Skip to main content
Defence

Tier 2 UK Aerospace Supplier Achieves Cyber Essentials Plus and JOSCAR Submission in Fourteen Weeks

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

6 min read

Contents

    The procurement context

    A tier-2 UK aerospace supplier with 35 FTE, headquartered in the South West, was facing a pipeline risk that had not been visible twelve months earlier. Two prime contracts under bid carried updated cyber security clauses. The BAE Hawk-class supply chain assessment now required JOSCAR Stage 2 with the cyber security module complete and validated, Cyber Essentials Plus held at the time of contract award, and DEFCON 658 risk assessment evidence aligned to the prime's interpretation of the contract risk profile. The Babcock submarine support framework had similar requirements layered with additional DEFSTAN 05-138 evidence for sub-contracts assigned at Moderate risk profile and above.

    The supplier had been on the framework lists for both primes for six years. The cyber clauses on the new bids were materially stricter than the contracts they had previously delivered. The Operations Director estimated that the two prime bids together represented approximately £2.4 million of annual revenue at risk if the cyber gate could not be cleared in the bid timeline.

    The challenge was not the technical work. The supplier had a competent in-house IT lead, a Cyber Essentials basic certification renewed annually, and an informal information security posture that worked operationally. The challenge was that the documented evidence required by JOSCAR Stage 2 and the prime-specific SAQs did not exist in the format procurement required, and the in-house team did not have the bandwidth or the specific compliance expertise to assemble it in the timeline the bids demanded.

    The starting position at week zero

    A discovery assessment in the week before engagement kick-off documented the supplier's compliance starting position.

    Cyber Essentials basic certification held, renewed annually with no surveillance assessment between renewals. Cyber Essentials Plus had been discussed internally for two years but never started because the team did not have time to prepare for the technical assessment.

    No ISO 27001 certification. No information security management system. Some policies existed (acceptable use, password policy, mobile device policy) but they were not version-controlled, not reviewed on a defined cadence, and not approved by a documented governance body.

    No formal DEFCON 658 documentation. Risk assessments had been performed for individual contracts on an ad hoc basis, but there was no central risk register, no documented assessment methodology, and no evidence that risks were reviewed when the contract scope or the threat landscape changed.

    No JOSCAR Stage 2 submission. The supplier held a JOSCAR Stage 1 registration but had not progressed to Stage 2 because the work to assemble the cyber security module evidence had been deprioritised against operational delivery pressures.

    Three areas of strength. The supplier had a documented and tested incident response procedure (originally built for a customer audit two years earlier). They had a current asset register held by the IT lead. They had a relationship with a UKAS-accredited certification body from a previous ISO 9001 quality management certification, which meant the audit body selection for ISO 27001 was straightforward when the engagement started.

    This starting position is typical of UK defence supply chain SMEs in the 25 to 75 FTE band. Competent operational security. Genuine compliance gaps. No reserved capacity to close the gaps against a prime contract deadline.

    The Defence Cyber Foundation engagement

    The engagement ran for sixteen weeks across four phases.

    Phase 1: Foundation. Weeks 1 to 4. A senior practitioner kick-off established the engagement scope, the JOSCAR Stage 2 target submission date (week 14), the Cyber Essentials Plus target assessment date (week 9), and the prime-bid deadlines that determined the critical path. An asset and information inventory was completed, covering the supplier's IT estate, the data flows associated with each prime customer, and the sub-processor relationships in scope. A risk assessment methodology was documented, including the criteria for DEFSTAN 05-138 risk profile mapping. The policy library was rebuilt from the existing fragments into a structured set of seventeen policies aligned to ISO 27001 Annex A and the Cyber Essentials Plus technical controls. A leadership and governance structure was documented, naming the cyber risk owner at director level and establishing a monthly information security forum.

    Phase 2: Implement. Weeks 5 to 9. Technical controls were assessed against the Cyber Essentials Plus requirements. Two configuration changes were required (multi-factor authentication on the cloud-hosted ERP system, secure configuration baseline applied to laptop estate). A vulnerability scan was run on a representative sample of internal hosts and the external-facing infrastructure. Two findings were remediated before the Cyber Essentials Plus assessment was booked. The CE Plus assessment was completed in week 9. Certification was awarded the same week.

