DEFCON 658

DEFCON 658 and Cyber Security Model v4

The MOD contract condition that flows down the whole supply chain, and the deadline attached to it.

CSM v4 went live on 3 December 2025, replacing the old five-tier risk profile with four levels, 0 to 3. MOD has asked all industry partners to hold Defence Cyber Certification Level 0 by 31 December 2026.

Why this reaches the test bench

DEFCON 658 flows down through every tier, subcontractors included. A test-equipment supplier sitting beneath a prime on a defence programme is inside it, not adjacent to it.

A document you can actually read

Def Stan 05-138 Issue 4 is free, public and citable — published 23 May 2024, updated 3 December 2025.

How this differs from the American regime

The American analogue is DFARS 252.204-7012 and CMMC — a different clause, a different assessment regime, and a different certificate.

Careful

Cite the edition, and cite it exactly. GOV.UK's reference line reads 'Edition 10/17 12/22' — the edition is October 2017, the file was last revised in December 2022, and an interim version was added in September 2021. Those are three different numbers describing one document, and picking the wrong one is how a supplier ends up citing an edition that does not exist. We have seen 10/22 quoted; it is a misreading of the reference line. The authoritative DEFCON library sits behind Defence Gateway SSO, so the GOV.UK copy is what a supplier can actually check.

Sources