Skip to content

Evidence request lists

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers

Evidence request list. 30 controls, 30 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Asset and Access

UKDEFSTD-2
Asset Management, Access Control, Cryptography

Per Def-Std 05-138: Asset Management + Access Control + Cryptography + Secure Configuration.

Artefacts an auditor will ask for
  • Def-Std 05-138 evidence for UKDEFSTD-2
Where this commonly fails
  • CRP + supply chain partial

Contractual Flow-Down and Scope

DEFSTAN-DEFCON658
DEFCON 658 Flow-Down to Supply Chain

DEFCON 658 requires suppliers to flow Def Stan 05-138 obligations through the supply chain to any subcontractor that will handle MOD Identifiable Information.

Artefacts an auditor will ask for
  • Master subcontract template containing DEFCON 658 clauses
  • Subcontractor flow-down register
  • Evidence of subcontractor Risk Profile assessments
  • Annual flow-down audit results
  • Variance log for suppliers refusing flow-down
  • Procurement training records covering DEFCON 658
Where this commonly fails
  • Flow-down clauses missing for legacy contracts
  • No subcontractor Risk Profile records
  • Procurement teams unaware of obligation
DEFSTAN-MIIDEF
Definition and Identification of MOD Identifiable Information

MOD Identifiable Information includes any information held under, or generated in connection with, a MOD contract that could damage UK defence interests if compromised.

Artefacts an auditor will ask for
  • Data classification policy referencing MOD definitions
  • Inventory of MOD Identifiable Information by contract
  • Labelling and marking standards
  • Aggregation risk assessment
  • Data discovery scan results
  • Disposal procedure for MOD data
Where this commonly fails
  • MOD data not labelled distinctly
  • Aggregation risk not assessed
  • Disposal procedure absent

Cyber Risk Profile

UKDEFSTD-1
Cyber Defence Cyber Risk Profile (CRP)

Per UK Defence Standard 05-138 + Cyber Defence Information Assurance Notice (DCDP): Cyber Risk Profile + Risk Assessment + applicability per CRP level.

Artefacts an auditor will ask for
  • Def-Std 05-138 evidence for UKDEFSTD-1
Where this commonly fails
  • CRP + supply chain partial

Cyber Risk Profile Levels

DEFSTAN-CHANGE
Risk Profile Change Management

Changes to contract scope, data handled, or processing environments may alter the Risk Profile and require re-assessment, with timely communication to the MOD.

Artefacts an auditor will ask for
  • Risk Profile change trigger criteria
  • Re-assessment evidence after scope change
  • Contract change notice register
  • Communication log with MOD Defence Authority
  • Internal change advisory board minutes
  • Risk acceptance records for transitional periods
Where this commonly fails
  • No trigger criteria
  • MOD not informed of scope changes
  • Transitional risk unrecorded
DEFSTAN-L0
Risk Profile L0 Not Applicable

L0 applies where no MOD Identifiable Information is processed and no additional cyber controls beyond standard contract terms are required.

Artefacts an auditor will ask for
  • Scope statement confirming no MOD Identifiable Information
  • Data classification check at contract award
  • Change control trigger for scope creep
  • Records of L0 contracts maintained for audit
  • Re-assessment evidence if scope changes
  • Communication to delivery team confirming L0
Where this commonly fails
  • L0 assumed without documented scope
  • Scope creep not detected
  • Records of L0 decision missing
DEFSTAN-L1
Risk Profile L1 Very Low

L1 requires the supplier to hold Cyber Essentials certification and apply the controls specified in Def Stan 05-138 Annex A at the L1 level.

Artefacts an auditor will ask for
  • Current Cyber Essentials certificate (within validity period)
  • Scope statement covering MOD-relevant systems
  • L1 control implementation evidence
  • Annual self-assessment record
  • Asset register covering in-scope systems
  • Boundary firewall and gateway configuration baselines
Where this commonly fails
  • Cyber Essentials scope excludes MOD systems
  • Certificate lapsed
  • Asset register out of date
DEFSTAN-L2
Risk Profile L2 Low

L2 requires Cyber Essentials Plus along with additional controls covering access management, malware protection, secure configuration, and event logging.

