Change of https://www.gov.uk/guidance/cyber-security-model

Change description : 2025-10-27 08:00:00: Updated webpage with information on the now-live CSM version 4. [Guidance and regulation]

Showing diff : 2025-05-08 04:00:08.791484253 +00:00..2025-10-27 08:00:33.056710887 +00:00

Guidance

Cyber Security Model

Information on the Ministry of Defence Cyber Security Model (CSM), including the standards suppliersand mustguidance meet for CSMsuppliers version 3 and how to preparemeet for CSM version 4.

The Defence Cyber Certification (DCC) has been created in partnership with IASME and forms a crucial element of the Cyber Security Model v4.

MoreVersion information4 guidance on thethis Defencepage Cyberis Certification (DCC) for theinformation Cyberonly Securityuntil Model3rd v4November (CSMv4).2025.

The Cyber Security Model (CSM) is how Defence builds cyber security into its supply chain. It is a risk-based proportionate approach which includes:

  • CSM Risk Assessments: MODMinistry of Defence (MOD) Delivery Teams complete an initial Risk Assessment. Assessment. This This determines a Cyber Risk Profile.
  • Cyber Security Standard for Defence Suppliers: Defence Standard 05-138 (Def Stan 05-138) lists the cyber security controls required for each Cyber Risk Profile. Suppliers are contractually required to meet DefenceDef StandardStan 05-138 controls.
  • Supplier Assurance Questionnaires:Questionnaires (SAQ): Suppliers self-assess against the CSM requirements using a Supplier Assurance Questionnaire.
  • Flow down: Where suppliers are sub-contracting the supplier will complete a Risk Assessment to generate a new Cyber Risk Profile.  The sub-contractor completes the appropriate Supplier Assurance Questionnaire.

If a supplier cannot meet the requirements, (including whether compliance is certified under Defence Cyber Certification (DCC) - see below) they must submit a Cyber Implementation/ImprovementImprovement Plan (CIP).(CIP) detailing when they will meet the required level of compliance, together with associated timescales or reasons why they are unable to comply. The CIP template can be found here.

Defence Conditioncondition 658 (DEFCON(DEFCON 658)658) lays out the contractual terms for the Cyber Security Model.

ThereThe are two versions of the CSM inhas usebeen for procurements:updated:

  • Cyber Security Model v3 (CSMv3) (current)(legacy)
  • Cyber Security Model v4 (CSMv4) (under development)(current)

Existing and new procurements should continuenow to use CSMv3CSMv4. untilPlease CSMv4see isthe rolledIndustry out. WeSecurity willNotice communicate2025/04 transitionalfor arrangementsmore ininformation dueon course.this transition and existing contracts. CSM v3 Cyber Risk Profiles (N/A High) are not consistent with CSMv4.

Cyber Security Model v3v4 (CSMv3)(CSMv4)

CSMv3:CSM version 4 is a significant change to the CSM which supports the MOD’s Cyber Resilience Strategy for Defence.

CSMv4:

  • focuseschanges onthe protectionCSM offocus electronicfrom “MOD Identifiable Information” to organisational security and resilience
  • hasintroduces four new Cyber Risk Profiles: “Very“Level Low”,0”, “Low”,“Level “Moderate”1”, “Level 2” and “High”“Level 3”
  • uses controls specified in Defence Standard 05-138 Issue 34
  • hasprovides operateda sincenew Juneonline 2021Supplier usingCyber anProtection InterimService Processfor ascompletion perof Industrynew CSM Risk Assessments and SAQs

Video series about changes to the CSM

Cyber Security NoticeModel 2021/05version 4: Overview.

Cyber ThisSecurity includes:

    Model version 4: Risk Assessment

    Cyber Security Model version 4: Supplier Assurance Questionnaire

    Cyber Security Model version 4: Roles and Responsibilities

    Cyber Security Model v4 process

    1. flowNew downopportunity: obligationsA beingRisk pausedAssessment forReference a(RAR) number and required Cyber Risk Profile of(CRP) “VeryLevel Low”,(Levels “Low”0-3) relevant to a new or existing MOD activity will be provided by the authority at the earliest market engagement, and “Moderate”
    2. annualwill renewalusually obligationsbe beingfound pausedin the invitation to tender.
    3. DEFCONComplete 658a isSAQ: If the supplier intends to bebid includedfor wherethis MODopportunity Identifiablewith informationthe isMOD, passedthe tosupplier must use the Supplier Cyber Protection Service and complete a sub-contractor,SAQ, evenself-assessing thoughagainst flowthe downCRP. hasPlease paused
    4. requiringrefer submissionsto throughthe MicrosoftSupplier FormsCyber (below)Protection orService PDF

MSdemonstration Formsvideo below for CSMv3:

Thewill Cyberbe &automatically Supplyscored Chainagainst Securitythe teamCRP, willand respondthe bysupplier emailimmediately toinformed Riskif Assessmentsit andis Suppliercompliant.

  • Cyber AssuranceImprovement QuestionnairesPlan within(CIP): twoIf workingthe days.supplier Youis non-compliant, they must contactcomplete ukstratcomdd-cydr-dcpp@mod.gov.uka ifCIP. youThe haveCIP notwill receivedform apart timelyof responsethe tocontract yourdocument submission.

    Ifitself requirementsand areDEFCON not658 met,will be included in the suppliercontract willterms needand toconditions. completeThe aCIP Cyberenables Implementationa Plansupplier (CIP).

    Cyberto Securitycommit Modelto v4improving (CSMv4)

    CSMtheir versioncyber 4resilience isand allows a significantcontracting changeauthority planned to thepermit CSMa whichsupplier willto supportwork implementationtowards ofcompliance with the MOD’srequired Cyber ResilienceRisk StrategyProfile forLevel Defence.

