Bridging the gap between academic research and real-world solutions
In the pursuit of scientific advancement, the journey from theoretical research to tangible solutions is often fraught with challenges.

Written by
Joshua Ashton
Insight
29 Sept 2026
4 min read

Defence Supply-Chain Flow-Down Requirements: What SMEs Need to Know
For many SMEs, Defence cyber requirements do not arrive directly from the Ministry of Defence.
They arrive from a prime contractor.
Or from another supplier sitting one or two levels higher in the supply chain.
That is where flow-down becomes important.
Under the Ministry of Defence Cyber Security Model Version 4, flow-down is the process used to apply appropriate cyber requirements from a prime contractor into lower-tier subcontracting arrangements — and then onwards through subsequent subcontracting tiers where necessary. The MOD states that this process is required down the supply chain so it can gain assurance over the organisations involved in delivering Defence work. GOV.UK
For SMEs, the practical message is straightforward:
You do not need to hold a direct MOD contract for CSMv4 requirements to become relevant to your business.
What does “flow-down” mean?
Flow-down is the process by which a supplier contracting with the MOD passes appropriate cyber-security requirements into its subcontracting arrangements.
The requirement does not simply stop with the prime.
If a prime contractor outsources part of its delivery, the subcontracted activity needs to be assessed so that the appropriate Cyber Risk Profile can be established for the organisation performing that work.
The subcontractor then completes the relevant Supplier Assurance Questionnaire (SAQ) against that Cyber Risk Profile.
If that subcontractor then outsources part of its own delivery, the same principle continues further down the chain. GOV.UK
This is why even relatively small engineering, manufacturing, software, consultancy or specialist-service businesses can find Defence cyber requirements appearing in commercial agreements.
Who is responsible for flow-down?
The MOD guidance is clear:
suppliers are responsible for flow-down.
DEFCON 658 contains the contractual obligations that suppliers are required to place upon subcontractors where appropriate. GOV.UK
That means a prime contractor cannot simply assume that its subcontractors are secure because they hold a general cyber certification or use a reputable MSP.
The appropriate Cyber Security Model process needs to be followed.
Likewise, a subcontractor may itself become responsible for flow-down if it further subcontracts part of the Defence-related work.
This creates a chain of responsibility.
What does the flow-down process look like?
The MOD provides a practical example of how this should work.
A prime contractor performs a CSM Risk Assessment against the activity it intends to subcontract.
That Risk Assessment generates:
a Cyber Risk Profile; and
a Risk Assessment Reference (RAR).
The prime then provides that RAR to the subcontractor.
The subcontractor uses the Supplier Cyber Protection Service to complete the appropriate SAQ and demonstrate whether it meets the controls required by the assigned Cyber Risk Profile.
If the subcontractor then outsources part of its own activity, it completes another Risk Assessment for that downstream requirement and passes the resulting RAR to the next supplier.
The process can continue through multiple tiers. GOV.UK
The MOD has also published dedicated Flow Down Risk Assessment question sets as part of CSMv4, alongside SAQ question sets for Levels 0 through 3. Suppliers, including subcontractors, are expected to use the Supplier Cyber Protection Service for these activities. GOV.UK
Does the subcontractor automatically inherit the prime’s Cyber Risk Profile?
No.
This is an important distinction.
If the prime contract carries a particular Cyber Risk Profile, that does not automatically mean every subcontractor receives exactly the same level.
Instead, the supplier performs a new Risk Assessment for the subcontracted activity.
That assessment determines the Cyber Risk Profile appropriate to the work being passed down. GOV.UK
This reflects the risk-based nature of the Cyber Security Model.
A subcontractor performing a small, low-risk activity may require a different assurance level from another subcontractor handling critical systems, sensitive data or an essential part of the contracted capability.
The requirement should be proportionate to the risk of the activity being outsourced.
What are Cyber Risk Profiles?
CSMv4 uses four Cyber Risk Profiles:
Level 0
Level 1
Level 2
Level 3
The assigned profile determines which minimum controls from Defence Standard 05-138 Issue 4 the supplier needs to meet.
