DefStan 05-138

What is Defence Standard 05-138 and which controls does it require?

Defence Standard 05-138 (DefStan 05-138) is the MOD's standard defining the cyber security controls that defence suppliers must implement. Issue 4, which underpins Cyber Security Model v4, sets out four tiers of controls corresponding to the four Cyber Risk Profiles: Cyber Essentials plus basic resilience at Level 0, rising to 101 controls at Level 1, 139 at Level 2, and 144 at Level 3.

If CSM v4 is the framework that decides how much assurance your contract needs, DefStan 05-138 is the document that tells you what to actually build.

How the levels break down

Level 0 (Basic). For very low risk contracts. Cyber Essentials, UK GDPR compliance, and resilient networks, meaning working backups and a disaster recovery plan. No long control list; this level is deliberately achievable for small suppliers.

Level 1 (Foundational). 101 controls. This is where a real security programme starts: alongside technical controls such as network monitoring, you need policy and governance controls covering risk management, roles and responsibilities, and organisational process.

Level 2 (Advanced). 139 controls, and Cyber Essentials Plus becomes the prerequisite rather than standard Cyber Essentials. Expect more demanding requirements across planning, oversight, and technical assurance.

Level 3 (Expert). 144 controls for the most critical contracted outputs, requiring a full defence-in-depth approach.

What kind of controls are they?

The standard deliberately covers the whole organisation, not just IT. Controls span technical measures (monitoring, hardening, access management), governance (risk management, policy, accountability), and operational resilience. Cyber Essentials forms the core at every level, which is why holding a valid CE certificate is the universal starting point.

The important cultural point in Issue 4 is evidence. Assessors want proof that controls operate day to day, not a policy library written the week before assessment. A monitoring control means logs someone actually reviews. A risk management control means a register that gets updated when the business changes.

How do I know which level applies to me?

You do not choose it; the contract does. The MOD assigns a Cyber Risk Profile to each contract and communicates it in the invitation to tender. If you are a subcontractor, your prime contractor conducts the risk assessment and flows the requirement down to you.

Most SMEs entering the supply chain will encounter Level 0 or Level 1 first.

How does DefStan 05-138 relate to DCC?

Directly. Defence Cyber Certification, administered by IASME, certifies against the DefStan 05-138 controls at the corresponding level. The controls are identical; DCC is simply the independent evidence that you meet them.

Achieve the controls once, certify once, and the certificate covers all your contracts at that level for three years with annual attestation.

Where do most suppliers get stuck?

Two places.

First, underestimating the jump from Level 0 to Level 1. Going from three requirements to 101 controls is a step change that needs a programme, not a weekend.

Second, treating the standard as a paperwork exercise. The gap between documented and lived controls is precisely what independent assessment is designed to find.

Find the size of your delta first

The useful first move is rarely to read the standard cover to cover. It is to find out which controls you meet today, which ones still need building, and what that means for the level your contracts demand.

Dave Collins OBE
Chief Technology Officer

Dave Collins OBE spent 18 years in the Royal Air Force, including the Ministry of Defence, GCHQ, and command of the RAF's cyber defence wing. He was awarded the OBE in 2024 for services to RAF and MOD cyber defence. More about Dave →