System Status: Operational/// DISP DEFENCE TECH NETWORK ///DISP COMPLIANCE PLATFORM
Latest Intelligence
Purpose-Built DISP Management SoftwareIncomplete applications are the leading cause of DISP delay

DISP MEMBERSHIP,
DONE FOR YOU.

Expert DISP consulting, GRC platform and sovereign cloud for Australian defence contractors — achieve and sustain DISP membership with clarity, control and confidence.

Australian & UK Defence experience50+ DISP engagementsAustralian-owned & operated
Defence backlog
High demand
Defence reports a significant DISP application backlog
Typical cost
$80k+
Consultant-led DISP engagement (indicative)
Timeline
6–18 months
Without structured readiness support
[PROBLEM_STATEMENT]

DISP IS SLOW,
EXPENSIVE,
AND MOST
PEOPLE FAIL.

6–18 months
Typical DISP timeline

Without a structured readiness programme, organisations spend months in remediation loops before submission — and still get rejected.

$20k–$100k
Traditional consultant cost

Hourly-rate consulting firms charge for every meeting, every document review, every email. The bill compounds fast with no guaranteed outcome.

Backlog
Defence-reported demand

Defence continues to experience significant demand for DISP accreditation. Incomplete applications are the leading cause of delay — Defence requests documentation post-submission, with 10-business-day response windows before withdrawal.

[DISPULSE // PRODUCT ANNOUNCEMENT]
Purpose-Built

PURPOSE-BUILT
DISP MANAGEMENT
SOFTWARE.

DISPulse is Australia's purpose-built compliance platform for the Defence Industry Security Program. It consolidates every compliance framework your organisation must meet — in one audit-ready system.

Explore DISPulse
[FRAMEWORKS MANAGED]
DISPDefence Industry Security Program
NATIVE
E8 ML2Essential Eight Maturity Level 2
NATIVE
CMMC 2.0Cybersecurity Maturity Model Certification
MAPPED
PSPFProtective Security Policy Framework
ALIGNED
ISO 27001Information Security Management
ALIGNED
DSPFDefence Security Principles Framework
NATIVE

One platform. Six frameworks. Zero duplication. DISPulse maps controls across frameworks so you never answer the same question twice.

[OUTCOME_ACHIEVED]

WHAT DISP MEMBERSHIP
ACTUALLY UNLOCKS

DISP is not a compliance checkbox. It is the entry ticket to the $368 billion AUKUS supply chain — and the prerequisite for every classified Defence contract in Australia.

  • Access classified Defence contracts
    DISP membership is mandatory for any organisation handling PROTECTED or above information.
  • Participate in the AUKUS supply chain
    The $368B AUKUS programme requires DISP as the baseline security credential for industry participants.
  • Win tenders that require DISP
    Primes increasingly mandate DISP for subcontractors — without it, you are disqualified before evaluation.
  • Demonstrate sovereign capability
    DISP signals to Defence that your organisation can be trusted with sensitive national security work.
[FIELD_REPORT_01]
"DISPulse allows us to leverage compliance into a business advantage, operate with a holistic view of our risk and compliance posture."
AB
Andre Baruch
CEO, SafeSky
[FIELD_REPORT_02]
"The promise of automation has long been discussed in the compliance world, but never truly realised. Serious Defence has turned promise into reality."
RM
Rakz Mathur
COO, Pounce Agency
[METHODOLOGY]

THREE STEPS TO DISP MEMBERSHIP

01

ASSESS

Gap Analysis & Scoping

We run a structured gap assessment across all four DISP security domains — governance, personnel, physical, and ICT. You get a clear picture of where you stand and exactly what needs to be done.

See the full process
02

REMEDIATE

Build & Evidence

We guide your team through implementing the required controls — Security Management Plan, Essential Eight ML2, physical security upgrades, personnel clearances — and capture all evidence in DISPulse.

View the requirements checklist
03

CERTIFY

Application & Accreditation

We prepare your DISP application, conduct a pre-submission review, and support you through the Defence assessment process — giving you the best possible chance of first-attempt approval.

Understand the accreditation process
[PRODUCT_SUITE]

THREE CONNECTED SOLUTIONS.
ONE COMPLIANCE OUTCOME.

View all solutions
[FOUNDATION]

WHAT IS THE DEFENCE INDUSTRY SECURITY PROGRAM (DISP)?

Administered by
Defence
Defence
Framework
DSPF
Principles and controls across the DSPF outcome areas

The Defence Industry Security Program (DISP) is Australia's mandatory security framework for companies supplying goods, services, or technology to the Department of Defence. Without it, you cannot legally access classified Defence information, attend restricted briefings, or hold contracts requiring PROTECTED or above material under the Commonwealth Procurement Rules.

