Defence manufacturing: when one contract changes the whole risk profile
Winning a larger defence work package can change far more than the order book. Revenue concentration, production priorities, site approvals, cleared personnel, subcontractors, protected information and long-term support obligations can all become tied to one programme.
Not every defence supplier handles classified material or requires Facility Security Clearance. But where a contract introduces specific security, cyber, export, quality or record-keeping requirements, one overlooked dependency can prevent affected work continuing even while the machinery and workforce remain available.
The leadership challenge is therefore not simply winning the contract. It is understanding what must remain true for the business to deliver it safely, lawfully and profitably throughout its life.
Commercial changes that can alter the risk profile
UK defence investment and procurement reform are intended to expand industrial capacity, accelerate innovation and bring more businesses into defence supply chains. That creates opportunity, but the risk profile can change quickly when larger work packages, new sites, classified activity, export markets and contract-specific controls arrive together.
Larger contracts and production commitments
A materially larger work package may require new machinery, additional shifts, increased stock, specialist recruitment, more subcontracting and a different production schedule.
The danger is not the additional volume itself. It is committing to delivery milestones before the dependencies behind capacity, inspection, security, suppliers and recovery have been tested together.
New sites and cleared capacity
Opening or expanding a facility may increase output, but classified work cannot automatically be transferred to any available site.
Where a contract requires Facility Security Clearance, the approval is location-specific. Production planning should distinguish ordinary capacity from capacity that is appropriately approved for the work concerned.
Exports and dual-use activity
Military and dual-use goods, software and technology may require export authorisation depending on their classification, destination, end user and intended use.
The responsibility is wider than physical shipments. Controlled technology, technical data and some forms of remote transfer may also fall within the export-control framework.
Contract-specific cyber obligations
MOD contracts can be assigned a Cyber Risk Profile under the Cyber Security Model. The required controls depend on that profile, and relevant requirements may need to flow from prime contractors through successive subcontracting tiers.
A manufacturer entering defence work should therefore understand the exact cyber obligations attached to the contract rather than relying on a general assumption that its existing controls are sufficient.
Long-term support and configuration responsibility
Where a contract includes maintenance, spares, upgrades or through-life support, responsibility may continue long after the original production run ends.
Configuration records, approved changes, component obsolescence, supplier continuity and technical knowledge may need to remain usable for the operational life of the equipment or capability.
Where the exposure often sits
Defence-manufacturing exposure rarely sits in one machine or one contract clause. It develops through the interaction between programme concentration, approved capacity, contractual obligations, controlled information, specialist people and the evidence required to demonstrate compliance.
Programme and customer concentration
A major MOD or prime-contractor programme can support investment and growth while making revenue, capacity and working capital increasingly dependent on one decision-making chain.
Leadership should understand the effect of a pause, scope reduction, recompetition, delayed acceptance or changed production profile before it happens.
Milestones, acceptance and contractual consequences
Delivery dates, acceptance criteria, reporting requirements, warranties, indemnities and agreed consequences of delay vary by contract.
The business should know which obligations could create a material financial consequence and ensure that legal, operational, financial and insurance reviews are working from the same version of the agreement. Do not assume that liquidated damages are automatically insured.
Facility and personnel security dependencies
Facility Security Clearance, formerly known as List X, is relevant where a contractor or subcontractor is contractually required to hold, process or manufacture qualifying classified material at a particular location.
Individual vetting and personnel-clearance requirements can create additional dependencies. The important question is which activities would be affected if a site or key person could not undertake the classified work—not whether every defence activity would stop.
Export classification and licence control
Export-control responsibility depends on the item or technology, its classification, destination, end user and intended use.
Licences also carry conditions and validity periods. Product changes, new customers, remote access to controlled technology or entry into a different market should therefore trigger a fresh compliance check before transfer or shipment.
