← Signal to Noise
Episode 2/Deep Dive/21 May 2026/32:03

The UK MOD Cyber Security Model Explained

Dave explains the UK MOD’s Cyber Security Model and Defence Cyber Certification

Watch
Listen

In this video, Dave Collins explains the UK MOD's new Cyber Security Model. He unpacks the Cyber Risk Profile Levels, Defence Cyber Certification, and what it means for small businesses trying to get into the defence sector.

Transcript

Machine-generated from the recording, so expect the odd mis-hearing. 5,345 words.

Dave Collins: Right, Dave, we're going to be talking about something that's got a lot of question marks right now and a lot of confusion, I think, in industry, specifically in the sector around ⁓ DCC, new cybersecurity model, ⁓ DefStans it all means, how they stitch together. ⁓ So today would be good to spend a little bit of time to talk about ⁓ what it they are, how they work, and specifically try and illuminate some of the ways these things work and most importantly what they mean for our potential clients. Yeah sounds good. Okay cool.

So why don't we just start right at the top. What is version four of the MOD's cyber security model? Sure well maybe even let's go one step further than that. So structurally the MOD, set out UK MOD we're talking about specifically and we can talk about other nations a bit as well and how it comes together but But fundamentally, the UK MOD wants to set a cybersecurity expectation for the supply chain.

So everything from ⁓ ships airplanes to ammunition to commodities like, I don't catering supplies or anything, literally anything. The is going to go and buy stuff from the private sector. and has judged that the sort of the baseline government standards aren't enough for this sector and therefore sets out its own cybersecurity standards. Now there are a number of intersecting sets of cybersecurity standards, but what we're talking about here specifically, and again, we can talk about the others later, ⁓ is the model, which is effectively around an organizational or operational cybersecurity standard ⁓ as from secure by design.

which is about a thing. So if you imagine, the cybersecurity model is about the business, the company, the supplier, secure by design is about the thing they're producing. Got it. That's not what we're talking about here.

We can talk about that a bit as well, but this is about the cybersecurity model. So historically, and this has existed for a long time. ⁓ CSM? Yeah.

In various iterations. Historically, it was about protecting something called defence identifiable information. You could hear the capitalization. You know, the MOD loves a three letter acronym.

And that was really about making sure that sensitive information did not end up either in the public domain, plastered all over a newspaper, which is embarrassing, or in the hands of foreign intelligence. That was where the standard and its previous iteration was really focused and set out a series of controls ⁓ and process was supplier would told what level they needed to achieve. They would complete a questionnaire which basically said, yes, we've got this. No, we don't have that.

⁓ And a judgment could made then about the risk profile. Fundamentally that concept's not changed in terms of the process. What has changed with, and you mentioned version four, which came out in December last year, or went live in December last year. So that's the latest iteration.

The change in this latest model is it still applies to the organization. It still applies to the operational cybersecurity, but now it's gone from purely protecting information to also adding a layer about operational resilience. So are you as an organization in the supply chain? able to continue operating in the face of cyber threats, cyber attacks?

the CSM encompasses things like policy and process, but it includes technical things. It includes your approach to risk management, includes governance, not just as a policy. Do you have a policy for X, but specific questions around, ⁓ do you have a board member responsible for this? Or do you have cyber security?

⁓ considered in these kinds of ways. So it's a much broader waterfront. Okay. So if that's CSM then, what's the Defence Cyber Certification?

What's DCC? So the Defence Cyber Certification is another new scheme broadly at the same time. As CSM version 4? it at ⁓ end of last year.

⁓ And the Cyber Certification is effectively ⁓ a certification wrap around the cybersecurity model. So I mentioned earlier on this idea of completing a questionnaire. That is one way that companies can prove compliance and talk a bit more about compliance with what, maybe in a minute. That's definitely something to explore.

But the DCC has been created to give organizations a different route to prove compliance. So rather proving every time you go for a specific contract that you're compliant to a given risk level. ⁓ And again, we're throwing around a lot of terms here, so hopefully we'll unpack those over the course of this. ⁓ the DCC allows you to take a certification approach.

