Skip to main content
JOSCAR

JOSCAR Stage 2: What UK Tier-2 Defence SMEs Miss

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

11 min read

Contents

    UK tier-2 defence suppliers reading their prime contract bid documents in 2026 increasingly encounter the same requirement. Hellios JOSCAR Stage 2 registration must be held, the cyber security module must be validated, and the evidence must be current at contract award. The expectation has hardened over the past three years. Where Stage 1 registration was previously sufficient for many tier-2 bid invitations, Stage 2 has become the practical threshold for credible participation in BAE Systems, Babcock, Leonardo, Rolls-Royce Defence, Lockheed Martin UK, Northrop Grumman UK, and Thales UK supply chains.

    The challenge for UK defence SMEs is not the existence of JOSCAR Stage 2 as a requirement. The challenge is that the cyber security module specifically trips up suppliers more often than any other module in the Stage 2 questionnaire, the rework cycles are long, and the gap between the evidence suppliers think they have and the evidence Stage 2 expects is wider than the bid documentation suggests.

    This is a practitioner read on what JOSCAR is, the difference between Stage 1 and Stage 2, the modules inside Stage 2, why the cyber section trips up SMEs most often, the recurring evidence gaps, and a seven-question readiness checklist for tier-2 defence SMEs preparing for Stage 2 submission. For the wider MOD contract context, see our explainer on DEFCON 658 and on DEFSTAN 05-138 risk profiling.

    What JOSCAR is and who runs it

    JOSCAR is the Joint Supply Chain Accreditation Register, operated by Hellios Information Limited. The register is used by aerospace, defence, and security prime contractors as a single supplier accreditation source. Member primes share JOSCAR data, which means that supplier evidence submitted to JOSCAR is available across the prime customer base rather than rebuilt for each prime.

    The principal member primes include BAE Systems, Babcock International, Leonardo, Rolls-Royce, Lockheed Martin UK, Northrop Grumman UK, Thales UK, Airbus Defence and Space, and others operating in the UK defence supply chain. For suppliers in the tier-2 and tier-3 band, JOSCAR registration is increasingly the entry credential for credible bid participation across multiple primes simultaneously.

    Hellios operates JOSCAR on a member-funded model. Member primes pay for access to the supplier register. Suppliers register and provide evidence. The cost structure for suppliers is split between a free Stage 1 registration and a paid Stage 2 validation, which provides the depth of evidence the primes use for sub-contract awards beyond initial bid invitations.

    For UK defence supply chain SMEs, the practical reality is that JOSCAR registration is becoming a prerequisite for prime contract invitation, and Stage 2 specifically is becoming the threshold for bid eligibility on contracts above the smallest sub-contract values.

    Stage 1 versus Stage 2

    JOSCAR has two registration tiers. The difference between them is operationally and commercially material.

    Stage 1 registration is free. The supplier registers basic company information: legal entity, registered office, key personnel, primary services, customer references. Stage 1 makes the supplier searchable in the JOSCAR directory, which means a prime looking for suppliers in a specific service category can find the supplier through the search. Stage 1 does not validate any of the information beyond basic company verification, and does not establish supplier compliance against any of the deeper accreditation modules.

    Stage 2 registration is paid. The supplier pays an annual fee to Hellios and completes the Stage 2 questionnaire across multiple compliance modules. Stage 2 evidence is validated by Hellios against documentation the supplier provides. Once accepted, Stage 2 status appears on the supplier's JOSCAR profile and is visible to member primes assessing the supplier for bid invitation or sub-contract award.

    The commercial gap between Stage 1 and Stage 2 is substantial. Suppliers at Stage 1 are findable in the directory but are not pre-validated against the compliance criteria primes use to filter their supplier shortlists. Suppliers at Stage 2 are pre-validated against modules covering cyber security, financial, ESG, modern slavery, quality, and health and safety, which means the prime's procurement workflow accepts the JOSCAR validation as evidence and does not need to perform the equivalent due diligence independently.

    For tier-2 defence SMEs bidding into prime supply chains, Stage 1 alone is no longer credible. The cost of Stage 2 is recoverable on the first prime contract awarded that required it as a gate.

    The compliance modules inside Stage 2

    JOSCAR Stage 2 covers six principal compliance modules. Each module has its own evidence expectations and its own validation criteria.

    Cyber security module. The most demanding module for most defence supply chain SMEs. Covers information security management system maturity, technical controls (Cyber Essentials Plus is typically a floor expectation), incident response capability, supplier risk management, and evidence of compliance with relevant frameworks (ISO 27001, NIST, sector-specific standards).

    Financial module. Covers the supplier's financial standing, recent accounts, credit ratings, and financial stability indicators. The validation is principally documentary, with Hellios reviewing the supplier's accounts against the disclosed information.

    ESG module. Covers environmental, social, and governance posture. Includes environmental policy, sustainability initiatives, carbon reporting where applicable, and governance documentation.

