Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DEFSTAN 05-138 L1
UK Defence Standard 05-138 cybersecurity requirements at assurance level L1 for the defence supply chain.
Level L1 is the low assurance tier of the Defence Standard 05-138 Cyber Security Model, applied to MOD contracts whose cyber risk is judged to be low but no longer negligible. It aligns closely with foundational cyber hygiene of the kind set out in the UK Cyber Essentials scheme, giving a recognised baseline of protection against common, untargeted internet threats.
Suppliers at this tier are expected to put in place and maintain the core technical controls that reduce exposure to widespread attacks, and to evidence that they have done so through the assurance process. It marks the point where the model starts to require demonstrable controls rather than only confirming that a contract is low risk.
Implement core protections consistent with Cyber Essentials, covering areas such as boundary firewalls, secure configuration, access control, malware protection and patching.
Self-assess against the low-tier requirements and submit the declaration expected by the MOD to confirm the baseline controls are in place.
Keep the foundational controls current, applying updates and reviewing configuration so that the baseline does not degrade during the contract.
Ensure subcontractors handling in-scope information also meet the applicable low-tier expectations.
Read more
Anove scans your stack against DEFSTAN 05-138 L1 and 260+ other frameworks in minutes.