So approach a certifying body, They have an auditor, they have process to follow. And at the end of that process, if you are successful, you get awarded a certification, a badge you can put on your website. In fact, we've got it. We've got DCC level zero, which is the foundational level, which was all that was available at the time we initially applied.

And you get a badge, you can put on your website and you are effectively then treated as compliant for a period of three years with two caveats. One caveat is that The whole of the DCC scheme, the whole of cybersecurity model for that matter has cyber essentials as its foundation. So it's either cyber essentials or plus depending on the level. NCSC cyber essentials.

Correct, yeah, the national scheme. And you have to retain cyber essentials, which is an annual certification. So you have to commit to doing that. Otherwise your DCC is invalid.

Okay, so it's valid for three years, but if your cyber essentials or cyber essentials plus lapses, You not only lose cyber essentials or cyber essentials plus you lose your DCC certification. And then the other thing, there's a attestation part to it where you say you attest to maintain the standards ⁓ for period. So at level zero, there are three controls that make up the DCC, the cybersecurity model at that level. Basically, Cyber Essentials, a GDPR policy, and effectively a sort of resilience plan.

If you go up to level three, the other end of the spectrum, Cyber Essentials Plus, and then 140 other controls. I think that's an excellent segue to the next question, which is you were mentioning levels here. I wonder if you could get into a little bit of detail about what these levels are, specifically what they mean for businesses, because I think that's what the question is going to be is, is a lot of people are going to be looking at this and saying, what do I need , as a defence supplier, what do I need? to be successful in business.

Sure. So ⁓ a critical document here, another one that's got a snappy title, which is the defence standard 05-138. You can tell I've spent a lot of time looking at this recently. ⁓ This effectively the of the meat of the cybersecurity model and the defence cyber certification.

⁓ And is exactly as it says a defence standard. There are defence standards for everything from ⁓ logistics ammunition to facilities, whatever, pick a thing, there's probably a defence standard for it. ⁓ anyone who lives in the defence supply chain lives and breathes these documents. ⁓ this case, the DefStan defence standard sets out a series of controls.

⁓ These are the measures that need be implemented to be compliant. And it defines four levels, ⁓ level zero, one, and three with 0 being the most foundational, applied to the lowest risk activities, projects, capabilities, level 3 being the highest. as you go up those increasing levels, ⁓ the expectations the level of complexity increases. And that is because those levels are driven by the risk profile.

So let's take an example. If defence is contracting for a, I don't know, let's say defence needs a contract for some commodity item, stationary, defence needs to buy stationary. I would argue that the supply chain for pencils is pretty low risk. So taking into consideration, it's a commodity item.

So lots of suppliers can supply you pencils. It's not necessarily operationally critical. Although, you know, some of the headquarters ⁓ I've ⁓ would very quickly, they ran out of a supply of ⁓ Fair ⁓ You know, it's not particularly subject to interest from foreign intelligence services. So that's the thing that would awarded a very low level of cyber risk.

And in the invitation to tender or in the RFP documents, ⁓ that will specified CRP level zero. ⁓ And that basically an organization wanting to engage with that contract, with that opportunity ⁓ would need essentials. They need a GDPR ⁓ policy and would need ⁓ this resilience plan. And effectively, they would either self-attest through a supplier assurance questionnaire at the point of bidding, or they would go to one of the certifying bodies, get themselves a DCC level zero, which, depending on the size of the organization, costs a few hundred pounds for the certification.

And then they're good to go. So that's the level zero So we've looked to the other end together, you the extreme, ⁓ and so, ⁓ you know, really to be talking here about things that are absolutely operationally critical in the supply chain that are going attract the attention of a foreign intelligence service that maybe are. Only a small handful or maybe a single supplier is able to provide and therefore the resilience of the supply chain becomes really important. Coming back to that point about operational resilience being a critical factor in this new scheme, they're going to be at a higher level.