    CSMv4(Levels will:

    • change0-3). The supplier should include the CSMCIP focusas frompart “MODof Identifiabletheir Information”tender. toThe organisationalCIP securitytemplate andcan resiliencebe found here.
    • introduceSupplier fourSelection: newThe Cyberauthority Riskwill Profiles:take “Levelinto 0”,consideration “Levelsupplier 1”,compliance “Level(or 2”CIP andproposal) “Levelin 3”supplier selection.
    • useContract controlsAward: specifiedContracts inwill Defencebe Standardagreed 05-138between Issuethe 4 authority and supplier, which will include any agreed CIP.
    • provideContract Maintenance: Annually, the supplier will complete a new onlineSAQ Supplierto Cyberdetermine Protectionif Servicethey forremain completioncompliant. ofIf Riskthe Assessmentssupplier andis Suppliernon-compliant, Assurancea QuestionnairesCIP will be considered.

    Flow down guidance for defence suppliers

    AsThe CSMv3information Cyberin Riskthis Profilesguidance cannotis maprelevant for both MOD personnel (authority) and current/prospect suppliers.

    What is flow down?

    Flow down is how MOD requests prime contractor requirements into lower-tier sub-contractor agreements. Flow down is required from the prime contractor to CSMv4their Cybersub-contractors Riskand Profiles,onwards newdown Riskthe Assessmentssub-contracting tiers to the end of the supply chain. The flow down process allows the MOD to monitor and Suppliergain Assuranceassurance Questionnaireson willits besupply required.chain.

    CSMv4Who Transitionis responsible for flow down?

    ThereSuppliers willare beresponsible for flow down. DEFCON 658 contains the contractual obligations that suppliers must place upon subcontractors.

    Flow down example scenario:

    A prime contractor, Company A, is bidding on a phasedMOD transitioncontract to CSMv4. build Untilmilitary then,drone organisationsparts. shouldCompany continueA expects to applyhire CSMv3.a sub-contractor, Company B, to help manufacture components, which Company B will sub-contract to Company C.

    To

    1. Company supportA organisationscompletes thata wishCSM Risk Assessment (RA) to preparedetermine the Cyber Risk Profile (CRP) level for CSMv4,their sub-contractor(s). This CSM RA completion automatically generates a Risk Assessment Reference (RAR).
    2. Company A should pass this RAR to Company B to complete a SAQ to determine if they meet compliance with the CRP level required.
    3. Company B can now commence the onwards flow down, following resourcesin haveCompany beenA’s releasedfootsteps by completing a CSM RA to determine the CRP level required for informationtheir only:

    Learn how to use the Supplier Cyber Protection Service

    PlannedThe Supplier Cyber Protection Service is a Public Beta. This demonstration video will show you how to use its current functionality. Alongside this, we are also exploring additional resources:features to make CSM v4 even more flexible and user-friendly.

    Defence Cyber Certification (DCC) for the Cyber Security Model v4 (CSMv4).

    Related resources for UK suppliers

    Defence Supply Chain organisations in the UK are encouraged to sign up for free services provided by the UK National Cyber Security Centre (NCSC):

    • Active Cyber Defence and MyNCSC. Registered organisations can access Active Cyber Defence (ACD) tools such as ‘Early Warning’ and keep updated on new capabilities and offerings beneficial to their cyber resilience.
    • Cyber Security Information Sharing Partnership (CISP). Suppliers can join the Defence Supplier Community on CISP to discuss current cyber issues with peers and keep up to date with the latest developments.

    QueriesCyber Security Model v3 (CSMv3)

    Email:The ukstratcomdd-cydr-csm@mod.gov.ukcontent below is for the legacy CSMv3 process. Please refer to Industry Security Notice 2025/04 to determine your required action.

    ResponsesCSMv3:

    • focuses willon normallyprotection of electronic “MOD Identifiable Information”
    • has four Cyber Risk Profiles: “Very Low”, “Low”, “Moderate” and “High”
    • uses controls specified in Defence Standard 05-138 Issue 3
    • has operated since June 2021 using an Interim Process as per Industry Security Notice 2021/05. This includes:
      • annual renewal obligations being paused
      • DEFCON 658 is to be providedincluded where MOD Identifiable information is passed to a sub-contractor, even though flow down has paused
      • requiring submissions through Microsoft Forms (below) or PDF

    MS Form for CSMv3:

    The Cyber & Supply Chain Security team will respond by email to Risk Assessments and Supplier Assurance Questionnaires within two working days.

    If requirements are not met, the supplier will need to complete Cyber Implementation Plan (CIP).

    Contact

    Email: UKStratComDD-IES-CC-CRP-SCPS@mod.gov.uk

    Monday to Friday, 9am to 5pm - excluding bank holidays.

  • Updates to this page

    Published 9 September 2024
    Last updated 827 MayOctober 2025 + show all updates
    1. Updated webpage with information on the Defence Cyber Certification (DCC).

    Sign up for emails or print this page

    Update history

    2025-11-03 08:00
    Updated call to action box with the latest information.

    2025-10-27 08:00
    Updated webpage with information on the now-live CSM version 4.

    2025-05-08 05:00
    Updated webpage with information on the Defence Cyber Certification (DCC).

    2025-02-06 09:20
    Updated: ‘Supplier Assurance Questionnaire’

    2025-01-02 10:44
    Added ‘Letter to Defence Industry CEOs/Defence Leads about driving cyber resilience in the supply chain’.

    2024-09-09 10:26
    First published.