Def Stan 05-138
Def Stan 05-138 and the four Cyber Risk Profile levels
The control set behind DEFCON 658 — what a supplier must actually hold at Level 0, 1, 2 and 3, and where Cyber Essentials fits.
Issue 4 was published on 23 May 2024 and last updated on 3 December 2025. It replaced five Cyber Risk Profiles — N/A, Very Low, Low, Moderate, High — with four: Level 0 to Level 3. CSM v3 profiles are not consistent with CSM v4, so a supplier working from the older vocabulary is describing a regime that no longer exists.
Why this reaches the test bench
What gets tested
- Level 0 'Basic' — 3 controls, for a very low assessed cyber risk
- Level 1 'Foundational' — 101 controls
- Level 2 'Advanced' — 139 controls
- Level 3 'Expert' — 144 controls
Also current
A document you can actually read
How this differs from the American regime
The American analogue is DFARS 252.204-7012 with NIST SP 800-171 and CMMC — a different clause, a different control catalogue and a different certificate. The MOD publishes a mapping document between Def Stan 05-138 and NIST, ISO 27001 and Cyber Essentials, so existing evidence can be reused rather than rebuilt.
Careful
The assigned Cyber Risk Profile — not your own internal risk assessment — determines the minimum controls. The level is set by the MOD delivery team and arrives with the opportunity as a Risk Assessment Reference. A supplier who self-assesses to a level nobody assigned them has assessed the wrong thing.
Sources
- Cyber security for defence suppliers (Def Stan 05-138, Issue 4) — GOV.UK. Retrieved 2026-09-06.Supports: Issue 4 published 23 May 2024, last updated 3 December 2025; four Cyber Risk Profile levels; applies to MOD procurements, suppliers and subcontractors
- Defence Standard 05-138 Issue 4 — Cyber Security for Defence Suppliers — GOV.UK (publishing.service.gov.uk). Retrieved 2026-09-06.Supports: Control counts 3/101/139/144; control 0001 Cyber Essentials at all levels; control 0002 Cyber Essentials Plus at Levels 2 and 3; supersedes Issue 3
- Cyber Security Model — GOV.UK. Retrieved 2026-09-06.Supports: CSM v4 risk assessment and Supplier Assurance Questionnaire process; Cyber Improvement Plan; Defence Cyber Certification; DEFCON 658 carries the flow-down requirement
- Mapping document — cyber security for defence suppliers (Def Stan 05-138, Issue 4) — GOV.UK. Retrieved 2026-09-06.Supports: Mapping to CAF v3.1, NIST SP 800-171 Rev 3, NIST CSF, Cyber Essentials, ISO 27001:2022
