Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
DEFSTAN 05-138 L3
UK Defence Standard 05-138 cybersecurity requirements at assurance level L3 for the defence supply chain.
Level L3 is the highest assurance tier in this set of the Defence Standard 05-138 Cyber Security Model, applied to MOD contracts assessed as carrying the greatest cyber risk. It is intended for work involving the most sensitive defence information or the greatest potential impact from compromise, and it demands the most extensive and rigorous set of controls in the framework.
At this tier suppliers are expected to demonstrate mature, defence-in-depth security spanning technical controls, governance, continuous monitoring, robust incident response and thorough supply chain assurance, building on every lower tier. The level of scrutiny and the expectation of demonstrable, well-managed protection are correspondingly high, and controls must be sustained and reviewed throughout the contract.
Deploy comprehensive, defence-in-depth technical and organisational controls that build on all lower tiers to protect the most sensitive contracts.
Maintain strong security governance, continuous monitoring and logging, and tested incident response capable of handling capable, targeted threats.
Ensure subcontractors handling high-risk information meet correspondingly stringent requirements and that assurance extends end to end.
Demonstrate conformity through detailed assurance evidence and sustain and reassess the controls continuously across the contract.
Read more
Anove scans your stack against DEFSTAN 05-138 L3 and 260+ other frameworks in minutes.