of cyber controls expected at higher profiles.
Low
The cyber risk is limited but not negligible. The contract may involve sensitive but unclassified information handling, may touch operationally relevant supply chain risk, or may involve information system exposure that requires baseline cyber controls beyond CE basic. Cyber Essentials Plus is typically the floor expectation, supplemented by documented information security policies, incident response capability, and evidence of supplier cyber risk awareness. The supplier should be able to evidence a documented information security position even if it falls short of full ISO 27001 management system maturity.
Moderate
The cyber risk is material. The contract involves OFFICIAL or OFFICIAL-SENSITIVE information handling, supplies operationally relevant equipment or services, or has supply chain exposure that requires controls beyond the Cyber Essentials Plus baseline. Evidence expectations include a documented information security management system (ISO 27001 or equivalent), a risk register reviewed on a defined cadence, demonstrable supplier cyber risk management, and evidence of internal audit. ISO 27001 certification is typically the most credible evidence pathway at Moderate, though documented equivalent management systems can satisfy the requirement.
High
The cyber risk is significant. The contract involves higher-classification information handling (subject to security aspects letters), supplies systems or services with operational impact on MOD capability, or has supply chain exposure where cyber compromise could materially affect MOD operations. Evidence expectations include a mature information security management system (typically ISO 27001 certified with surveillance cycle established), an active internal audit programme, board-level reporting on cyber risk, additional technical controls (network segregation, enhanced monitoring, access control aligned to clearance status), and personnel security measures appropriate to the information sensitivity. SC Clearance for personnel with contract-relevant access becomes a recurring requirement at High.
Very High
The cyber risk is the highest the framework recognises. The contract involves SECRET or above information handling, supplies systems with critical national infrastructure or operational impact, or has supply chain exposure where compromise has direct national security implications. Evidence expectations are extensive and typically include specific MOD-approved control implementations beyond ISO 27001, classified network handling, personnel clearance management at DV (Developed Vetting) level for some roles, continuous monitoring obligations, and integration with MOD-specific incident reporting frameworks. Very High profile contracts are typically held by tier-1 primes and only flow to specialised tier-2 sub-contractors with mature classified handling capability.
How the prime contractor assigns the profile
The profile assignment process varies between primes in terms of internal language and tooling, but the substantive process is consistent across BAE Systems, Babcock, Leonardo, Rolls-Royce Defence, Lockheed Martin UK, Northrop Grumman UK, Thales UK, and Airbus Defence and Space.
The prime receives the MOD contract with the DEFCON 658 clause and the MOD's own DEFSTAN 05-138 profile assignment for the prime contract. The prime then decomposes the contract scope into sub-contractable workstreams, assesses the cyber risk associated with each workstream, and assigns a DEFSTAN 05-138 profile to each sub-contract. The profile assigned to a sub-contract may differ from the profile assigned to the prime contract, with sub-contracts typically assigned at the same level or one level below the prime profile depending on the scope.
The profile is communicated to the supplier in the bid documentation, typically in the cyber annex or the supplier security requirements section of the tender. Where the profile is not explicit in the bid documentation, the supplier should request clarification before submitting cyber evidence, because the wrong assumed profile leads to over-compliance (wasted effort at higher profile evidence) or under-compliance (rejected evidence at lower profile preparation).
The profile is not negotiable in normal circumstances. Suppliers cannot self-assess at a lower profile than the prime has assigned. Where the supplier believes the profile assignment is misaligned with the actual contract risk (typically because the prime has assigned conservatively), the supplier can request a profile review with the prime's contract compliance team. Profile reviews are uncommon and the prime typically defends its assignment.
Evidence requirements at each profile level
The evidence expectations at each profile level can be summarised structurally, though specific evidence requirements vary by prime and by contract context.
At Very Low: Cyber Essentials basic certification (or equivalent baseline evidence). Documented acceptable use policy. Documented incident reporting process even if not formally tested. Basic supplier risk awareness.
At Low: Cyber Essentials Plus certification. Documented information security policies covering access control, incident response, asset management, and supplier risk. Evidence of policy approval and communication. Incident response capability with a tested procedure within the last twelve months.
