Skip to main content
New feature

The Cyber Security Model

How the MOD decides what cyber security your contract needs, and how to meet it.

Def Stan 05-138 Issue 4, 14 May 2024.

How it works

The procurement process, end to end

Four phases, from the risk assessment that sets your Cyber Risk Profile through to the improvement plan if you cannot yet meet it.

01

Procurement Risk Triage

A new procurement case is raised. The MOD delivery team completes the CSM Risk Assessment, which sets the Cyber Risk Profile for the contract, and a RAR is issued.

StepsNew Procurement CaseCSM Risk AssessmentRAR Issued
MOD Cyber Security Model Procurement Process Overview
Cyber Risk Profile

Four levels, 148 controls

There are 148 controls in total, but no single level contains all of them. Some controls are replaced by more comprehensive controls at a higher level.

98additional controls from Level 0 to Level 1
38additional controls from Level 1 to Level 2
5additional controls from Level 2 to Level 3
By objective

Start from an objective

Controls are grouped under four security objectives. Two foundation controls sit outside them.

Find the controls for your Cyber Risk Profile

Filter all 148 controls by level and objective, and open any control for the full requirement text.