Artefacts an auditor will ask for
  • Current Cyber Essentials Plus certificate
  • CE+ technical audit report
  • Privileged access management evidence
  • Endpoint protection deployment coverage report
  • Secure configuration baselines (CIS or vendor hardening)
  • Centralised logging configuration
Where this commonly fails
  • CE Plus assessor scope partial
  • PAM not enforced for admins
  • Logging not centralised
DEFSTAN-L3
Risk Profile L3 Moderate

L3 requires the L2 baseline plus additional controls covering supply chain security, threat intelligence, vulnerability management, and incident response capability.

Artefacts an auditor will ask for
  • Vulnerability scanning schedule and reports
  • Remediation SLA tracker by severity
  • Threat intelligence subscription evidence
  • Supply chain risk register
  • Incident response plan tested in last 12 months
  • Penetration test report for in-scope systems
Where this commonly fails
  • Patch SLAs missed for criticals
  • Threat intelligence not actioned
  • IR plan untested
DEFSTAN-L4
Risk Profile L4 High

L4 adds controls including independent assurance of the security management system, secure development, advanced monitoring, and cryptographic key management.

Artefacts an auditor will ask for
  • ISO 27001 certificate or equivalent assurance evidence
  • Secure development lifecycle policy
  • SOC monitoring runbooks and use case catalogue
  • Cryptographic key management policy and HSM records
  • Third party security audit report
  • Annual board-level cyber security report
Where this commonly fails
  • ISO 27001 scope excludes MOD systems
  • Key management ad hoc
  • SOC use cases not tuned
DEFSTAN-L5
Risk Profile L5 Very High

L5 applies to contracts handling the most sensitive MOD information, requiring controls aligned with Cabinet Office Security Policy Framework and JSP 440, with active MOD oversight.

Artefacts an auditor will ask for
  • List X site approval or equivalent
  • JSP 440 alignment statement
  • Government Functional Standard GovS 007 compliance evidence
  • Vetting records for personnel (SC, DV)
  • Secret-tier handling procedures
  • MOD security inspection reports
Where this commonly fails
  • List X status not maintained
  • Personnel vetting expired
  • JSP 440 alignment partial
DEFSTAN-RP-ASSESS
Cyber Risk Profile Assessment via SCRA

Contracts are assessed using the Supplier Cyber Protection Service (Risk Assessment) to determine a Cyber Risk Profile from L0 (Not Applicable) to L5 (Very High).

Artefacts an auditor will ask for
  • SCRA submission record for each MOD contract
  • Risk Profile confirmation from Defence Authority
  • Bid stage assessment process and gates
  • Risk Profile register with contract IDs and CIDs
  • Annual re-assessment evidence
  • Internal challenge process for Risk Profile disputes
Where this commonly fails
  • SCRA reference numbers not retained
  • Risk Profile not re-validated annually
  • No internal challenge process

DEFSTAN 05-138 Section D: Minimising the Impact of Incidents

D.1
Incident Response Planning

The supplier must have capabilities to minimise the adverse impact of a cyber security incident on operations and data protection.

Artefacts an auditor will ask for
  • Incident response plan and runbook
  • Incident register with classification and timelines
  • Regulator notification templates and timestamps
  • Post-incident review reports with lessons learned
Where this commonly fails
  • Notification clock starts at detection, not initial signal
  • Roles in plan diverge from actual response
  • No tested tabletop within prior twelve months
  • Lessons learned not fed back into controls
D.2
Incident Reporting

The supplier must report cyber security incidents to MOD in accordance with contractual and regulatory requirements.

Artefacts an auditor will ask for
  • Incident response plan and runbook
  • Incident register with classification and timelines
  • Regulator notification templates and timestamps
  • Post-incident review reports with lessons learned
Where this commonly fails
  • Notification clock starts at detection, not initial signal
  • Roles in plan diverge from actual response
  • No tested tabletop within prior twelve months
  • Lessons learned not fed back into controls
D.3
Backup and Recovery

The supplier must maintain regular off-line backups of data off-site to enable recovery from cyber incidents.

