Siege Cyber provides end-to-end DISP compliance consulting for Australian defence contractors and subcontractors. We assess your readiness across all four security domains, implement Essential Eight Maturity Level 2, prepare your DISP membership application, and provide ongoing support to maintain compliance once membership is granted. You get DISP approval and sustainable security controls that satisfy Defence Security Authority requirements.
Here is what you get:

We have guided Australian defence contractors through DISP membership application and compliance. Here is how it works.
We meet with your leadership team to understand your defence industry engagement (prime contractor, subcontractor, or aspiring bidder), target classification level for DISP membership (PROTECTED, SECRET, TOP SECRET), current security posture across the four domains, and timeline requirements (existing contract obligations, upcoming tender deadlines). We conduct a DISP readiness assessment to determine gaps, realistic timeline to application-ready status, and estimated effort required. This establishes whether DISP membership is achievable within your required timeline.
We assess your current Essential Eight maturity level and plan implementation to reach Maturity Level 2 across all corporate IT systems. This includes detailed gap analysis for all eight strategies, prioritised remediation roadmap, technical implementation plan, evidence collection framework, and timeline to Essential Eight ML2 compliance. Without Essential Eight ML2, your DISP application will not be approved, so ICT/Cyber Security domain readiness is critical path.
We establish or enhance your security governance framework to meet DISP requirements including board or executive security oversight, security risk management processes, comprehensive security policies and procedures, incident management framework, third-party security requirements, and annual security reporting processes. The Defence Security Authority assesses whether your governance is genuine and sustainable, not superficial documentation created solely for compliance.
While Essential Eight implementation progresses, we establish personnel and physical security programmes including personnel security vetting procedures, security clearance management, secure area access control, classified information handling procedures, visitor management protocols, and ongoing suitability monitoring. These domains require coordination with HR, facilities, and management, and implementation timelines vary based on your starting point.
We compile comprehensive evidence demonstrating compliance across all four security domains including Essential Eight ML2 technical validation, security governance documentation, personnel security records, physical security assessments, incident management logs, and third-party security agreements. The Defence Security Authority requires documented proof of compliance, not claims. We ensure evidence is complete, accurate, and audit-ready before application submission.
We prepare and submit your formal DISP membership application, coordinate with Defence Security Authority processing officers, respond to queries or requests for additional information, facilitate any required site assessments, and track application progress through the 90-day processing timeline. Once membership is granted, we establish ongoing compliance monitoring to maintain your DISP membership and prepare annual security reports.
This service is designed for Australian businesses that work or intend to work with the Australian Defence Force, defence primes, or on defence-related projects requiring DISP membership.
You are a good fit if:
20+ years of information security and compliance expertise. Our Technical Director, Peter Stewart, has spent over two decades in cybersecurity roles including security assessments, penetration testing, and compliance consulting. We understand both the technical implementation and governance aspects of DISP requirements, allowing us to guide you through all four security domains effectively.
Deep expertise in Essential Eight Maturity Level 2 implementation. DISP's 2026 ICT/Cyber Security requirements mandate Essential Eight ML2, which is significantly more demanding than the previous "Top 4" approach. We have extensive experience implementing Essential Eight across Australian organisations and understand the ASD maturity model requirements, evidence expectations, and sustainable implementation approaches. We know how to achieve and maintain Essential Eight ML2 efficiently.
Understanding of Australian defence security requirements. Beyond technical controls, DISP requires understanding of the Defence Security Principles Framework (DSPF), Australian Government Protective Security Policy Framework (PSPF), and Defence Security Authority expectations. We understand what the DSA looks for during assessments, what documentation satisfies requirements, and what constitutes genuine governance versus superficial compliance. You get guidance grounded in defence industry security standards.
Practical approach to the four security domains. Technology companies typically have reasonable ICT security but weak governance and physical security programmes. We help you address all four DISP domains systematically, leveraging existing controls where possible and implementing new controls where required. We prioritise based on your timeline, classification level requirements, and available resources.
Proven track record with Australian defence contractors. We have guided defence primes, subcontractors, and aspiring defence industry participants through DISP membership application and compliance. You benefit from our experience with Defence Security Authority processes, common application issues, and what actually satisfies DSA assessment requirements versus what looks good on paper but fails scrutiny.
In September 2024, DISP introduced significant cyber security updates effective for 2026. Previously, DISP required only four Essential Eight strategies ("Top 4": Application Whitelisting, Patching Applications, Restricting Administrative Privileges, Patching Operating Systems) at Maturity Level 1. From 2026, DISP requires all eight Essential Eight mitigation strategies at Maturity Level 2 across your entire corporate IT environment. This represents a substantial increase in requirements and implementation effort.
The Defence Security Authority processing timeline is approximately 90 days once your application is assigned to a processing officer. However, this assumes your application is complete and your security controls meet requirements when submitted. Most organisations require 6-12 months of preparation before submitting, depending on their starting security posture. Attempting to rush the preparation phase typically results in application rejection or extensive delays as the DSA requests additional information or remediation.
DISP membership levels align with Australian Government security classifications: PROTECTED, SECRET, and TOP SECRET. The appropriate level depends on the classification of defence information you will handle. Most defence contractors start with PROTECTED level, which is sufficient for most non-classified or low-classification defence work. Higher classification levels require increasingly stringent security controls, longer processing times, and more extensive personnel security vetting. Start with the minimum classification level your defence work requires.
Not necessarily. Personnel security requirements depend on your DISP membership level and the specific defence work involved. At minimum, key personnel who will handle classified information need appropriate security clearances. Some contracts require all staff with access to defence systems or information to hold clearances, while others only require clearance for specific roles. We help you determine which personnel require vetting based on your DISP classification level and contract requirements.
Yes, though it requires established processes and periodic expert support. Many smaller defence contractors use a combination of internal IT staff managing day-to-day security operations, periodic security consultant support for quarterly or annual assessments, and external audit or vCISO services for governance oversight and annual security reporting. The key is establishing sustainable processes that maintain Essential Eight ML2 compliance and evidence collection without requiring full-time dedicated security personnel.
The Defence Security Authority typically does not outright reject applications but rather identifies deficiencies requiring remediation before approval. Common issues include insufficient Essential Eight maturity, inadequate security governance documentation, gaps in personnel security vetting, or physical security deficiencies. If your application reveals deficiencies, you remediate the identified gaps and resubmit evidence. This extends the approval timeline but does not permanently disqualify you from DISP membership.
DISP membership itself does not have a fixed expiration date, but the Defence Security Authority requires annual security reports demonstrating ongoing compliance with membership requirements. Additionally, security clearances for personnel have defined validity periods requiring renewal. If your security posture degrades significantly or you fail to provide required annual reporting, your DISP membership can be suspended or revoked. Ongoing compliance is mandatory, not optional.