And at that point you are talking about cyber essentials plus as table stakes, you know, that's absolutely given at that level. then 140 additional controls. What do I by controls? Well, it's everything.

So the controls can range from risk policy, ⁓ physical security, you who can access keys to get into server rooms, right through to really technical things like monitoring of security ⁓ ⁓ role-based access controls, control of software, ⁓ data at rest, data transit all of the things that make up a really comprehensive cybersecurity model and the specific language in level three is around defence in depth. the supplier assurance questionnaire at that level runs to hundreds of questions. ⁓ You're being asked all kinds of really technical questions. And I guess one thing that is interesting about this scheme is, and you mentioned what does it mean for companies?

I think it means different things for different companies. If you're a very small company, you might look at that list of controls and go, how on earth am I going to implement all of those things? But equally, if you're an enterprise, even BAE systems, one of the primes, even at that level, there are going to be things in there which aren't currently in place, controls which aren't currently in place. And implementing those things at enterprise level across a company of tens of thousands or hundreds of thousands is going to be tricky, which is where the scoping then becomes really important.

Well, let's talk about scoping, because I think it's a really important way of understanding where the... use an phrase, the arcs of fire are in this, right? So what the different ways that scoping is approached by the MOD on this? So just maybe clarify what we mean by scoping.

⁓ So when talk about scope, we are effectively talking about what is the part of your operation, ⁓ operationally and technically, is in the of this scheme. Now, this is where this gets little bit interesting and where this is very much a live developing ⁓ field. ⁓ when the cybersecurity model version four was first issued, narrative, the documentation said that whole are immediately in scope. And you see why.

⁓ if the is this is about operational resilience, ⁓ you you to think about, okay, what threat vectors or what kinds of attack or impact could disrupt the supply chain? So could disrupting the department of a critical supplier have an impact on the supply chain? ⁓ I would argue could. Yeah, of course it could.

I think there was a recognition, however, that that was probably a bit too much of a simplistic view. So there is a sort of amendment that's recently been issued. I'm going to say recently, I mean in the last three weeks. So this is brand new stuff.

And some people might not seen this because it wasn't necessarily actively pushed out, I think, particularly well, but it's there on the MOD website. And what that effectively does is it says... It's about business critical. about operationally critical.

Now there's a lot of wiggle room in that. ⁓ again, not seeing the case law. We've not seen this all work through. So I think we need to see that play through a little bit.

But there's a diagram that explains that. And hopefully with the wizardry of the platform we're using, that diagram is now displayed for a few seconds while I talk over it, which basically shows that you can take an intersecting segment of your business, of your digital estate, and put that in scope. So let's assume for a second that I am a, a supplier of the MOD, a supplier of some commodity or service or something for the MOD. And I want to start bidding for, for tenders that are coming out for RFPs and ITTs and you these types of things.

How do I approach this? What do I do? So two approaches, I would say. ⁓ One approach is the ⁓ process, and the other is the DCC route.

⁓ Start with the traditional process. So the first thing to do in any case is to understand what is the assigned cyber risk profile of that activity. And where is that going to be listed? So it's in the ITT.

It'll be in the ITT. It should be in the ITT. Now I've been a bit of searching on find a tender. Yeah.

I just have a look and not every ITT has specified it yet. But let's assume that it's all fine and that it's there in the ITT, and that will specify two things that ITT or it should do. there is the cyber risk profile level, zero to three, and a risk assessment reference, RAR, another three letter acronym. And that number effectively allows you to then access the system, the cyber security model system.

Got it, okay. I see. So ⁓ a business, I'll see that it's, let's assume for a second it says that it's DCC level two. Or CRP level Sorry, CRP level two.

Right. Remind me to come back though on DCC being mandated, because that is an important point. Okay. We'll come back to that.

We do need to come back to that. But let's say it says it's CRP level two. Yeah. I'm a business.

I don't have anything yet. What do I do? ⁓ So I guess there's a couple of things you can do. So lot of this depends on what capabilities you've got in-house.