DISP is not a one-time certification — it is a continuous compliance obligation. Members must submit an Annual Security Report (ASR) to Defence, complete mandatory security awareness training, and notify Defence of any material changes to ownership, key personnel, or the scope of Defence work. Failure to maintain compliance can result in suspension or cancellation of membership.

For companies serious about the Australian defence market, DISP membership is not a compliance burden — it is a competitive differentiator. Primes and Defence project offices actively require DISP-member subcontractors. Achieving membership signals the governance maturity and security culture needed to be trusted with sensitive national security work.

Read the full guide to DISP
01Personnel Security

Suitability of key staff. The Chief Security Officer (CSO) and Security Officer (SO) must be able to obtain a clearance commensurate with the membership level.

02Physical Security

Zone classifications, access controls, and certified secure areas scaled to membership level.

03ICT & Cyber Security

Essential Eight ML2 minimum across ICT corporate systems used to correspond with Defence.

04Security Governance

Accountability, plans and reporting across all domains — CSO/SO roles, security policies, incident reporting, and the Annual Security Report.

[ELIGIBILITY]

WHO NEEDS DISP MEMBERSHIP?

Any company accessing, storing, or transmitting classified Defence information — directly or as a subcontractor — must hold DISP membership.

Defence Primes & Subs

BAE Systems, Thales, Lockheed Martin and other primes mandate DISP for all subcontractors as a condition of engagement.

ICT & Cyber

Firms supporting Defence networks, data centres, or mission-critical systems must hold DISP before accessing any classified environment.

Engineering & Construction

Companies working on Defence facilities, bases, or infrastructure projects require membership regardless of classification level.

Professional Services

Legal, financial, and consulting organisations advising on sensitive Defence matters are within scope of DISP requirements.

Smaller companies are increasingly finding DISP is a prerequisite even at the subcontractor level. As Defence supply chains tighten in response to the 2023 Defence Strategic Review and AUKUS obligations, appropriate security credentials are becoming standard practice. DISP applications take three to twelve months — the clock starts only when a complete, compliant application is submitted.

[STRUCTURE]

DISP MEMBERSHIP LEVELS EXPLAINED

DISP membership is tiered across four levels — Entry Level, Level 1, Level 2, and Level 3 — each corresponding to the classification level of information the member organisation can access. The level required is determined by the nature of the Defence work, not by the company's preference.

ENTRY LEVELOFFICIAL (no classified access)

The entry point for most defence supply chain participants. Establishes foundational governance, personnel, physical and cyber security requirements. Entry Level members cannot sponsor personnel security clearances.

LEVEL 1PROTECTED and below

Required for companies accessing PROTECTED-classified material. Key personnel must hold Baseline personnel security clearances, with physical and information security controls matched to PROTECTED-level work.

LEVEL 2SECRET and below

Required for companies accessing SECRET-classified material. Key personnel must hold Negative Vetting Level 1 (NV1) clearances, with enhanced physical security controls and more rigorous information security practices.

LEVEL 3TOP SECRET and below

The highest tier, for organisations working with TOP SECRET material. Requires Negative Vetting Level 2 (NV2) clearances for key personnel and significantly elevated security infrastructure.

Most SMEs entering the defence market will apply at Entry Level or Level 1. Upgrading to a higher level requires a formal variation application to Defence and is typically driven by a specific contract requirement rather than a proactive choice.

Read the full DISP requirements checklist
[CYBER REQUIREMENTS]

ESSENTIAL EIGHT ML2: THE CYBER BASELINE FOR DISP

ML2E8 ML2 required at every level
Sep '24ML2 became the DISP floor
E1Application ControlPrevent unapproved executables
E2Patch ApplicationsWithin 2 weeks for internet-facing (48h at ML3)
E3Office Macro SettingsBlock macros from the internet
E4User App HardeningDisable Flash, ads, Java in browsers
E5Admin PrivilegesRestrict and review regularly
E6Patch OSWithin 2 weeks for internet-facing (48h at ML3)
E7MFAAll users, all remote access
E8Regular BackupsTested, offline, 3 copies

At ML2, each control must be implemented consistently across all in-scope systems with evidence of effectiveness — not just policy documentation. This shift from policy to evidence is where most organisations struggle and where the majority of assessment findings occur.

Essential Eight ML2 must be demonstrated to Defence through the Entry Level Assessment, covering all systems used to process, store, or transmit Defence information. Many applicants commission an independent assessment (e.g. from an IRAP assessor) to evidence their posture, though this is not mandated.