Artefacts an auditor will ask for
  • Backup standard with RPO and RTO targets
  • Backup job logs across in-scope systems
  • Restore test reports with success evidence
  • Disaster recovery plan tested annually
Where this commonly fails
  • Restores never tested end to end
  • Immutable copy missing for ransomware scenarios
  • RPO and RTO not aligned to business impact
  • Offsite copy retention inadequate
D.4
Lessons Learned

The supplier must conduct post-incident reviews and incorporate lessons learned into security improvement programmes.

Artefacts an auditor will ask for
  • Documented procedure addressing lessons learned
  • Evidence of executive or risk owner approval
  • Operational records demonstrating execution
  • Independent assurance or review report
Where this commonly fails
  • Procedure exists but execution inconsistent
  • Owner accountability not codified
  • Review cadence missed or undocumented
  • Coverage gaps for in scope entities or systems

Incident

UKDEFSTD-4
Incident Response and Reporting

Per Def-Std 05-138: incident response + reporting to MOD + cooperation.

Artefacts an auditor will ask for
  • Def-Std 05-138 evidence for UKDEFSTD-4
Where this commonly fails
  • CRP + supply chain partial

Incident Reporting and Assurance

DEFSTAN-AUDIT
Assurance and Audit Evidence Maintenance

Suppliers must maintain auditable evidence of Def Stan 05-138 implementation and make it available to the MOD or its representatives on request.

Artefacts an auditor will ask for
  • Evidence library indexed against Def Stan 05-138 controls
  • Annual self-assessment outputs
  • Independent audit reports
  • Corrective action plan tracker
  • MOD inspection visit records
  • Document retention policy for assurance records
Where this commonly fails
  • Evidence not indexed to controls
  • Self-assessment skipped
  • Corrective actions not closed
DEFSTAN-INCIDENT-MODCERT
Incident Reporting to MOD via JSyCC

Suppliers must report cyber incidents involving MOD Identifiable Information to the MOD Joint Security Coordination Centre (JSyCC) and follow MOD investigation procedures.

Artefacts an auditor will ask for
  • Incident reporting procedure with JSyCC contact details
  • Escalation matrix specifying timeframes
  • Past incident reports submitted to JSyCC
  • Containment runbooks
  • Forensic readiness policy
  • Lessons learned register
Where this commonly fails
  • JSyCC contact not in procedure
  • Reporting timeframes ambiguous
  • Forensic readiness untested

Personnel and Physical Security

DEFSTAN-PERSONNEL
Personnel Security and Clearances

Personnel handling MOD Identifiable Information must hold the appropriate level of national security vetting and complete role-relevant security training.

Artefacts an auditor will ask for
  • Vetting register (BPSS, SC, DV) by role
  • Vetting renewal calendar
  • Insider risk awareness training records
  • Role-based security training matrix
  • Leaver clearance return procedures
  • Foreign national employment review process
Where this commonly fails
  • Vetting renewals overdue
  • Insider risk training absent
  • Leaver returns not tracked
DEFSTAN-PHYSICAL
Physical Security

Premises and equipment processing MOD Identifiable Information must be physically protected proportionate to Risk Profile, including reception controls, access logs, and secure rooms where required.

Artefacts an auditor will ask for
  • Physical security policy and zoning plan
  • Access control system records
  • CCTV configuration and retention
  • Visitor escort procedure
  • Secure room inspection records
  • Clear desk and screen audit results
Where this commonly fails
  • Visitor logs incomplete
  • Clear desk audits not done
  • Secure room inspections lapsed

Supply Chain

UKDEFSTD-3
Supply Chain Risk Management

Per Def-Std 05-138 + DCDP: Supply Chain Risk Management + flow-down to sub-contractors.

Artefacts an auditor will ask for
  • Def-Std 05-138 evidence for UKDEFSTD-3
Where this commonly fails
  • CRP + supply chain partial

Technical Controls

DEFSTAN-ACCESS
Access Control and Identity Management

Access to MOD Identifiable Information must be restricted to personnel with a genuine business need, appropriate clearance, and authenticated access.

