Siege Cyber provides end-to-end DISP compliance consulting for Australian defence contractors and subcontractors. We assess your readiness across all four security domains, implement Essential Eight Maturity Level 2, prepare your DISP membership application, and provide ongoing support to maintain compliance once membership is granted. You get DISP approval and sustainable security controls that satisfy Defence Security Authority requirements.
Here is what you get:

We have guided Australian defence contractors through DISP membership application and compliance. Here is how it works.
We meet with your leadership team to understand your defence industry engagement (prime contractor, subcontractor, or aspiring bidder), target classification level for DISP membership (PROTECTED, SECRET, TOP SECRET), current security posture across the four domains, and timeline requirements (existing contract obligations, upcoming tender deadlines). We conduct a DISP readiness assessment to determine gaps, realistic timeline to application-ready status, and estimated effort required. This establishes whether DISP membership is achievable within your required timeline.
We assess your current Essential Eight maturity level and plan implementation to reach Maturity Level 2 across all corporate IT systems. This includes detailed gap analysis for all eight strategies, prioritised remediation roadmap, technical implementation plan, evidence collection framework, and timeline to Essential Eight ML2 compliance. Without Essential Eight ML2, your DISP application will not be approved, so ICT/Cyber Security domain readiness is critical path.
We establish or enhance your security governance framework to meet DISP requirements including board or executive security oversight, security risk management processes, comprehensive security policies and procedures, incident management framework, third-party security requirements, and annual security reporting processes. The Defence Security Authority assesses whether your governance is genuine and sustainable, not superficial documentation created solely for compliance.
While Essential Eight implementation progresses, we establish personnel and physical security programmes including personnel security vetting procedures, security clearance management, secure area access control, classified information handling procedures, visitor management protocols, and ongoing suitability monitoring. These domains require coordination with HR, facilities, and management, and implementation timelines vary based on your starting point.
We compile comprehensive evidence demonstrating compliance across all four security domains including Essential Eight ML2 technical validation, security governance documentation, personnel security records, physical security assessments, incident management logs, and third-party security agreements. The Defence Security Authority requires documented proof of compliance, not claims. We ensure evidence is complete, accurate, and audit-ready before application submission.
We prepare and submit your formal DISP membership application, coordinate with Defence Security Authority processing officers, respond to queries or requests for additional information, facilitate any required site assessments, and track application progress through the 90-day processing timeline. Once membership is granted, we establish ongoing compliance monitoring to maintain your DISP membership and prepare annual security reports.
This service is designed for Australian businesses that work or intend to work with the Australian Defence Force, defence primes, or on defence-related projects requiring DISP membership.
You are a good fit if:
20+ years of information security and compliance expertise. Our Technical Director, Peter Stewart, has spent over two decades in cybersecurity roles including security assessments, penetration testing, and compliance consulting. We understand both the technical implementation and governance aspects of DISP requirements, allowing us to guide you through all four security domains effectively.
Deep expertise in Essential Eight Maturity Level 2 implementation. DISP's 2026 ICT/Cyber Security requirements mandate Essential Eight ML2, which is significantly more demanding than the previous "Top 4" approach. We have extensive experience implementing Essential Eight across Australian organisations and understand the ASD maturity model requirements, evidence expectations, and sustainable implementation approaches. We know how to achieve and maintain Essential Eight ML2 efficiently.
Understanding of Australian defence security requirements. Beyond technical controls, DISP requires understanding of the Defence Security Principles Framework (DSPF), Australian Government Protective Security Policy Framework (PSPF), and Defence Security Authority expectations. We understand what the DSA looks for during assessments, what documentation satisfies requirements, and what constitutes genuine governance versus superficial compliance. You get guidance grounded in defence industry security standards.
Practical approach to the four security domains. Technology companies typically have reasonable ICT security but weak governance and physical security programmes. We help you address all four DISP domains systematically, leveraging existing controls where possible and implementing new controls where required. We prioritise based on your timeline, classification level requirements, and available resources.
Proven track record with Australian defence contractors. We have guided defence primes, subcontractors, and aspiring defence industry participants through DISP membership application and compliance. You benefit from our experience with Defence Security Authority processes, common application issues, and what actually satisfies DSA assessment requirements versus what looks good on paper but fails scrutiny.
In September 2024, DISP introduced significant cyber security updates effective for 2026. Previously, DISP required only four Essential Eight strategies ("Top 4": Application Whitelisting, Patching Applications, Restricting Administrative Privileges, Patching Operating Systems) at Maturity Level 1. From 2026, DISP requires all eight Essential Eight mitigation strategies at Maturity Level 2 across your entire corporate IT environment. This represents a substantial increase in requirements and implementation effort.
The Defence Security Authority processing timeline is approximately 90 days once your application is assigned to a processing officer. However, this assumes your application is complete and your security controls meet requirements when submitted. Most organisations require 6-12 months of preparation before submitting, depending on their starting security posture. Attempting to rush the preparation phase typically results in application rejection or extensive delays as the DSA requests additional information or remediation.
DISP membership levels align with Australian Government security classifications: PROTECTED, SECRET, and TOP SECRET. The appropriate level depends on the classification of defence information you will handle. Most defence contractors start with PROTECTED level, which is sufficient for most non-classified or low-classification defence work. Higher classification levels require increasingly stringent security controls, longer processing times, and more extensive personnel security vetting. Start with the minimum classification level your defence work requires.
Not necessarily. Personnel security requirements depend on your DISP membership level and the specific defence work involved. At minimum, key personnel who will handle classified information need appropriate security clearances. Some contracts require all staff with access to defence systems or information to hold clearances, while others only require clearance for specific roles. We help you determine which personnel require vetting based on your DISP classification level and contract requirements.
Yes, though it requires established processes and periodic expert support. Many smaller defence contractors use a combination of internal IT staff managing day-to-day security operations, periodic security consultant support for quarterly or annual assessments, and external audit or vCISO services for governance oversight and annual security reporting. The key is establishing sustainable processes that maintain Essential Eight ML2 compliance and evidence collection without requiring full-time dedicated security personnel.
The Defence Security Authority typically does not outright reject applications but rather identifies deficiencies requiring remediation before approval. Common issues include insufficient Essential Eight maturity, inadequate security governance documentation, gaps in personnel security vetting, or physical security deficiencies. If your application reveals deficiencies, you remediate the identified gaps and resubmit evidence. This extends the approval timeline but does not permanently disqualify you from DISP membership.
DISP membership itself does not have a fixed expiration date, but the Defence Security Authority requires annual security reports demonstrating ongoing compliance with membership requirements. Additionally, security clearances for personnel have defined validity periods requiring renewal. If your security posture degrades significantly or you fail to provide required annual reporting, your DISP membership can be suspended or revoked. Ongoing compliance is mandatory, not optional.

DISP membership is not optional for Australian defence contractors. It is mandatory for bidding on defence tenders, working on defence projects, or handling classified defence information. The 2026 requirements are significantly more demanding than previous years, with Essential Eight Maturity Level 2 now required across your entire corporate IT environment. Attempting to navigate DISP compliance without expert guidance typically results in extended timelines, application delays, or outright rejection.
Book a free 30-minute consultation with our team. We will assess your current security posture across the four DISP domains, explain what Essential Eight ML2 implementation involves, and provide a realistic timeline to DISP membership approval. You will leave the call understanding exactly what is required and whether you can achieve DISP membership within your contract deadlines.