Read the full Essential Eight ML2 guide
ML1 vs ML2
ML1Controls implemented ad hoc. Policy-based. No evidence required.
ML2Controls implemented consistently. Exceptions managed. Evidence of effectiveness required across all in-scope systems.
[COMPARISON]

DISP VS ISO 27001: WHAT'S THE DIFFERENCE?

ISO 27001 can support a DISP application but does not substitute for it. Many defence organisations hold both.

DimensionDISPISO 27001
AuthorityAustralian DoD / DefenceInternational Standards Organisation
ScopeAustralian defence supply chainAny organisation globally
Mandatory?Yes — for Defence contractsVoluntary certification
Personnel SecurityRequired (AGSVA vetting)Not covered
Physical SecurityPrescriptive requirementsRisk-based, flexible
Cyber FrameworkEssential Eight (ACSC)Annex A controls (ISO 27002)
AssessmentDefence Entry Level Assessment (ELA)Third-party certification body
Ongoing obligationAnnual Security Report to DefenceAnnual surveillance audit

ISO 27001 certification can support a DISP application by demonstrating that an organisation has a mature information security management system (ISMS), but it does not substitute for DISP membership. Conversely, achieving DISP membership does not grant ISO 27001 certification. Many organisations in the defence sector hold both, using ISO 27001 as the foundation and DISP as the specific overlay for Defence-classified work.

[COMMON PITFALLS]

WHY DISP APPLICATIONS FAIL — AND HOW TO AVOID IT

Backlog
Defence reports significant DISP application demand
01

Incomplete Security Plan

The Security Plan is the centrepiece of a DISP application. Defence expects a comprehensive, evidence-based document covering all four security domains. Vague policy statements without supporting procedures, diagrams, or evidence of implementation are the single most common reason for application delays.

02

Key Personnel Not Cleared

DISP requires that the Chief Security Officer (CSO) and Security Officer (SO) hold appropriate AGSVA security clearances before the application is assessed. Applications submitted without cleared personnel in these roles are returned immediately.

03

Essential Eight Evidence Gaps

If the Entry Level Assessment — or an independent assessment — identifies Essential Eight gaps, particularly at ML2, the application will stall until remediation is complete and the uplifted posture can be re-evidenced. Submitting before gaps are closed is a costly mistake.

04

Physical Security Non-Compliance

Failure to meet the physical security requirements for the proposed membership level — including zone classifications, access controls, and SCIF requirements at higher tiers — is a common rejection reason for companies that underestimate the infrastructure investment required.

05

Mismatched Membership Level

Applying for a higher membership level than the contract actually requires creates unnecessary complexity and delays. Defence assesses applications against the actual risk profile of the work. Applying at the right level from the start is faster and cheaper.

[FAQs]

FREQUENTLY ASKED QUESTIONS ABOUT DISP

15 questions covering applications, compliance, costs, personnel, audits, and the DISP Member Portal.

How long does a DISP application take?

Processing times vary significantly based on the completeness of the application and the membership level sought. A well-prepared Entry Level or Level 1 application typically takes three to six months. Level 2 and above applications can take six to twelve months or longer, particularly where personnel clearance processing is on the critical path. Incomplete applications are returned and restart the clock. Working with an experienced DISP consultant to prepare a complete, compliant application from the outset is the most effective way to minimise processing time.

Can a small business apply for DISP membership?

Yes. DISP membership is open to Australian businesses of all sizes, including sole traders and small-to-medium enterprises (SMEs). Defence has specific guidance for SMEs recognising that the compliance burden must be proportionate to the size and risk profile of the organisation. Many of the most successful DISP members are SMEs that have invested in the right security foundations and positioned themselves as trusted suppliers to Defence primes.

What is an Annual Security Report (ASR) and when is it due?

The Annual Security Report is a mandatory submission to Defence that all DISP members must complete each year. It requires the Chief Security Officer to attest to the organisation's ongoing compliance with DISP requirements across all four security domains, report any security incidents that occurred during the year, and confirm that mandatory security awareness training has been completed by all relevant personnel. ASRs are due every 12 months, within 10 business days of the anniversary of membership being granted. Failure to submit on time is a compliance breach and can trigger a Defence audit.

What is the difference between a Chief Security Officer and a Security Officer in DISP?

The Chief Security Officer (CSO) is the senior executive accountable for the organisation's overall security posture and DISP compliance. The CSO must hold a security clearance appropriate to the membership level and is the ultimate authority on all security matters within the organisation. The Security Officer (SO) is responsible for day-to-day security operations and is the primary point of contact with Defence for administrative matters. Both roles require AGSVA security clearances and must be nominated in the DISP application.

