Back to Frameworks

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers

United Kingdom (MOD)
vIssue 3 (2024)
5 domains
5 controls

UK Defence Standard 05-138 establishes cyber security requirements for organisations in the UK defence supply chain. Mandated by the Ministry of Defence (MOD) for contracts handling MOD information and systems. Issue 3 (2024) aligns with NCSC Cyber Essentials Plus and the MOD Cyber Security Model. Requirements cover: organisational security, asset management, access control, cryptography, physical security, operations security, communications security, supply chain security, incident management, and business continuity. Suppliers must achieve Cyber Essentials Plus certification as a minimum, with enhanced requirements for higher-sensitivity contracts.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

Asset and Access

1 controls
Controls in the Asset and Access domain of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers1 controls
CodeTitle
UKDEFSTD-2Asset Management, Access Control, Cryptography

Cyber Risk Profile

1 controls
Controls in the Cyber Risk Profile domain of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers1 controls
CodeTitle
UKDEFSTD-1Cyber Defence Cyber Risk Profile (CRP)

Incident

1 controls
Controls in the Incident domain of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers1 controls
CodeTitle
UKDEFSTD-4Incident Response and Reporting

Supply Chain

1 controls
Controls in the Supply Chain domain of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers1 controls
CodeTitle
UKDEFSTD-3Supply Chain Risk Management

Training

1 controls
Controls in the Training domain of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers1 controls
CodeTitle
UKDEFSTD-5Training, Audit, Continuous Improvement

Your Compliance Coverage

If you comply with UK Defence Standard 05-138 - Cyber Security for Defence Suppliers, you already cover:

