Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DEFSTAN 05-138 L0
UK Defence Standard 05-138 cybersecurity requirements at assurance level L0 for the defence supply chain.
Level L0 is the lowest assurance tier within the Defence Standard 05-138 Cyber Security Model, applied to MOD contracts assessed as carrying the least cyber risk. It represents the entry point of the graduated model, where the work involves little or no sensitive defence information and the likelihood or impact of a cyber compromise is judged to be minimal.
At this tier the emphasis is on confirming that the contract genuinely falls into the lowest risk category and on maintaining basic good practice, rather than on implementing the heavier control sets required higher up the scale. Suppliers still complete the risk assessment process so that the L0 outcome is properly recorded, and they remain responsible for reassessing if the nature of the work changes.
Complete the cyber risk assessment for the contract and record the outcome that places the work at the L0 baseline tier.
Keep routine good practice in place, such as sensible account management and up to date systems, proportionate to minimal-risk work.
Provide the required self-assessment declaration so the MOD has a record that the baseline expectations are met.
Trigger a new risk assessment if the contract begins to involve more sensitive information or higher-risk activity that would warrant a higher tier.
Read more
Anove scans your stack against DEFSTAN 05-138 L0 and 260+ other frameworks in minutes.