The MOD describes CSMv4 as an organisation-wide approach to security and resilience, rather than a model focused only on individual pieces of MOD information. GOV.UK
Defence Standard 05-138 Issue 4 applies not only to MOD suppliers but also to their subcontract suppliers where there is a relationship to one or more MOD contracts. GOV.UK
For SMEs, that means the relevant requirement may assess areas such as:
identity and access;
endpoint security;
vulnerability management;
monitoring;
incident response;
backup and recovery;
governance;
supply-chain risk; and
organisational resilience.
The exact control set depends on the assigned level.
What happens when the subcontractor receives the RAR?
The subcontractor completes the appropriate Supplier Assurance Questionnaire through the Supplier Cyber Protection Service.
The SAQ assesses the organisation against the controls associated with the relevant Cyber Risk Profile.
The MOD's current process automatically scores the SAQ and tells the supplier whether it is compliant with the required level. GOV.UK
This is where preparation matters.
A subcontractor should not wait until receiving the RAR before asking:
“What does Level 1 mean?”
or:
“Can we evidence the controls we have?”
By that point the requirement may already be sitting inside a live procurement or commercial negotiation.
What if the subcontractor is not compliant?
Non-compliance does not necessarily mean the subcontract must immediately be abandoned.
Where a subcontractor cannot meet the required controls, a Cyber Improvement Plan (CIP) may be needed.
The current MOD flow-down guidance states that if a downstream supplier is not compliant with the Def Stan 05-138 controls required for its Cyber Risk Profile, CIP requirements must be agreed between the parties and visibility provided to the MOD delivery team. GOV.UK
A CIP sets out:
where the gaps are;
what needs to be remediated;
planned actions;
timescales; and
where relevant, why a particular requirement cannot currently be met.
The wider CSM process allows the contracting authority to take the compliance position — or an agreed CIP — into account when selecting and contracting with the supplier. GOV.UK
For SMEs, the important lesson is:
finding gaps early gives you options.
Finding them during final contract negotiation creates commercial pressure.
Does DCC remove the need for flow-down?
No.
Defence Cyber Certification and flow-down are related, but they perform different functions.
DCC provides independent assurance that an organisation meets the relevant requirements of the Cyber Security Model at a particular level.
The Cyber Risk Profile, however, applies to the specific contractual requirement.
The MOD's current guidance also says that suppliers holding valid DCC certificates are not yet exempt from completing the relevant SAQ through the Supplier Cyber Protection Service. GOV.UK
So a subcontractor with DCC certification may have a strong assurance position, but the contractual flow-down and risk-assessment process still matters.
What about existing contracts?
Existing contracts need particular care.
The MOD states that a supplier must first receive a CSMv4 Cyber Risk Profile and RAR from its customer before it can undertake new CSMv4 flow-down activity.
If that information has not yet been received, suppliers are advised to request it from the relevant MOD delivery team or buyer, complete their own SAQ, and then begin flow-down activity. GOV.UK
This is worth checking rather than assuming that older CSMv3 processes continue unchanged.
CSMv4 is now the current model for existing and new procurements transitioning onto the updated framework. GOV.UK
Why does flow-down matter to SMEs?
This is where the commercial impact becomes real.
An SME may never see a Find a Tender notice from the MOD.
It may never have a direct relationship with Defence procurement.
But if it supplies:
precision engineering;
software;
cloud services;
consultancy;
logistics;
electronics;
manufacturing;
data services;
managed IT;
specialist recruitment; or
another capability to a Defence prime,
then contractual cyber requirements can arrive through its customer.
That can affect whether the organisation is considered suitable for future work.
A supplier that can respond quickly to a flow-down request with:
a clear understanding of CSMv4;
current Cyber Essentials where applicable;
mature controls;
supporting evidence;
a known Cyber Risk Profile;
and an organised remediation plan where gaps exist,
is in a much stronger commercial position than one starting from scratch.
