What is the MOD Cyber Security Model v4 and does it apply to my company?
The Cyber Security Model v4 (CSM v4) is the Ministry of Defence's framework for assessing and managing cyber security risk across its supply chain. It went live in December 2025, replacing the interim measures that had operated under DEFCON 658. If your company holds or bids for MOD work, directly or as a subcontractor at any tier, CSM v4 applies to you.
What changed from CSM v3?
The biggest shift is scope. Earlier versions focused on protecting MOD Identifiable Information, meaning only the parts of your business that touched MOD data were in scope. CSM v4 assesses organisational security and resilience, meaning your whole company is in scope, not just the project team on the MOD contract.
If you take one thing from this guide, take that. It invalidates the most common compliance strategy of the previous decade, which was to ring-fence a small, tidy environment for MOD work and leave the rest of the business alone.
The second shift is evidence. Self-declared policy statements carry less weight; the framework is built around independently verifiable assurance, primarily through Defence Cyber Certification (DCC).
The four Cyber Risk Profiles
Every MOD contract under CSM v4 is assigned a Cyber Risk Profile (CRP), which determines what suppliers must demonstrate.
| Level | Name | Assessed risk | What it requires |
|---|---|---|---|
| 0 | Basic | Very low | Cyber Essentials, UK GDPR compliance, resilient networks |
| 1 | Foundational | Low to moderate | 101 controls, technical and governance |
| 2 | Advanced | High | 139 controls, and Cyber Essentials Plus |
| 3 | Expert | Most critical outputs | 144 controls, full defence in depth |
The control sets themselves are defined in Defence Standard 05-138 Issue 4. DCC certification evidences them independently.
How the process works on a new contract
- The MOD provides a Risk Assessment Reference (RAR) and the required CRP level, usually in the invitation to tender.
- You complete a Supplier Assurance Questionnaire (SAQ) through the Supplier Cyber Protection Service, self-assessing against that CRP.
- If you are not fully compliant, you complete a Cyber Improvement Plan (CIP) setting out the gaps, remediation steps, and timeline. The CIP becomes part of the contract, so its deadlines carry commercial weight.
- If you are a subcontractor, flow-down applies: the contractor above you conducts the risk assessment and generates your RAR and CRP.
What this means for SMEs
Two practical consequences.
First, you can no longer ring-fence compliance to one project. Your organisation's overall posture is what gets assessed, which means the unmanaged laptop in the corner and the founder's personal cloud storage are now in scope.
Second, certification is moving from nice-to-have to precursor. The MOD has asked all industry partners to hold DCC Level 0 by 31 December 2026, and holding certification at the right level before bidding is fast becoming the expectation rather than a differentiator.
The sensible sequence for a small supplier is Cyber Essentials first, then DCC Level 0, then higher levels only when a contract's CRP demands it.
What does it require of you, specifically?
CSM v4 is easier to understand than to act on. The useful question is not what the framework is, but what it demands of your business given your contracts and your current posture. The free readiness check answers that in a few minutes.