Won Your First MOD Contract? The Penetration Testing the Cyber Security Model Expects

Won Your First MOD Contract? The Penetration Testing the Cyber Security Model Expects

By EJN Labs · 27 Jul 2026 · 8 min read

The MOD Cyber Security Model (CSM) does not mandate penetration testing in one blanket clause. Instead, each contract carrying DEFCON 658 is given a Cyber Risk Profile, and higher profiles expect evidence of independent technical testing of the systems that handle MOD identifiable information. Most defence suppliers meet this with a CREST-accredited penetration test of 4 to 8 days at £1,200 to £1,400 per day, typically £4,800 to £11,200.

CSM penetration testing: what the Cyber Security Model actually expects

CSM penetration testing is one of the first questions a new defence supplier asks after contract award. The Cyber Security Model is the Ministry of Defence’s framework for assuring the cyber security of its supply chain, and it is mandatory for MOD contracts where DEFCON 658 applies. The model does not contain a single sentence saying every supplier must buy a penetration test. It assigns your contract a Cyber Risk Profile, requires a Supplier Assurance Questionnaire against that profile, and expects proportionate evidence that your controls actually work. At the higher profiles, credible evidence means independent technical testing from a CREST-accredited firm. This guide covers what to commission, when, and at what cost.

Why your first MOD contract changes your security obligations

Your first MOD contract moves you into a different assurance regime, because the MOD treats its supply chain as part of its own attack surface. Hostile states target defence subcontractors precisely because they are softer than the prime or the department itself.

MOD identifiable information may include technical specifications, delivery schedules, personnel details or design data, and even at OFFICIAL its aggregation is valuable to an adversary.

The obligations do not stop at your front door either. CSM requirements flow down: if you subcontract work involving MOD identifiable information, you must ensure your subcontractors meet the controls appropriate to their share of the risk. A supplier that treats the questionnaire as paperwork puts the contract and future bid eligibility at risk; one that builds real testing evidence early finds every subsequent bid easier.

The contractual driver: DEFCON 658 and the Cyber Risk Profile

The mechanism is contractual rather than statutory. DEFCON 658 is the defence condition the MOD inserts into contracts involving MOD identifiable information, obliging the supplier to comply with the Cyber Security Model in three steps:

  1. A risk assessment of the contract produces a Cyber Risk Profile, up to High, reflecting the sensitivity of the information and the impact of compromise.
  2. You complete a Supplier Assurance Questionnaire declaring how you meet the controls required at that profile.
  3. You maintain compliance for the life of the contract and flow the relevant requirements down to your subcontractors.

Lower profiles lean on foundational certification such as Cyber Essentials. Moderate and High profiles expect hands-on assurance, including Cyber Essentials Plus and evidence of proportionate security testing of the systems in scope. The MOD is also moving new procurements towards a Secure by Design approach, where continuous, evidenced assurance matters even more. The honest position: the CSM is a direct technical-testing trigger at the higher profiles, and testing evidence may be required proportionately at the lower ones. If your contract sits at Moderate or above, budget for a penetration test rather than arguing over clause wording.

What to test: scoping around MOD identifiable information

The scoping principle is simple: follow the MOD identifiable information. Anything that stores, processes or transmits it belongs in scope, which for most first-time defence suppliers means four estates.

External infrastructure and remote access

Your internet-facing perimeter is the first thing an adversary probes: VPN gateways, firewalls, mail routing and exposed management interfaces. An external infrastructure penetration test establishes whether the perimeter around your defence workload holds.

Cloud tenancies and file sharing

Suppliers commonly hold contract data in Microsoft 365, SharePoint or a cloud project environment, where misconfigured sharing links, weak conditional access and over-permissioned service accounts are the most common findings we see. A cloud penetration test reviews the tenancy configuration as well as attacking it.

Engineering and delivery systems

If you develop software or hardware for the contract, the CAD vault, source repositories, build pipeline and any APIs that move design data all handle MOD identifiable information and should be tested, not just the corporate network around them.

Internal network and user estate

An internal test answers the question your questionnaire implies: if one laptop is phished, can the attacker reach the defence data? Active Directory weaknesses and flat networks are where that answer usually goes wrong. Our penetration testing checklist walks through scope preparation.

