US suppliers entering UK defence · 4 of 8

Cyber: Defence Standard 05-138 and the risk profiles

Every MOD contract carries a cyber risk profile of Very Low, Low, Moderate or High, and that profile dictates the controls you must hold under Defence Standard 05-138. Compliance is contractual, it flows down to your subcontractors, and it has to be in place by contract start.

What this involves

  • Determine the cyber risk profile attaching to your target contracts and therefore the control set you must evidence under Defence Standard 05-138.
  • Work through the Supplier Assurance Questionnaire honestly, because an optimistic SAQ creates a contractual exposure rather than an advantage.
  • Close the gap between your existing US-facing certifications and what MOD requires, which is rarely a straight mapping.
  • Handle the flow-down, since prime contractors must cascade the same requirements to subcontractors and your supply chain becomes your problem to evidence.

The assumption that costs US entrants the most

Assuming NIST 800-171 or CMMC compliance satisfies MOD. It does not map across. A US supplier with a mature security posture is in a good starting position, but the UK regime asks for evidence against its own control set and its own questionnaire, and the assessment is contractual. Budget for the translation exercise rather than expecting recognition.

Why it matters

This is a hard gate rather than a scored criterion. If the controls are not in place by contract start you have a compliance problem on day one, and it flows down to everyone you subcontract to.

Common questions

Does CMMC or NIST 800-171 satisfy UK MOD cyber requirements?

No, not automatically. UK defence cyber requirements run through the Cyber Security Model and Defence Standard 05-138, assessed via the Supplier Assurance Questionnaire against the risk profile assigned to the contract. Existing US compliance is genuinely useful groundwork because the underlying controls overlap, but it is not recognised as equivalent and you will need to evidence against the UK standard.

What is DEFCON 658?

It is the contract condition that brings cyber requirements into MOD contracts, and in practice it is where Cyber Essentials and the wider cyber risk profile obligations attach. If DEFCON 658 appears in your contract, the cyber controls are contractual terms rather than good practice.

When do the controls need to be in place?

By contract start. This is the point most often missed by suppliers who treat cyber compliance as something to work on during mobilisation. If your risk profile requires controls you do not yet hold, the time to close that gap is during capture, not after award.

Cleared support

Consultants cleared to Baseline Personnel Security Standard and Security Check, with Developed Vetting cleared personnel available where a requirement demands it.

Reviewed 22 August 2026 against MOD published policy. Nothing here is legal, export control or security advice, and defence policy moves: confirm the current published position before planning around anything on this page.

Testing whether the UK is worth it?

That is the right question and we will answer it straight, including when the answer is not yet. A director replies. We work US business hours by arrangement.

Cyber: Defence Standard 05-138 and the risk profiles

What do you supply, who buys it in the US today, and what has prompted the UK question?

Or call us directly: 020 3668 5488

Professional Bid Writing Services UK. 93% Success Rate.

Expert bid consultancy and tender writing for government, NHS and CCS frameworks. £500M+ contracts won. Same-day response. 24/7 urgent support.

Get a Free Quote. Same Day Response. ☎ 020 3668 5488
✓ 93% Success Rate ✓ £500M+ Won ✓ 500+ Tenders ✓ 2-Hour Response

Recent Wins

✓ Won £45M NHS FM contract for healthcare provider

✓ Secured £12M MoD framework for defence SME

✓ Won £8M G-Cloud lot for SaaS company