UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Asset and Access
Per Def-Std 05-138: Asset Management + Access Control + Cryptography + Secure Configuration.
- Def-Std 05-138 evidence for UKDEFSTD-2
- CRP + supply chain partial
Contractual Flow-Down and Scope
DEFCON 658 requires suppliers to flow Def Stan 05-138 obligations through the supply chain to any subcontractor that will handle MOD Identifiable Information.
- Master subcontract template containing DEFCON 658 clauses
- Subcontractor flow-down register
- Evidence of subcontractor Risk Profile assessments
- Annual flow-down audit results
- Variance log for suppliers refusing flow-down
- Procurement training records covering DEFCON 658
- Flow-down clauses missing for legacy contracts
- No subcontractor Risk Profile records
- Procurement teams unaware of obligation
MOD Identifiable Information includes any information held under, or generated in connection with, a MOD contract that could damage UK defence interests if compromised.
- Data classification policy referencing MOD definitions
- Inventory of MOD Identifiable Information by contract
- Labelling and marking standards
- Aggregation risk assessment
- Data discovery scan results
- Disposal procedure for MOD data
- MOD data not labelled distinctly
- Aggregation risk not assessed
- Disposal procedure absent
Cyber Risk Profile
Per UK Defence Standard 05-138 + Cyber Defence Information Assurance Notice (DCDP): Cyber Risk Profile + Risk Assessment + applicability per CRP level.
- Def-Std 05-138 evidence for UKDEFSTD-1
- CRP + supply chain partial
Cyber Risk Profile Levels
Changes to contract scope, data handled, or processing environments may alter the Risk Profile and require re-assessment, with timely communication to the MOD.
- Risk Profile change trigger criteria
- Re-assessment evidence after scope change
- Contract change notice register
- Communication log with MOD Defence Authority
- Internal change advisory board minutes
- Risk acceptance records for transitional periods
- No trigger criteria
- MOD not informed of scope changes
- Transitional risk unrecorded
L0 applies where no MOD Identifiable Information is processed and no additional cyber controls beyond standard contract terms are required.
- Scope statement confirming no MOD Identifiable Information
- Data classification check at contract award
- Change control trigger for scope creep
- Records of L0 contracts maintained for audit
- Re-assessment evidence if scope changes
- Communication to delivery team confirming L0
- L0 assumed without documented scope
- Scope creep not detected
- Records of L0 decision missing
L1 requires the supplier to hold Cyber Essentials certification and apply the controls specified in Def Stan 05-138 Annex A at the L1 level.
- Current Cyber Essentials certificate (within validity period)
- Scope statement covering MOD-relevant systems
- L1 control implementation evidence
- Annual self-assessment record
- Asset register covering in-scope systems
- Boundary firewall and gateway configuration baselines
- Cyber Essentials scope excludes MOD systems
- Certificate lapsed
- Asset register out of date
L2 requires Cyber Essentials Plus along with additional controls covering access management, malware protection, secure configuration, and event logging.
- Current Cyber Essentials Plus certificate
- CE+ technical audit report
- Privileged access management evidence
- Endpoint protection deployment coverage report
- Secure configuration baselines (CIS or vendor hardening)
- Centralised logging configuration
- CE Plus assessor scope partial
- PAM not enforced for admins
- Logging not centralised
L3 requires the L2 baseline plus additional controls covering supply chain security, threat intelligence, vulnerability management, and incident response capability.
- Vulnerability scanning schedule and reports
- Remediation SLA tracker by severity
- Threat intelligence subscription evidence
- Supply chain risk register
- Incident response plan tested in last 12 months
- Penetration test report for in-scope systems
- Patch SLAs missed for criticals
- Threat intelligence not actioned
- IR plan untested
L4 adds controls including independent assurance of the security management system, secure development, advanced monitoring, and cryptographic key management.
