What is the difference between CSM v4, DefStan 05-138 and DCC?
They are three parts of one system. The Cyber Security Model v4 (CSM v4) is the MOD's risk framework: it decides how much cyber assurance a contract needs. Defence Standard 05-138 is the control set: it defines what suppliers must actually implement at each level. Defence Cyber Certification (DCC) is the certification: it independently evidences that you meet the controls. One decides, one defines, one proves.
If you keep that sentence in your head, the rest of the MOD's cyber assurance landscape falls into place.
CSM v4: the framework that decides
CSM v4, live since December 2025, is how the MOD assesses the cyber risk of every contract. Each contract gets a Cyber Risk Profile from Level 0 (very low risk) to Level 3 (the most critical outputs). The profile arrives with the invitation to tender, or is flowed down to you by your prime contractor if you are subcontracting.
CSM v4 also defines the process: the Supplier Assurance Questionnaire through the Supplier Cyber Protection Service, and the Cyber Improvement Plan if you have gaps. Its major change from earlier versions is scope: it assesses your whole organisation's security and resilience, not just the parts touching MOD data.
DefStan 05-138: the standard that defines
Defence Standard 05-138 Issue 4 contains the actual controls behind each level. Cyber Essentials forms its core, and the control count grows with risk: Level 1 has 101 controls, Level 2 has 139, and Level 3 has 144, spanning technical measures, governance, and risk management. Levels 2 and 3 require Cyber Essentials Plus rather than standard Cyber Essentials.
When someone says "we need to be DefStan compliant", the right follow-up question is always "at which level?", because the difference between Level 0 and Level 3 is the difference between a questionnaire and a full defence-in-depth programme.
DCC: the certificate that proves
DCC, administered by IASME and delivered through its network of certification bodies, is the independent certification against those DefStan controls. Its four levels map one-to-one onto the Cyber Risk Profiles.
A certificate is valid for three years with annual attestation, replacing the old contract-by-contract assessment grind with a single organisational credential. Lockheed Martin has already taken the first Level 3 certification, and the MOD has asked all industry partners to hold Level 0 by 31 December 2026.
What about Secure by Design?
Secure by Design (SbD) is the one that confuses people, because it sits alongside this system rather than inside it.
CSM, DefStan and DCC apply to your organisation. SbD applies to the capability or service you are building for Defence. If you are delivering a product or system that handles Defence data, you will meet SbD requirements on that product in addition to holding organisational certification. Different object, different assurance.
So what do I actually need to do?
For most SMEs entering or already in the supply chain, the sequence is: get Cyber Essentials, use it to achieve DCC Level 0 before the end of 2026, understand the Cyber Risk Profile your contracts are likely to carry, and only build to higher levels when a real contract demands it.
Certification aligned to your pipeline, not collected for its own sake.
Skip the vocabulary
If the terminology is still tangling, the readiness check ignores it entirely and just tells you what your position is.