So let's take a model where you've got a cybersecurity team in-house. maybe you're a dual ⁓ or maybe done work in another nation. ⁓ defence supply chain, you've got cybersecurity team, you understand the principles of what this is all about. So in that case, you'll be going to the cybersecurity model documentation online, to the DefStan looking at level two and effectively auditing yourself, I would say, as a first step against those controls, going through one by one, is that in place?

Yes, no, yes, no. When you're sufficiently confident in that, you would then engage with the portal, which again is all linked on the MOD site, in that risk assessment reference, and allows you to then complete a supplier assurance questionnaire, SAQ. ⁓ So then effectively the self-assessment ⁓ against process. Would a company need to do that if they had DCC certification level two?

No. So that's the other route. Now there's a little bit of ⁓ connective that isn't currently there. So what you can't do at the moment is in an auto-magical way, access the portal and just give it your DCC reference.

That I've been told is coming, ⁓ I don't know when. ⁓ there was another recent bulletin issued again in the last couple of weeks, which said that DCC is now going to be accepted as evidence. So ⁓ just taking one back from that specific point is when you are submitting your ITT or your response to into ⁓ your delivery team, you are going to need to give them evidence of compliance. And that will be either an output from the SAQ portal, the Supply Assurance Questionnaire, or your DCC reference.

So you show them at level two. Now, only two routes that you've got to demonstrate that you're meeting CRP level two. On the assumption that you're meeting it at that point. Right.

what I hear you ask, do you do if you're not quite there yet? Yeah, what do do if you're falling short? So if you're falling short, there is a process to that too. Of course there is.

It's the MOD They love a process. I spent 18 years in the organization. Who doesn't love a process? Exactly.

And the process for that is you need a cyber improvement plan. Yeah. So that cyber improvement plan. CIP.

CIP. And another three letter. You can hear the capitalization when I say it. The whole point of that cyber improvement plan is to say, I know I need to be here.

I am currently here. Here is my plan. And I think historically, that has been a concern that this would be signed off, non-compliant bid, but here's a plan, a notional cyber improvement plan. And there'd be no follow up on this.

So one of the other aspects of this new model is an expectation of greater checking of homework, I think. even where, even though the supply assurance questionnaire is a self attestation, there is an expectation that will be more scrutiny, more audits, more checking. And that's not just to the primes, that's also subcontractors because this stuff flows down through the supply chain. just to sort of round that bit off, so you produce a cyber improvement plan which says we're here, we need to get to here, we're going to get there by this one.

So just to give you a live example of somebody we worked with recently. There were a couple of elements on there where it just needed, they needed to get the response in. They didn't want to miss a contractual deadline to get a response in, but there were a couple of controls that hadn't been fully implemented yet. We knew what that looked like.

We knew how we needed to implement them. We're supporting the business in doing that. And we stated by contract starts, which was, think only two weeks in. was quite a...

fast burn thing of sort of an innovation project, that those would be in place. ⁓ And it would then be reasonable of the delivery team to come back and say, show me the evidence then, that these things are now in place. Show me the money. Yeah.

So that's the process. The other nuance in terms of compliance or 100 % compliance versus not 100 % compliance is, and this is contentious. I think this is contentious. I absolutely understand the thinking here, but again, we need to see how this plays out in real life.

The supplier assurance questionnaire is a binary thing. You're engaging with a computer. Question, do you have this in place? Tick yes, no.

⁓ The boxes are literally yes, no, variations of 60 days, 90 days, whatever. But then they're not free text. The only way you can have a conversation with that system, as it were, is through a cyber improvement plan. Or you just have a conversation with the delivery team.

You know, that's that's also a valid thing and effectively you say we are going to be non-compliant on this and they go Yeah, fine. We understand why Yes, okay with the DCC because you're talking to a human the auditor has the leeway Yeah, so the auditor can say Yes by the letter of the law it's not compliant but I but I see you are achieving the security value Therefore I'm going to I'm going to take this control as compliant even though you've achieved in a different way Yeah, that's a really important nuance and I think for me that's one of the strengths of DCC and I think that's where we will see people wanting to go down that route. it allows you to take a more nuanced approach ⁓ to everything from scoping to technical controls. we talk an awful lot about the MOD in this context, but the MOD very rarely operates in isolation.

