Bridging the gap between academic research and real-world solutions
In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by
Joshua Ashton
Insight
22 Sept 2026
4 min read

CSMv4 and Cyber Risk Profiles Explained for Defence Suppliers
If you supply the Ministry of Defence, or form part of a defence supply chain, you may increasingly see terms such as CSMv4, Cyber Risk Profile, Def Stan 05-138, SAQ and Defence Cyber Certification appearing in tenders and contracts.
For many smaller suppliers, the difficult part is not understanding that cyber security matters. It is understanding exactly what level applies, what needs to be demonstrated, and what to do next.
The key point is this:
A Cyber Risk Profile determines the level of cyber security controls your organisation must be able to demonstrate for a particular defence requirement.
Under the current Cyber Security Model Version 4, those profiles are:
Level 0 – Basic
Level 1 – Foundational
Level 2 – Advanced
Level 3 – Expert
The higher the assessed cyber risk associated with the contract, the greater the level of organisational security and resilience expected from the supplier.
What is the Cyber Security Model?
The Ministry of Defence uses the Cyber Security Model (CSM) to introduce proportionate cyber security requirements throughout its supply chain.
CSMv4 is now the current model for new and existing procurements transitioning onto the updated framework.
It represents a significant change from CSMv3.
The previous model focused heavily on protecting MOD Identifiable Information and used the classifications Very Low, Low, Moderate and High.
CSMv4 takes a broader view.
It focuses on the cyber resilience of the supplier organisation itself and introduces the four Cyber Risk Profiles of Level 0 through Level 3.
This means suppliers need to think beyond simply asking:
“Where is the MOD data stored?”
They increasingly need to demonstrate that their wider organisation has appropriate controls around identity, devices, vulnerability management, security governance, incident response, resilience, recovery and supply-chain risk.
The MOD describes CSM as a risk-based and proportionate model built around a contract risk assessment, Defence Standard 05-138, the Supplier Assurance Questionnaire and flow-down requirements.
How is a Cyber Risk Profile determined?
The Cyber Risk Profile is not simply selected by the supplier.
For a MOD procurement, the relevant Defence delivery team performs a CSM Risk Assessment against the requirement.
That process generates the Cyber Risk Profile applying to the contract.
Under CSMv4, the four possible profiles are:
Level 0 – Basic
Level 0 is intended for requirements presenting a very low level of assessed cyber risk.
The emphasis is on demonstrating basic organisational cyber security practices.
It should not, however, be interpreted as meaning that cyber security is optional.
Level 0 sits at the entry point of the new defence cyber assurance model and is increasingly important because the MOD has asked industry partners to work towards Level 0 Defence Cyber Certification by 31 December 2026.
That Level 0 certification includes a Cyber Essentials requirement for applicable business-critical systems.
Level 1 – Foundational
Level 1 applies where there is a low to moderate level of assessed cyber risk.
At this point the expectations move considerably beyond basic cyber hygiene.
The supplier is expected to demonstrate a more comprehensive cyber security programme, including established processes, governance and operational controls.
This is an important distinction for SMEs.
Having Microsoft 365, antivirus software, multifactor authentication and Cyber Essentials does not automatically mean that the organisation will satisfy everything required at Level 1.
The organisation needs to be able to demonstrate that the required controls are implemented, managed and evidenced.
Level 2 – Advanced
Level 2 is associated with a high level of assessed cyber risk.
The expectation rises towards advanced security oversight, planning and organisational resilience.
Suppliers operating at this level should expect significantly more scrutiny around areas such as security governance, monitoring, privileged access, vulnerability management, incident response, resilience and the ability to demonstrate that controls are functioning consistently.
Level 3 – Expert
Level 3 is the highest CSMv4 profile.
It is intended for requirements carrying a substantial level of assessed cyber risk and expects expert cyber security capabilities, including a defence-in-depth approach capable of protecting the organisation against sophisticated and evolving threats.
The distinction between the four levels is defined in Defence Standard 05-138 Issue 4.
Where does Def Stan 05-138 Issue 4 fit in?
The Cyber Risk Profile tells you how much assurance is required.
Defence Standard 05-138 Issue 4 tells you which cyber security controls you need to satisfy.
The standard applies to MOD procurements, suppliers and subcontractors that have a relationship with one or more MOD contracts.
The number and sophistication of controls increase substantially between the different profiles.
The published standard describes:
Level 0 as having 3 controls;
Level 1 as having 101 controls;
Level 2 as having 139 controls;
with Level 3 representing the highest level of assurance.
The important point is therefore not simply to identify your Cyber Risk Profile.
You need to understand the underlying control set and determine whether your organisation can demonstrate those controls with evidence.
That final word matters.
Compliance is not simply about having a policy document that says something should happen.
The current MOD clarification explicitly states that control requirements should be supported by documented and implemented controls with auditable evidence available.
What is the Supplier Assurance Questionnaire?
Once the Cyber Risk Profile has been established, suppliers use the Supplier Assurance Questionnaire, or SAQ, to demonstrate their position against the requirements associated with that profile.
Separate question sets now exist for Levels 0, 1, 2 and 3.
The MOD published the CSMv4 SAQ question sets in March 2026, along with the corresponding Flow Down Risk Assessment questions.
Suppliers complete the operational SAQ through the Supplier Cyber Protection Service.
This is where evidence readiness becomes important.
A supplier answering an SAQ should be able to support its responses with evidence such as:
security policies and standards;
identity and privileged-access configurations;
device-compliance policies;
vulnerability and patch-management reports;
security monitoring records;
incident-response procedures;
backup and recovery testing;
risk registers;
access reviews;
supplier-management processes;
staff training records;
business continuity testing;
security governance records.
