By David Webb, Director at Forensic Control
DEFCON 658 is one of the Ministry of Defence’s standard contract conditions, and it carries the cyber security obligation. It is included in any contract, and any subcontract beneath it, where the supplier will hold, process or transmit MOD identifiable information. The condition does not set the controls itself. It points the supplier to the MOD’s Cyber Security Model, which was reinstated in its fourth version on 3 December 2025, and to the control standard behind it, Defence Standard 05-138 Issue 4.
The model works from a risk assessment carried out by the contracting authority. Each contract is given a cyber risk profile, and the profile sets the control level the supplier has to meet and evidence. The supplier records its position in a Supplier Assurance Questionnaire, which the MOD now requires to be reviewed every year on the anniversary of the contract. The obligation flows down: a prime contractor is responsible for placing the same requirement on any subcontractor that will handle the information.
Having spent 26 years in the armed forces before moving into corporate security, I would read DEFCON 658 as a description of what the MOD will check. The risk profile tells you the level, the standard tells you the controls, and the questionnaire is where you show your work. The quickest way through the first two levels is a certificate the MOD already recognises, and for those levels that certificate is Cyber Essentials.