Defence Industry Security Program

DISP membership, made achievable for your business

If you want to work with Defence, DISP membership is often the door you have to walk through first. It can look daunting: four security domains, four levels, security clearances and an ICT network that has to meet a recognised standard. We help Australian businesses work out what they need, close the gaps, and get through the application with less guesswork.

Check your DISP readiness
ISO 27001 certifiedISO 9001 certifiedEssential EightSecurity & compliance specialistsVeteran owned

We get your business DISP-ready

You likely already understand what DISP membership involves. What you need is a partner to guide you through it. We translate the DISP requirements into a clear, prioritised plan, deliver the security and ICT work they call for, and support your team through to lodging your application.

Many businesses engage us part way through, unsure which membership level they require, or held up by the Essential Eight and ICT accreditation the application depends on. We help you determine the right level for each security domain, so your investment in clearances, facilities and infrastructure reflects what your contracts genuinely require, then we close the gaps: Essential Eight maturity, the security policies and registers, and the documentation Defence expects.

We are certified to ISO 27001 and ISO 9001, and we work across the security and ICT requirements of DISP every day. Whether you are beginning the process or finalising an application, we will give you a clear, honest assessment of where you stand and what it takes to achieve membership.

Who needs it, and can you apply?

If you want to tender for Defence work, hold a Defence contract that calls for it, or join the Defence supply chain, you will usually need DISP membership. Before you apply, your business must meet a set of eligibility requirements.

  • Registered in Australia with an ABN, and financially solvent.
  • A nominated Chief Security Officer (CSO) and Security Officer (SO), who can obtain a Digital ID such as myID linked to your entity through Relationship Authorisation Manager (RAM). They can be the same person.
  • Satisfy Defence requirements for Foreign Ownership, Control or Influence (FOCI).
  • No relationships with sanctioned or listed entities, including listed terrorist organisations, regimes under UN or Australian sanctions, or persons and entities on the DFAT Consolidated List.
  • An ICT network that meets a recognised cyber security standard, being one of the ASD Essential Eight, ISO/IEC 27001 and 27002, NIST SP 800-171, or UK Def Stan 05-138.

Not sure whether you tick these boxes yet? That is exactly what the readiness check below is for.

The four DISP membership levels

Levels align with Australian Government security classifications. You hold a level in each of the four security domains, so your membership is shaped to what you handle, not a single blanket rating.

LevelInformation classificationPersonnel clearanceTypical fit
Entry LevelOFFICIAL / OFFICIAL: SensitiveSponsored by Defence or another agencyMost businesses entering the Defence supply chain
Level 1PROTECTEDUp to BaselineHandling PROTECTED information or assets
Level 2SECRETUp to Negative Vetting 1 (NV1)Handling SECRET information or assets
Level 3TOP SECRETUp to Negative Vetting 2 (NV2)Handling TOP SECRET information or assets

The Essential Eight applies at every level. Across all four DISP membership levels, your ICT network must meet the ASD Essential Eight at Maturity Level Two or above.

A higher level means a more rigorous and time-consuming assessment, more governance, and higher infrastructure and accreditation costs. For Physical Security and Information and Cyber Security, Defence recommends Entry Level unless you have a specific requirement for more. Choose the level you genuinely need.

The four security domains

You select a membership level in each of these.

Governance

Your security leadership, policies, risk management and reporting, set by the highest level you choose across the other three domains.

Personnel Security

Whether you need to sponsor and manage security clearances for your people, and at what level.

Physical Security

Whether you need to handle or store classified information or assets physically on your premises.

Information & Cyber Security

Whether your ICT networks need to handle classified information, and to what classification.

What you need to have in place

Membership is not granted on intent alone. These are the things Defence expects you to evidence. The good news: you can submit your application before everything is finished, and Defence will help you finalise some items, but the closer you are to ready, the faster it moves.

Security governance

A nominated CSO and SO, documented security policies and plans, and a mechanism for the governing body to approve and submit the Annual Security Report.

People and culture

An annual security awareness program, an insider threat program for all staff, and employment screening that meets Australian Standard AS 4811-2022.

ICT accreditation

An ICT network accredited to one of the four accepted standards. For most businesses that means the ASD Essential Eight at the right maturity level for what you handle.

Registers and records

A security register covering incidents, contact reports, overseas travel briefings and training, plus a Designated Security Assessed Positions (DSAP) list for Level 1 and above.

