By EJN Labs · 21 Jul 2026 · 8 min read
CSM penetration testing is not named as a blanket requirement in the MOD Cyber Security Model, but the model is a strong technical-testing trigger. Contracts covered by DEFCON 658 carry a cyber risk profile, and at Moderate and High profiles suppliers are expected to evidence controls that independent testing demonstrates best. Typical UK engagements run 4 to 10 days at £1,200 to £1,400 per day, so £4,800 to £14,000.
CSM penetration testing: why defence suppliers keep asking the question
If you hold or are bidding for a Ministry of Defence contract, you will meet the MOD Cyber Security Model (CSM) early. It is how the MOD makes sure every supplier handling MOD-identifiable information protects it proportionately, enforced through the contract where DEFCON 658 applies. CSM penetration testing sits in an awkward spot for bid leads: the model does not print the words “penetration test” against every contract, yet contracting authorities and primes routinely ask for testing evidence before accepting a supplier onto a programme.
The contractual driver: DEFCON 658 and cyber risk profiles
The CSM is owned by the Ministry of Defence and is mandatory for MOD contracts where DEFCON 658 applies. DEFCON 658 is the contract condition requiring suppliers to protect MOD-identifiable information and to flow the same obligation down to subcontractors who handle it, which is how a second-tier engineering supplier or software vendor gets pulled into the CSM without ever contracting directly with the MOD.
The process works in three steps:
- The contracting authority assigns the contract a cyber risk profile, ranging from Very Low up to High, based on the sensitivity of the information the supplier will hold.
- The supplier completes a Supplier Assurance Questionnaire declaring which controls it has in place against that profile.
- Where gaps exist, the supplier agrees a plan to close them, and the evidence sits behind the contract for the life of the programme.
The controls expected at each profile step up sharply. Lower profiles anchor on Cyber Essentials and Cyber Essentials Plus. Moderate and High profiles add a much wider control set covering vulnerability management, secure configuration, monitoring and incident response. The MOD is also transitioning suppliers towards its Secure by Design approach, which raises the bar on demonstrable, evidence-based assurance rather than one-off self-declaration.
Does the CSM actually mandate a penetration test?
The honest answer: the CSM contains no universal clause saying every supplier must commission a penetration test. What it does is create three routes by which testing becomes required or expected in practice:
- Cyber Essentials Plus, expected from the lower risk profiles upwards, is itself a hands-on technical assessment of your workstations, email, browsers and external services rather than a paper declaration.
- At Moderate and High risk profiles, suppliers must evidence controls around vulnerability identification and management, and an independent penetration test is the most widely accepted way to demonstrate those controls work rather than merely exist on paper.
- Contracting authorities and primes can, and frequently do, write explicit testing requirements into individual contracts, and those flow-down terms are binding regardless of what the baseline model says.
So treat the CSM as a strong technical-testing trigger. If your contract carries a Moderate or High profile, or your prime asks for assurance evidence, budget for a test from a CREST-accredited penetration testing firm rather than arguing the point at contract award, when a delay costs far more than the test.
What to test in a defence supplier estate
Scope should follow the MOD-identifiable information, not your whole IT estate. The recurring priorities when we scope defence suppliers:
- External infrastructure: the internet-facing perimeter, VPNs and remote access used by project staff. Our external infrastructure penetration testing covers this layer.
- The segregated project environment: test the segregation itself, because a flat network quietly bridging office IT and the project enclave is the single most common serious finding we raise.
- File stores and engineering data: CAD repositories, PLM systems and shared drives holding designs and programme documents.
- Email and identity: Microsoft 365 or equivalent, because phishing against named programme staff is the realistic attack path.
- Any software or APIs you deliver into the programme, where API penetration testing may be a contractual expectation in its own right.
How a CSM-aligned engagement runs
A typical engagement follows five stages:
- Scoping call: we map where MOD-identifiable information lives, agree the risk profile context and confirm what evidence your contracting authority or prime expects, with NDAs signed first.
- Rules of engagement: testing windows, out-of-scope systems and escalation contacts agreed in writing. All testing and data handling stays within the UK, performed by UK-based testers.
- Testing: external, internal or application testing runs against the agreed scope, with any critical finding phoned through the same day rather than saved for the report.