Does DISP membership cover all of my company's work, or just Defence work?

DISP membership applies to the specific facilities, systems, and personnel nominated in the application. It does not automatically cover all of a company's operations. If your organisation performs both Defence and commercial work, you will need to establish appropriate separation between the two — particularly for information systems and physical access. Defence will assess whether your proposed security arrangements adequately protect Defence information from inadvertent disclosure to non-cleared personnel or systems.

What happens if I have a security incident?

DISP members are required to report security incidents to Defence within prescribed timeframes. The reporting obligation applies to a broad range of incidents including unauthorised access to classified information, loss or theft of classified material, cyber security incidents affecting systems used for Defence work, and personnel security concerns. Prompt, transparent reporting is viewed favourably by Defence. Attempting to conceal or minimise incidents is treated as a serious compliance failure and can result in suspension or cancellation of membership.

Can I lose my DISP membership?

Yes. Defence can suspend or cancel DISP membership for a range of reasons including failure to maintain the required security standards, non-submission of the Annual Security Report, failure to notify Defence of material changes to the business, serious or repeated security incidents, and loss of key cleared personnel without adequate succession planning. Cancellation of DISP membership immediately disqualifies the organisation from holding active Defence contracts that require membership, which can have severe commercial consequences.

How does DISPulse help with DISP compliance?

DISPulse is purpose-built software for DISP compliance management. It automates the Annual Security Report process, maps your control evidence to DSPF requirements and the Essential Eight, tracks personnel clearance expiry dates, manages incident reporting workflows, and provides real-time visibility of your compliance posture across all four DISP security domains. For organisations managing DISP compliance manually through spreadsheets and email, DISPulse is designed to reduce compliance overhead dramatically while significantly improving the quality and completeness of evidence maintained for Defence audits.

What is a DISP Maturity Action Plan (MAP)?

A Maturity Action Plan (MAP) is a structured remediation document issued by Defence when a DISP applicant or existing member cannot yet demonstrate full compliance with the required security standards. The MAP identifies each gap, specifies the remediation action required, assigns a target completion date, and establishes a review schedule. For new applicants, a MAP allows Defence to grant conditional membership while the organisation works through its uplift program — meaning you do not need to be fully compliant before your application is accepted. For existing members, a MAP is typically issued following an Ongoing Suitability Assessment (OSA) or Deep Dive Audit (DDA) that identifies deficiencies. Failure to meet MAP milestones can result in membership suspension.

Can foreign-owned companies apply for DISP membership?

Yes, but foreign ownership introduces significant complexity. Defence assesses Foreign Ownership, Control, and Influence (FOCI) as part of every DISP application. If a company is majority foreign-owned or subject to foreign control — including through board composition, shareholder agreements, or financial dependency — Defence will conduct a more detailed assessment to determine whether the foreign interest creates an unacceptable security risk. In some cases, Defence may require structural mitigation measures such as a Security Control Agreement (SCA), a Special Security Agreement (SSA), or the appointment of an Outside Director or Security Committee to insulate the Australian operations from foreign influence.

What is the DISP Member Portal?

The DISP Member Portal is the secure online platform through which DISP members and applicants manage their relationship with Defence. It is used to submit new membership applications, lodge Annual Security Reports (ASRs), report security incidents, notify Defence of material changes to the business, manage personnel clearance sponsorships, and communicate with Defence case officers. The portal replaced the previous paper-based and email submission processes and is now the primary channel for all DISP administrative activity. Access is restricted to nominated Chief Security Officers (CSOs) and Security Officers (SOs). DISPulse integrates with the portal workflow, allowing members to prepare and review their ASR content within the platform before final submission.

How much does DISP membership cost?

Defence does not charge a government application fee or annual membership levy. However, the cost of achieving compliance is substantial. Primary costs include: an independent Essential Eight assessment (e.g. from an IRAP assessor — indicative market rates typically $15,000–$40,000 depending on scope and complexity); preparing the Security Plan and supporting documentation; implementing the required physical security infrastructure; and the ongoing operational cost of maintaining compliance. For most SMEs, the indicative total cost of achieving DISP membership at Entry Level or Level 1 ranges from $30,000 to $100,000, depending on the starting maturity of the organisation.

What is the difference between DISP Entry Level and the higher membership levels in practice?

