Skip to content

How defence secures modern software supply chains with D2S

21 May 20265 min read
Guest Insights
How defence secures modern software supply chains with D2S

Modern software development introduces complex supply chains which are difficult to manage, monitor, assure and guarantee are free of cyber threats.

For Defence, the challenge is how to enable rapid delivery without losing control of security and assurance. Defence Developer Services (D2S) is the authorised solution that addresses this directly.

What is D2S

Defence Developer Services (D2S) provides end-to-end application development services across the MOD.

This includes modern containerisation platforms, backed by an integrated tooling suite within a Continuous Integration / Continuous Deployment (CI/CD) environment,

allowing Development, Security and Operations (DevSecOps) teams to build

applications across platforms. These components represent the current service and will continue to evolve and expand.

D2S’ vision is to provide a service that enables users across Defence to rapidly and securely develop and deploy applications for a range of use cases, including military operations.

Through innovative solutions and cyber security governance, risk and compliance processes, D2S facilitates a through-life “code to commit in 24 hours” service.

D2S operates within MOD infrastructure, including cloud-hosted environments, and continues to develop capabilities that support emerging technologies, including

artificial intelligence, as part of the application development lifecycle.

A unified model for supply chain security

D2S is an established multi-disciplinary team currently consisting of MOD, Digital Allies, Red Hat and Defence SMEs, working under a single mission goal.

Under an innovative assurance framework, Continuous Authority to Operate (CAtO), application teams engage with a pipeline of security tooling that provides in-depth security checks to validate and assure the entire application development supply chain.

This automation and validation process has been accessible in D2S since 2023 and continues to be the only programme to operate under CAtO in Defence.

Applications being developed in D2S benefit from a rapid but secure route to security

assurance owing to automated security validation steps, fulfilling the rapid deployment vision of the service.

Securing the platform and runtime

D2S platform services are entirely hosted within MOD infrastructure and sit within containerised hosting environments.

Specifically, D2S currently resides within Red Hat OpenShift Container Platform (OCP), where each application team resides in its own Kubernetes container across development and production environments.

Using Kubernetes offers a layer of security and operational assurance to each

application team. Containerised applications are virtually segmented from other teams hosted on the same platform. Negative effects such as technical failure or cyber security incidents within one container cannot affect another, limiting the blast radius.

OCP allows application teams control of networking, services such as databases, storage and image repositories, secrets management and access to a library of

operators, all within defined security and operational parameters of the overall service.

All environments are subject to 24/7 security monitoring by a MOD-provided Security Operations Centre (SOC).

Controlling code, access and secrets

Teams commit code to a dedicated, access-controlled instance of GitHub, managing both public and private repositories.

D2S CI/CD services pull code into development environments where users test integration with D2S services and runtime.

Development environments are protected through MOD infrastructure and OCP to prevent internet access, except where services are benign and subject to testing.

D2S provides a secrets vault allowing managed, programmatic access to securely

stored secrets such as API keys or credentials. Applications call secrets from the vault, which are rotated frequently as required.

Embedded, non-bypassable security validation

Code is regularly scanned by a pipeline of security tooling providing compliance and defence-in-depth assurance.

These steps are mandated within the CI/CD pipeline and cannot be circumvented. Applications undergo:

  • Static Application Security Testing (SAST) to identify vulnerabilities prior to deployment

  • Dynamic Application Security Testing (DAST), using automated attacks in a simulated runtime environment to identify vulnerabilities

  • Image scanning to provide visibility of vulnerabilities (CVEs) and software composition

  • Software Bill of Materials (SBOM) generation in user-friendly or JSON format

  • Supply chain analysis across all components, whether integrated or inherited

  • Dependency tracking to identify risks and unused components

  • Secret scanning, verified by D2S Security Teams prior to deployment

Teams also undertake risk analysis and security validation, including alignment to NIST 800-53 controls, which is verified.

Managing supply chain complexity

The use of open-source code is essential in the rapid development of applications. It enables efficient build, rapid solutions, prevention of repetition and modular design patterns.

However, this introduces risk through extensive supply chains which are difficult to manage, monitor, assure and guarantee are free of cyber threats.

D2S mitigates this through extensive tooling, monitoring, established processes and continuous risk management. Security policies and processes alert application and security teams to newly identified vulnerabilities over time, with validation checks in place to ensure remedy.

Assured path to production

Applications follow a defined Path to Production process.

D2S and application teams mutually agree any residual risk associated with deployment, alongside its management and application support plans. Upon agreement, applications can deploy.

Containers in the development environment are cryptographically signed with a digital signature. These are deployed into production, where the signature is verified before execution, ensuring the container is as intended and free from interference.

Continuous assurance at scale

D2S provides an end-to-end DevSecOps service using security tooling to ensure integrity and safety in the software development lifecycle for Defence users.

Through Continuous Authority to Operate, assurance is continuously maintained and reported live, with data available for MOD scrutiny.

As assurance runs continuously, it is not subject to expiry. Services remain authorised provided standards are maintained.

Collectively, these capabilities assure the background supply chain and provide certainty of service continuation to the foreground supply chain.

Looking ahead

As software development continues to evolve, the complexity of application supply chains will continue to increase.

D2S provides a model for securing this environment, combining platform, tooling and continuous assurance to enable rapid and secure application delivery.

Working with industry

D2S is not a closed environment. It is designed to work with industry.

By standardising how applications are built, tested and assured, D2S creates a common model that can be applied across both MOD and industry-delivered software.

For industry, this creates clearer expectations and a more predictable environment to develop and integrate software. It reduces duplication in assurance activity and

provides a more direct route to deploying secure applications into Defence environments.

This supports alignment to Defence security requirements from the outset.