In other words, the goal should not be to write the right answer to a questionnaire.
The goal should be to operate the organisation in a way that means the answer is already demonstrable.
How does Defence Cyber Certification fit in?
Defence Cyber Certification (DCC) provides independent assurance against the Cyber Security Model.
Like the Cyber Risk Profiles, DCC has four levels from Level 0 to Level 3.
A valid DCC certification at the same or a higher level than the relevant contractual requirement can be accepted as assurance that the organisation satisfies the corresponding Def Stan 05-138 control requirement.
For example:
DCC Level 0 can satisfy a Level 0 control requirement;
DCC Level 1 can satisfy Level 0 and Level 1;
DCC Level 2 can satisfy Levels 0, 1 and 2;
DCC Level 3 can satisfy all four levels.
This was formally clarified by the MOD in Industry Security Notice 2026/02.
There is, however, an important practical distinction.
Holding DCC certification does not currently mean you can simply ignore the CSM procurement process.
The MOD's current guidance states that suppliers holding valid DCC certificates are not yet exempt from completing the relevant SAQ through the Supplier Cyber Protection Service.
The tooling is expected to recognise DCC more directly over time, but as things stand, the SAQ remains part of the contractual procurement process.
That distinction is worth understanding because DCC and the Cyber Risk Profile are related, but they are not the same thing.
The Cyber Risk Profile applies to the contractual requirement.
The DCC certificate provides assurance about the supplier organisation.
What if we do not yet meet the required level?
Receiving a particular Cyber Risk Profile does not necessarily mean that a supplier with gaps must immediately walk away from the opportunity.
Where the required compliance position cannot yet be demonstrated, the CSM provides for a Cyber Improvement Plan (CIP).
The CIP describes:
the areas where compliance is not yet achieved;
the remediation required;
the planned actions;
the intended timescales;
and, where relevant, why a requirement cannot currently be met.
The MOD updated the CSMv4 CIP template and guidance in July 2026.
Its current guidance also states that a supplier that does not hold DCC to the required level must submit a CIP.
The practical lesson for suppliers is straightforward:
Identify gaps early.
Discovering them during a live bid or immediately before contract award creates unnecessary commercial risk.
A readiness assessment performed before the procurement process gives the organisation time to remediate technical gaps, improve governance and establish the evidence needed to demonstrate that controls are genuinely operating.
What happens when subcontractors are involved?
One of the most important elements of CSMv4 is flow-down.
If a prime supplier subcontracts part of the delivery of a defence contract, the cyber requirements do not simply stop with the prime.
The supplier needs to complete a Flow Down Risk Assessment for the subcontract.
That assessment generates the appropriate Cyber Risk Profile for the subcontracted requirement.
The subcontractor then completes the appropriate Supplier Assurance Questionnaire.
If that subcontractor subsequently subcontracts part of its own delivery, the process can continue further down the chain.
The MOD's CSM guidance explicitly includes flow-down as part of the model, and the current question-set guidance provides a dedicated Flow Down Risk Assessment.
This is particularly relevant for SMEs that may not contract with the MOD directly.
You can still find CSM requirements arriving through a prime contractor or another organisation higher in the supply chain.
That is why defence cyber readiness increasingly matters to organisations that may never have considered themselves traditional defence suppliers.
What should a defence supplier do now?
For most SMEs, the starting point should not be attempting to implement every possible security technology.
Start with understanding your requirement and your current position.
A sensible sequence is:
1. Identify your contractual Cyber Risk Profile
Establish whether the requirement has been assessed as Level 0, 1, 2 or 3.
2. Review the corresponding Def Stan 05-138 controls
Understand the security outcomes required at your level.
3. Map your existing controls
Determine what you already have across Microsoft 365, Azure, endpoints, identity, networks, backup, security monitoring and governance.
4. Gather the evidence
For every control you believe you satisfy, ask:
“How would we prove this?”
5. Identify the gaps
Separate technology gaps from process, policy, governance and evidence gaps.
6. Build a remediation plan
Prioritise requirements that could prevent you from demonstrating compliance during a procurement.
7. Consider DCC readiness
For organisations intending to remain active within Defence, DCC should increasingly form part of the longer-term assurance strategy.
The MOD has asked industry partners to achieve at least DCC Level 0 by 31 December 2026, making this particularly relevant for suppliers preparing for future defence opportunities.
CSMv4 is ultimately about evidence, not paperwork
The biggest mistake organisations can make is to treat CSMv4 as another questionnaire exercise.
The direction of travel is different.
Defence increasingly expects suppliers to demonstrate that cyber security and resilience are embedded into the way their organisation operates.
That means being able to show:
what controls exist;
how those controls are implemented;
who is responsible for them;
whether they are tested;
whether weaknesses are identified;
and whether the organisation can produce reliable evidence.
For suppliers already operating mature Microsoft 365, Azure and security environments, much of the technical capability required may already exist.
The challenge is often configuring it correctly, filling the governance gaps and turning day-to-day security activity into auditable assurance.
Preparing for CSMv4 and DCC
Symposium IT works with organisations to understand their defence cyber requirements, assess their Microsoft and cloud environments, identify control and evidence gaps, and create a practical path towards CSMv4 and Defence Cyber Certification readiness.
If your organisation has received a Cyber Risk Profile, is preparing for DCC, or needs to understand where your existing environment sits against the new requirements, visit:
defence.symposium-it.co.uk
Assured today. Ready tomorrow.