- ISO 27001 certificate or equivalent assurance evidence
- Secure development lifecycle policy
- SOC monitoring runbooks and use case catalogue
- Cryptographic key management policy and HSM records
- Third party security audit report
- Annual board-level cyber security report
- ISO 27001 scope excludes MOD systems
- Key management ad hoc
- SOC use cases not tuned
L5 applies to contracts handling the most sensitive MOD information, requiring controls aligned with Cabinet Office Security Policy Framework and JSP 440, with active MOD oversight.
- List X site approval or equivalent
- JSP 440 alignment statement
- Government Functional Standard GovS 007 compliance evidence
- Vetting records for personnel (SC, DV)
- Secret-tier handling procedures
- MOD security inspection reports
- List X status not maintained
- Personnel vetting expired
- JSP 440 alignment partial
Contracts are assessed using the Supplier Cyber Protection Service (Risk Assessment) to determine a Cyber Risk Profile from L0 (Not Applicable) to L5 (Very High).
- SCRA submission record for each MOD contract
- Risk Profile confirmation from Defence Authority
- Bid stage assessment process and gates
- Risk Profile register with contract IDs and CIDs
- Annual re-assessment evidence
- Internal challenge process for Risk Profile disputes
- SCRA reference numbers not retained
- Risk Profile not re-validated annually
- No internal challenge process
DEFSTAN 05-138 Section D: Minimising the Impact of Incidents
The supplier must have capabilities to minimise the adverse impact of a cyber security incident on operations and data protection.
- Incident response plan and runbook
- Incident register with classification and timelines
- Regulator notification templates and timestamps
- Post-incident review reports with lessons learned
- Notification clock starts at detection, not initial signal
- Roles in plan diverge from actual response
- No tested tabletop within prior twelve months
- Lessons learned not fed back into controls
The supplier must report cyber security incidents to MOD in accordance with contractual and regulatory requirements.
- Incident response plan and runbook
- Incident register with classification and timelines
- Regulator notification templates and timestamps
- Post-incident review reports with lessons learned
- Notification clock starts at detection, not initial signal
- Roles in plan diverge from actual response
- No tested tabletop within prior twelve months
- Lessons learned not fed back into controls
The supplier must maintain regular off-line backups of data off-site to enable recovery from cyber incidents.
- Backup standard with RPO and RTO targets
- Backup job logs across in-scope systems
- Restore test reports with success evidence
- Disaster recovery plan tested annually
- Restores never tested end to end
- Immutable copy missing for ransomware scenarios
- RPO and RTO not aligned to business impact
- Offsite copy retention inadequate
The supplier must conduct post-incident reviews and incorporate lessons learned into security improvement programmes.
- Documented procedure addressing lessons learned
- Evidence of executive or risk owner approval
- Operational records demonstrating execution
- Independent assurance or review report
- Procedure exists but execution inconsistent
- Owner accountability not codified
- Review cadence missed or undocumented
- Coverage gaps for in scope entities or systems
Incident
Per Def-Std 05-138: incident response + reporting to MOD + cooperation.
- Def-Std 05-138 evidence for UKDEFSTD-4
- CRP + supply chain partial
Incident Reporting and Assurance
Suppliers must maintain auditable evidence of Def Stan 05-138 implementation and make it available to the MOD or its representatives on request.
- Evidence library indexed against Def Stan 05-138 controls
- Annual self-assessment outputs
- Independent audit reports
- Corrective action plan tracker
- MOD inspection visit records
- Document retention policy for assurance records
- Evidence not indexed to controls
- Self-assessment skipped
- Corrective actions not closed
Suppliers must report cyber incidents involving MOD Identifiable Information to the MOD Joint Security Coordination Centre (JSyCC) and follow MOD investigation procedures.
- Incident reporting procedure with JSyCC contact details
- Escalation matrix specifying timeframes
- Past incident reports submitted to JSyCC
- Containment runbooks
- Forensic readiness policy
- Lessons learned register
- JSyCC contact not in procedure
- Reporting timeframes ambiguous
- Forensic readiness untested
Personnel and Physical Security
Personnel handling MOD Identifiable Information must hold the appropriate level of national security vetting and complete role-relevant security training.