At Level 1, you can access PROTECTED and below information, which covers the vast majority of defence supply chain work. Your ICT systems must meet Essential Eight ML2, your key personnel must hold Baseline personnel security clearances, and your facilities must meet the physical security requirements for PROTECTED-level work. At Level 2, you can access SECRET information — which requires Negative Vetting Level 1 clearances and facilities configured as Secure Working Areas (SWAs). Level 3 is reserved for organisations working with TOP SECRET material and requires correspondingly elevated infrastructure, personnel clearances, and governance arrangements.

What is an IRAP assessor and do I need one for DISP?

An IRAP (Information Security Registered Assessors Program) assessor is an individual certified by the ACSC to conduct independent assessments of information security controls against government frameworks, including the Essential Eight. For DISP applications, Essential Eight ML2 must be demonstrated to Defence through the Entry Level Assessment (ELA) — a review of security documentation, a phone interview with security staff, and completion of the Cyber Security Questionnaire. Many applicants commission an independent assessment (e.g. from an IRAP assessor) to evidence their posture, though this is not mandated. IRAP assessors are independent of Defence and Serious Defence; you engage one directly. Serious Defence can recommend accredited IRAP assessors and help you prepare your environment to maximise the outcome of the assessment.

What is a DISP Deep Dive Audit (DDA)?

A Deep Dive Audit (DDA) is a comprehensive compliance review conducted by Defence on existing DISP members. Unlike the annual ASR self-attestation, a DDA involves Defence officers visiting your facilities, reviewing your security documentation, interviewing key personnel, and testing the effectiveness of your security controls. DDAs are triggered by a range of factors including significant changes to your business, security incidents, intelligence concerns, or as part of Defence's routine audit programme. A DDA finding that identifies material non-compliance can result in a Maturity Action Plan, membership suspension, or in serious cases, cancellation of membership.

Have a question not answered here?

Speak to a DISP Expert
[REGULATORY TIMELINE]

DISP Compliance
Key Milestones

The regulatory landscape for Australian defence suppliers has shifted significantly since 2023. Understanding the timeline is critical for planning your DISP application and ongoing compliance obligations.

CURRENT STATUS
Full E8 ML2 Mandatory
All DISP members — from 30 Sep 2024
Apr 2023
DSR RELEASE

Defence Strategic Review Published

The 2023 Defence Strategic Review (DSR) fundamentally reoriented Australian defence policy toward near-term deterrence and supply chain resilience. The DSR directed Defence to accelerate DISP uptake across the broader defence industrial base and strengthen cyber security requirements for all members — setting the foundation for the 2024–2025 E8 uplift program.

Pre Sep 2024
TOP 4 ERA

Essential Eight 'Top 4' Cyber Baseline

Until September 2024, the DISP cyber requirement was based on the ACSC Essential Eight 'Top 4' mitigation strategies: Application Control, Patch Applications, Configure Microsoft Office Macro Settings, and User Application Hardening.

30 Sep 2024
FULL E8 ML2 MANDATORY

Full Essential Eight ML2 Required for DISP Membership

From 30 September 2024, DISP requires the full Essential Eight at Maturity Level 2 across systems used to correspond with Defence — at every membership level, including Entry. Defence assesses cyber posture through the Entry Level Assessment (ELA): a review of security documentation, a phone interview with security staff, and completion of the Cyber Security Questionnaire (CSQ).

Ongoing
CONDITIONAL PATHWAY

E8 ML2 Maturity Action Plan (MAP)

Applicants not yet at Maturity Level 2 can be granted conditional membership via an E8 ML2 Maturity Action Plan (MAP) — a structured remediation program with a 12-month extension to reach full compliance. Failure to meet MAP milestones can result in membership suspension.

Every 12 Months
ASR CYCLE

Annual Security Report — Ongoing Obligation

Every DISP member must submit an Annual Security Report (ASR) every 12 months, within 10 business days of the anniversary of membership being granted. The ASR is declared by the Chief Security Officer (CSO) and confirms ongoing compliance across all four security domains.

2026 +
AUKUS & CMMC ALIGNMENT

AUKUS Pillar II and CMMC 2.0 Integration Expected

As AUKUS Pillar II industrial cooperation deepens, Australian defence suppliers engaging with US DoD programs will face additional CMMC 2.0 requirements layered on top of DISP obligations. Defence is expected to publish updated DSPF guidance aligning DISP cyber requirements with CMMC Level 2 controls, enabling Australian companies to satisfy both frameworks through a single compliance program.

Server Core
[MISSION_BRIEF]

DON'T STALL IN THE BACKLOG.

Start your DISP Readiness Assessment today. We'll identify your gaps, scope the work, and give you a clear path to first-attempt approval.