Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DEFSTAN 05-138 L2
UK Defence Standard 05-138 cybersecurity requirements at assurance level L2 for the defence supply chain.
Level L2 is the moderate assurance tier of the Defence Standard 05-138 Cyber Security Model, applied to MOD contracts that carry a middling cyber risk. At this level the foundational hygiene expected at the lower tiers is no longer considered sufficient on its own, and suppliers must add further controls that address more capable or more determined threats.
The additional measures typically extend into areas such as stronger access and identity management, monitoring and logging, incident response readiness and supply chain assurance, building on the Cyber Essentials style baseline rather than replacing it. Suppliers are expected to evidence these controls through the assurance process and to maintain them across the life of the contract.
Maintain the foundational hygiene of the lower tiers and add further technical and organisational measures suited to a moderate-risk contract.
Introduce stronger identity and access management, logging and monitoring, and defined incident response arrangements appropriate to the elevated risk.
Extend cyber expectations to relevant subcontractors and confirm that in-scope information is protected across the chain.
Demonstrate the moderate-tier controls through the assurance process and keep them effective throughout the contract.
Read more
Anove scans your stack against DEFSTAN 05-138 L2 and 260+ other frameworks in minutes.