BDI

Defense technology.
Buyers, markets, opportunities.

Can a Cyber Improvement Plan keep an MOD bid viable while assurance gaps are closed?

A remediation plan can be considered in supplier selection, but its commitments need a delivery budget and an accountable owner.

In this article
  1. The current template page makes certification part of the question
  2. An improvement plan can determine when a project is ready to start
  3. Subcontracting creates another agreement to manage
  4. Acceptance needs to remain visible during delivery
  5. Sources & evidence

A Cyber Improvement Plan can provide a documented route for addressing assurance gaps, but it does not give a supplier an automatic right to receive an MOD contract. The useful business question is whether the company can credibly deliver the proposed improvements while also delivering the purchased work.

The MOD's CSM guidance requires a non-compliant supplier to submit a plan explaining how and when it will meet the required level, or why it cannot. The authority considers compliance or the proposed plan during selection. An agreed plan becomes part of the contract. The guidance also describes recurring supplier assessment after award. MOD Cyber Security Model process The Defence Cyber Certification and MOD questionnaire comparison separates certification from the assurance required by a particular procurement.

That structure makes a remediation promise commercially significant. A bid writer should not insert an optimistic completion date simply to clear a questionnaire. The delivery team must understand what work the date implies, which dependencies are outside its control and what evidence will demonstrate completion.

Start with a gap register that uses the buyer's actual requirements. For each unresolved item, identify the responsible role, the work needed, the expected evidence and the dependency that could delay completion. Keep sensitive implementation detail in the appropriate controlled channel. A public marketing document is not the place to describe a company's security shortcomings.

Cost the plan independently from the technical project. A research contract may already consume the company's specialist engineering capacity. If those same people must implement assurance changes, their time cannot be allocated twice. External assistance may reduce the internal workload, but it introduces procurement, coordination and acceptance tasks of its own.

The finance decision should consider cash timing as well as total expenditure. Some improvements may need to happen before the company can begin particular activities or receive particular information. If that work precedes the first contract payment, the company must be able to fund the interval. A small headline contract value can therefore conceal a substantial initial commitment.

Clarify what the buyer expects to review and when. A milestone called “security complete” is difficult to manage because it does not say what is complete or what evidence will be accepted. A defined submission and review process provides a more usable basis for planning. Buyer acceptance should be recorded through the authorised contractual process.

There is also a bid discipline question. Where a necessary improvement depends on a third party that has not agreed to participate, the plan should expose that dependency. A company may decide the opportunity is premature if it cannot make a credible commitment within the tender's timetable. That is a commercial judgement about deliverability, not a conclusion that the product has no defence market. The CR14 cyber range evaluation case examines the scope and reusable evidence a defensive-product experiment should produce.

After award, incorporate the agreed commitments into the same management process as the main deliverables. Review progress, expenditure and changes together. The plan should survive the handover from business development to project delivery. The French Diag Cybersécurité Défense provides a separate example of a management assessment rather than a customer-specific approval.

The current template page makes certification part of the question

MOD updated its separate CIP publication on 17 July 2026, replacing the template and amending the explanation of when a plan is required. The page now says a defence supplier without DCC at the required level must submit a CIP. This adds an explicit certification consideration to the wider CSM process described above. Suppliers should use the current CSMv4 template and the conditions in the actual procurement, rather than an archived plan retained from an earlier project. MOD's July 2026 CIP publication

The significance for commercial planning is that implementing a control and producing independent evidence of compliance may follow different schedules. A company might finish an internal change before an assessor is available. Another might hold a certificate while proposing delivery arrangements that require further explanation. The plan should make the actual remaining work intelligible to the authority. Calling every activity a certification exercise can conceal implementation effort; calling everything remediation can conceal the timing of independent assurance.

An improvement plan can determine when a project is ready to start

Consider a hypothetical research supplier preparing a six-month software evaluation. Its technical team can begin the research quickly, but the proposed delivery organisation still needs to complete specified assurance work. The company must connect those activities to its project schedule. If a necessary process or assessment is due after the first deliverable, the proposed sequence may be commercially unrealistic even when each date looks achievable in isolation.

The useful planning exercise is to trace dependencies from the research work back to the remaining assurance tasks. Which people must complete them? Which external appointments are needed? Which steps can run alongside technical preparation, and which must precede the relevant delivery activity? This turns a list of intentions into a schedule that commercial and technical staff can discuss with the authority. It also exposes the point at which an apparently minor delay would change the proposed start date.

The financial consequences are similarly specific. Staff preparing evidence may be the same staff assigned to a paid milestone. An external assessment may require expenditure before that milestone is accepted. A supplier pricing the project only from engineering days will overlook these constraints. The commercial question is whether the company can fund the agreed sequence and still deliver the research with the promised people, rather than whether the plan appears affordable as a separate line in a spreadsheet.

Subcontracting creates another agreement to manage

The CSM guidance describes flow down through successive subcontracting tiers. A supplier first needs the current risk profile and risk assessment reference for its own activity before initiating the corresponding process for a subcontractor. Where a lower-tier supplier is noncompliant, the parties must agree CIP requirements and provide visibility to the MOD delivery team. This makes the prime's plan dependent on information and actions elsewhere in the delivery chain. CSMv4 flow-down process

For a small prime using an external research specialist, a general promise that the partner will become compliant is not enough to build a reliable schedule. The parties need to understand the partner's work, the requirement assigned to that work and the evidence expected at the relevant point. A change of specialist can alter those assumptions even when the subcontract price and technical task remain unchanged. The prime should therefore connect supplier selection with its assurance planning before treating the delivery team as settled.

The same logic applies to a specialist negotiating with a larger prime. It benefits from asking for the actual requirement and procurement context early. That allows it to distinguish work needed for this subcontract from a wider aspiration to improve its business systems. The distinction supports a more accurate quote and a clearer discussion about timing. It also reduces the risk of discovering a material assurance cost after the commercial price has already been agreed.

Acceptance needs to remain visible during delivery

An agreed CIP becomes part of the contract record. Its practical owner therefore needs a route for reporting progress and raising a changed assumption with the authorised customer contact. Completing a task internally is not always the same as providing the evidence the customer expects. The company should know what closes each commitment and retain that evidence with the relevant contract documents.

A recurring project review can keep these obligations connected to delivery without turning every meeting into a separate assurance exercise. The useful questions are whether the agreed dates still hold, whether the responsible people remain available and whether a change in delivery affects the plan. That keeps the CIP tied to the actual business undertaking. It is a means of managing a defined route towards the required assurance, with its costs and responsibilities visible to both parties.

This analysis does not predict whether a particular plan will be accepted. It explains why the document belongs in bid costing and contract governance. A realistic plan helps the authority assess the proposal and helps the supplier avoid winning work on assumptions its delivery team cannot fulfil.

Sources & evidence

  1. Cyber Security ModelUK Ministry of Defence · 6 March 2026
  2. Cyber Improvement Plan: template and July 2026 guidanceUK Ministry of Defence

The official CSM process was checked on 6 September 2026. A plan's acceptance is a decision for the contracting authority, not an entitlement.

Suggest a correction