UK DEF STAN 05-138 — Cyber Security for Defence Systems

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
UK DEF STAN 05-138 is a cybersecurity framework that helps organizations secure and assure the cyber resilience of defence systems throughout their lifecycle. It establishes mandatory requirements and controls to protect military platforms, networks, and associated digital assets from evolving cyber threats.
Issued by the UK Ministry of Defence (MOD), DEF STAN 05-138 is used by defence contractors, suppliers, and MOD internal teams to address cybersecurity, risk management, and compliance across design, procurement, integration, and operation of defence systems. The standard covers key areas such as risk assessment, security testing, supply chain security, incident management, and assurance processes specific to defence environments.
Organizations implement UK DEF STAN 05-138 by integrating its requirements into project risk management, security control design, and contract compliance activities. This framework supports alignment with other defence and governmental cybersecurity standards, ensuring robust protection of sensitive information and operational capabilities within the MOD’s broader risk management and governance programs.
Why it Matters
UK DEF STAN 05-138 establishes consistent and robust cyber security requirements for defence systems, helping organizations secure critical assets against evolving threats.
Key benefits include:
- Strengthen governance of defence systems
Provide structured oversight and accountability, ensuring cyber risks are managed across lifecycle stages of defence technology.
- Enhance supplier assurance
Mandate verifiable security requirements for third-party vendors, reducing the risk of vulnerabilities in the supply chain.
- Align with defence regulations
Support compliance with UK Ministry of Defence directives, making it easier to meet contractual and regulatory obligations.
- Improve incident response readiness
Standardize reporting and mitigation processes to accelerate detection and handling of cyber incidents impacting defence assets.
- Promote operational resilience
Reduce operational disruption and mission risk by embedding security controls that protect against advanced cyber threats targeting defence environments.
How it Works
UK DEF STAN 05-138 structures its guidance around a set of cyber security principles and requirements tailored for defence systems throughout their lifecycle. The framework integrates risk management processes, control objectives, and security measures into defined governance domains. It emphasizes a lifecycle approach, ensuring that cyber security considerations are addressed from system conception, through development and operation, to decommissioning.
In practice, organizations adopting DEF STAN 05-138 conduct regular risk assessments, implement mandated security controls, and demonstrate compliance with regulatory standards specific to defence environments. Security teams work to align both technical and organizational practices with the standard's requirements, integrating monitoring and incident response processes to maintain a robust security posture. Assessment cycles and ongoing verification support assurance efforts across program and project management activities.
With SmartSuite, organizations operationalize DEF STAN 05-138 by utilizing control libraries mapped to the standard's requirements, maintaining risk registers, and coordinating compliance tracking. Capabilities for policy governance, evidence collection, and automated remediation workflows support effective implementation. Reporting dashboards facilitate audit readiness and enable continuous monitoring of security practices and compliance with defence sector regulations.
Key Elements
- Cyber Security Management Framework
Establishes an overarching structure for defining, implementing, and maintaining cyber security controls across defence systems.
- Risk and Threat Assessment Processes
Outlines methodologies for evaluating current and emerging threats, vulnerabilities, and associated risks within defence environments.
- Supply Chain Security Requirements
Specifies criteria to ensure third-party suppliers adhere to cyber security standards throughout the acquisition lifecycle.
- System Lifecycle Cyber Assurance
Describes cybersecurity activities integrated into each stage of the system development and operational lifecycle.
- Incident Detection and Response Mechanisms
Defines processes for identifying, managing, and recovering from cyber incidents impacting defence systems.
- Governance and Accountability Structures
Organizes roles, responsibilities, and oversight functions to maintain compliance and effective security governance.
Framework Scope
UK DEF STAN 05-138 is adopted by defence contractors and suppliers responsible for securing military and defence-related assets, including weapons systems, command and control platforms, and operational networks. The standard governs the implementation of cyber security controls across defence systems, typically to support risk management, assurance requirements, and meeting regulated defence security obligations.
Framework Objectives
UK DEF STAN 05-138 defines the essential objectives for cybersecurity, risk management, and data protection in defence systems.
Strengthen cybersecurity governance across all defence system lifecycle stages
Enhance risk management to reduce vulnerabilities and potential cyber threats
Ensure compliance with relevant regulatory and defence-specific security requirements
Improve operational resilience against evolving cyber attack vectors
Safeguard sensitive data through robust security controls and data protection measures
Support audit readiness with documented processes and control effectiveness
Framework in Context
UK DEF STAN 05-138 aligns with standards such as ISO 27001, NIST SP 800-53, and the NCSC Cyber Assessment Framework, focusing on cyber security for defense systems. Organizations implement it to meet UK Ministry of Defence requirements, ensure regulatory compliance, and enhance operational security within defense procurement and supply chain contexts.
