Defence Industry Security Program
If you want to work with Defence, DISP membership is often the door you have to walk through first. It can look daunting: four security domains, four levels, security clearances and an ICT network that has to meet a recognised standard. We help Australian businesses work out what they need, close the gaps, and get through the application with less guesswork.
Check your DISP readinessYou likely already understand what DISP membership involves. What you need is a partner to guide you through it. We translate the DISP requirements into a clear, prioritised plan, deliver the security and ICT work they call for, and support your team through to lodging your application.
Many businesses engage us part way through, unsure which membership level they require, or held up by the Essential Eight and ICT accreditation the application depends on. We help you determine the right level for each security domain, so your investment in clearances, facilities and infrastructure reflects what your contracts genuinely require, then we close the gaps: Essential Eight maturity, the security policies and registers, and the documentation Defence expects.
We are certified to ISO 27001 and ISO 9001, and we work across the security and ICT requirements of DISP every day. Whether you are beginning the process or finalising an application, we will give you a clear, honest assessment of where you stand and what it takes to achieve membership.
If you want to tender for Defence work, hold a Defence contract that calls for it, or join the Defence supply chain, you will usually need DISP membership. Before you apply, your business must meet a set of eligibility requirements.
Not sure whether you tick these boxes yet? That is exactly what the readiness check below is for.
Levels align with Australian Government security classifications. You hold a level in each of the four security domains, so your membership is shaped to what you handle, not a single blanket rating.
| Level | Information classification | Personnel clearance | Typical fit |
|---|---|---|---|
| Entry Level | OFFICIAL / OFFICIAL: Sensitive | Sponsored by Defence or another agency | Most businesses entering the Defence supply chain |
| Level 1 | PROTECTED | Up to Baseline | Handling PROTECTED information or assets |
| Level 2 | SECRET | Up to Negative Vetting 1 (NV1) | Handling SECRET information or assets |
| Level 3 | TOP SECRET | Up to Negative Vetting 2 (NV2) | Handling TOP SECRET information or assets |
The Essential Eight applies at every level. Across all four DISP membership levels, your ICT network must meet the ASD Essential Eight at Maturity Level Two or above.
A higher level means a more rigorous and time-consuming assessment, more governance, and higher infrastructure and accreditation costs. For Physical Security and Information and Cyber Security, Defence recommends Entry Level unless you have a specific requirement for more. Choose the level you genuinely need.
You select a membership level in each of these.
Your security leadership, policies, risk management and reporting, set by the highest level you choose across the other three domains.
Whether you need to sponsor and manage security clearances for your people, and at what level.
Whether you need to handle or store classified information or assets physically on your premises.
Whether your ICT networks need to handle classified information, and to what classification.
Membership is not granted on intent alone. These are the things Defence expects you to evidence. The good news: you can submit your application before everything is finished, and Defence will help you finalise some items, but the closer you are to ready, the faster it moves.
A nominated CSO and SO, documented security policies and plans, and a mechanism for the governing body to approve and submit the Annual Security Report.
An annual security awareness program, an insider threat program for all staff, and employment screening that meets Australian Standard AS 4811-2022.
An ICT network accredited to one of the four accepted standards. For most businesses that means the ASD Essential Eight at the right maturity level for what you handle.
A security register covering incidents, contact reports, overseas travel briefings and training, plus a Designated Security Assessed Positions (DSAP) list for Level 1 and above.
A financial ownership diagram covering parent companies and beneficiaries, and, where a Defence contract requires membership, a completed AE250-2 form from your Defence contract manager.
Only if you are applying for Physical Security membership at Level 1 or above: an accredited facility or room able to handle or store classified material.
Every DISP member needs a Chief Security Officer and a Security Officer. Both must be Australian citizens able to obtain and maintain an AGSVA security clearance at the level your membership requires. In a smaller business, one person can hold both roles.
If your CSO or SO does not yet hold a clearance or has not completed Security Officer Training, you can still apply. Membership is granted once they receive their clearances and attest to completing the training. We help you get the right people nominated and supported.
Defence frames the application in five stages. Here is what each one involves.
Get across the program, the DSPF framework and the requirements, and gather your documents. Read the Eligibility and Suitability criteria before you start.
Work out the membership level you need in each of the four security domains, based on what your business genuinely handles, not the highest level you could ask for.
Use the DISP Membership Requirements Checklist to confirm where you stand, and collect the mandatory documents. Make sure every detail matches your ASIC record, especially your ABN and registered address.
The SO completes the nine sections of the application in the DISP Member Portal, signing in with a Digital ID. Sections cover entity and officer details, contracts, physical and ICT, levels, FOCI, the Cyber Questionnaire and attachments.
The CSO reviews and declares, then the SO submits. Defence triages, assigns you a Processing Officer, and assesses the application.Indicative processing: 2 to 3 months for Entry Level, 4 to 6 months for Levels 1, 2 and 3.
Read our step-by-step walkthrough in the guide to applying for DISP membership, or see the DISP FAQ for the questions we hear most.
Working with Defence
DISP membership is how Australian businesses show they can be trusted with Defence information, contracts and supply chains. We help you meet the bar and keep it.
We are certified to ISO 27001 and ISO 9001, and we work with Australian businesses on the security and ICT side of DISP membership every day. We translate the requirements into a plan you can actually work through.
