Bidding for MOD Contracts: Navigating DEFCON 658 & Cyber Essentials
Securing UK Ministry of Defence (MOD) contracts requires more than technical excellence and commercial competitiveness. It demands strict compliance with the MOD Cyber Security Model (CSM) and mandatory adherence to DEFCON 658 (Cyber Security).
Whether you are a Prime contractor delivering complex defense platforms or an SME supplying sub-components, failing to meet DEFCON 658 requirements during the tender phase results in immediate disqualification.
This comprehensive guide explains how the MOD Cyber Security Model operates, how to complete the Supplier Assurance Questionnaire (SAQ), how Cyber Essentials and Cyber Essentials Plus apply, and how capture leads must manage DEFCON 658 flow-down rules across their supply chain.
1.Overview of the MOD Cyber Security Model (CSM)
The MOD Cyber Security Model was developed under DEFCON 658 and DEFSTAN 05-138 (Cyber Security for Defence Suppliers) to protect MOD Identifiable Information (MODII) across the defense supply chain.
┌────────────────────────────────────────────────────────────────────────┐
│ MOD CYBER SECURITY MODEL (CSM) │
├──────────────────────────┬─────────────────────────────────────────────┤
│ Cyber Risk Profiles │ Mandatory Accreditation │
├──────────────────────────┼─────────────────────────────────────────────┤
│ • Very Low │ • Cyber Essentials Baseline │
│ • Low │ • Cyber Essentials Plus Verified │
│ • Moderate │ • Cyber Essentials Plus + ISO 27001 │
│ • High │ • Advanced Threat Protection & Continuous │
└──────────────────────────┴─────────────────────────────────────────────┘
When the MOD issues a contract opportunity, the contracting officer conducts a Cyber Risk Assessment (CRA) using the MOD's Industry Security Notice (ISN) tools to assign a Cyber Risk Profile (CRP) to the procurement.
2.Cyber Risk Profiles (CRP) & Certification Requirements
The assigned Cyber Risk Profile determines the exact cybersecurity controls, certifications, and assurance tasks required of the winning bidder:
| Cyber Risk Profile (CRP) | Typical Contract Nature | Certification Required | Key Technical Controls |
|---|---|---|---|
| Very Low | Standard non-sensitive commercial off-the-shelf (COTS) goods. | Cyber Essentials (Self-Assessment) | Basic firewalls, patch management, access controls. |
| Low | Services handling limited MODII or non-classified technical data. | Cyber Essentials Plus (Audited) | Multi-Factor Authentication (MFA), vulnerability scanning, malware defense. |
| Moderate | Defense IT networks, sensitive logistics, equipment maintenance. | Cyber Essentials Plus + DEFSTAN 05-138 | Endpoint detection, audit logging, security incident response plan. |
| High | Critical national infrastructure, weapons systems, classified intelligence. | Cyber Essentials Plus + Bespoke MOD Accreditation | Air-gapped networks, encrypted communications, 24/7 SOC monitoring. |
3.The 4-Step DEFCON 658 Bidding Process
To ensure compliance during tender submission, capture teams must follow a structured 4-step process:
Step 1: Obtain RAR Reference ──► Step 2: Complete Supplier SAQ ──► Step 3: Audit Sub-Tier Primes ──► Step 4: Submit Cyber Plan
Step 1: Obtain the Risk Assessment Reference (RAR)
The MOD tender documentation will specify a unique Risk Assessment Reference (RAR) number generated by the MOD Cyber Risk Assessment tool.
Step 2: Complete the Supplier Assurance Questionnaire (SAQ)
Using the RAR number, the bidder must access the MOD's Supplier Cyber Protection Service portal and complete the Supplier Assurance Questionnaire (SAQ). The SAQ measures your organization's compliance against the specific controls required for that CRP.
Step 3: Sub-Contractor Flow-Down Audit
Under DEFCON 658, Primes are legally responsible for flowing down cybersecurity requirements to all sub-contractors. You must evaluate your supply chain and require each sub-tier vendor to complete their own SAQ.
Step 4: Submit Cyber Implementation Plan (CIP)
If your organization or sub-contractors do not fully meet the required CRP controls at the time of bid submission, you must submit a Cyber Implementation Plan (CIP) outlining how compliance will be achieved prior to contract award.
4.Common DEFCON 658 Pitfalls for Bidders
- Underestimating Flow-Down Timelines: Waiting until RFP submission to audit sub-tier suppliers often leads to non-compliant bids if a sub-contractor lacks Cyber Essentials Plus.
- Ignoring Cloud Storage Limits: Storing MODII on non-approved commercial cloud platforms (e.g. standard public dropboxes) violates DEFSTAN 05-138 controls.
- Miscalculating Implementation Costs: Achieving Cyber Essentials Plus certification and deploying technical controls (e.g. SOC monitoring) can carry significant costs that must be factored into your baseline cost model.
5.Summary & Key Takeaways
- DEFCON 658 Is Mandatory: All UK MOD tenders handling MODII require compliance with the Cyber Security Model.
- CRP Determines Requirements: Certification ranges from Cyber Essentials (Very Low risk) to Cyber Essentials Plus and bespoke DEFSTAN 05-138 audits (Moderate/High risk).
- Flow-Down Is Legally Binding: Primes must audit and enforce DEFCON 658 across all sub-tier suppliers.
Explore Stratify's tools for defense bidding and compliance:
- Defense Standards Directory – Inspect DEFCON 658, Cyber Essentials, and NIST SP 800-171 standards.
- Global Taxonomy Crosswalk Engine – Cross-reference DEFCON standards with CPV and NATO Stock Numbers.
- PWIN Calculator – Evaluate risk factors and competitive positioning for MOD pursuits.
Related Operational Briefings
Resilient Supply Chains in Volatile Geopolitics
Adapting procurement strategies to maintain stability in a rapidly shifting international landscape.
AI in UK Procurement: Buyer & Bidder Insights
How AI is revolutionising government entities and the supply chain, including critical regulatory updates like PPN 017.
The Future of AI-Driven Capture Management
Discover how machine learning is reshaping the way firms identify and win high-value strategic contracts.