    Modern slavery module. Covers the supplier's compliance with the Modern Slavery Act 2015. Includes the modern slavery statement (where the supplier exceeds the £36 million turnover threshold), supplier due diligence on labour practices in the supply chain, and training and awareness evidence.

    Quality module. Covers quality management system maturity. ISO 9001 certification is typically the expected evidence for tier-2 suppliers, with sector-specific quality standards (AS9100 for aerospace, IRIS for rail) where applicable.

    Health and safety module. Covers the supplier's health and safety management system. Includes policies, incident reporting, training records, and certification where applicable.

    The cyber security module is where this article concentrates because it is the module that most consistently trips up UK defence supply chain SMEs at Stage 2 submission.

    Why Stage 2 cyber section trips up SMEs most often

    Three structural reasons explain why the cyber section is the most frequent point of Stage 2 rework for tier-2 and tier-3 defence supply chain SMEs.

    The first reason is evidence specificity. The cyber section asks for evidence at a depth that operational SMEs often do not maintain by default. Incident response procedure tested within the last twelve months, with evidence of the test outcome. Supplier cyber due diligence performed on key sub-processors, with documented assessment criteria. Cyber Essentials Plus certificate with validity dates clearly shown. ISO 27001 certificate where held, with scope statement and certification body identified. The questions do not accept summary statements. They expect documented evidence with verifiable dates.

    The second reason is the gap between operational security and documented security. UK defence supply chain SMEs typically operate competent security in practice. Multi-factor authentication is enforced. Access reviews happen. Incidents are managed. Backups are tested. But the documentary evidence of these operational practices is often informal, held in operational tools rather than in an information security management system, and not formatted to evidence the JOSCAR question structure. The work to convert operational evidence into JOSCAR-ready documentation is substantial.

    The third reason is the layering of additional requirements from member primes. JOSCAR Stage 2 is a baseline. Member primes overlay their own supplier assessment questionnaires (SAQs) that ask cyber questions in prime-specific formats. BAE Systems supply chain assessment, Babcock supplier framework requirements, Leonardo supplier portal, and Rolls-Royce procurement cyber annexes all ask questions that build on JOSCAR Stage 2 evidence but require prime-specific formatting and additional depth. A supplier whose JOSCAR Stage 2 cyber evidence is at the floor of the module expectations will frequently then face additional rework when the prime-specific SAQ arrives.

    Common evidence gaps at Stage 2 cyber submission

    From engagement experience with UK defence supply chain SMEs preparing JOSCAR Stage 2 cyber submissions, six evidence gaps appear consistently.

    Cyber Essentials Plus certificate is held but the validity date has expired or is within sixty days of expiry. Stage 2 expects current CE Plus, not lapsed CE Plus and not renewing CE Plus. Suppliers preparing Stage 2 submission should validate the CE Plus expiry date at the start of the JOSCAR work and book the renewal assessment if expiry falls inside the submission window.

    Incident response procedure exists but has not been tested in the last twelve months. Stage 2 expects evidence of testing, not the procedure document alone. A tabletop exercise with documented findings and action tracking is the minimum credible evidence. Suppliers without a recent test should schedule one before submission rather than submit and rework.

    Supplier cyber due diligence is informal. Stage 2 expects documented assessment of key sub-processors, with assessment criteria, evidence collected, and risk findings recorded. An informal "we trust them" position fails this requirement. The supplier risk management process needs to be documented and operating.

    ISO 27001 scope statement does not match the JOSCAR-registered legal entity or the contract scope. Where the supplier holds ISO 27001 certification, Stage 2 reviewers check that the certificate scope covers the operations relevant to the prime customer base. Mismatches between the ISO 27001 legal entity, the JOSCAR registered legal entity, and the contracting entity are flagged.

    Risk register exists but is not current. Stage 2 expects evidence that cyber risk is actively managed, not documented historically. A risk register last reviewed twelve months ago, with no evidence of subsequent review or update, indicates a management system that is not operating. Stage 2 reviewers expect quarterly review cadence as a credible minimum.

    Training records are incomplete. Stage 2 asks about cyber security awareness training. Evidence of training delivery is expected with attendance and completion records. Annual mandatory cyber training is the floor expectation. Suppliers with informal training arrangements should formalise records before submission.

    Closing these six gaps before submission reduces rework cycles materially. The alternative is to submit, receive Hellios reviewer feedback, and rework against findings, which typically extends the submission timeline by four to eight weeks.

    How JOSCAR interacts with prime-specific SAQs

    JOSCAR Stage 2 is a foundation. It is not a complete answer to prime supplier assessment. Each member prime overlays its own supplier assessment questionnaire on top of JOSCAR.

    BAE Systems supply chain assessment includes a cyber section that asks JOSCAR-equivalent questions in BAE-specific phrasing, plus additional questions on supply chain risk management, classified information handling, and security aspects letter compliance.

    Babcock supplier framework requirements ask for evidence of cyber controls in operating contexts (specific contracts, specific sites) rather than at the supplier level only.