At Moderate: Cyber Essentials Plus current. ISO 27001 certification or equivalent management system evidence with documented scope, Statement of Applicability, and risk register. Internal audit programme operating with documented findings and corrective action tracking. Management review cadence with documented outputs. Supplier cyber risk management documented and operating across the principal sub-processor estate.
At High: All Moderate evidence plus additional controls. ISO 27001 surveillance cycle established and operating. Enhanced technical controls including network segregation and monitoring appropriate to contract context. Personnel security with SC Clearance for relevant roles. Board-level cyber risk reporting documented. Security aspects letter compliance where applicable.
At Very High: All High evidence plus MOD-specific control implementations. Classified network handling capability. DV Clearance for relevant roles. Continuous monitoring with MOD-aligned incident reporting. Integration with MOD-specific cyber frameworks beyond commercial standards. Personnel security and physical security to MOD standards.
The evidence pack assembled for each profile is reviewed by the prime's contract compliance team and accepted, rejected, or returned for additional evidence. Suppliers are expected to maintain evidence currency throughout the contract life, with periodic review at defined intervals.
The relationship to DCC (Defence Cyber Certification) Levels 0 to 4
DCC (Defence Cyber Certification) is the MOD scheme that provides a graded certification pathway for defence supply chain cyber controls. The scheme is in advanced rollout as of mid-2026 and operates in parallel to DEFSTAN 05-138.
DCC defines five certification levels from Level 0 to Level 4, with the levels corresponding broadly to the DEFSTAN 05-138 profiles though the mapping is not formally one-to-one.
DCC Level 0 corresponds broadly to Very Low profile expectations. Basic cyber hygiene evidenced through CE basic or equivalent.
DCC Level 1 corresponds broadly to Low profile expectations. CE Plus and documented information security position.
DCC Level 2 corresponds broadly to Moderate profile expectations. ISO 27001 or equivalent management system.
DCC Level 3 corresponds broadly to High profile expectations. Mature ISMS plus enhanced controls.
DCC Level 4 corresponds broadly to Very High profile expectations. MOD-aligned classified handling and continuous monitoring.
DCC certification is a graded credential that suppliers can hold independently of any specific contract. The relationship to DEFSTAN 05-138 is operational: a supplier holding DCC Level 2 has typically already evidenced the controls a Moderate profile contract requires, which materially shortens the prime-side validation effort when the contract is awarded.
For UK defence supply chain SMEs in the 25 to 200 FTE band, DCC certification at Level 1 or Level 2 is becoming a credible standing credential that supports bid eligibility across multiple primes without rebuilding the evidence for each contract.
The relationship to Cyber Essentials Plus and ISO 27001
DEFSTAN 05-138 is the framework. CE Plus and ISO 27001 are evidence frameworks that contribute to satisfying the standard at different profile levels.
Cyber Essentials Plus is the technical control baseline. It evidences specific technical controls (boundary firewalls, secure configuration, access control, malware protection, security update management) at a one-day audited assessment. CE Plus is the floor expectation at Low profile and a recurring component of the evidence pack at Moderate and above.
ISO 27001 is the information security management system standard. It evidences the supplier has a documented, operating, and audited management system covering information security across the organisation. ISO 27001 is typically the principal evidence at Moderate profile and above, with the certificate, scope statement, Statement of Applicability, risk register, and internal audit programme all contributing to DEFSTAN 05-138 evidence.
For UK defence supply chain SMEs, the practical position is that CE Plus alone satisfies DEFSTAN 05-138 at Very Low and Low, while Moderate and above require ISO 27001 or equivalent management system evidence alongside CE Plus.
Practical examples by sector
The DEFSTAN 05-138 framework operates differently in practice depending on the sector and the typical contract profile a sector encounters.
Aerospace tier-2 example
A 35 FTE aerospace tier-2 supplier providing precision-machined components to BAE Hawk-class and Babcock submarine support programmes typically encounters DEFSTAN 05-138 Low and Moderate profile contracts. Drawings and technical specifications are handled at OFFICIAL or OFFICIAL-SENSITIVE classification. The supplier's information systems are not exposed to operational MOD systems but handle contract-relevant intellectual property and supply chain information.
