Skip to main content

UK Cyber Schemes

DEFCON 658

The MOD contract condition that applies the Cyber Security Model to a contract. Where it is incorporated, the contractor must complete the risk assessment and Supplier Assurance Questionnaire, meet the applicable DEFSTAN 05-138 controls or an agreed Cyber Improvement Plan, report incidents, and flow the same obligations down to relevant subcontractors.

Why it matters: the flow-down is what pulls Tier 2 and Tier 3 suppliers into scope.

Questions about how this applies to you? Book a free 45 minute diagnostic.

Back to the glossary

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.