Defence Standard 05-138 — Customer Guide¶
Last updated: 2026-05-21 (Plan 145 v1)
What is Def Stan 05-138, and why does it matter to you?¶
Defence Standard 05-138 (current revision: Issue 4, July 2024) sets the mandatory cyber assurance level (CAL) every organisation holding a UK Ministry of Defence contract must declare against. Without a current and defensible CAL declaration backed by evidence, your MoD contract is at risk and your next bid is screened out. The quickest way to take pressure off your team is to keep the technical-control evidence behind every CAL line current — so the declaration is signed in days, not weeks, and every MoD contract reuses the same evidence base.
What Def Stan 05-138-specific features does Secruna ship?¶
- Rule book v1 — rules at
rule_book/ds_05_138/v1/covering the CAL 1-4 control sets. Loader picks it up viaKNOWN_FRAMEWORKS["ds_05_138"]. - CAL evidence pack export — PDF / CSV per CAL, with the technical control evidence behind the declaration.
- Cross-framework signal share — shared with NCSC CAF and Cyber Essentials Plus where the same controls apply.
- Counsel-review routing — every rule carries
pending_counsel_review: trueso high-stakes verdicts route through counsel before they ship. - Operator surface —
/admin/regulationslists DS 05-138 under shipped frameworks.
Limitations (v1)¶
- On-premise endpoint posture — Secruna's discovery covers cloud workloads, not on-premise endpoints. CAL controls that need per-endpoint evidence are operator-attested.
- List X / List N facility posture — for List X-cleared sites, the physical-security and personnel-security evidence sits with the Defence Industry Security Officer (DISO), not Secruna.
- No automatic DEFCON 658 supply-chain extension — DEFCON 658 cyber-security flow-down across the supply chain is operator- managed.
What Def Stan 05-138 is¶
Defence Standard 05-138 is the MoD's mandatory cyber-security standard for contractors. It defines four Cyber Assurance Levels (CAL 1 - CAL 4) by sensitivity of information handled, with a control set per level. The control set draws heavily from NCSC Cyber Essentials, the NCSC CAF and ISO/IEC 27001 but tightens several controls for the defence context.
The four levels:
- CAL 1 — handling of OFFICIAL information, baseline cyber hygiene. Cyber Essentials-grade.
- CAL 2 — handling of OFFICIAL with caveats or higher-impact OFFICIAL-SENSITIVE. Cyber Essentials Plus-grade.
- CAL 3 — handling of OFFICIAL-SENSITIVE under controlled conditions. CAF principle-aligned.
- CAL 4 — handling of SECRET via approved enclaves. List X site controls and approved secure systems required.
What Secruna covers¶
The v1 rule book covers technical controls for CAL 1-3:
- Access control — MFA enforcement, privileged access management, joiner / mover / leaver lifecycle.
- Secure configuration — hardening baselines, default-credential rotation, configuration drift detection.
- Vulnerability management — patch cadence, exposed-service scanning, dependency posture.
- Logging and monitoring — centralised log retention, SIEM coverage, anomalous-activity detection.
- Cryptography — TLS enforcement, key-management posture, data-at-rest encryption.
- Supply-chain security — vendor inventory, vendor security posture, DEFCON 658 flow-down scaffolding.
- Incident response — IR plan posture, tabletop exercise record, reporting workflow.
CAL 4 evidence is captured as operator-attested controls — Secruna does not access SECRET systems.
Using the CAL evidence pack¶
The CAL evidence pack is generated from the dashboard under Exports → Def Stan 05-138 Evidence Pack (org_admin role required). The file is a PDF / CSV per CAL:
- Cover — supplier name, declared CAL, generation timestamp.
- §1. Declaration summary — counts of controls at each verdict.
- §2. Per-control evidence — one row per CAL control with the verdict and a short evidence summary.
- §3. Gaps — Partial / Unmet controls surfaced as a remediation list.
- §4. Audit trail — last 90 days of platform activity.
Filename: secruna-ds-05-138-CAL{n}-{supplier_slug}-{date}.pdf.
What Secruna does NOT cover¶
- CAL 4 / SECRET system evidence. Out of platform scope.
- List X site physical security. DISO-managed.
- DEFCON 658 flow-down automation. Operator-managed.
- MoD declaration submission. Secruna ships the pack; the supplier files the declaration.
Frequently asked¶
Q. We hold an MoD contract requiring CAL 2 but also a NCSC CAF assessment. Do we run both? Yes — and Secruna shares evidence across both. CAL 2 control evidence reuses on the CAF assessment where the controls overlap.
Q. What is the relationship to Cyber Essentials Plus? CAL 1 broadly aligns with Cyber Essentials, CAL 2 with Cyber Essentials Plus. Reuse is intentional.
Q. The Issue changes regularly. How does Secruna keep up? The rule book is versioned. New Issues land as a new version with counsel review before the customer's pack switches over.