Evidence pathway: Cyber Essentials Plus held continuously. ISO 27001 certified with scope covering aerospace contract delivery and supply chain management. Risk register reviewed quarterly. Internal audit programme operating. JOSCAR Stage 2 cyber module validated. The evidence pack satisfies Low and Moderate profile bids without contract-specific rework.
Defence software vendor example
A 75 FTE defence software vendor providing logistics, training, or simulation software to MOD or MOD primes typically encounters Moderate and High profile contracts. The software may handle OFFICIAL-SENSITIVE or higher classified information, may integrate with MOD systems, and may have operational impact if compromised.
Evidence pathway: Cyber Essentials Plus current. ISO 27001 certified with comprehensive scope. ISO 27017 and ISO 27018 supplementary where cloud delivery is in scope. Personnel security with SC Clearance for development and operations staff with contract-relevant access. Enhanced technical controls including network segregation between MOD-relevant and commercial-relevant systems. Board-level cyber risk reporting. Security aspects letter compliance.
Defence engineering SME example
A 120 FTE defence engineering SME providing specialised engineering services across multiple primes typically encounters mixed profile contracts, with some Low and some Moderate and occasionally High. The evidence challenge is maintaining a unified management system that satisfies the most demanding profile encountered while not over-investing for the lowest profile contracts.
Evidence pathway: Cyber Essentials Plus current. ISO 27001 certified with scope covering engineering services across all customer sectors. Risk register segmented by contract risk profile. Personnel security with SC Clearance for staff working on Moderate and High profile contracts. Internal audit programme operating across the unified management system. DCC Level 2 certification held as a standing credential.
A reasonable working position
UK defence supply chain SMEs facing DEFSTAN 05-138 references in their prime contract bids in 2026 have three operational priorities. Read the profile assignment carefully, build the evidence pathway proportionate to the highest profile encountered, and maintain evidence currency throughout the contract life.
For 25 to 200 FTE suppliers bidding into BAE Systems, Babcock, Leonardo, Rolls-Royce Defence, Lockheed Martin UK, Northrop Grumman UK, and Thales UK supply chains, the unified evidence approach typically lands cleanest. Cyber Essentials Plus held continuously. ISO 27001 certified with scope sufficient to cover the most demanding contract profile encountered. DCC certification as a standing credential. JOSCAR Stage 2 cyber module validated. The combined evidence pack satisfies the substantial majority of DEFSTAN 05-138 evidence expectations at Low and Moderate profiles, with additional controls layered for High profile contracts as they arise.
Book a 30-minute strategy call to scope your DEFSTAN 05-138 readiness.
Frequently asked questions
Who decides which DEFSTAN 05-138 profile applies to our contract? The prime contractor assigns the profile to each sub-contract, derived from the prime's own DEFCON 658 obligations and the prime's assessment of the sub-contract cyber risk. The profile is communicated to the supplier in the bid documentation. Suppliers do not self-assess the profile.
Can I challenge the profile assignment? Profile reviews are possible but uncommon. Where a supplier believes the profile is misaligned with the actual contract risk, the supplier can request a review with the prime's contract compliance team. The prime typically defends its assignment unless the supplier can demonstrate the contract scope has been misunderstood. Profile downgrades are rare.
Does Very Low mean almost no cyber work? No. Very Low means proportionate cyber work. Cyber Essentials basic certification, documented acceptable use policy, and incident reporting process are still expected. Very Low is the floor, not the absence of expectations.
What is the cost difference between Very Low and Very High? Material. Very Low can typically be evidenced with Cyber Essentials basic at a few hundred pounds annually. Very High requires mature ISMS, personnel security at DV level, MOD-aligned classified handling, and continuous monitoring, which typically costs tens of thousands of pounds annually to operate and maintain. The gap is one to two orders of magnitude.
How does DCC certification map to DEFSTAN 05-138 profiles? DCC Levels 0 to 4 correspond broadly to DEFSTAN 05-138 profiles Very Low to Very High, though the mapping is not formally one-to-one. DCC certification at Level 2 typically evidences the controls expected at Moderate profile. Suppliers holding DCC certification have typically already satisfied the substantial majority of DEFSTAN 05-138 evidence expectations for contracts at the corresponding profile.
