DEFCON 658 reaches you, whether or not you contract with the MOD
The clause flows down every tier of the supply chain, the risk model changed in December 2025, and there is a date on it.
DEFCON 658The reference page for this document
Suppliers who sit beneath a prime often assume defence cyber requirements are the prime's problem. DEFCON 658 flows down through every tier of the supply chain, subcontractors included. If your equipment ends up on a British defence programme, the clause reaches you.
What changed, and when
The Cyber Security Model moved to version 4 on 3 December 2025. The old five-tier risk profile — Not Applicable, Very Low, Low, Moderate, High — was replaced by four levels, 0 to 3. Any assessment, questionnaire or internal policy written against the five-tier model is describing a scheme that no longer exists.
The date that matters
The Ministry of Defence has asked all industry partners to hold Defence Cyber Certification at Level 0 by 31 December 2026. For a supplier who has not started, that is a short runway for something that touches policy, evidence and third-party assessment.
One document you can actually read
Def Stan 05-138 Issue 4 is free, public and citable — published 23 May 2024 and updated 3 December 2025. Most of the Def Stan catalogue sits behind Defence Gateway SSO, and a contractor cannot self-register; an application has to be sponsored by an existing user. 05-138 is the exception, and it is the one worth reading first.
A caution on edition numbers
GOV.UK publishes DEFCON 658 as Edition 10/17. We have seen a later edition number quoted in the market and could not confirm it, because the authoritative DEFCON library is SSO-gated. Print 10/17 or print nothing — an invented edition number on a compliance document is the kind of detail an assessor checks.
The American analogue is DFARS 252.204-7012 with CMMC. Different clause, different assessment regime, different certificate. Holding one does not satisfy the other.
Sources
- Cyber Security Model — GOV.UK. Retrieved 2026-09-05.Supports: CSM v4; four risk levels replacing five; DEFCON 658 as the contractual mechanism
- Cyber security for defence suppliers (Def Stan 05-138 Issue 4) — GOV.UK. Retrieved 2026-09-05.Supports: Issue 4 published 23 May 2024, updated 3 December 2025; free and public
- UK Defence Standardization — GOV.UK. Retrieved 2026-09-05.Supports: DStan as publisher; access route