We benchmark you against the DISP requirements and your target level through an IT security assessment, and give you a clear, prioritised list of gaps to close.
We assess your current Essential Eight maturity and lift it to the level your classification needs, so your network meets an accepted standard. See our work on the Essential Eight. Read how we did this for Ngamuru Advisory, a Canberra defence consultancy.
We help you put the security governance, documentation and registers in place, drawing on the DISP Security Officer toolkit and our own ISO-certified practices. See our technology leadership service.
We support your nominated officers through the portal, the Cyber Questionnaire and the documentation, so the application is complete and accurate before you submit.
Membership is not one and done. We help you maintain it: the Annual Security Report, the registers, awareness training and your ongoing security posture.
From a compliant DISP email address to cyber insurance and compliance, we handle the details that trip businesses up.
The Defence Industry Security Program (DISP) is a membership program run by the Department of Defence that helps Australian businesses improve their security when working with Defence. It sits under Control 16.1 of the Defence Security Principles Framework. Membership lets you sponsor your own security clearances, access Defence security training and advice, and tender for a broader range of contracts. Your business needs only one DISP membership, regardless of how many Defence contracts it holds.
Businesses that want to work on Defence contracts, tender for Defence work, or join the Defence supply chain generally need DISP membership, and some contracts require it as a condition. If you handle Defence information or assets, or need to sponsor security clearances for your people, DISP membership is usually the path to do that.
There are four levels that align with Australian Government security classifications: Entry Level (OFFICIAL and OFFICIAL: Sensitive), Level 1 (PROTECTED, up to Baseline clearance), Level 2 (SECRET, up to NV1) and Level 3 (TOP SECRET, up to NV2). You select a level for each of the four security domains: Governance, Personnel Security, Physical Security, and Information and Cyber Security.
You must be registered in Australia with an ABN, be financially solvent, have a nominated CSO and SO, satisfy Defence requirements for Foreign Ownership, Control or Influence, have no links to sanctioned or listed entities, and run an ICT network that meets one of four accepted cyber security standards: the ASD Essential Eight, ISO/IEC 27001 and 27002, NIST SP 800-171, or UK Def Stan 05-138. You also need documented security policies, an annual security awareness program, insider threat awareness, and a security register.
Once your application is complete and you hold the required clearances, certifications and accreditations, Defence expects processing to take about 2 to 3 months for Entry Level, and 4 to 6 months for Levels 1, 2 and 3. Getting your security governance, documentation and ICT accreditation ready before you apply is what saves the most time.
Your ICT network must meet one of four accepted standards, and for most Australian businesses the ASD Essential Eight is the practical choice. The Essential Eight is assessed at Maturity Level One, Two or Three, and the level you need depends on the classification of information you handle. We can assess your current maturity and close the gaps.
Defence does not charge an application fee for DISP membership itself. The real cost is in meeting the requirements: security governance, documentation, ICT accreditation, and at higher levels, physical security and facility accreditation. Higher membership levels carry higher infrastructure and accreditation costs. We can scope what your target level realistically involves.
Yes. We guide Australian businesses through the process, from working out the right level, to getting your ICT network to Essential Eight, to preparing the policies, registers and documentation, to supporting your CSO and SO through the application in the DISP Member Portal.
We can. The Essential Eight is central to our security work, and it is the ICT standard most Australian businesses use to meet the DISP requirement. We assess your current maturity against the eight controls, give you a prioritised plan, and lift you to the level your classification needs.
We cover the controls businesses need day to day and for DISP: email and network security, DNS filtering, managed anti-virus, managed detection and response, security awareness training and ongoing monitoring. We usually start with a security assessment so you can see where the gaps are.
Yes. Most of the Essential Eight controls can be met on Microsoft 365, particularly Business Premium. We configure application and macro controls, hardening and multi-factor authentication, then document it for your accreditation. See Essential Eight on Microsoft 365.
Yes. An IT security assessment benchmarks you against the Essential Eight and the DISP requirements and gives you a clear, prioritised list of what to fix. It is usually the best place to start if you are working towards membership.
Yes. The same security controls that support DISP also satisfy what cyber insurers and compliance frameworks ask for. We can align your environment and provide the evidence you need at renewal.
Practical guides we have written for Australian businesses working towards Defence and DISP requirements.
A step-by-step walkthrough of the application, from eligibility to submission.
DISP FAQThe questions Australian businesses ask us most about DISP.
DISP startA clear starting point if DISP is new to your business.
DISP how-toWhat a DISP@ email address is and how to set one up properly.
Essential EightHow the Essential Eight underpins your DISP ICT accreditation.
Essential EightMeeting Essential Eight macro controls on Microsoft 365 Business Premium.
Essential EightSecuring Microsoft 365 against the Essential Eight controls.
ISOWhy information security and quality certification matters for Defence work.
AwarenessThe annual awareness program DISP expects, done properly.
Supply chainWhat primes and suppliers owe each other in the Defence supply chain.
The services we lean on to get businesses DISP-ready and keep them there.
Straight from the source. Always confirm the current detail on the Department of Defence website before you rely on it.
Talk to us
Tell us where you are up to. We will help you work out the right level, close the gaps, and get your application moving. Prefer to talk? Call 1300 920 866.
Tell us where you are up to and we will be in touch.