Cyber Essentials

DEFCON 658 and Cyber Essentials for MOD suppliers

DEFCON 658 is the Ministry of Defence contract condition that requires suppliers handling MOD identifiable information to meet a defined cyber security standard. For most suppliers that standard starts with Cyber Essentials, and from 2026 the MOD expects every industry partner to hold Defence Cyber Certification Level 0, which is built on it.

DEFCON 658 applies wherever a contract touches MOD identifiable information

By David Webb, Director at Forensic Control

DEFCON 658 is one of the Ministry of Defence’s standard contract conditions, and it carries the cyber security obligation. It is included in any contract, and any subcontract beneath it, where the supplier will hold, process or transmit MOD identifiable information. The condition does not set the controls itself. It points the supplier to the MOD’s Cyber Security Model, which was reinstated in its fourth version on 3 December 2025, and to the control standard behind it, Defence Standard 05-138 Issue 4.

The model works from a risk assessment carried out by the contracting authority. Each contract is given a cyber risk profile, and the profile sets the control level the supplier has to meet and evidence. The supplier records its position in a Supplier Assurance Questionnaire, which the MOD now requires to be reviewed every year on the anniversary of the contract. The obligation flows down: a prime contractor is responsible for placing the same requirement on any subcontractor that will handle the information.

Having spent 26 years in the armed forces before moving into corporate security, I would read DEFCON 658 as a description of what the MOD will check. The risk profile tells you the level, the standard tells you the controls, and the questionnaire is where you show your work. The quickest way through the first two levels is a certificate the MOD already recognises, and for those levels that certificate is Cyber Essentials.

 

Which DEFCON is asking you for what

Suppliers searching for one DEFCON usually find three or four in the same contract. These are the ones that matter for cyber and data.
DEFCON 658, cyber security

DEFCON 658, cyber security

The cyber condition. Requires you to meet the control level set by your contract's cyber risk profile under the Cyber Security Model and Def Stan 05-138. Cyber Essentials and Defence Cyber Certification are how suppliers satisfy it.

DEFCON 532B, personal data

DEFCON 532B, personal data

The data protection condition where you process personal data on behalf of the MOD. DEFCON 532A is its counterpart where you do not. Both sit alongside DEFCON 658. A contract that involves MOD personal data will usually carry the data condition and the cyber condition together.

Defence Cyber Certification

Defence Cyber Certification

The MOD's own scheme, launched in May 2025 and delivered through IASME certification bodies. Four levels, 0 to 3. Since March 2026 a valid certificate at the right level counts as assured evidence under DEFCON 658.

The 31 December 2026 request

The 31 December 2026 request

The MOD has asked all industry partners to achieve Defence Cyber Certification Level 0 by 31 December 2026. Level 0 requires Cyber Essentials on your business critical systems. A supplier holding a DEFCON 658 contract without a certificate has until then to get one.

Your cyber risk profile decides whether you need Cyber Essentials or Plus

Defence Cyber Certification has four levels, and each one is built on the IASME scheme. Every level starts with Cyber Essentials, and Levels 2 and 3 require Cyber Essentials Plus. Level 0 covers three controls and is the floor the MOD has asked every supplier to reach this year. Level 1 adds around a hundred controls from Def Stan 05-138, and Levels 2 and 3 add more again, so a supplier’s DCC level tracks the cyber risk profile of the most demanding contract it holds.

The practical consequence is that a contract with a very low or low profile can usually be evidenced with Cyber Essentials and a Level 0 or Level 1 certificate, and anything above that will ask for Plus as the starting point. The MOD’s matrix in Industry Security Notice 2026/02 sets out which certification level satisfies which control level, and a certificate at a higher level satisfies everything beneath it. Certification is valid for three years with an annual attestation, and the Supplier Assurance Questionnaire still has to be completed and reviewed annually; the certificate is the evidence that goes with it.

What to do when DEFCON 658 appears in your contract

Five steps, in the order the MOD will check them.

1
Find the clause and the risk profile
DEFCON 658 will be listed in the contract conditions. The cyber risk profile and the risk assessment reference come from the contracting authority; ask for them if they are not in the pack.
2
Confirm what is in scope
Identify every system that will hold, process or transmit MOD identifiable information on this contract. The profile applies to that set of systems, which is usually smaller than your whole estate, and that is what your certificate has to cover.
3
Check your subcontractors are covered
Any subcontractor that touches the information inherits the requirement, and the contract makes you responsible for placing it on them. Ask for their certificate and their profile before you rely on them.
4
Certify at the level the profile asks for
Cyber Essentials for Level 0 and Level 1, Cyber Essentials Plus as the base for Levels 2 and 3. Once the certificate is in place, the Defence Cyber Certification assessment is carried out by an IASME body licensed for DCC. Our assessment process guide explains what happens after you submit your Cyber Essentials application.
5
Complete the questionnaire and diarise the anniversary
Submit the Supplier Assurance Questionnaire with the certificate as evidence, then set a reminder for the contract anniversary, when the MOD expects it reviewed, and for the annual DCC attestation.
Forensic Control logo

“A supplier holding and maintaining current, valid, DCC certification at a level equal to, or greater than, the commensurate level to the requirement, is to be considered in satisfaction of the control requirement.”

Ministry of Defence
Industry Security Notice 2026/02, 30 March 2026
What is DEFCON 658?
Which DEFCON applies if we process personal data on behalf of the MOD?
Do our subcontractors need Cyber Essentials under DEFCON 658?
Is Cyber Essentials Plus mandatory for defence contracts?
Does Defence Cyber Certification replace Cyber Essentials?
How much does defence cyber certification cost?

Talk to us before the contract anniversary, or before 31 December

We are an IASME Certification Body and certify defence suppliers remotely across the UK. We do not assess Defence Cyber Certification ourselves, but every DCC level starts with the Cyber Essentials certificate we do issue. Send us the DEFCON 658 clause and your risk profile and we can discuss what your contract needs.

Forensic Control
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.