Inclusion criteria describe evidence that can establish this activity. Exclusion criteria identify circumstances that do not establish it on that basis alone. The evaluation remains connected to its taxonomy version and supporting evidence.
Included when supported
Evidence may support involvement when it matches one or more of these inclusion criteria.
- 01Criterion
Include military tactical networks, battlefield data links, deployable network systems, and mission-data infrastructure specifically designed or materially configured for defence operations.
- 02Criterion
Include encrypted military communications networks, protected gateways, secure network-management systems, and deployable communications infrastructure.
- 03Criterion
Include military command-and-control network backbones, battle-management networks, mission clouds, and operational data architectures that connect defence sensors, decision-makers, and effectors.
- 04Criterion
Include defensive cybersecurity platforms, security-operations systems, cyber-range infrastructure, and managed defensive operations specifically designed or materially configured for military networks.
- 05Criterion
Include material integration, operation, or modernization of a military-specific network or defence information-technology system where the entity has system-level responsibility.
Excluded on this basis alone
These circumstances do not establish this activity unless separate evidence also meets an inclusion criterion.
- 01Criterion
Historical-Only Defence IT, Network or Defensive-Cyber Involvement
Defined as: Entities with verified past development, supply, integration, operation, or material modernization of qualifying defence information-technology, network, communications, or defensive-cyber systems, where reliable evidence establishes that the qualifying activity has fully ceased, been divested, transferred, dismantled, terminated, or otherwise ended and no current qualifying involvement remains. Historical-only activity does not qualify as current involvement. Preserve the historical record separately with the activity period, effective cessation or transfer date, relevant entity, product, programme, facility, or contract, and supporting evidence. Absence of recent evidence alone is not sufficient to establish cessation.
- 02Criterion
Exclude general enterprise software, public cloud, ordinary data centres, office information technology, and commercial systems integration supplied without material military configuration.
- 03Criterion
Exclude ordinary telecommunications, internet, satellite-connectivity, and carrier services without a military-specific system or dedicated protected deliverable.
- 04Criterion
Exclude broadly marketed cybersecurity products, audits, compliance, consulting, and managed services without a military-specific configuration or contract deliverable.
- 05Criterion
Exclude malware, exploits, spyware, offensive intrusion systems, and managed offensive cyber operations.
- 06Criterion
Exclude nuclear command, control and communications systems classified under the applicable Nuclear Weapons screen.
- 07Criterion
Exclude staffing, training, subcontract presence, and generic programme support that does not establish a qualifying defence IT, network, or cybersecurity system.
Evidence and evaluation methodology
How sources, entity pathways, decisions, qualifiers, and review history are handled.
Map screens to a client policy
How to choose provider screens, document coverage, and decide what happens after an outcome.