And obviously ⁓ with our European with NATO with our transatlantic partners, there's an awful lot of interoperability that goes on. there, does any of this, is any of this interoperable with our partners? Could I get DCC level two ⁓ the UK and that would apply to a that I'm writing for the German market? Wouldn't that be great?

Wouldn't that be lovely, Or Canada or the US or Japan or South Korea. So that is the intent. 100 % that is intent. So the two things I say about that ⁓ in a top-down way, ⁓ there is an intent to do that.

And there are, as far as I'm aware, not being in government there are talks going on with different nations to agree that ⁓ reciprocity and effectively allow that to apply in different places. one would reasonably expect that ⁓ NATO, for example, across NATO nations, one certificate would be good. Not at the moment, though. Does NATO have its It actually doesn't.

So NATO has a bunch of standards, but they're more around technical interoperability and security. Like Link 16 and stuff like Yeah, but also things like the standards to protect NATO secret, for example. But the implementation of those is handled at national level. One thing we've not talked about is where these controls have come from.

these, know, 140 was level three or whatever. Who's dreamt these up? And the answer is the MoD has not just dreamt these up. They are based on international best practice, which comes from NIST.

So the US NIST system, who set standards for all kinds of things. And in this case is the NIST 800-171, which is the US Department of Defence or Department of War, we must now call it. specification around cybersecurity. Yeah.

So for clarification, that's the National Institute for Standards and Technology. I wasn't going to try and remember it, but you did, so that's fine. So NIST 800-171 is the control set. And that is the control set that has been used to develop the DefStan 05138.

So the ⁓ underlying controls are in large part the I would argue, sorry to interrupt, but I would argue ⁓ that it comes to cyber controls, only so many ways that you can talk about it. ⁓ You can them differently, you can catalog them differently, but ultimately the controls are all going to they're all going to be the same no matter how you choose to categorize. So they are, but this is more than a philosophical alignment. There is a direct read across.

The controls map pretty much like the numbers are broadly the same. There's 110 controls in NIST 800 171, which maps to level two CRP. So the underlying bit's the same. There's sort of a top-down thing which says, in the future we'll have reciprocity.

But the reality is in the middle of all of that, which is where businesses are operating, they are different schemes. The way of proving them is different. The evidence required is different. The audit regime is let's say I'm ⁓ a defence supplier.

I am building counter drone capabilities in the ⁓ We're a small team based in the Midlands. This is all hypothetical. And we 25 staff, know, decent turnover, we're not loaded. We're not making huge amounts of revenue.

This all sounds pretty expensive if I'm an SME trying ⁓ to help the become more resilient to the threats that we're facing these days. ⁓ So it can one of the things we've been talking about quite a bit recently is exactly that question is how do we help people through that? So if we take the example of the Defence Tech startup we're working with at the moment, which started off as one person, came to us right at the start. On day one, That company, he, that person, doesn't need to have all the compliance in place.

He needs a secure environment to build his business. They've now scaled to three. Then they started to look at some MOD contracts and we're starting that conversation now about the next level of compliance. But I think the key thing here is about, and the whole point of us having this conversation, right, is to help people understand the scheme.

⁓ Because don't need to hit all the marks ⁓ from one. What you need to do is understand where you're going to likely be and when. So for that example, let's say they're, I don't know, they've got some seed money. I would be advising that company to get the foundations in place.

Get Cyber Essentials, to look at. ⁓ the DefStan, start to look at the foundational controls that are maybe at level one and start to think about what it looks like to implement those. What if that company you've described has maybe got one person, I don't know, let's say the chief operating officer who notionally has cybersecurity under their thing. but they're not a cybersecurity expert.

that's where we're trying to build a set of services that can help people through that. And as we'll discuss in other videos, we'll unpack this in a bit more detail, our cybersecurity as a service model, our... you know, get in the trenches and do the work model. think really applies here ⁓ what that company could do by engaging ⁓ someone us, ⁓ and are different ways you go into about this, but by engaging someone like us is to effectively ⁓ get the in help with that problem.

