HomeFrameworksNational Cyber & Cloud SchemesUK MoD compliance requirements

Framework  National Cyber & Cloud Schemes

UK MoD compliance requirements

UK Ministry of Defence supplier compliance is an umbrella label for the security conditions written into MOD contracts.

The core cyber element is the Cyber Security Model (CSM): DEFCON 658 is the contract condition that obliges a supplier to meet the cyber controls in Defence Standard 05-138 at the Cyber Risk Profile (Very Low, Low, Moderate, or High, numbered 0 to 3 in the current issue) that the MOD assigns to the contract, and to flow the same obligations down to subcontractors.

Suppliers demonstrate compliance through a Supplier Assurance Questionnaire on the MOD's Supplier Cyber Protection Service portal, renewed annually and whenever the contract changes.

The MOD has also introduced Defence Cyber Certification (DCC) with IASME as delivery partner, a certification aligned to Def Stan 05-138 that suppliers are increasingly expected to hold for the life of the contract (verify current rollout status).

Around the cyber core sit the other MOD conditions: DEFCON 659A and the Security Aspects Letter for classified work, the Industry Security Notices and JSP 440 rules for handling classified information, List X facility security clearance for holding SECRET material on site, Baseline Personnel Security Standard and national security vetting for staff, and Def Stan 05-135 and related quality standards.

In writing, a supplier needs the completed Supplier Assurance Questionnaire and evidence for each Def Stan 05-138 control at its risk profile (Cyber Essentials or Cyber Essentials Plus is the baseline at the lower profiles, with governance, asset management, access, monitoring, incident response, and supply chain controls added as the profile rises), a cyber implementation plan for any gaps, flow-down records for subcontractors, incident reporting procedures that meet the MOD's notification requirements, and where classified work is involved the security aspects letter, facility security documentation, and personnel clearance records.

AI-compiled
Share
Sponsored
UK
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with UK MoD compliance requirements
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Any supplier or subcontractor at any tier holding a MOD contract that carries DEFCON 658 (contracts where MOD-identifiable information is handled), plus the classified-work conditions where the contract includes a Security Aspects Letter. Small suppliers are in scope; the risk profile scales the requirements.

What the assessor asks to see

Contract and risk profile notification; Supplier Assurance Questionnaire responses; Cyber Essentials or Cyber Essentials Plus certificate; policies and evidence for each Def Stan 05-138 control at the profile (governance, asset register, access control and MFA, patching, logging and monitoring, incident response and MOD notification, supplier flow-down and assurance); cyber implementation plan for gaps; subcontractor flow-down records; for classified work, the Security Aspects Letter, facility security plan and List X records, personnel clearance and BPSS records, and classified information handling procedures.

Cyber Risk Profiles

Def Stan 05-138 sets controls for each Cyber Risk Profile assigned by the MOD to a contract. Lower profiles rest on Cyber Essentials; higher profiles add controls on governance, asset management, access management, monitoring, incident management, and supply chain assurance.

The current issue of the standard and the Supplier Cyber Protection Service portal define the exact control set per profile.

Assessors

Who assesses UK MoD compliance requirements

MOD reviews Supplier Assurance Questionnaires through the Supplier Cyber Protection Service and may audit; Cyber Essentials certification bodies licensed by IASME certify the baseline; Defence Cyber Certification is assessed by IASME-licensed certification bodies; MOD security staff (and DE&S Principal Security Advisers) assess facility and classified-handling compliance.

Accredited by IASME (on behalf of NCSC for Cyber Essentials and of the MOD for Defence Cyber Certification) licenses certification bodies; the MOD assesses directly for the remainder.

Public register of assessors: https://iasme.co.uk/cyber-essentials/find-a-certification-body/

No firm has claimed a UK MoD compliance requirements assessor listing yet. Claim yours →

Consultants

Who helps with UK MoD compliance requirements

UK defense-sector cybersecurity consultancies, Cyber Essentials certification bodies, and facility security officer service providers help suppliers complete the questionnaire, achieve Cyber Essentials Plus, implement the higher-profile controls, and prepare for DCC. Engagements range from a few weeks at Very Low profile to many months at High.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a UK MoD compliance requirements consultant listing yet. Claim yours →

Software

Tools for UK MoD compliance requirements

Tools that name this framework in their own material.

No firm has claimed a UK MoD compliance requirements tool listing yet. Claim yours →

Need a hand implementing it?

Find a Consultant for UK MoD Compliance Requirements

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with UK MoD Compliance Requirements

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.