- Reporting: an executive summary written for commercial officers and assessors, plus technical detail and remediation steps for your IT team.
- Retest: once fixes land, we retest the findings and issue an updated report you can attach to your assurance evidence.
Preparing internally first? Our penetration testing checklist covers what to have ready before a tester arrives.
What CSM penetration testing costs and how scope drives price
UK penetration testing is priced by the day, at £1,200 to £1,400 per tester day for accredited firms. The scope, not the framework, drives the day count:
| Scope | Typical effort | Typical cost |
|---|---|---|
| External infrastructure and remote access | 3 to 5 days | £3,600 to £7,000 |
| Internal network and project enclave segregation | 5 to 8 days | £6,000 to £11,200 |
| Web application or API you deliver into the programme | 4 to 6 days | £4,800 to £8,400 |
| Combined external, internal and application scope | 8 to 12 days | £9,600 to £16,800 |
Most defence-supplier engagements land at 4 to 10 days, which is £4,800 to £14,000. These are typical UK ranges rather than a quote; an exact price depends on host counts, applications and the complexity of your segregation. For how these numbers break down across engagement types, see our guide to penetration testing cost in the UK, or use our quote form for a fixed figure on your own estate.
How EJN Labs approaches testing for MOD suppliers
Evidence written for assessors, not just administrators
EJN Labs is a CREST-accredited UK penetration testing firm, certified to Cyber Essentials Plus and ISO 27001, using UK-based testers only, so your assurance evidence carries the weight of an independent, accredited assessment and no testing data leaves the UK.
We scope defence-supplier work around the information flow rather than the asset list: where MOD-identifiable information enters your organisation, who touches it, and where it rests, then we test the boundaries around that path, meaning the remote access into the enclave, the segregation between office IT and project networks, and the identity layer that gates both. Reports map each finding to the control area it undermines, so your security controller can lift the evidence straight into a Supplier Assurance Questionnaire response. If you are comparing suppliers, our guide to choosing the best UK penetration testing provider sets out the questions worth asking any firm, including us.
Frequently Asked Questions
Does the MOD Cyber Security Model require a penetration test?
Not as a universal clause. The CSM assigns each contract a cyber risk profile and expects controls proportionate to it. Cyber Essentials Plus, expected from the lower profiles upwards, is itself a hands-on technical assessment, and at Moderate and High profiles independent penetration testing is the most widely accepted way to evidence vulnerability management controls. Individual contracts and prime flow-downs can also require testing explicitly.
What does CSM penetration testing cost?
UK day rates for accredited firms run £1,200 to £1,400 per tester day, and most defence-supplier engagements take 4 to 10 days, so £4,800 to £14,000. A focused external infrastructure test sits at 3 to 5 days (£3,600 to £7,000), while a combined external, internal and application scope runs 8 to 12 days (£9,600 to £16,800). Exact pricing depends on scope, so get a quote against your actual estate.
Do subcontractors have to comply with the CSM as well?
Yes, where they handle MOD-identifiable information. DEFCON 658 requires prime contractors to flow the same protection obligations down the supply chain, so a subcontractor can inherit CSM requirements through its prime without contracting directly with the MOD. If your prime has asked for a risk profile response or testing evidence, that request is contractually grounded and worth taking seriously at bid stage.
Is Cyber Essentials Plus enough on its own for an MOD contract?
It depends on the contract’s risk profile. For lower profiles, Cyber Essentials or Cyber Essentials Plus may satisfy the expected controls. Moderate and High profiles add a much wider control set covering vulnerability management, monitoring and secure configuration, where a scoped penetration test provides evidence Cyber Essentials Plus does not. Check the profile assigned to your specific contract before assuming certification alone will carry you through.
What should a defence supplier put in scope for a penetration test?
Follow the MOD-identifiable information. Priority targets are the external perimeter and remote access, the segregation between office IT and any project enclave, file stores and engineering data systems holding programme material, email and identity, and any software or APIs you deliver into the programme. Testing the segregation itself is the part most suppliers miss and the source of the most serious findings.
Get testing evidence your contracting authority will accept
The cheapest time to sort testing evidence is before your assurance response is challenged. Tell us your risk profile and what your contract or prime is asking for. Request a CREST penetration testing quote and we will come back with a fixed price and timeline.




Leave a Reply