DEFCON 658
DEFCON 658 and Cyber Security Model v4
The MOD contract condition that flows down the whole supply chain, and the deadline attached to it.
CSM v4 went live on 3 December 2025, replacing the old five-tier risk profile with four levels, 0 to 3. MOD has asked all industry partners to hold Defence Cyber Certification Level 0 by 31 December 2026.
Why this reaches the test bench
A document you can actually read
How this differs from the American regime
The American analogue is DFARS 252.204-7012 and CMMC — a different clause, a different assessment regime, and a different certificate.
Careful
Cite the edition, and cite it exactly. GOV.UK's reference line reads 'Edition 10/17 12/22' — the edition is October 2017, the file was last revised in December 2022, and an interim version was added in September 2021. Those are three different numbers describing one document, and picking the wrong one is how a supplier ends up citing an edition that does not exist. We have seen 10/22 quoted; it is a misreading of the reference line. The authoritative DEFCON library sits behind Defence Gateway SSO, so the GOV.UK copy is what a supplier can actually check.
Sources
- Cyber Security Model — GOV.UK. Retrieved 2026-09-05.Supports: CSM v4; four risk levels; DEFCON 658 as the contractual mechanism
- Cyber security for defence suppliers (Def Stan 05-138 Issue 4) — GOV.UK. Retrieved 2026-09-05.Supports: Issue 4 published 23 May 2024, updated 3 December 2025
- Defence Condition 658 (cyber flow-down) — GOV.UK. Retrieved 2026-09-06.Supports: Reference 'Edition 10/17 12/22'; first published 17 October 2017, 9/21 version added 10 September 2021, last updated 13 December 2022
