Guidance

Defence Cyber Protection Partnership

Defence Cyber Protection Partnership (DCPP) is a joint Ministry of Defence (MOD) and industry initiative to improve the protection of the defence supply chain from the cyber threat.

Please

Supplier noteCyber thatProtection DCPPService have- aInterim newprocess

Current email address: UKStratComDD-CyDR-DCPP@mod.gov.uk.

Status

The Octavian Supplier Cyber EssentialsProtection isService changing.was Findswitched outoff morein here.

TheJune DCPP2021. TeamWe planare tocurrently standon downan frominterim 12pmprocess 14until Aprilthe 2022replacement tool is ready to 9amgo 3live.

Cyber MaySecurity 2022.Model process

The interim process offers a choice to complete Risk Assessments (RA)(RAs) /and Supplier Assurance Questionnaires (SAQ)(SAQs) willvia noteither beMS processedForms duringor this time.PDF.

Interim

The processMS forForms newlinks contracts

are:

  • Industry Risk Assessment
  • The MODPDFs, Project/Deliveryif Managernot needsprovided toby complete the RiskContracting AssessmentDelivery (RA)team viacan thebe interimrequested process.from Please request forms via email to the DCPP Team:team at: ukstratcomdd-cydr-dcpp@mod.gov.uk.

    The PleaseDCPP returnteam formsare asworking Microsoftto (preferred)a or2-day convertturnaround totime. PDF.We do welcome emails if you think a response has not been provided in this time.

    Supplier Assurance QuestionnaireQuestionnaires (SAQ)(SAQs) in the tender process

    TenderersWhen mustcompleting stillthe complete an SAQ, toplease beinclude providedthe withRisk tenderAssessment responses.Reference The(RAR). This should be provided by the MOD ProjectDelivery Team or other related competition publication.

    For competition bids, unless otherwise stated, you will provideneed to submit to the MOD Delivery team:

    • A copy of your SAQ. OnMS completion,Forms thissubmissions mustcan be sentsaved tovia the DCPPPrint Teamoption forand asending result to bePDF, provided.rather Thethan completeda SAQspecified printer; and
    • Our resultresponse mustemail.
    • If beour includedresponse withemail tendersays, responses,“Not alongmet”, withyou will also need to submit a Cyber Implementation Plan (CIP) ifto appropriate.

      Flowthe down

      WhilstContracting Delivery team. The team are currently reviewing the interimguidance processotherwise isfound in place,Annex flowD down of the RiskBuyer Assessment/SupplierSupplier AssuranceGuide. QuestionnaireSome processcompetition toprocesses sub-contractssuch willas beDASA requiredmay forpost contractsalternative withCIP ainstructions.
      Please high-riskdo profilenot only.send AllCIPs otherto levelsthe mustDCPP team as these need to be completedconsidered duringagainst athe gracespecific periodproject afterrequirements.

    • If the newCyber toolRisk goesProfile live.

      is HIGH, DCPP will send out the necessary flow down instructions.

    DEFCON 658

    DEFCONPlease 658note, willas continueper tothis beIndustry includedSecurity inNotice

    • Annual contracts.renewals Cyberhave Implementationbeen Planspaused.
    • Flow (CIPs)downs willare continuealso topaused beunless neededthe asCyber usualRisk whereProfile SAQs(CRP) indicateis non-complianceHIGH. (forIf allthis Tieris 1the SAQscase and Highyour flowCRP down).

      Thankis HIGH, then you forshould proceed with your patience.

      flow down submissions.

    Future Tool

    ForThe morenew information,tool contactis currently undergoing testing. Suppliers/bidders will be informed by the DCPPMOD Team:Delivery team at a point where roll out of the tool can start. There is currently no release date.

    Additional information

    Def Stan 05-138

    This is the Defence Standard defining the controls required for each Cyber Risk Profile (level).

    DEFCON 658

    This is the contractual Defence Condition that references supply chain cyber security.

    Defence Industry Warning, Advice and Reporting Point (WARP)

    There is a requirement to report security incidents where MOD data might be involved

    Understanding more about the Cyber Security Model

    Watch a video explaining the Cyber Security Model

    The Cyber Risk Profile is assessed on 6 questions relating to:

    Cyber Essentials underpins the MOD Cyber Risk Profiles. Cyber Essentials is a certification scheme identifying the minimum steps an organisation should take to protect themselves against cyber risk.

    The Supplier Assurance Questionnaire is a self-assessment for organisations to demonstrate how they meet our requirements. The online tool allows sample questionnaires to be completed to identify gaps. Where there are differences a Cyber Implementation Plan (CIP) should be completed, particularly if an alternative cyber security standard is used.

    Further information on CIPs can be found in:

    News

    Def Stan 05-138 v3 Cyber Security for defence suppliers

    Contact us

    The DCPP Team can be contacted by email on: ukstratcomdd-cydr-dcpp@mod.gov.uk or DCPP LinkedIn Group.

    DCPP group on the NCSC’s Cyber Information Sharing Partnership (CISP), register at NCSC’s Cyber Information Sharing Partnership (requires sponsorship).

    Recommended links

    Useful links

    This unclassified presentation was recorded for internal MOD audiences to raise their awareness of the Cyber Security Model although most of it still applies to industry.

    DCPP internal presentation

    Other media sources

    Published 12 September 2019
    Last updated 3111 MarchAugust 2022 + show all updates
    1. Added 'Supplier Cyber Protection Service - Interim Process' section.

    2. Updated a call to action box.

    3. Updated the page with a new interim process for new contracts (first paragraph), and added links to version 3 of "Cyber security for defence suppliers (Def Stan 05-138)".

    4. Added new content under page heading: Interim DCPP Cyber Security Model process. Removed old content.

    5. Updated main page content.

    6. Updated page information.

    7. Added 'Recommended links', removed update from November 2019.

    8. Updated the COVID-19 message under the 'latest' heading. .

    9. Added a COVID-19 update under the 'latest' heading.

    10. Addition of links: 'Supplier Cyber Protection Service: Pre 12/11/19 Risk Assessment workflow' and 'Supplier Cyber Protection Service: Pre 12/11/19 Supplier Assurance Questionnaire'.

    11. Updated 'Supplier Assurance Questionnaire' and useful links section.

    12. Updated links.

    13. Updated the information in the 'latest' section.

    14. First published.