Common Framework Mappings
UK DEF STAN 05-138 is often mapped to globally recognized cybersecurity and defense frameworks to ensure alignment with best practices, facilitate risk management, and streamline compliance across multinational operations.
Mapped frameworks include:
CIS Critical Security Controls
Cyber Essentials
ISO/IEC 27001
ISO/IEC 27002
NIST Cybersecurity Framework
NIST SP 800-53
SOC 2
UK NCSC Cyber Assessment Framework
UK National Cyber Security Strategy
US DoD Cybersecurity Maturity Model Certification (CMMC)
- ClassificationCategoryCybersecurityDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorDefense SectorIndustryAerospace & Defense
- Region / PublisherRegionEuropeRegion DetailUnited KingdomPublisherUK Defence Standard 05‑138 — Cyber Security for Defence Systems Ministry of Defence (United Kingdom)
- VersioningVersionIssue 4Effective Date17 October 2017Issue Date17 October 2017
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityVery High
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
DEF STAN 05-138 is published by the UK Ministry of Defence and is publicly available via official UK Defence Standards publications on gov.uk.License included with platform
How SmartSuite Supports DEF STAN 05-138
Manage UK DEF STAN 05-138 defence cybersecurity requirements by organizing security controls, tracking system assurance activities, and maintaining evidence supporting compliance across defence systems and suppliers.
Defence Security Control Framework
Structure DEF STAN 05-138 controls with ownership, scope, and implementation tracking across programmes.
Defence Risk Assessment and Assurance
Link cybersecurity risks to defence systems and manage assurance activities throughout the lifecycle.
Governance, Policy, and Secure Design Oversight
Centralize security policies, design controls, and governance aligned to defence requirements.
Supplier and Secure Development Tracking
Track supplier requirements, component assurance, and secure development practices.
Incident Response and Security Operations
Manage detection, response workflows, and incident documentation across defence environments.
Control Coverage and Audit Readiness Reporting
Provide dashboards showing control coverage, system assurance status, and audit readiness.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO/IEC 27017 provides cloud-specific security controls to help organizations protect data and manage cloud-related risks.

ISO/IEC 27018 provides guidelines for protecting personally identifiable information processed in public cloud services.
Frequently Asked Questions For UK DEF STAN 05-138 (Cyber Security for Defence Systems)
UK DEF STAN 05-138 establishes minimum cyber security requirements for defence systems procured by the UK Ministry of Defence (MOD). It is used to ensure that suppliers address cyber risks throughout the lifecycle of MOD systems, from concept through disposal. The standard focuses on protecting sensitive information and maintaining operational capability.
Yes, UK DEF STAN 05-138 is mandatory for all relevant MOD contracts involving defence systems and equipment. Suppliers must demonstrate compliance as part of the procurement process, and ongoing adherence is regularly monitored by MOD accreditation authorities.
The scope of UK DEF STAN 05-138 covers all defence systems, including ICT, operational technology, and components that process, store, or transmit MOD information. It applies to both new projects and modifications to existing systems, regardless of whether systems are developed in-house or sourced from third parties.
The standard requires suppliers to perform cyber risk assessments, implement technical and procedural controls, manage supply chain security, and produce key artifacts such as Cyber Security Management Plans (CSMPs) and Security Cases. Emphasis is placed on demonstrating proactive risk management and documenting compliance throughout system development.
Implementation begins with a cyber risk assessment to identify threats and vulnerabilities. Organizations must then develop a CSMP outlining mitigation strategies, apply technical controls, ensure secure system design, and provide traceable evidence throughout the system lifecycle. Regular reviews and updates are required as threats and system scopes evolve.
UK DEF STAN 05-138 aligns with MOD and wider UK Government policies, and is often used alongside standards such as ISO 27001 and NIST SP 800-53. However, it specifies requirements tailored for MOD operational environments and the unique nature of defence systems, providing more detailed guidance than some general-purpose frameworks.
Organizations must regularly review cyber risks, update security documentation, and conduct periodic audits to verify control effectiveness. Continual improvement processes should be in place to address new vulnerabilities, and any significant changes to systems require reassessment against the standard’s requirements.
SmartSuite can help organizations manage UK DEF STAN 05-138 compliance by enabling risk tracking, managing cyber controls, and automating evidence collection for audits. The platform facilitates documentation of key artifacts such as CSMPs, supports workflow automation for compliance tasks, and provides robust reporting to demonstrate MOD audit readiness and ongoing compliance.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

