Skip to content
Defence Standard 05-138 · MoD suppliers

Declare your cyber assurance level with the file behind it.

Defence Standard 05-138 Issue 4 sets the mandatory cyber assurance level for any organisation holding an MoD contract. Secruna keeps the evidence the declaration rests on.

What you get

Three outcomes for a CAL declaration.

The CAL evidence pack

One PDF per Cyber Assurance Level — the technical control evidence behind the declaration.

An honest gap list

Each control shown as Met, Partial or Unmet. No more guessing whether the firm could pass an MoD audit.

Reuse across contracts

One inventory. Every MoD contract reuses the same evidence base. No bespoke spreadsheet per programme.

How it works

Connect. Map. Declare.

1. Connect

Read-only OAuth into the cloud and SaaS behind the contract.

2. Map

Each control mapped to evidence. Two reviewers sign off.

3. Declare

One-click CAL evidence pack attached to the declaration.

Who it’s for

Any organisation holding an MoD contract.

Defence primes. Tier-2 and tier-3 suppliers. SMEs delivering into the MoD supply chain via DASA, DSTL or front-door routes.

Deep detail

Each CAL, mapped — in our docs.

The full walkthrough — CAL 1, 2, 3 and 4, the technical control evidence behind each — lives on docs.secruna.com.

Want to see your CAL gap?
Talk to us for 30 minutes.

A 30-minute call tells you which CAL controls are Met today and which would fail an MoD audit.