Building Software for Defence? The Penetration Testing the MOD Cyber Security Model Expects

Building Software for Defence? The Penetration Testing the MOD Cyber Security Model Expects

By EJN Labs · 24 Jul 2026 · 8 min read

CSM penetration testing is the technical assurance evidence defence suppliers use to satisfy the MOD Cyber Security Model. Where DEFCON 658 applies, your contract is given a cyber risk profile, and moderate or high profiles commonly mean independent security testing of the systems that touch MOD identifiable information. A typical engagement runs 4 to 6 days at £1,200 to £1,400 per day, so £4,800 to £8,400.

Why CSM penetration testing matters if you build software for defence

CSM penetration testing matters because the Cyber Security Model is how the Ministry of Defence decides how much security assurance your contract must carry. It is not a voluntary maturity framework: where DEFCON 658 is in the contract, CSM compliance is a contractual condition.

That condition flows down from the prime to every subcontractor handling MOD identifiable information, so it reaches you wherever your software sits in the MOD supply chain.

For a software vendor this lands in a specific way. The delivery authority assigns the contract a cyber risk profile, and you then demonstrate, through the Supplier Assurance Questionnaire, that you operate the controls that profile demands. At lower profiles the evidence is largely certification and policy. As the profile rises, the questions shift towards proof that controls actually work, which is where penetration testing becomes the expected form of evidence.

Bid teams feel this earliest. A commercial officer or prime security controller reviewing your bid wants assurance already in place, not promised for later. A recent independent test report from a CREST-accredited firm answers that question before it is asked.

The contractual driver: DEFCON 658 and the cyber risk profile

The CSM is administered by the Ministry of Defence and is mandatory for MOD contracts where DEFCON 658 applies. In practice the process runs in three steps:

  • The delivering authority sets the contract’s cyber risk profile, from very low to high, based on the sensitivity of the MOD identifiable information involved.
  • The supplier completes a Supplier Assurance Questionnaire against the controls required for that profile.
  • Primes flow the requirement down. Subcontractors must meet the profile relevant to the information they handle, and the prime will ask for evidence.

Two honest points. First, the CSM contains no single universal clause requiring every supplier to commission a penetration test, and we will not pretend it does. Second, suppliers at moderate and high risk profiles must operate and evidence technical security controls, and testing evidence may be required by profile, by the delivery authority, or by the prime’s own supply chain assurance. In our experience, primes rarely accept self-assessment alone for software that processes sensitive programme data. An independent test is how the gap between claimed controls and working controls gets closed.

Cyber Essentials sits underneath all of this as the baseline for handling MOD identifiable information. The CSM’s higher profiles ask a harder question than certification can answer: can your product and estate withstand a competent attacker.

What to test in a defence software estate

Scope should follow the MOD identifiable information. When we scope for defence software vendors, we map where contract data is created, stored and transmitted, then test the systems on that path rather than the whole company. Typical components:

  • The product itself: the web application, its APIs and any integration endpoints the prime or MOD systems will call. API penetration testing matters disproportionately here, because defence integrations are usually machine-to-machine.
  • The hosting environment: most modern defence software runs in UK sovereign cloud regions, so cloud penetration testing of the configuration, identity model and segregation between environments is core scope.
  • The build pipeline: source control, CI/CD and artefact repositories. A compromised pipeline is a supply chain attack on the MOD, which is precisely the scenario the CSM exists to prevent.
  • Your perimeter: the external infrastructure a real attacker would enumerate first, including VPNs, remote access and anything exposed by development teams.

Where a prime wants assurance against a realistic threat actor rather than a checklist, scenario-led red teaming can be layered on top. For most vendors entering the defence supply chain, though, a well-scoped application, API and cloud test covers what the SAQ evidence needs to show.

How a CSM-aligned engagement runs

A defence-facing engagement follows a disciplined path, with extra care around data handling because the estate touches MOD identifiable information:

  • Scoping call: we map the contract’s risk profile, the data flows and the systems in scope, and agree what evidence your SAQ response or your prime actually needs. Usually under an hour.
  • Rules of engagement: written authorisation, test windows, environment choice and escalation contacts. For defence work we test with UK-based testers only, and agree in advance how findings that touch contract data are stored and transmitted.
  • Testing: typically 4 to 6 days for an application, API and supporting cloud scope, longer for multi-component estates.
  • Reporting: findings rated by severity with reproduction steps and remediation, plus an executive summary a commercial officer or prime security controller can read without translation.
  • Retesting: we verify fixes and issue an updated report, normally the document that goes into the assurance pack.

