Information on the Ministry of Defence Cyber Security Model (CSM), including the standards suppliers must meet for CSM version 3 and how to prepare for CSM version 4.
The Cyber Security Model (CSM) is how Defence builds cyber security into its supply chain. It is a risk-based proportionate approach which includes:
Risk Assessments: MOD Delivery Teams complete an initial Risk Assessment. This determines a Cyber Risk Profile.
Cyber Security Standard for Defence Suppliers: Defence Standard 05-138 lists the cyber security controls required for each Cyber Risk Profile. Suppliers are contractually required to meet Defence Standard 05-138 controls.
Supplier Assurance Questionnaires: Suppliers self-assess against the CSM requirements using a Supplier Assurance Questionnaire.
Flow down: Where suppliers are sub-contracting the supplier will complete a Risk Assessment to generate a new Cyber Risk Profile. The sub-contractor completes the appropriate Supplier Assurance Questionnaire.
If a supplier cannot meet the requirements, they must submit a Cyber Implementation/Improvement Plan (CIP).
The Cyber & Supply Chain Security team will respond by email to Risk Assessments and Supplier Assurance Questionnaires within two working days. You must contact ukstratcomdd-cydr-dcpp@mod.gov.uk if you have not received a timely response to your submission.
guidance on complying with each Cyber Risk Profile
guidance on flow down requirements
guidance on completing CIPs
Related resources for UK suppliers
Defence Supply Chain organisations in the UK are encouraged to sign up for free services provided by the UK National Cyber Security Centre (NCSC):
Active Cyber Defence and MyNCSC. Registered organisations can access Active Cyber Defence (ACD) tools such as ‘Early Warning’ and keep updated on new capabilities and offerings beneficial to their cyber resilience.