The Defence Supply Chain Risk Nobody Priced In


Every prospective defence supplier who calls me wants roughly the same thing: help understanding what the MOD actually requires, so they can get into the supply chain and start earning from it. Nobody opens the conversation asking what they’re taking on. They open it asking how to get in.

One of them, a small manufacturer that had just won its first MOD contract, was three weeks from a Supplier Assurance Questionnaire they had no idea existed when they submitted the bid.

That gap, between winning and understanding what you’ve won, is where the real risk in defence procurement now lives. And it’s about to get a lot more crowded.


The commercial reality nobody is putting on the invoice

The UK government’s Defence Investment Plan has core defence spending rising to 2.6% of GDP in 2026-27, then 2.7% through 2027-28 and 2028-29, on a path to NATO’s 3.5% core defence target by 2035. At the 2025 NATO summit in The Hague, members agreed a wider 5% of GDP commitment across the alliance by 2035: 3.5% on core defence, 1.5% on broader security and resilience spending. Those numbers are not aspirational anymore. The money is moving into procurement now, and it is moving into a supply base that has to grow to absorb it.

That means new suppliers. It means companies that have never held a defence contract being brought into DEFCON 658 arrangements. It means growth-stage businesses being pulled into the same governance framework that established primes have been resourcing for years.

And here is what most of them are not being told upfront.


What is actually mandatory, and from when

Since 3 December 2025, CSMv4 has been mandatory for every contract carrying DEFCON 658. That is not a phased rollout. That is the current state of every new award.

Before a supplier receives one of those contracts, they have to:

  • Register on the Supplier Cyber Protection Service (SCPS) portal
  • Complete a Supplier Assurance Questionnaire against the Cyber Risk Profile rating the buyer has assigned to that contract
  • Hold Cyber Essentials, now under the Danzell question set that went live on 27 April 2026
  • Sit inside the flow-down obligations of DEFSTAN 05-138 Issue 4, mandatory since 3 November 2025

If the supplier cannot pass the SAQ at the required Cyber Risk Profile level, they have one other route: submit a Cyber Improvement Plan and accept the contract with that plan attached.

This is where the trap sits.


The Cyber Improvement Plan was not built for this

The CIP was designed as a bridge. It gave established suppliers, companies with existing cyber governance programmes, a way to transition from CSMv3 to CSMv4 within managed timescales. The assumption was that a business signing a CIP had the internal capability to close its gaps against a known plan.

That assumption does not hold for a manufacturer winning its first MOD contract.

A CIP is not a waiver. It is a contractual commitment to reach compliance by a defined date. The clock starts the day the contract is awarded. If the supplier misses the timeline, they are in breach of contract terms, not just short on a certificate.

For a company that priced the bid without a cyber governance programme in place, the CIP is not what it looks like.

A deferred liability.

It defers the audit. It does not defer the spend, the resourcing, or the operational disruption. And it puts a compliance deadline on top of a delivery deadline that was already tight enough to win the bid.

I have seen companies celebrate signing a CIP as if they had passed the test. They had done the opposite. They had accepted a second contract, this one against themselves, and they had not costed it.


What becomes visible next

The first cohort of CIP-holders is now approaching a full trading year on their contracts. Their first anniversary SAQ is the moment the deferred liability becomes real.

Three things happen from here.

Buyer scrutiny of CIP timelines is going to increase. Contracting authorities are not going to keep accepting improvement plans as a substitute for evidence forever. As the first wave comes up for review, the acceptable answer moves from “we have a plan” to “here is our progress against it.”

Primes will start asking sub-contractors for CIP evidence too. They manage flow-down compliance under DEFSTAN 05-138, which exposes them to their sub-tier suppliers’ governance in a way they were not exposed before. Expect CIP progress requests to become part of ongoing programme reviews, not an annual box-tick.

And somewhere in the middle of that, a cohort of new entrants will find themselves unprepared. The companies that treated the CIP as a paperwork hurdle rather than a governance commitment will have those conversations without evidence. That’s a commercial event, not a compliance one.


Who is exposed first

Three groups sit in the first line of fire.

Smaller manufacturers and other first-time suppliers winning their first MOD contract are being onboarded into a governance framework built for larger, more mature suppliers, and they are being onboarded fast.

Defence-adjacent SMEs entering through frameworks or consortium bids are being pulled into DEFCON 658 flow-downs through partners, often without understanding the full scope of what they have signed up to.

And managed service providers are now in dual scope. The Cyber Security and Resilience Bill passed the Commons on 16 June 2026. MSPs serving regulated entities sit inside that scope, and they sit inside CSMv4 flow-down too if any of their clients are in defence. That’s two regulatory regimes converging on one delivery capability.

If any of those descriptions fits your business, “we’ll sort it after the win” is the assumption to stop making.


Where the opportunity is

Here is the part that is easy to miss when the pressure feels one-sided.

The organisations that build cyber posture ahead of the contract are competing on different terms to the ones building it in response to the CIP. They can evidence compliance at tender stage instead of deferring it. They walk into procurement conversations without a caveat attached. They do not need a CIP.

That matters to a prime managing flow-down risk and to a contracting authority managing oversight across a supply base that is scaling faster than it can certify. Being the supplier that needs the least managing is not a governance position. It is a commercial one.


From new entrant to contract-ready: a maturity ladder

Five steps. In order. No skipping.

  1. Baseline. Achieve Cyber Essentials under the Danzell control set. Before you start, understand your own business-critical operations and which systems support them. Cyber Essentials is not paperwork. It is the first honest audit of what you actually run.
  2. Assess. You cannot register on the Supplier Cyber Protection Service or run a Cyber Risk Profile self-assessment until the buyer issues you a Risk Assessment Reference. That normally arrives at first market engagement or with the invitation to tender, not before. What you can do earlier: ask the buying authority, at that first contact, what Cyber Risk Profile level the opportunity is likely to carry. Then the moment the reference lands, register and run the SAQ against it immediately. Most suppliers let it sit while they focus on the technical bid. Do not be one of them.
  3. Map. Identify your Tier 2 dependencies, the suppliers whose unavailability would stop you delivering. List them. Check their Cyber Essentials status. Your resilience is their resilience, and under DEFSTAN 05-138 flow-down, so is your exposure.
  4. Evidence. Build the documentation trail before anyone asks for it: governance policy, incident response plan, patch management process, MFA configuration evidence across every cloud tool you use. This is the difference between saying you are compliant and being able to show it in the room.
  5. Certify. Apply for DCC certification at the appropriate level. The scheme was announced in May 2025 and is administered by IASME. DCC certification demonstrates your posture without requiring the buyer to accept your word for it. That last part is the whole point.

Where this ends

The surge in defence procurement is a real opportunity, the kind of growth window manufacturing has not seen in decades. It is opening to businesses that have never touched a defence contract before.

The suppliers still holding those contracts in three years will be the ones who worked out their posture before they needed it, not the ones racing a CIP deadline they did not know they had signed up for.

Go back to how most of these conversations start. Everyone wants to know how to get in. Almost nobody asks what they are taking on once they are in. That is the gap this piece has been about, and it is worth closing before you submit the next bid, not after you win it.

If you are bidding on a defence contract right now, do you actually know what you are signing up for?

Reference list


Discover more from Acceptable Risk (Documented)

Subscribe now to keep reading and get access to the full archive.

Continue reading