
DISP Application Checklist for Australian Defence Suppliers
If you’re preparing for DISP membership, you’re already taking a meaningful step toward working in Australia’s defence supply chain. DISP sits alongside frameworks like the Defence Security Principles Framework, Australian Cyber Security Centre guidance, the Australian Privacy Principles, ASD Essential Eight and ISO 27001 – and your application is one of the first places Defence will see how seriously you take them.
This checklist gives you a clear view of the main areas Defence will expect you to think about when you apply.
1. understand what DISP is asking for
The Defence Industry Security Program (DISP) helps Defence assess whether a supplier has the governance, controls and culture needed to handle Defence‑related work responsibly.
It isn’t just a cyber exercise. Defence will look at:
-
Governance and accountability
-
Personnel security
-
Physical security
-
Cyber security and privacy (including ACSC/ASD Essential Eight and APPs)
Before you start you should confirm:
-
Which DISP level you’re targeting and why
-
Who will own security oversight in your business
-
That your business details and ownership structure are clear and consistent

2. Build a coherent document pack
Defence wants to see more than isolated policies. Your document pack should tell a consistent story about how you manage security.
At a high level, you’ll need documentation that covers:
-
Business identity and structure, including any control/ownership issues
-
Security governance and how it links to frameworks you use (e.g. ISO 27001, ACSC/ASD guidance)
-
Defined security responsibilities and DISP‑specific roles
-
Physical, cyber and personnel security arrangements
-
Any relevant privacy and data‑handling obligations (APPs)
If you use platforms like Vanta or Drata for other standards, they can be useful inputs – but they still need to be interpreted in a DISP context rather than copied across unchanged.
3. Make roles and responsibilities explicit
One of the first things Defence checks is whether security responsibilities are clearly assigned.
You should be able to point to:
-
Named individuals with clear DISP‑related responsibilities
-
How those responsibilities fit into your existing governance (board, exec, ISO 27001 committee, etc.)
-
Where those roles are documented in your application and supporting materials
In smaller organisations, one person might wear multiple hats, but the accountability still needs to be obvious and documented.

4. Prepare meaningful security evidence
DISP security ‘evidence’ is about proving that your approach works in practice, not just on paper.
Useful, high‑level evidence often shows that you have:
-
A practical security governance structure with real meetings and actions
-
Documented responsibilities that people understand
-
Basic recordkeeping for security matters (actions, incidents, risks)
-
Coverage across people, premises, systems and data – including privacy and cyber baselines
If you already work with ASD Essential Eight, ACSC guidance, ISO 27001 or tools like Vanta and Drata, there is usually plenty of raw evidence available. The real task is selecting and aligning it so it makes sense to Defence.
5. Treat the application as a readiness review
The organisations that move through DISP more smoothly are typically those that:
-
Review their business and security posture before completing the application
-
Map existing controls and documentation to DISP, DSPF, ACSC and APP expectations
-
Use gaps as a prompt to strengthen security, not just as boxes to tick
A short readiness review – looking at your structure, documentation, roles and evidence – will quickly show whether you’re ready for the level you’re targeting or whether some preparation work is still needed.
6. Avoid common pitfalls
Typical issues that slow DISP applications include:
-
Treating DISP as “mainly cyber” and overlooking governance, people and physical security
-
Inconsistent business or ownership details between documents and forms
-
Vague or undocumented security roles
-
Assuming policies alone will be enough, without evidence of use in practice
-
Leaving preparation until a Defence opportunity is already under time pressure
Most of these can be avoided with early review and a clear plan.

A practical next step
If your business is preparing to work with Defence, the practical next step is a DISP readiness review before you submit anything. That gives you a clear view of where you stand, how you can leverage existing frameworks and tooling (ASD Essential Eight, ACSC guidance, ISO 27001 work, Vanta/Drata data), and what needs attention to give Defence confidence in your application.
Siege Cyber helps Australian businesses with DISP membership requirements, gap analysis, security documentation and broader compliance preparation. Visit siegecyber.com.au, review our DISP service page, and check our compliance pricing to get started.