Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DEFSTAN 05-138
UK Defence Standard 05-138 defining cybersecurity requirements for suppliers in the defence supply chain.
UK Defence Standard 05-138 (DEFSTAN 05-138) sets out the cybersecurity requirements that organisations must meet to supply the UK Ministry of Defence (MOD). It is delivered through the Defence Cyber Protection Partnership (DCPP) and its Cyber Security Model, a risk-based approach that judges how much protection each contract needs rather than applying a single fixed rule to every supplier.
Under the model, each contract is assessed through a cyber risk assessment that produces a risk profile and an associated Risk Assessment Reference. That profile maps to one of a series of graduated assurance levels, shown in this catalogue as L0 to L3, ranging from a minimal baseline for the lowest-risk work up to the most extensive control set for the highest-risk work. Lower tiers build on the UK Cyber Essentials scheme, while higher tiers layer on many additional technical and organisational controls. Suppliers typically demonstrate conformity by completing a supplier assurance questionnaire and are expected to flow the relevant requirements down to their own subcontractors.
Work with the MOD or prime contractor to assess the cyber risk of each contract and obtain the resulting risk profile and Risk Assessment Reference that sets the required assurance level.
Implement the technical and organisational controls that correspond to the assigned tier (L0 to L3), building up from Cyber Essentials style hygiene at the lower tiers to substantially more demanding measures at the higher tiers.
Self-assess and declare conformity, typically through a supplier assurance questionnaire, and keep evidence available so the MOD can gain confidence that the required controls are in place.
Pass the applicable cyber requirements to subcontractors who handle relevant defence information so that protection is maintained end to end.
Read more
Anove scans your stack against DEFSTAN 05-138 and 260+ other frameworks in minutes.
Sustain the controls throughout the contract and reassess if the nature of the work or the information handled changes.