How a CSM-driven engagement runs

A defence-supplier engagement adds two things to a well-run test: scoping anchored to your Cyber Risk Profile, and reporting written to serve as assurance evidence. A typical engagement:

  1. Scoping call. We map where MOD identifiable information lives, agree the estates in scope and confirm handling constraints.
  2. Rules of engagement. Testing windows, contacts, data-handling terms and escalation routes are agreed in writing.
  3. Testing. UK-based testers work through the agreed scope, combining automated discovery with manual exploitation, and flag any critical finding the day it is confirmed.
  4. Reporting. Findings are ranked by real-world risk, each with reproduction steps and a specific fix, plus an executive summary you can hand to a prime or an MOD assurance contact.
  5. Retest. Once fixes are applied, we verify them and issue an updated report, the artefact that closes the assurance loop.

What it costs and how scope drives the price

Penetration testing in the UK is priced by effort. Day rates at CREST-accredited firms typically run £1,200 to £1,400, and the number of days is set by the size and complexity of the scope. Typical ranges:

ScopeTypical effortTypical UK cost
External infrastructure3 to 5 days£3,600 to £7,000
Cloud tenancy (Microsoft 365 or AWS/Azure)4 to 7 days£4,800 to £9,800
Internal network and Active Directory5 to 8 days£6,000 to £11,200
Combined CSM-driven engagement4 to 8 days£4,800 to £11,200

These are typical UK ranges rather than a quote: the exact price depends on how many hosts, applications and tenancies handle MOD identifiable information, and combining scopes into one engagement is usually cheaper than testing piecemeal. For a fuller breakdown, see our guide to penetration testing costs in the UK; for an exact figure, use the quote form.

How EJN Labs approaches CSM penetration testing

EJN Labs is a UK firm delivering CREST-accredited penetration testing with UK-based testers, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit inside the same assurance regime our defence clients are entering. When we scope a first MOD contract, we start from the Cyber Risk Profile and the contract paperwork rather than a generic tick-list: asking where MOD identifiable information actually flows usually surfaces systems the supplier had not considered, such as a subcontractor file-transfer route or a legacy engineering server. Findings are prioritised by exploitability, and retesting is built in so you finish with a clean artefact. Our guide to the best UK penetration testing provider sets out the questions worth asking when comparing firms.

Frequently Asked Questions

Does the MOD Cyber Security Model require a penetration test?

Not as a blanket clause. The CSM is mandatory for MOD contracts where DEFCON 658 applies and assigns each contract a Cyber Risk Profile. Moderate and High profiles expect independently verified controls and proportionate testing evidence, while lower profiles lean on certification such as Cyber Essentials.

In practice, suppliers at the higher profiles meet that expectation with a penetration test from a CREST-accredited firm.

What does CSM penetration testing cost?

Expect £4,800 to £11,200 for a combined CSM-driven engagement as a first-time defence supplier, typically 4 to 8 days at £1,200 to £1,400 per day. Individual scopes run from 3 to 5 days for external infrastructure up to 5 to 8 days for an internal network test.

The exact price depends on scope, so request a quote against your contract.

What is DEFCON 658 and does it apply to my contract?

DEFCON 658 is the defence condition the Ministry of Defence includes in contracts involving MOD identifiable information, and it applies only if it appears in your contract. Where it does, the Cyber Security Model applies and your contract receives a Cyber Risk Profile.

You must then complete a Supplier Assurance Questionnaire against that profile. Check your contract schedule, or ask your commercial contact if you are unsure.

Do CSM requirements flow down to subcontractors?

Yes. If you subcontract work involving MOD identifiable information, you must ensure your subcontractors meet the controls appropriate to the risk their share of the work carries. Primes apply the same discipline to you, so expect to be asked for your own testing evidence.

Meeting that duty means assessing what information each subcontractor handles, flowing the relevant requirements into your subcontracts and being able to evidence their compliance.

Is Cyber Essentials Plus enough, or do I need a full penetration test?

Most suppliers at Moderate and High profiles need both, because they answer different questions. Cyber Essentials Plus verifies a fixed set of baseline controls through independent checks, while a penetration test attempts to compromise the specific systems holding MOD identifiable information.

The CSM expects Cyber Essentials Plus at higher risk profiles, and a penetration test goes further by showing what an attacker could actually reach.

Turn your first MOD contract into a security track record

The suppliers that thrive in defence have their assurance evidence ready before anyone asks. If DEFCON 658 sits in your contract, scope the test now and walk into your next bid with proof rather than promises. Tell us about your contract through our CREST pentesting quote form and we will come back with a scoped proposal and a fixed price.

Leave a Reply

Your email address will not be published. Required fields are marked *