Maps to 156 other frameworks

5 total controls
ISO 27701:2019
1 source controls mapped|1 target controls covered
20%
OECD AI Principles
1 source controls mapped|2 target controls covered
20%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|2 target controls covered
20%
ISO/IEC 27011:2024
1 source controls mapped|2 target controls covered
20%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|5 target controls covered
20%
FDA 21 CFR Part 11
1 source controls mapped|2 target controls covered
20%
FIRST CSIRT Services Framework and Standards
1 source controls mapped|1 target controls covered
20%
IATA Operational Safety Audit (IOSA) Standards Manual
1 source controls mapped|1 target controls covered
20%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|2 target controls covered
20%
MARS-E
1 source controls mapped|2 target controls covered
20%
MDS2 (Medical Device)
1 source controls mapped|2 target controls covered
20%
NIST SP 800-66
1 source controls mapped|2 target controls covered
20%
Oman National Cybersecurity Framework
1 source controls mapped|1 target controls covered
20%
OWASP DevSecOps Maturity Model (DSOMM)
1 source controls mapped|3 target controls covered
20%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|1 target controls covered
20%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
20%
ASIS SPC.1-2009 - Organizational Resilience Standard
1 source controls mapped|1 target controls covered
20%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|7 target controls covered
20%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
20%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
20%
ISO/IEC 27031:2011
1 source controls mapped|1 target controls covered
20%
FATF Recommendation 16 - Virtual Asset Travel Rule
1 source controls mapped|1 target controls covered
20%
20%
FedRAMP Rev 5
1 source controls mapped|2 target controls covered
20%
Family Educational Rights and Privacy Act (FERPA)
1 source controls mapped|1 target controls covered
20%
FISMA
1 source controls mapped|3 target controls covered
20%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
20%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|2 target controls covered
20%
FSSC 22000 - Food Safety System Certification
1 source controls mapped|1 target controls covered
20%
FTC GLBA Safeguards Rule (16 CFR Part 314)
1 source controls mapped|4 target controls covered
20%
Ghana Cybersecurity Act
1 source controls mapped|2 target controls covered
20%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|3 target controls covered
20%
20%
IEEE 1686
1 source controls mapped|4 target controls covered
20%
India CERT-In Cyber Security Directions 2022
1 source controls mapped|1 target controls covered
20%
India DPDP Act
1 source controls mapped|1 target controls covered
20%
Indiana Consumer Data Protection Act
1 source controls mapped|1 target controls covered
20%
Indonesia PDP Law
1 source controls mapped|1 target controls covered
20%
Iowa Consumer Data Protection Act
1 source controls mapped|1 target controls covered
20%
ISMAP (Japan)
1 source controls mapped|1 target controls covered
20%
Jamaica Data Protection Act 2020
1 source controls mapped|1 target controls covered
20%
Japan AI Guidelines
1 source controls mapped|4 target controls covered
20%
Kentucky Consumer Data Protection Act
1 source controls mapped|1 target controls covered
20%
South Korea PIPA
1 source controls mapped|1 target controls covered
20%
Law No. 172-13 on the Protection of Personal Data
1 source controls mapped|1 target controls covered
20%
Ley Orgánica de Protección de Datos Personales (LOPDP)
1 source controls mapped|1 target controls covered
20%
LGPD
1 source controls mapped|1 target controls covered
20%
Liechtenstein DPA
1 source controls mapped|1 target controls covered
20%
Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
1 source controls mapped|2 target controls covered
20%
Malaysia PDPA 2010
1 source controls mapped|1 target controls covered
20%
Maryland Online Data Privacy Act of 2024
1 source controls mapped|1 target controls covered
20%
Mauritius DPA
1 source controls mapped|1 target controls covered
20%
Mexico LFPDPPP
1 source controls mapped|1 target controls covered
20%
Minnesota Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
20%
Montana Consumer Data Privacy Act
1 source controls mapped|1 target controls covered
20%
NAIC Insurance Data Security Model Law (MDL-668)
1 source controls mapped|2 target controls covered
20%
Nebraska Data Privacy Act
1 source controls mapped|2 target controls covered
20%
Nevada Gaming Control Board Cybersecurity Requirements
1 source controls mapped|3 target controls covered
20%
New Hampshire Data Privacy Act
1 source controls mapped|1 target controls covered
20%
New Jersey Data Privacy Act
1 source controls mapped|1 target controls covered
20%
New Zealand Information Security Manual (NZISM)
1 source controls mapped|2 target controls covered
20%
Nigeria Data Protection Act 2023 (NDPA)
1 source controls mapped|2 target controls covered
20%
Nigeria Data Protection Regulation (NDPR)
1 source controls mapped|1 target controls covered
20%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
20%
NIST SP 800-122
1 source controls mapped|1 target controls covered
20%
NIST SP 800-144
1 source controls mapped|1 target controls covered
20%
NIST SP 800-145
1 source controls mapped|1 target controls covered
20%
NIST SP 800-146
1 source controls mapped|1 target controls covered
20%
NIST SP 800-30
1 source controls mapped|6 target controls covered
20%
NIST SP 800-37
1 source controls mapped|4 target controls covered
20%
NIST SP 800-39
1 source controls mapped|3 target controls covered
20%
Oregon Consumer Privacy Act
1 source controls mapped|1 target controls covered
20%
Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
1 source controls mapped|2 target controls covered
20%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
20%
PDPA Singapore
1 source controls mapped|1 target controls covered
20%
PDPA Thailand
1 source controls mapped|1 target controls covered
20%
Personal Data Act (personopplysningsloven)
1 source controls mapped|1 target controls covered
20%
POPIA
1 source controls mapped|1 target controls covered
20%
Privacy Act 1988 (Australia)
1 source controls mapped|1 target controls covered
20%
Privacy Act 2020
1 source controls mapped|1 target controls covered
20%
Qatar DPL
1 source controls mapped|1 target controls covered
20%
Taiwan PDPA
1 source controls mapped|1 target controls covered
20%
Texas Data Privacy Act
1 source controls mapped|1 target controls covered
20%
TSA Pipeline Cybersecurity Directives
1 source controls mapped|1 target controls covered
20%
Turkey KVKK
1 source controls mapped|1 target controls covered
20%
UK GDPR (UK General Data Protection Regulation)
1 source controls mapped|1 target controls covered
20%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|2 target controls covered
20%
ISO/IEC 27010:2015
1 source controls mapped|2 target controls covered
20%
MITRE ATT&CK
1 source controls mapped|2 target controls covered
20%
MITRE D3FEND
1 source controls mapped|2 target controls covered
20%
NIS2 Directive Implementing Acts
1 source controls mapped|2 target controls covered
20%
NIST SP 800-123
1 source controls mapped|1 target controls covered
20%
NIST SP 800-137
1 source controls mapped|1 target controls covered
20%
NIST SP 800-61
1 source controls mapped|3 target controls covered
20%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
20%
NIST SP 800-88
1 source controls mapped|2 target controls covered
20%
NIST SP 800-92
1 source controls mapped|2 target controls covered
20%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
20%
OWASP ASVS
1 source controls mapped|1 target controls covered
20%
OWASP MASVS
1 source controls mapped|1 target controls covered
20%
OWASP SAMM
1 source controls mapped|2 target controls covered
20%
PTES
1 source controls mapped|1 target controls covered
20%
SIG (Shared Assessments)
1 source controls mapped|2 target controls covered
20%
Sigstore - Software Artifact Signing and Verification
1 source controls mapped|1 target controls covered
20%
SLSA
1 source controls mapped|1 target controls covered
20%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|2 target controls covered
20%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|3 target controls covered
20%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|2 target controls covered
20%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|1 target controls covered
20%
20%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
20%
GAMP 5 - Good Automated Manufacturing Practice
1 source controls mapped|1 target controls covered
20%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|3 target controls covered
20%
GLBA
1 source controls mapped|1 target controls covered
20%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
20%
Global Cross-Border Privacy Rules (Global CBPR) Forum
1 source controls mapped|1 target controls covered
20%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|1 target controls covered
20%
GS1 Global Standards - Supply Chain Traceability and Data Security
1 source controls mapped|2 target controls covered
20%
HKMA Cyber Resilience Assessment Framework (C-RAF)
1 source controls mapped|2 target controls covered
20%
HKMA SPM
1 source controls mapped|1 target controls covered
20%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|2 target controls covered
20%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|1 target controls covered
20%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|2 target controls covered
20%
ICMM Mining Principles (2024 Update)
1 source controls mapped|1 target controls covered
20%
IEEE 7000
1 source controls mapped|2 target controls covered
20%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
1 source controls mapped|2 target controls covered
20%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|2 target controls covered
20%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
20%
MTCS (Singapore)
1 source controls mapped|1 target controls covered
20%
NERC CIP
1 source controls mapped|2 target controls covered
20%
NIS2 Directive
1 source controls mapped|3 target controls covered
20%
NIST Privacy Framework
1 source controls mapped|3 target controls covered
20%
20%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
1 source controls mapped|2 target controls covered
20%
O-RAN WG11 Security Specification
1 source controls mapped|1 target controls covered
20%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|2 target controls covered
20%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
20%
SEC Climate Disclosure Rule
1 source controls mapped|1 target controls covered
20%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
20%
SASB Standards
1 source controls mapped|2 target controls covered
20%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
20%
PSD2 SCA
1 source controls mapped|2 target controls covered
20%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|2 target controls covered
20%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
20%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|1 target controls covered
20%
OSFI B-13
1 source controls mapped|2 target controls covered
20%
Open Banking Security
1 source controls mapped|1 target controls covered
20%
OECD Recommendation on Artificial Intelligence (2024 Update)
1 source controls mapped|1 target controls covered
20%