DISP membership is not optional for Australian defence contractors. It is mandatory for bidding on defence tenders, working on defence projects, or handling classified defence information. The 2026 DISP accreditation requirements are significantly more demanding than previous years, with Essential Eight Maturity Level 2 now required across your entire corporate IT environment. Without experienced DISP consultants guiding the process, businesses routinely face extended timelines, application delays, or outright rejection.
Book a free 30-minute consultation with our team. We will assess your current security posture across all four DISP domains, explain the different DISP levels and what Essential Eight ML2 implementation involves, and provide a realistic timeline to DISP certification and membership approval. You will leave the call understanding exactly what is required and whether you can achieve DISP membership within your contract deadlines.

Most of the confusion we are asked to clear up is about which level a business actually needs. Defence does not expect every supplier to hold the highest level, and applying for more than your contracts require adds cost and time without adding work you can win.
Entry Level suits suppliers who need to demonstrate baseline governance and cyber security but do not handle classified information. It is the most common starting point, and for many businesses it is the only level they will ever need.
Level 1 applies where you handle information up to PROTECTED. It brings formal personnel security obligations, appointed security officers and a higher evidence bar across all four domains.
Level 2 and Level 3 apply at SECRET and TOP SECRET, and bring physical security and personnel clearance requirements that materially change how your business operates. If a contract genuinely requires these, the conversation starts well before the application.
We work through this with you before any paperwork starts, because the level determines everything that follows. There is a longer treatment in our guide to DISP Entry Level versus Level 1 and in DISP levels and requirements explained.
DISP is not a cyber security certification, which is the single most common misunderstanding we encounter. It covers four domains, and cyber is one of them:
A business with excellent cyber security and no governance documentation fails. So does a business with perfect policies and an unpatched network. We cover all four, which is why this is a programme rather than an assessment.
Defence does not charge an application fee. The cost is the work required to meet the standard, and the cost of keeping it current once you have it.
We price that as a fixed monthly programme: $3,750 per month excluding GST over twelve months, for up to 50 employees, then $1,000 per month for each additional 40 employees. That covers the four domain gap analysis, ISM-aligned controls, a customised DISP policy and procedure suite, CSO and SO advisory support, Defence-aligned incident response planning and Annual Security Report preparation.
What it does not cover is the external audit or Defence's own assessment, which sit outside any provider's control. The full breakdown is on our compliance pricing page, and there is a longer discussion in what DISP certification costs in Australia.
From a standing start, plan on three to nine months to be application ready, then Defence's own assessment time on top. The variables are how much governance documentation already exists, whether you are close to Essential Eight Maturity Level 2, and how quickly your people can be made available for the personnel security work.
The businesses that take longest are usually the ones that applied first and discovered the gaps afterwards. A gap analysis before you apply is the cheapest part of the whole exercise.
These overlap more than most suppliers expect, and the overlap is worth using. Essential Eight Maturity Level 2 is effectively the ICT and cyber component of DISP, so work done there counts twice. ISO 27001 gives you the governance and risk management structure that the governance domain asks for, which is why suppliers already certified tend to move faster. IRAP is a different thing again, assessing systems rather than organisations, and is usually driven by a specific contract.
If you are weighing these up, we have written about how DISP relates to ISO 27001 and other frameworks and how Essential Eight, ISO 27001 and DISP work together.
Not every Defence supplier does. DISP is required where a contract says it is required, and the trigger is usually access to Defence information, Defence assets or Defence sites. Plenty of businesses in the supply chain never touch any of those, and for them a DISP application is an expensive answer to a question nobody asked.
It is also increasingly requested by primes further up the chain as a condition of subcontracting, whether or not Defence itself requires it. If a prime has asked you for it, that is a commercial requirement and the answer is usually yes.
We will tell you if we think you do not need it. More detail in is DISP certification mandatory in Australia.
Membership is not a certificate you file away. Defence expects an Annual Security Report, ongoing reporting of security incidents and changes to your business, and evidence that your controls are still operating. Suppliers most often come unstuck here rather than at the application.
Our programme continues past the application for exactly that reason, which is also why it is priced monthly rather than as a project.
Tell us which level your contracts require, roughly how many people you employ and where you are starting from. We will come back with a fixed monthly price and a realistic date for being application ready. If a gap analysis is the sensible first step rather than a full programme, we will say so.
Next step: Book 30 minutes with Peter, or send us your details and we will put a number in front of you.