Add Think Technology as a trusted source Defence Industry Security Program: an overview for SMEs

The Defence Industry Security Program: an overview for Australian SMEs

Royal Australian Navy warship in Sydney Harbour with a helicopter overhead, representing the Defence Industry Security Program.

The Defence Industry Security Program (DISP) is Defence’s security assurance service for Australian businesses that want to work with Defence. For many small and medium-sized enterprises (SMEs), it’s the first formal step into the Defence supply chain, and it shapes how the business manages people, information, facilities and technology from then on.

Owners and directors often come to DISP with sensible questions. Do we need it? What will it cost? How long will it take, and what do we have to keep doing once we’re in? The answers are spread across a number of Defence documents, which can make the program feel harder to approach than it is.

Defence’s DISP Membership Program brochure brings the main points together in one place. This article summarises that overview, adds points from Defence’s newer policy documents, and explains where the work tends to sit for a smaller business. For how we help with readiness and ongoing membership, see our DISP membership support page.

What the Defence Industry Security Program is

DISP is a membership-based program managed by the Defence Industry Security Branch. It sits under Principle 16 and Control 16.1 of the Defence Security Principles Framework (DSPF), which sets out the security requirements members must meet.

The program has four aims:

  • It confirms that industry has appropriate security in place for Defence tenders and contracts.
  • It gives industry access to security advice and support.
  • It helps businesses understand and manage security risk.
  • It gives Defence and other government agencies confidence when buying from members.

Membership isn’t automatic. A business must show it meets the security standards for the levels it nominates, and it must pass suitability checks, including a foreign ownership, control and influence (FOCI) assessment.

There is no membership fee. The costs come from putting security measures in place and keeping them there, such as facility accreditation, security clearances, cyber security uplift and physical security.

Who can apply

Any Australian entity with an Australian Business Number (ABN) or Australian Company Number (ACN) that wants to join the Defence supply chain can apply. You don’t need a Defence contract to become a member.

Membership is mandatory in some situations. Under Defence’s current policy, this includes businesses that need access to PROTECTED or higher classified information, handle weapons or explosive ordnance, provide security services for Defence bases, or hold a contract that requires membership. Where it isn’t mandatory, Defence still strongly recommends it for businesses working on, or seeking, Defence projects.

What membership offers

Members gain access to Defence security services, security training and materials (including cyber security guidance) and current security information to support planning. Members at Level 1 and above can sponsor security clearances for their own staff, which isn’t available at Entry Level.

Membership doesn’t guarantee Defence work. Contracts still go through normal procurement processes. The brochure also points to an improved security operating environment as practices strengthen.

DISP membership levels and security domains

DISP requirements are set out across four security domains:

  • Security governance covers accountability, plans, processes, training and incident reporting.
  • Personnel security covers the suitability of staff and contractors, including screening to Australian Standard AS 4811:2022.
  • Physical security covers the protection of people, property and assets at your sites.
  • Information and cyber security covers the protection of Defence information on your corporate systems.

Each domain has four membership levels that align with Australian Government security classifications:

  • Entry Level covers OFFICIAL and OFFICIAL: Sensitive information.
  • Level 1 covers PROTECTED.
  • Level 2 covers SECRET.
  • Level 3 covers TOP SECRET.

You nominate your own levels, and they should reflect your current or likely Defence security obligations. Levels 1 to 3 need a supporting business case, and your governance level must match the highest level you hold in any other domain. Businesses entering new contracts or projects may later need to upgrade.

How the application process works

Defence describes three broad steps. You learn the DSPF, clearance and membership requirements. You work out the level you need and assess how close you are to meeting it. Then you complete the application in the DISP Member Portal, which Defence launched in December 2023.

Behind the scenes, Defence checks the application is complete, prioritises it and confirms the level. Assessment includes Security Officer training, personnel clearances, the FOCI assessment, an Entry Level Assessment and a cyber security questionnaire. Where a business doesn’t yet meet the standard, security uplift may be needed before membership is granted.

The brochure says an application generally takes 90 to 180 days, depending on the level sought, the priority of the Defence work, the business’s suitability and how well prepared it is. Preparation is the factor most within your control.

Ongoing obligations for members

DISP membership comes with ongoing responsibilities at every level. Drawing on the brochure and Defence’s August 2026 member requirements factsheet, these include:

  • Protecting Defence and industry people, information and assets.
  • Appointing and keeping a Chief Security Officer (CSO) and a Security Officer (SO).
  • Reporting changes that could affect membership.
  • Submitting an Annual Security Report (ASR) on the anniversary of your membership, after it has been agreed by an Australian board or board equivalent.
  • Running regular staff security training, including induction and annual security awareness training.
  • Maintaining ongoing employment screening and suitability checks.
  • Keeping a document register where you access sensitive or classified Defence information.
  • Following Defence’s rules on staff access to Defence buildings and systems.

Security incidents are reported to Defence on an XP188 form. The newer factsheet sets a 24-hour timeframe from when the incident happens or becomes known, and asks members to record it in their security register. People engaged under a Defence contract also report incidents to their contract manager.

How Defence checks compliance

DISP uses layered assurance. The ASR is a yearly self-attestation. Ongoing Suitability Assessments are desktop audits, selected on a risk basis, that review documents, include a phone interview with security staff and involve a cyber questionnaire. Deep Dive Audits are more detailed and can include site visits. Defence describes them as collaborative, with a draft report to review and follow-up on agreed actions.

Where a member persistently disregards requirements or doesn’t complete agreed corrective actions, Defence can downgrade, suspend or terminate membership.

Cyber security uplift and the Essential Eight

To meet the information and cyber security requirements, members must meet or exceed the Australian Signals Directorate’s Essential Eight at Maturity Level Two across the corporate systems they use to correspond with Defence. The eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups.

The cyber security questionnaire has been expanded to cover all eight. Defence says it will provide a maturity action plan where uplift is needed. At the time the brochure was published, Defence also pointed SMEs to a dedicated security grant of between $10,000 and $100,000 to help with uplift. Check the current grant details with Defence before planning around it.

Our Ngamuru Advisory case study shows how we supported a defence consultancy to reach Essential Eight Maturity Level Two alongside its DISP requirements.

Training for your security officers

Defence offers several courses through its ADELE training platform, using an enrolment key provided during the process. They include an annual security awareness course, a Security Officer course, a course on assessing and protecting official information, and a security risk management workshop. Members can also download some training packages for their own learning systems.

A short readiness check

Before you apply, work through these points with your leadership team:

  • Identify which current or planned Defence work would require membership, and at what level.
  • Decide who in the business can take on the CSO and SO roles.
  • Check whether your ownership, funding or overseas arrangements could raise FOCI questions.
  • Assess how close your Defence-facing systems are to Essential Eight Maturity Level Two.
  • Confirm you have security policies, registers and a training plan you can maintain.

Starting with a clear view

DISP involves steady work for a smaller business, but the requirements are well defined and manageable with a plan. Our DISP certification starting point article is a good next read. We’re ISO 27001 and ISO 9001 certified, and we work with businesses on DISP readiness, security documentation, Essential Eight uplift and ongoing membership support.

How do we get started?

A short conversation is usually the easiest first step. We’ll ask about your Defence plans and current setup, then help you understand what membership would involve. Get in touch with us to start the conversation.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.