UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
UK Defence Standard 05-138 establishes cyber security requirements for organisations in the UK defence supply chain. Mandated by the Ministry of Defence (MOD) for contracts handling MOD information and systems. Issue 3 (2024) aligns with NCSC Cyber Essentials Plus and the MOD Cyber Security Model. Requirements cover: organisational security, asset management, access control, cryptography, physical security, operations security, communications security, supply chain security, incident management, and business continuity. Suppliers must achieve Cyber Essentials Plus certification as a minimum, with enhanced requirements for higher-sensitivity contracts.
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers is a compliance framework from United Kingdom (MOD) with 11 domains and 30 controls that map to 244 other frameworks. The largest domains are Cyber Risk Profile Levels (8 controls), Technical Controls (7 controls), DEFSTAN 05-138 Section D: Minimising the Impact of Incidents (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Asset and Access
| Code | Title |
|---|---|
| UKDEFSTD-2 | Asset Management, Access Control, Cryptography |
Contractual Flow-Down and Scope
Contractual Flow-Down and Scope
| Code | Title |
|---|---|
| DEFSTAN-DEFCON658 | DEFCON 658 Flow-Down to Supply Chain |
| DEFSTAN-MIIDEF | Definition and Identification of MOD Identifiable Information |
Cyber Risk Profile
| Code | Title |
|---|---|
| UKDEFSTD-1 | Cyber Defence Cyber Risk Profile (CRP) |
Cyber Risk Profile Levels
Cyber Risk Profile Levels
| Code | Title |
|---|---|
| DEFSTAN-CHANGE | Risk Profile Change Management |
| DEFSTAN-L0 | Risk Profile L0 Not Applicable |
| DEFSTAN-L1 | Risk Profile L1 Very Low |
| DEFSTAN-L2 | Risk Profile L2 Low |
| DEFSTAN-L3 | Risk Profile L3 Moderate |
| DEFSTAN-L4 | Risk Profile L4 High |
| DEFSTAN-L5 | Risk Profile L5 Very High |
| DEFSTAN-RP-ASSESS | Cyber Risk Profile Assessment via SCRA |
DEFSTAN 05-138 Section D: Minimising the Impact of Incidents
Incident
| Code | Title |
|---|---|
| UKDEFSTD-4 | Incident Response and Reporting |
Incident Reporting and Assurance
Incident Reporting and Assurance
| Code | Title |
|---|---|
| DEFSTAN-AUDIT | Assurance and Audit Evidence Maintenance |
| DEFSTAN-INCIDENT-MODCERT | Incident Reporting to MOD via JSyCC |
Personnel and Physical Security
Personnel and Physical Security
| Code | Title |
|---|---|
| DEFSTAN-PERSONNEL | Personnel Security and Clearances |
| DEFSTAN-PHYSICAL | Physical Security |
Supply Chain
| Code | Title |
|---|---|
| UKDEFSTD-3 | Supply Chain Risk Management |
Technical Controls
Technical Controls
| Code | Title |
|---|---|
| DEFSTAN-ACCESS | Access Control and Identity Management |
| DEFSTAN-CONFIG | Secure Configuration and Hardening |
| DEFSTAN-CRYPTO | Cryptography and Key Management |
| DEFSTAN-DEV | Secure Development and System Acquisition |
| DEFSTAN-MALWARE | Malware Protection |
| DEFSTAN-MONITOR | Security Monitoring and Logging |
| DEFSTAN-PATCH | Patch and Vulnerability Management |
Training
| Code | Title |
|---|---|
| UKDEFSTD-5 | Training, Audit, Continuous Improvement |
Your Compliance Coverage
If you comply with UK Defence Standard 05-138 - Cyber Security for Defence Suppliers, you already cover:
TSA Pipeline Cybersecurity Directives
13%
4 controls mapped
Compare →PSD2 SCA
13%
4 controls mapped
Compare →OSFI B-13
13%
4 controls mapped
Compare →+ 241 more: Open Banking Security (13%), Oman National Cybersecurity Framework (13%)
See all 244 mapped frameworks ↓Maps to 244 other frameworks
What is UK Defence Standard 05-138 - Cyber Security for Defence Suppliers and who does it apply to?
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers is a compliance framework from United Kingdom (MOD) with 11 domains and 30 controls. UK Defence Standard 05-138 establishes cyber security requirements for organisations in the UK defence supply chain. Mandated by the Ministry of Defence (MOD) for contracts handling MOD information and systems. Issue 3 (2024) aligns with NCSC Cyber Essentials Plus and the MOD Cyber Security Model. Requirements cover: organisational security, asset management, access control, cryptography, physical security, operations security, communications security, supply chain security, incident management, and business continuity. Suppliers must achieve Cyber Essentials Plus certification as a minimum, with enhanced requirements for higher-sensitivity contracts. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does UK Defence Standard 05-138 - Cyber Security for Defence Suppliers actually require?
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers has 30 controls organised across 11 domains. The largest domains are Cyber Risk Profile Levels (8 controls), Technical Controls (7 controls), DEFSTAN 05-138 Section D: Minimising the Impact of Incidents (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of UK Defence Standard 05-138 - Cyber Security for Defence Suppliers do I already cover?
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers maps to 244 other compliance frameworks. The top mapping partners are TSA Pipeline Cybersecurity Directives (13% coverage), PSD2 SCA (13% coverage), OSFI B-13 (13% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement UK Defence Standard 05-138 - Cyber Security for Defence Suppliers?
Start your UK Defence Standard 05-138 - Cyber Security for Defence Suppliers compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about UK Defence Standard 05-138 - Cyber Security for Defence Suppliers requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 30 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required