    DEFCON 658 documentation was developed in parallel during weeks 5 to 9. A risk assessment was completed for each of the two prime contracts in active bid, mapped to the DEFSTAN 05-138 risk profile assigned by the prime (Moderate for the BAE bid, Low for the Babcock bid). The risk assessments documented threat actors, attack surfaces, asset classifications, and control mappings to demonstrate that the cyber risk treatment was proportionate to the profile assigned.

    Phase 3: Submit. Weeks 10 to 14. The JOSCAR Stage 2 cyber security module evidence was assembled. The supplier's existing modules (financial, quality, ESG, modern slavery) were reviewed for currency and resubmitted where evidence had aged beyond the eighteen-month validity window. The cyber module was assembled from the policy library, the risk assessments, the Cyber Essentials Plus certificate, and the incident response evidence. The JOSCAR Stage 2 submission was filed in week 14, three days ahead of the working deadline.

    Prime-specific SAQs were completed in parallel during weeks 12 to 14. The BAE supply chain assessment and the Babcock framework cyber section both used evidence already assembled for JOSCAR Stage 2, with prime-specific phrasing applied to the responses where each prime's questionnaire asked the same question in different language.

    Phase 4: Stabilise. Weeks 15 to 16. The ISO 27001 Stage 2 audit was booked with the supplier's existing UKAS-accredited certification body for week 22, eight weeks after the engagement formally closed. The internal audit programme was established, with the first internal audit scheduled for week 18. A management review cadence was documented, with quarterly forum and annual full review. The supplier's IT lead was inducted as the ongoing internal owner of the information security management system, with senior practitioner support available on a retained basis for the surveillance audit window.

    The outcome at week sixteen

    The supplier closed the engagement with:

    • Cyber Essentials Plus certification awarded in week 11
    • JOSCAR Stage 2 submission filed in week 14, accepted by Hellios in week 16 without rework
    • ISO 27001 Stage 2 audit booked for week 22 with the existing UKAS-accredited certification body
    • Both prime bids progressed to the next procurement gate, with the cyber clauses cleared
    • DEFCON 658 risk assessments completed and accepted for both active bids
    • Policy library, risk register, asset inventory, incident response procedure, and management review cadence all documented and operating

    The two prime contracts were not awarded by the close of the engagement. The procurement decisions sat with the primes and ran their own timelines beyond the cyber gate. What the engagement delivered was the cyber compliance evidence pack that took both bids past the gate that had previously blocked them.

    What changed for the buyer

    Three things changed materially for the supplier in the twelve months that followed.

    The procurement signal in the prime supply chain shifted. The supplier was now a Stage 2 JOSCAR-validated tier-2 with current CE Plus and an ISO 27001 certification in progress. Both primes flagged the supplier as preferred for tier-2 sourcing in the supply chain reviews that followed. One additional bid invitation arrived during the ISO 27001 implementation window that the supplier had not been invited to bid for in the previous twelve months.

    The surveillance audit posture became defensible. When the BAE supply chain reassessment ran in month nine after engagement close, the supplier passed without rework. The Babcock annual cyber review in month eleven similarly required only a current evidence pack submission. The recurring annual cost of compliance evidence assembly dropped from an estimated forty staff-days per year (across the IT lead, the Operations Director, and the bid manager) to approximately fifteen.

    The next year looked different. With ISO 27001 certified at the Stage 2 audit and the JOSCAR Stage 2 submission validated, the supplier was bidding into prime supply chains they had not been able to credibly bid into before. The cyber compliance posture moved from a contract-pipeline risk to a commercial differentiator.

    For a 35 FTE supplier with £2.4 million of revenue at stake on two bids alone, the engagement paid back inside the first prime contract award window.

    Closing note

    For UK MOD and Prime Contractor supply chain SMEs facing the same procurement gate, the Defence Cyber Foundation is the sixteen-week engagement that closes it. Read the full Defence Cyber Foundation programme.

    Composite case study built from anonymised engagement patterns. Specific dates, FTE counts, and procurement references have been generalised. The engagement structure, compliance milestones, and outcome pattern are representative of the work the Defence Cyber Foundation delivers.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.