Def Stan 05-138

Def Stan 05-138 and the four Cyber Risk Profile levels

The control set behind DEFCON 658 — what a supplier must actually hold at Level 0, 1, 2 and 3, and where Cyber Essentials fits.

Issue 4 was published on 23 May 2024 and last updated on 3 December 2025. It replaced five Cyber Risk Profiles — N/A, Very Low, Low, Moderate, High — with four: Level 0 to Level 3. CSM v3 profiles are not consistent with CSM v4, so a supplier working from the older vocabulary is describing a regime that no longer exists.

Why this reaches the test bench

DEFCON 658 is the contract condition that makes cyber requirements flow down the supply chain. Def Stan 05-138 is the document that says what you must actually have. A test system delivered into a defence programme sits inside both, and the controls land mostly on the delivered software and the test executive rather than on the power hardware.

What gets tested

  • Level 0 'Basic' — 3 controls, for a very low assessed cyber risk
  • Level 1 'Foundational' — 101 controls
  • Level 2 'Advanced' — 139 controls
  • Level 3 'Expert' — 144 controls

Also current

Control 0001 requires Cyber Essentials certification at EVERY level, 0 through 3. Control 0002 requires Cyber Essentials Plus at Levels 2 and 3 only. That single distinction is the one most often got wrong, and it is the difference between a certificate you can self-assess and one that is independently audited.

A document you can actually read

Def Stan 05-138 Issue 4 is free, public and citable on GOV.UK — 37 pages, published 23 May 2024.

How this differs from the American regime

The American analogue is DFARS 252.204-7012 with NIST SP 800-171 and CMMC — a different clause, a different control catalogue and a different certificate. The MOD publishes a mapping document between Def Stan 05-138 and NIST, ISO 27001 and Cyber Essentials, so existing evidence can be reused rather than rebuilt.

Careful

The assigned Cyber Risk Profile — not your own internal risk assessment — determines the minimum controls. The level is set by the MOD delivery team and arrives with the opportunity as a Risk Assessment Reference. A supplier who self-assesses to a level nobody assigned them has assessed the wrong thing.

Sources