Defence suppliers and delivery teams

MOD Secure by Design: Assurance for Defence Suppliers

MOD Secure by Design requires cyber security to be built into a capability and evidenced throughout its life. We manage the security case, the SbD activities and the evidence your delivery team needs at each review, with an accredited partner performing the assurance.

First, the right scheme

MOD Secure by Design, not the police scheme

Two different things share almost the same name. MOD Secure by Design is the Ministry of Defence approach to designing and assuring cyber security in defence capabilities. Secured by Design, spelled differently, is the police-backed scheme for physical security products such as doors, locks and windows. This page, and everything we do here, is the MOD scheme for defence suppliers and delivery teams. If you are looking for the physical-security certification, this is not it.

MOD Secure by Design is evidence-led. It expects security to be designed in from the start and proven at every project review, so the real work is producing and maintaining a credible security case. That is the load we manage, end to end.

The partner-delivered model

  • Support for MOD suppliers and delivery teams, not the police doors-and-locks scheme
  • CyPro fronts and manages the engagement; an accredited partner performs the assurance
  • Security case and evidence built to what the authority actually assesses
  • SbD activities mapped across the project lifecycle, not bolted on at a gate
  • Alignment with the NCSC Cyber Assessment Framework where the programme requires it
  • Indicative fixed-scope pricing, from GBP 8,500, published rather than quote-only

What the assessment looks at

The Secure by Design activities we manage

MOD Secure by Design is assessed through the artefacts your delivery team produces. These are the areas we build and keep current so a review confirms your security case rather than exposing gaps in it.

Security case

The living argument that your system is acceptably secure, backed by evidence. We help delivery teams build and maintain a security case that holds up when the authority asks to see it, rather than a document assembled the week before a gate.

Risk assessment and management

MOD Secure by Design expects risk to be identified, owned and tracked across the project lifecycle, not signed off once at the start. We structure the risk assessment so it maps to the activities the authority is looking for.

Evidence and artefacts

Requirements traceability, control implementation, test results and the SbD activity records that show the security work actually happened. We prepare the evidence base so a review confirms it rather than chases it.

Assurance through the gates

SbD is assessed at project gates and reviews, not as a one-off certificate. We manage the readiness for each review point so security keeps pace with delivery instead of becoming a blocker at the end.

Quick answers

Secure by Design questions, answered

Is this the MOD scheme or the police Secured by Design scheme?

This is MOD Secure by Design, the Ministry of Defence approach to building security into defence capabilities and the systems that support them. It is not Secured by Design, the separate physical-security scheme run by Police Crime Prevention Initiatives that certifies doors, locks and windows. Note the different spelling: Secure by Design (MOD) versus Secured by Design (police). We work only on the MOD scheme for defence suppliers and delivery teams.

What is MOD Secure by Design?

MOD Secure by Design is the Ministry of Defence policy that requires cyber security to be designed into a capability from the start and assured throughout its life, rather than tested at the end. Delivery teams are expected to run a defined set of SbD activities, maintain a security case and provide evidence at project reviews. It applies to the suppliers and delivery teams building or supporting MOD systems.

How the CAF fits in

What evidence does a defence supplier need to provide?

The core is a security case: a structured, evidenced argument that the system is acceptably secure, supported by risk assessments, requirements traceability, control implementation records and test results. MOD Secure by Design is evidence-led, so the practical work is producing and maintaining those artefacts across the project, which is exactly the load we manage.

How the engagement runs

Does CyPro perform the assurance itself?

The assurance activity is performed by our accredited delivery partner. CyPro fronts and manages the engagement: building the security case, preparing evidence and getting your delivery team ready for each review point. We are explicit about this split so you know the specialist work is done by the right accredited people under a single managed contract.

What does MOD Secure by Design support cost?

Indicative support starts from GBP 8,500, scaled to project size and the SbD tier that applies. Pricing is fixed-scope and published rather than quote-only, and delivery is partner-led. The pricing page shows the Secure by Design prices alongside CAF, GovAssure and ITHC work.

See the published prices

Rocket above the CAF Assessment call to action

Keep security ahead of the gate

Scope your Secure by Design support

A free 45 minute call establishes where your project sits, which SbD activities apply and the indicative fixed-scope cost of managed, partner-delivered Secure by Design support.