Flow-down is not just a prime-contractor problem
SMEs should also remember that they may themselves become the flowing party.
If you receive Defence work and then subcontract:
software development;
managed services;
hosting;
engineering;
manufacturing;
data processing;
security services;
technical support;
you may need to assess that subcontracted activity and apply the appropriate requirements to your own supplier.
This means understanding your supplier estate becomes increasingly important.
Ask:
Which third parties are critical to our Defence delivery?
What access do they have?
What systems or information do they handle?
Could we assess them if a flow-down requirement applied?
Do our contracts allow us to impose security requirements on them?
Those questions are better answered before the next tender arrives.
What evidence should you expect to need?
The exact evidence depends on the assigned Cyber Risk Profile, but typical areas may include:
security policies;
asset inventories;
device-management evidence;
privileged-access records;
patching and vulnerability reports;
security monitoring;
incident-response procedures;
backup and recovery testing;
risk registers;
training records;
supplier-assurance records;
access reviews;
continuity and recovery testing.
This is why our earlier DCC guidance focuses heavily on evidence readiness.
The goal should not be to produce a convincing answer to an SAQ.
The goal should be to operate the organisation so that the answers can be demonstrated with evidence.
Five practical steps for SMEs
1. Understand whether Defence work flows through your customers
Do not assume that because your customer is a private company, Defence cyber requirements cannot apply.
Ask whether your products or services support MOD contracts.
2. Identify your critical subcontractors
Understand which suppliers support the services you deliver into Defence.
3. Review your contract terms
Determine whether the required cyber-security obligations can be flowed down effectively.
4. Build evidence before you need it
Organise security evidence against the likely areas within CSMv4 and Def Stan 05-138.
5. Do not wait for an RAR to begin readiness work
The exact Cyber Risk Profile may depend on the subcontracted activity, but good organisational cyber resilience is valuable regardless of the eventual level.
A practical example
Imagine a Defence prime contracts Company A to manufacture a complex system.
Company A outsources some precision components to Company B.
Company B then uses Company C for specialist electronic testing.
The cyber-assurance chain may work like this:
MOD → Company A
The MOD determines the Cyber Risk Profile for the main requirement.
Company A → Company B
Company A performs a Risk Assessment for the work being subcontracted and passes the resulting RAR to Company B.
Company B completes the appropriate SAQ.
Company B → Company C
Company B performs its own Risk Assessment against the specialist testing being subcontracted.
Company C receives the RAR and completes the relevant SAQ.
This is essentially the model described in the MOD's own flow-down example. GOV.UK
The practical implication is that cyber assurance can follow the work all the way down the chain.
Flow-down turns cyber security into a supply-chain issue
This is perhaps the most important lesson.
Defence cyber assurance is not only about protecting one organisation.
It is about reducing weaknesses across the wider ecosystem supporting Defence.
A prime contractor can operate a mature security environment and still carry significant risk if a critical lower-tier supplier has weak controls.
Flow-down is the mechanism designed to reduce that gap.
For SMEs, it therefore creates both an obligation and an opportunity.
The obligation is to meet the requirements attached to the work.
The opportunity is to become a supplier that primes can work with confidently.
How Symposium IT can help
Symposium IT helps UK Defence suppliers understand and prepare for the cyber requirements that increasingly flow through Defence supply chains.
Through Symposium Defence, we can support organisations with:
CSMv4 readiness;
Cyber Risk Profiles;
DCC readiness;
Cyber Essentials;
Supplier Assurance Questionnaires;
evidence preparation;
Cyber Improvement Plans;
Microsoft 365;
Entra ID;
Intune;
Defender;
Azure;
endpoint security;
backup and recovery;
incident response; and
supplier cyber assurance.
For SMEs, the goal is to remove uncertainty before a prime contractor asks for evidence.
If Defence cyber requirements flowed into your business tomorrow, would you know what to do?
If the answer is unclear, now is the time to establish your position.
Explore Symposium Defence to understand your current readiness and the steps needed to operate confidently within the UK Defence supply chain.