Supporting documents

A financial ownership diagram covering parent companies and beneficiaries, and, where a Defence contract requires membership, a completed AE250-2 form from your Defence contract manager.

Facility accreditation

Only if you are applying for Physical Security membership at Level 1 or above: an accredited facility or room able to handle or store classified material.

The CSO and SO roles, explained

Every DISP member needs a Chief Security Officer and a Security Officer. Both must be Australian citizens able to obtain and maintain an AGSVA security clearance at the level your membership requires. In a smaller business, one person can hold both roles.

Chief Security Officer (CSO)

The accountable senior leader
  • A senior executive: a member of the board, executive, partnership group or senior management, with the authority to set policy and direct resources.
  • Reviews, declares and submits the application in the DISP Member Portal. The CSO does not start or edit it.
  • Owns the security culture, the risk and oversight system, and the Annual Security Report.
  • Reports any change that could affect membership, including changes in ownership or control. An entity has only one CSO.

Security Officer (SO)

The day-to-day owner
  • Develops and applies the entity's security policies and plans, acting on behalf of the CSO.
  • Starts, edits and submits entries to the CSO in the portal. Only one SO can complete the application.
  • Maintains the DSAP list and the security register, and supports clearance holders.
  • Can sponsor and manage clearances once they hold a minimum NV1 clearance and the right membership level. An entity may have several SOs.

If your CSO or SO does not yet hold a clearance or has not completed Security Officer Training, you can still apply. Membership is granted once they receive their clearances and attest to completing the training. We help you get the right people nominated and supported.

How to apply for DISP membership

Defence frames the application in five stages. Here is what each one involves.

Familiarise

Get across the program, the DSPF framework and the requirements, and gather your documents. Read the Eligibility and Suitability criteria before you start.

Determine your level

Work out the membership level you need in each of the four security domains, based on what your business genuinely handles, not the highest level you could ask for.

Assess and gather

Use the DISP Membership Requirements Checklist to confirm where you stand, and collect the mandatory documents. Make sure every detail matches your ASIC record, especially your ABN and registered address.

Complete in the portal

The SO completes the nine sections of the application in the DISP Member Portal, signing in with a Digital ID. Sections cover entity and officer details, contracts, physical and ICT, levels, FOCI, the Cyber Questionnaire and attachments.

Submit and wait

The CSO reviews and declares, then the SO submits. Defence triages, assigns you a Processing Officer, and assesses the application.Indicative processing: 2 to 3 months for Entry Level, 4 to 6 months for Levels 1, 2 and 3.

Read our step-by-step walkthrough in the guide to applying for DISP membership, or see the DISP FAQ for the questions we hear most.

Working with Defence

Get your security right, and the Defence work opens up

DISP membership is how Australian businesses show they can be trusted with Defence information, contracts and supply chains. We help you meet the bar and keep it.

Check your readiness

How Think Technology Australia helps you get there

We are certified to ISO 27001 and ISO 9001, and we work with Australian businesses on the security and ICT side of DISP membership every day. We translate the requirements into a plan you can actually work through.

Readiness assessment

We benchmark you against the DISP requirements and your target level through an IT security assessment, and give you a clear, prioritised list of gaps to close.

Essential Eight and ICT accreditation

We assess your current Essential Eight maturity and lift it to the level your classification needs, so your network meets an accepted standard. See our work on the Essential Eight. Read how we did this for Ngamuru Advisory, a Canberra defence consultancy.

Policies, plans and registers

We help you put the security governance, documentation and registers in place, drawing on the DISP Security Officer toolkit and our own ISO-certified practices. See our technology leadership service.

CSO and SO support

We support your nominated officers through the portal, the Cyber Questionnaire and the documentation, so the application is complete and accurate before you submit.

Ongoing membership

Membership is not one and done. We help you maintain it: the Annual Security Report, the registers, awareness training and your ongoing security posture.

The practical bits

From a compliant DISP email address to cyber insurance and compliance, we handle the details that trip businesses up.

Deep, hands-on knowledge of the DISP requirements and the application.
ISO 27001 and ISO 9001 certified.
Essential Eight delivered in the real world, not just on paper.
Veteran owned, with people you can talk to.

DISP membership: common questions

 

What is DISP membership?