Frequently Asked Questions

What is UK Defence Standard 05-138 - Cyber Security for Defence Suppliers?

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers is a compliance framework from United Kingdom (MOD) with 5 domains and 5 controls. UK Defence Standard 05-138 establishes cyber security requirements for organisations in the UK defence supply chain. Mandated by the Ministry of Defence (MOD) for contracts handling MOD information and systems. Issue 3 (2024) aligns with NCSC Cyber Essentials Plus and the MOD Cyber Security Model. Requirements cover: organisational security, asset management, access control, cryptography, physical security, operations security, communications security, supply chain security, incident management, and business continuity. Suppliers must achieve Cyber Essentials Plus certification as a minimum, with enhanced requirements for higher-sensitivity contracts. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does UK Defence Standard 05-138 - Cyber Security for Defence Suppliers have?

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers has 5 controls organised across 5 domains. The largest domains are Asset and Access (1 controls), Cyber Risk Profile (1 controls), Incident (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does UK Defence Standard 05-138 - Cyber Security for Defence Suppliers map to?

UK Defence Standard 05-138 - Cyber Security for Defence Suppliers maps to 156 other compliance frameworks. The top mapping partners are ISO 27701:2019 (20% coverage), OECD AI Principles (20% coverage), US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with UK Defence Standard 05-138 - Cyber Security for Defence Suppliers compliance?

Start your UK Defence Standard 05-138 - Cyber Security for Defence Suppliers compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Defence Standard 05-138 - Cyber Security for Defence Suppliers requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 5 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required