/01Home
/02FAQ
/03Links

Bidding for MOD Contracts: Navigating DEFCON 658 & Cyber Essentials

Securing UK Ministry of Defence (MOD) contracts requires more than technical excellence and commercial competitiveness. It demands strict compliance with the MOD Cyber Security Model (CSM) and mandatory adherence to DEFCON 658 (Cyber Security).

Whether you are a Prime contractor delivering complex defense platforms or an SME supplying sub-components, failing to meet DEFCON 658 requirements during the tender phase results in immediate disqualification.

This comprehensive guide explains how the MOD Cyber Security Model operates, how to complete the Supplier Assurance Questionnaire (SAQ), how Cyber Essentials and Cyber Essentials Plus apply, and how capture leads must manage DEFCON 658 flow-down rules across their supply chain.


1.Overview of the MOD Cyber Security Model (CSM)

The MOD Cyber Security Model was developed under DEFCON 658 and DEFSTAN 05-138 (Cyber Security for Defence Suppliers) to protect MOD Identifiable Information (MODII) across the defense supply chain.

┌────────────────────────────────────────────────────────────────────────┐
│                   MOD CYBER SECURITY MODEL (CSM)                       │
├──────────────────────────┬─────────────────────────────────────────────┤
│   Cyber Risk Profiles    │          Mandatory Accreditation            │
├──────────────────────────┼─────────────────────────────────────────────┤
│ • Very Low               │ • Cyber Essentials Baseline                 │
│ • Low                    │ • Cyber Essentials Plus Verified            │
│ • Moderate               │ • Cyber Essentials Plus + ISO 27001         │
│ • High                   │ • Advanced Threat Protection & Continuous   │
└──────────────────────────┴─────────────────────────────────────────────┘

When the MOD issues a contract opportunity, the contracting officer conducts a Cyber Risk Assessment (CRA) using the MOD's Industry Security Notice (ISN) tools to assign a Cyber Risk Profile (CRP) to the procurement.


2.Cyber Risk Profiles (CRP) & Certification Requirements

The assigned Cyber Risk Profile determines the exact cybersecurity controls, certifications, and assurance tasks required of the winning bidder:

Cyber Risk Profile (CRP)Typical Contract NatureCertification RequiredKey Technical Controls
Very LowStandard non-sensitive commercial off-the-shelf (COTS) goods.Cyber Essentials (Self-Assessment)Basic firewalls, patch management, access controls.
LowServices handling limited MODII or non-classified technical data.Cyber Essentials Plus (Audited)Multi-Factor Authentication (MFA), vulnerability scanning, malware defense.
ModerateDefense IT networks, sensitive logistics, equipment maintenance.Cyber Essentials Plus + DEFSTAN 05-138Endpoint detection, audit logging, security incident response plan.
HighCritical national infrastructure, weapons systems, classified intelligence.Cyber Essentials Plus + Bespoke MOD AccreditationAir-gapped networks, encrypted communications, 24/7 SOC monitoring.

3.The 4-Step DEFCON 658 Bidding Process

To ensure compliance during tender submission, capture teams must follow a structured 4-step process:

Step 1: Obtain RAR Reference  ──►  Step 2: Complete Supplier SAQ  ──►  Step 3: Audit Sub-Tier Primes  ──►  Step 4: Submit Cyber Plan

Step 1: Obtain the Risk Assessment Reference (RAR)

The MOD tender documentation will specify a unique Risk Assessment Reference (RAR) number generated by the MOD Cyber Risk Assessment tool.

Step 2: Complete the Supplier Assurance Questionnaire (SAQ)

Using the RAR number, the bidder must access the MOD's Supplier Cyber Protection Service portal and complete the Supplier Assurance Questionnaire (SAQ). The SAQ measures your organization's compliance against the specific controls required for that CRP.

Step 3: Sub-Contractor Flow-Down Audit

Under DEFCON 658, Primes are legally responsible for flowing down cybersecurity requirements to all sub-contractors. You must evaluate your supply chain and require each sub-tier vendor to complete their own SAQ.

Step 4: Submit Cyber Implementation Plan (CIP)

If your organization or sub-contractors do not fully meet the required CRP controls at the time of bid submission, you must submit a Cyber Implementation Plan (CIP) outlining how compliance will be achieved prior to contract award.


4.Common DEFCON 658 Pitfalls for Bidders

  1. Underestimating Flow-Down Timelines: Waiting until RFP submission to audit sub-tier suppliers often leads to non-compliant bids if a sub-contractor lacks Cyber Essentials Plus.
  2. Ignoring Cloud Storage Limits: Storing MODII on non-approved commercial cloud platforms (e.g. standard public dropboxes) violates DEFSTAN 05-138 controls.
  3. Miscalculating Implementation Costs: Achieving Cyber Essentials Plus certification and deploying technical controls (e.g. SOC monitoring) can carry significant costs that must be factored into your baseline cost model.

5.Summary & Key Takeaways

  • DEFCON 658 Is Mandatory: All UK MOD tenders handling MODII require compliance with the Cyber Security Model.
  • CRP Determines Requirements: Certification ranges from Cyber Essentials (Very Low risk) to Cyber Essentials Plus and bespoke DEFSTAN 05-138 audits (Moderate/High risk).
  • Flow-Down Is Legally Binding: Primes must audit and enforce DEFCON 658 across all sub-tier suppliers.

Explore Stratify's tools for defense bidding and compliance:

Continuous Intelligence

Related Operational Briefings

View All Briefings