Before your first engagement, our penetration testing checklist covers what to have ready so no testing time is wasted.

What CSM penetration testing costs and how scope drives price

UK penetration testing is priced by effort. Day rates at accredited firms typically run £1,200 to £1,400, and the number of days is set by the size of the estate, not the framework. These are typical ranges for defence software suppliers:

ScopeTypical effortTypical UK cost
External infrastructure and perimeter2 to 4 days£2,400 to £5,600
Web application and API4 to 6 days£4,800 to £8,400
Cloud environment and build pipeline4 to 7 days£4,800 to £9,800
Combined product, cloud and perimeter8 to 12 days£9,600 to £16,800

The main cost drivers are the number of applications and APIs, the complexity of the cloud estate, and whether the pipeline is in scope. For a fuller breakdown across engagement types, see our guide to penetration testing cost in the UK. For an exact figure, the fastest route is our quote form, which takes about two minutes.

How EJN Labs approaches testing for defence software suppliers

EJN Labs is a UK CREST-accredited penetration testing firm, certified to Cyber Essentials Plus, ISO 27001 and ISO 9001, with UK-based testers only. That combination matters in defence supply chains: our CREST penetration testing methodology gives primes an externally audited standard to point to, and our own certifications mean we meet the baseline the CSM expects of any supplier handling contract information, including us as your tester.

We scope from the contract, not from a menu: the risk profile, the flow-down requirements you have been given, and the systems that touch MOD identifiable information, with the report written to map cleanly onto your SAQ response or prime assurance review. Findings come with severity ratings and remediation your engineers can act on, and we retest fixes as standard. If you are still comparing suppliers, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any firm, including us.

Frequently Asked Questions

Does the MOD Cyber Security Model mandate a penetration test?

Not in a single universal clause. The CSM is mandatory where DEFCON 658 applies and requires controls proportionate to your contract’s cyber risk profile. In practice, independent penetration testing is the standard way suppliers demonstrate that those controls actually work.

At moderate and high profiles suppliers must evidence working technical controls, and testing evidence may be required by the delivery authority or your prime.

What is DEFCON 658 and does it apply to my contract?

DEFCON 658 is the MOD contract condition that makes cyber security requirements, assessed through the Cyber Security Model, legally binding on suppliers handling MOD identifiable information. It applies when the MOD includes it in your contract, and primes must flow it down to subcontractors.

Check your contract terms and any flow-down schedule from your prime. If you handle contract data, assume it reaches you.

What does CSM penetration testing cost?

Expect £2,400 to £16,800 depending on scope, at UK day rates of £1,200 to £1,400. A web application and API test usually takes 4 to 6 days, £4,800 to £8,400, while a combined estate engagement runs £9,600 to £16,800 at the top of the range.

External infrastructure runs £2,400 to £5,600 and cloud and pipeline £4,800 to £9,800. Scope drives the price, so an exact figure comes from a short scoping call or our quote form.

Do subcontractors need to test, or only primes?

Subcontractors need to test too, because the CSM flows down. Primes holding DEFCON 658 contracts must ensure subcontractors handling MOD identifiable information meet the relevant risk profile, and at higher profiles that routinely includes independent testing of the systems involved.

The requirement applies regardless of where you sit in the chain. If your software processes or stores contract data, your prime will ask you to evidence controls against the profile relevant to that information.

Is Cyber Essentials enough for MOD contracts?

Only at the lowest risk profiles. Cyber Essentials is the baseline expectation for suppliers handling MOD identifiable information, and Cyber Essentials Plus strengthens it with independent verification, but moderate and high profiles require substantially more controls and evidence that they work.

Certification alone cannot show that controls stand up in practice, so treat Cyber Essentials as the entry ticket and penetration testing as the proof for higher profiles.

Get the assurance evidence your defence bid needs

If a risk profile, an SAQ deadline or a prime’s assurance review is asking questions your evidence cannot answer, tell us what you build and what the contract requires through our CREST penetration testing quote form. We respond with a scoped proposal, usually within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *