NCSC CAF v4.0 is the gate on UK public sector and CNI tenders. Pass the assessment, win the contract. The 2026 supplier guide for tech firms.
How UK scale-ups close stalled enterprise deals: ISO 27001 against SIG and CAIQ vendor security reviews, the SOC 2 decision, and the typical UK stack.
MOD supplier compliance runs through JOSCAR, DEFCON 658, CSMv4 and Secure by Design. The sequence each defence subcontractor hits, and where bids stall.