    Leonardo supplier portal cyber section asks for evidence of compliance with Leonardo's supplier cyber standards, which reference international and Italian-specific requirements.

    Rolls-Royce procurement cyber annexes ask for evidence proportionate to the specific contract risk, with additional requirements for contracts touching aerospace defence-relevant information.

    The integrated answer for UK defence supply chain SMEs is to assemble the cyber evidence pack once, in a format that supports both JOSCAR Stage 2 and the most common prime-specific SAQ overlays. Evidence assembled for JOSCAR cyber module typically supports between 60% and 80% of the prime-specific SAQ requirements without rework, with the remaining 20% to 40% requiring prime-specific responses against the same underlying evidence.

    The seven-question readiness checklist below is the front gate for this work.

    The seven-question Stage 2 cyber readiness checklist

    Before submitting JOSCAR Stage 2 cyber module, UK defence supply chain SMEs should answer seven questions clearly.

    1. Do we hold Cyber Essentials Plus, and is the certificate valid for at least 90 days beyond our planned submission date?

    2. Do we have a documented information security management system, ideally certified to ISO 27001, with a scope statement that matches our JOSCAR-registered legal entity?

    3. Has our incident response procedure been tested within the last twelve months, and do we have documented evidence of the test, findings, and action tracking?

    4. Do we have a documented supplier cyber due diligence process with assessment criteria, evidence collected from at least our top tier of sub-processors, and risk findings recorded?

    5. Is our cyber risk register current, with the last review documented within the last quarter and a defined review cadence going forward?

    6. Do we have cyber security awareness training records for all staff in the last twelve months, including new joiners trained before first system access?

    7. Are our policies (information security, acceptable use, incident response, supplier management, data classification, access control, business continuity) documented, approved, version-controlled, and reviewed within the last twelve months?

    A supplier answering yes to all seven, with documented evidence behind each yes, can submit Stage 2 cyber module with credible confidence. A supplier answering no or partial yes to two or more should remediate the gaps before submission rather than submit and rework.

    A reasonable working position

    JOSCAR Stage 2 is becoming the practical entry credential for UK defence supply chain SMEs bidding into BAE Systems, Babcock, Leonardo, Rolls-Royce Defence, Lockheed Martin UK, Northrop Grumman UK, and Thales UK supply chains. The cyber security module is the most demanding module for most SMEs at Stage 2 submission, and the rework cycles are long when the evidence is incomplete at first submission.

    For tier-2 and tier-3 defence SMEs preparing for Stage 2 submission in 2026, the work is structured but demanding. It requires a documented information security management system, Cyber Essentials Plus held at submission date, evidence of supplier cyber due diligence, and discipline in keeping the risk register and training records current.

    Book a 30-minute strategy call to scope your JOSCAR Stage 2 readiness.

    Frequently asked questions

    How long does JOSCAR Stage 2 review take? Hellios reviews vary by module complexity and current submission volumes. Typical timelines for cyber security module review run between four and eight weeks from initial submission. Reviews that require rework extend the timeline materially, with each rework cycle adding two to four weeks. Suppliers preparing for prime contract deadlines should allow at least twelve weeks from submission start to validated Stage 2 status.

    Do I need Cyber Essentials Plus to pass JOSCAR Stage 2? Cyber Essentials Plus is the practical floor expectation for the JOSCAR Stage 2 cyber security module. Suppliers without CE Plus can attempt submission with alternative evidence (ISO 27001, NIST CSF mapping, equivalent certifications), but the validation is materially harder without CE Plus. For UK defence supply chain SMEs, CE Plus is the most efficient path to satisfying the technical control evidence requirement.

    Can I do JOSCAR Stage 2 without consulting help? Yes, suppliers with internal capacity and the right documentation discipline can complete Stage 2 submission internally. The work is documentary and methodology-driven rather than technical. SMEs in the 25 to 75 FTE band typically find Stage 2 submission requires between 80 and 160 hours of internal effort if all underlying compliance is in place. Where the underlying compliance has gaps, the effort is materially higher and senior practitioner support shortens the cycle.

    What happens if a prime requires JOSCAR Stage 3? JOSCAR does not operate a Stage 3 in the standard sense. Some primes layer additional assessment on top of Stage 2, which is sometimes referred to colloquially as Stage 3 or as prime-specific validation. Where this occurs, the additional assessment is a prime-specific SAQ overlay rather than an additional JOSCAR stage. Suppliers should clarify with the prime exactly what is being asked.

    How often do I need to renew JOSCAR? JOSCAR Stage 2 validation typically runs on an annual renewal cycle, with the supplier required to update evidence and confirm currency once per year. Specific modules within Stage 2 may have shorter validity windows where the underlying evidence has fixed validity dates (CE Plus annual renewal, ISO 27001 surveillance cycle). Suppliers should track module validity within the JOSCAR profile and renew before lapse.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.