Cyber and subcontractor flow-down
Defence cyber obligations do not necessarily end with the prime contract. Relevant Cyber Risk Profiles and controls may need to be passed through subcontracting tiers.
A manufacturer should understand which suppliers receive or process protected information, which systems support delivery and how a failure elsewhere in the chain could affect contractual compliance or production.
Records, configuration and obsolescence
Inspection results, concessions, approved deviations, configuration records, technical data and supplier evidence may remain important long after delivery.
Where support obligations extend over many years, the business should ensure that records remain readable, controlled and retrievable even after systems, employees and suppliers have changed.
The six InduX risk pillars applied to defence manufacturing
Each pillar connects a dimension of defence-manufacturing risk with the leadership questions that should accompany new contracts, facilities, technologies, markets and supply-chain responsibilities.
Questions a defence-manufacturing director should be able to answer
These are not insurance-proposal questions. They are intended to reveal whether the business understands the commercial, operational, security and compliance dependencies behind its defence work.
- 01What proportion of turnover, capacity and future investment now depends on one programme, MOD contract or prime contractor?
- 02If that programme paused, was rescoped or re-competed, which costs and production commitments could the business reduce—and which would remain?
- 03Before accepting a larger work package, has the business mapped the machinery, people, suppliers, approvals, information and working capital required to meet every important milestone?
- 04Which work depends on a particular Facility Security Cleared location or specifically cleared personnel, and what permitted alternative exists if that capacity becomes unavailable?
- 05Have the contract’s delivery milestones, acceptance criteria, warranties, indemnities, intellectual-property provisions, confidentiality requirements and consequences of delay been reviewed by the appropriate specialists?
- 06Does the business know the Cyber Risk Profile and Risk Assessment Reference associated with the contract, the controls it must meet and what must be flowed down to subcontractors?
- 07Who owns export classification, licensing, end-user and destination checks, and how are those checks repeated when the product, technology, customer or route changes?
- 08Which single-source component, special process, test facility or subcontractor would create the greatest delivery delay if it became unavailable?
- 09Could the business retrieve the approved drawings, configuration status, inspection evidence, concessions and licence records for equipment delivered many years earlier?
- 10Which cleared or highly specialised individuals hold knowledge that is not yet documented or transferable to another competent person?
Composite scenario
A precision-component manufacturer supplying a Tier 1 defence prime won a materially larger follow-on work package and opened a second facility to provide the additional capacity.
Part of the programme required protected information and production at an appropriately approved site. The delivery plan assumed the new facility would be ready to undertake that work on schedule, but its security-assurance process was not complete when production was due to transfer.
The affected work had to remain at the original approved location. That displaced other production, increased overtime and subcontracting pressure, and contributed to a missed contractual milestone.
The business had reviewed the new machinery and headcount separately, but it had not connected site approval, cleared capacity, contract timing, supplier dependencies and delivery consequences within one risk plan.
The weakness was not the contract or the decision to expand. The delivery timetable had moved faster than the business’s understanding of what the new site was permitted and prepared to do.
Start with what has changed
If your defence-manufacturing business has won a larger work package, opened a new facility, taken on classified activity, entered an export market, increased subcontracting or become more dependent on connected systems and specialist people, the useful question is not whether each change was approved separately.
It is whether your understanding of the combined risk has changed with the business.
Identify areas across growth, resilience, financial exposure, people, defensibility and emerging risk that may warrant further review.
Risk360 provides indicative risk insight and questions for further consideration. It is not an actuarial assessment and does not constitute legal, regulatory, export-control, security, cyber, technical or insurance advice.
Sources referenced on this page
- 01MOD: Defence Industrial Strategy 2025
- 02MOD: Strategic Defence Review 2025
- 03MOD: Cyber Security Model for defence suppliers
- 04MOD: Defence Standard 05-138 — cyber security for defence suppliers
- 05MOD: Industry Security Assurance Centre and Facility Security Clearance
- 06ECJU: UK strategic export controls