The Defence Industry Security Program (DISP) is a membership program run by the Department of Defence that helps Australian businesses improve their security when working with Defence. It sits under Control 16.1 of the Defence Security Principles Framework. Membership lets you sponsor your own security clearances, access Defence security training and advice, and tender for a broader range of contracts. Your business needs only one DISP membership, regardless of how many Defence contracts it holds.

Who needs DISP membership?

Businesses that want to work on Defence contracts, tender for Defence work, or join the Defence supply chain generally need DISP membership, and some contracts require it as a condition. If you handle Defence information or assets, or need to sponsor security clearances for your people, DISP membership is usually the path to do that.

What are the DISP membership levels?

There are four levels that align with Australian Government security classifications: Entry Level (OFFICIAL and OFFICIAL: Sensitive), Level 1 (PROTECTED, up to Baseline clearance), Level 2 (SECRET, up to NV1) and Level 3 (TOP SECRET, up to NV2). You select a level for each of the four security domains: Governance, Personnel Security, Physical Security, and Information and Cyber Security.

What are the requirements for DISP membership?

You must be registered in Australia with an ABN, be financially solvent, have a nominated CSO and SO, satisfy Defence requirements for Foreign Ownership, Control or Influence, have no links to sanctioned or listed entities, and run an ICT network that meets one of four accepted cyber security standards: the ASD Essential Eight, ISO/IEC 27001 and 27002, NIST SP 800-171, or UK Def Stan 05-138. You also need documented security policies, an annual security awareness program, insider threat awareness, and a security register.

How long does DISP membership take?

Once your application is complete and you hold the required clearances, certifications and accreditations, Defence expects processing to take about 2 to 3 months for Entry Level, and 4 to 6 months for Levels 1, 2 and 3. Getting your security governance, documentation and ICT accreditation ready before you apply is what saves the most time.

Does DISP require the Essential Eight?

Your ICT network must meet one of four accepted standards, and for most Australian businesses the ASD Essential Eight is the practical choice. The Essential Eight is assessed at Maturity Level One, Two or Three, and the level you need depends on the classification of information you handle. We can assess your current maturity and close the gaps.

How much does DISP membership cost?

Defence does not charge an application fee for DISP membership itself. The real cost is in meeting the requirements: security governance, documentation, ICT accreditation, and at higher levels, physical security and facility accreditation. Higher membership levels carry higher infrastructure and accreditation costs. We can scope what your target level realistically involves.

Can Think Technology Australia manage DISP for us?

Yes. We guide Australian businesses through the process, from working out the right level, to getting your ICT network to Essential Eight, to preparing the policies, registers and documentation, to supporting your CSO and SO through the application in the DISP Member Portal.

Who can help us with the Essential Eight?

We can. The Essential Eight is central to our security work, and it is the ICT standard most Australian businesses use to meet the DISP requirement. We assess your current maturity against the eight controls, give you a prioritised plan, and lift you to the level your classification needs.

What cyber security services do you provide?

We cover the controls businesses need day to day and for DISP: email and network security, DNS filtering, managed anti-virus, managed detection and response, security awareness training and ongoing monitoring. We usually start with a security assessment so you can see where the gaps are.

Can you get our Microsoft 365 environment to Essential Eight?

Yes. Most of the Essential Eight controls can be met on Microsoft 365, particularly Business Premium. We configure application and macro controls, hardening and multi-factor authentication, then document it for your accreditation. See Essential Eight on Microsoft 365.

Do you run IT security assessments and audits?

Yes. An IT security assessment benchmarks you against the Essential Eight and the DISP requirements and gives you a clear, prioritised list of what to fix. It is usually the best place to start if you are working towards membership.

Can you help with cyber insurance and compliance?

Yes. The same security controls that support DISP also satisfy what cyber insurers and compliance frameworks ask for. We can align your environment and provide the evidence you need at renewal.

More on DISP, the Essential Eight and security from our team

Practical guides we have written for Australian businesses working towards Defence and DISP requirements.

Related Think Technology Australia services

The services we lean on to get businesses DISP-ready and keep them there.

Official DISP resources

Straight from the source. Always confirm the current detail on the Department of Defence website before you rely on it.

Talk to us

Talk to us about your DISP membership

Tell us where you are up to. We will help you work out the right level, close the gaps, and get your application moving. Prefer to talk? Call 1300 920 866.

  • A clear, prioritised view of what to fix before you apply.
  • Help with the Essential Eight, policies, registers and the portal.
  • No obligation, just practical advice.

We will only use your details to respond to your enquiry.