Artefacts an auditor will ask for
  • Joiner mover leaver workflow with access reviews
  • Multi-factor authentication enforcement evidence
  • Privileged access management logs
  • Role-based access control matrix
  • Quarterly access recertification reports
  • Clearance status sync with HR
Where this commonly fails
  • MFA missing for VPN or admin
  • Recertification not performed
  • Clearance status not tracked
DEFSTAN-CONFIG
Secure Configuration and Hardening

Systems must be deployed using secure configurations, unnecessary services and ports must be disabled, and baselines must be maintained.

Artefacts an auditor will ask for
  • Hardening standards aligned to CIS Benchmarks or vendor guides
  • Configuration management database
  • Build-and-go templates for new systems
  • Drift detection reports
  • Default password change evidence
  • Cloud configuration posture management outputs
Where this commonly fails
  • No drift detection
  • Defaults left unchanged
  • Cloud posture untested
DEFSTAN-CRYPTO
Cryptography and Key Management

Cryptographic protection of MOD Identifiable Information at rest and in transit must use approved algorithms with strong key management aligned to MOD guidance.

Artefacts an auditor will ask for
  • Cryptographic standards policy aligned to NCSC and CAPS
  • Key management policy including rotation, escrow, destruction
  • HSM inventory and assurance evidence
  • Encryption coverage report for data at rest and in transit
  • Certificate management process
  • TLS configuration scan reports
Where this commonly fails
  • Self-signed certificates in production
  • Key rotation infrequent
  • Encryption coverage gaps
DEFSTAN-DEV
Secure Development and System Acquisition

Systems developed or acquired to process MOD Identifiable Information must follow secure development practices, including threat modelling, secure coding, and pre-deployment security testing.

Artefacts an auditor will ask for
  • Secure development lifecycle policy
  • Threat model artefacts for in-scope systems
  • Static and dynamic application security testing reports
  • Software composition analysis outputs
  • Pre-deployment security review sign-offs
  • Third party component assurance evidence
Where this commonly fails
  • No threat modelling
  • SAST/DAST not integrated to CI
  • Third party components unvetted
DEFSTAN-MALWARE
Malware Protection

Anti-malware protection must be deployed on systems processing MOD Identifiable Information, kept up to date, and monitored for incidents.

Artefacts an auditor will ask for
  • Endpoint protection platform deployment coverage
  • Signature and definition update cadence reports
  • EDR alert handling runbooks
  • Web and email filtering policies
  • USB and removable media controls
  • Quarterly anti-malware health report
Where this commonly fails
  • Coverage gaps on servers
  • EDR alerts not triaged
  • USB controls absent
DEFSTAN-MONITOR
Security Monitoring and Logging

Security-relevant events must be logged, centrally collected, and monitored for indicators of compromise relevant to MOD threat models.

Artefacts an auditor will ask for
  • Logging policy listing event types to capture
  • SIEM use case catalogue
  • Log retention schedule
  • Detection coverage assessment (MITRE ATT&CK)
  • Tuning records and false-positive rates
  • Out-of-hours monitoring coverage evidence
Where this commonly fails
  • Log coverage gaps
  • No out-of-hours monitoring
  • Detection rules not tuned
DEFSTAN-PATCH
Patch and Vulnerability Management

Operating systems, applications, and firmware must be patched within timescales appropriate to the severity of vulnerabilities and the Risk Profile of the contract.

Artefacts an auditor will ask for
  • Patch management policy with severity-based SLAs
  • Vulnerability scan and patch tracker
  • Emergency patching playbook
  • End-of-life software register with mitigations
  • Firmware update schedule
  • Patch exception register with risk acceptance
Where this commonly fails
  • EOL software still in use without mitigation
  • Patch SLAs missed for high severity
  • No firmware updates

Training

UKDEFSTD-5
Training, Audit, Continuous Improvement

Per Def-Std 05-138: training + audit + continuous improvement.

Artefacts an auditor will ask for
  • Def-Std 05-138 evidence for UKDEFSTD-5
Where this commonly fails
  • CRP + supply chain partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the UK Defence Standard 05-138 - Cyber Security for Defence Suppliers framework page.