- Vetting register (BPSS, SC, DV) by role
- Vetting renewal calendar
- Insider risk awareness training records
- Role-based security training matrix
- Leaver clearance return procedures
- Foreign national employment review process
- Vetting renewals overdue
- Insider risk training absent
- Leaver returns not tracked
Premises and equipment processing MOD Identifiable Information must be physically protected proportionate to Risk Profile, including reception controls, access logs, and secure rooms where required.
- Physical security policy and zoning plan
- Access control system records
- CCTV configuration and retention
- Visitor escort procedure
- Secure room inspection records
- Clear desk and screen audit results
- Visitor logs incomplete
- Clear desk audits not done
- Secure room inspections lapsed
Supply Chain
Per Def-Std 05-138 + DCDP: Supply Chain Risk Management + flow-down to sub-contractors.
- Def-Std 05-138 evidence for UKDEFSTD-3
- CRP + supply chain partial
Technical Controls
Access to MOD Identifiable Information must be restricted to personnel with a genuine business need, appropriate clearance, and authenticated access.
- Joiner mover leaver workflow with access reviews
- Multi-factor authentication enforcement evidence
- Privileged access management logs
- Role-based access control matrix
- Quarterly access recertification reports
- Clearance status sync with HR
- MFA missing for VPN or admin
- Recertification not performed
- Clearance status not tracked
Systems must be deployed using secure configurations, unnecessary services and ports must be disabled, and baselines must be maintained.
- Hardening standards aligned to CIS Benchmarks or vendor guides
- Configuration management database
- Build-and-go templates for new systems
- Drift detection reports
- Default password change evidence
- Cloud configuration posture management outputs
- No drift detection
- Defaults left unchanged
- Cloud posture untested
Cryptographic protection of MOD Identifiable Information at rest and in transit must use approved algorithms with strong key management aligned to MOD guidance.
- Cryptographic standards policy aligned to NCSC and CAPS
- Key management policy including rotation, escrow, destruction
- HSM inventory and assurance evidence
- Encryption coverage report for data at rest and in transit
- Certificate management process
- TLS configuration scan reports
- Self-signed certificates in production
- Key rotation infrequent
- Encryption coverage gaps
Systems developed or acquired to process MOD Identifiable Information must follow secure development practices, including threat modelling, secure coding, and pre-deployment security testing.
- Secure development lifecycle policy
- Threat model artefacts for in-scope systems
- Static and dynamic application security testing reports
- Software composition analysis outputs
- Pre-deployment security review sign-offs
- Third party component assurance evidence
- No threat modelling
- SAST/DAST not integrated to CI
- Third party components unvetted
Anti-malware protection must be deployed on systems processing MOD Identifiable Information, kept up to date, and monitored for incidents.
- Endpoint protection platform deployment coverage
- Signature and definition update cadence reports
- EDR alert handling runbooks
- Web and email filtering policies
- USB and removable media controls
- Quarterly anti-malware health report
- Coverage gaps on servers
- EDR alerts not triaged
- USB controls absent
Security-relevant events must be logged, centrally collected, and monitored for indicators of compromise relevant to MOD threat models.
- Logging policy listing event types to capture
- SIEM use case catalogue
- Log retention schedule
- Detection coverage assessment (MITRE ATT&CK)
- Tuning records and false-positive rates
- Out-of-hours monitoring coverage evidence
- Log coverage gaps
- No out-of-hours monitoring
- Detection rules not tuned
Operating systems, applications, and firmware must be patched within timescales appropriate to the severity of vulnerabilities and the Risk Profile of the contract.
- Patch management policy with severity-based SLAs
- Vulnerability scan and patch tracker
- Emergency patching playbook
- End-of-life software register with mitigations
- Firmware update schedule
- Patch exception register with risk acceptance
- EOL software still in use without mitigation
- Patch SLAs missed for high severity
- No firmware updates
Training
Per Def-Std 05-138: training + audit + continuous improvement.
- Def-Std 05-138 evidence for UKDEFSTD-5
- CRP + supply chain partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Defence Standard 05-138 - Cyber Security for Defence Suppliers framework page.