And essentially what you're looking for is not ⁓ necessarily someone to point the things that you're doing wrong. It's someone to point out the things that gaps where we're not currently achieving what we need to, and then jump into trenches, roll up the sleeves ⁓ get stuck into solving those problems. We've talked a lot about compliance today. ⁓ Compliance doesn't give you security in the of itself.

You know that. We've talked about this million times. The way that these schemes for me add value is by formalizing and codifying stuff that you should be doing anyway. having the right security to protect yourself against threats, ⁓ it should be...

an easy leap to go to compliance. Now we know that's not always true. The frameworks don't always align. We talked about example earlier on about split tunneling, for example.

But I think what MOD has done well with this scheme is to say, okay, it's a bigger picture. It's about being able to continue to operate in the face of the threats that are faced by the sector. So then coming back to it and we'll wrap up here, but coming back to it, what are the ways, if I was a supplier again, being asked to meet a certain CRP ⁓ then what are the things that I should be asking of suppliers? What are the things that I could be out there grabbing that are gonna help me here?

What are the different ways that they manifest themselves? Are they projects? Are they Do I need to hire a CISO? Do I need to talk to my IT?

What does that look like? We see this with our clients. There are so many different models out there, internal security teams, IT teams, external providers, whatever. I think a lot of it is start where you are.

One of the things we've developed to help out with this is our CSM snapshot tool. This is a free tool. again, know, link in the whatever it is. We'll put a link in the description, the show notes.

like subscribe. can't believe you said that. there's a screenshot of tool that's up there right now. ⁓ But we developed the tool help people get an initial view of where they are.

It works for level one, two and three. So you can select the level. There's a version for business leaders, which is not very technical. There's a version if you've got an internal technical person, who maybe looks after your IT or you could ask your MSP to fill it out, which takes about 10 minutes.

The business version eight questions takes five minutes, And it will give you an instant snapshot. It will give you a bit of a radar diagram and it will give you the top level. No, it is not an assessment, right? It is not a full-on, gap analysis.

It's a checker. It's a checker. It's a starting point. It will give you a sense of where you are.

And then from there, I think the conversation that we will be having is, okay, well, what do you want to achieve? By when? You know, what's that roadmap look like? And then it's effectively a series of implementation of controls.

people, process, technology, that will get you to where you need to be. Now, our approach to that is to sort of view that as all part of one thing, right? So we call it Midas. Yeah, exactly.

So our Midas service is designed specifically to take an taken as a service approach to which is to start to implement the security and then just, you know, tighten the levels of security as we go. calibrate them against the business, it as a change program, keep improving the security all the time. And then specifically for this sector, it's about doing that in the context of that compliance plan, right? So it's about recognizing that there's a tension between the threats and the compliance requirements, but that you can navigate that by doing some really good foundational things early and then layering the additional requirements on them as you go.

So understanding that requirement and that's something we are helping people with. helping people understand that roadmap, build that compliance plan, build that cyber implementation plan, write a cyber improvement plan if needs be, because the timings of contracts might be they need to get that in and then work from there. Cool. All Well, ⁓ I think this has been illuminating.

I really appreciate time. Hopefully people find this very valuable. I know there are a of questions about and CRPs and CMMCs and... DefStans and all that stuff.

So many acronyms. ⁓ It's good have somebody who's been in the trenches of this actually shine a light into it to talk about what the differences are, how they all integrate together, and importantly what it means for ⁓ the MoD supply base. well hopefully it's helpful and hopefully people find this useful. Get in touch and yeah, can do some more.

Thanks very much.

DefenceDCCCyber SecurityComplianceSmall Business
TALK TO A HUMAN

If any of this sounds like your organisation, a 30-minute assessment call will tell you where you actually stand - no obligation, no sales script.

Book an assessment