DISP Membership and Accreditation Support

Secure defence contracts with DISP Membership and Essential Eight Maturity Level 2 compliance

Simple monthly billing, everything included → DISP CERTIFY

Siege Cyber provides comprehensive DISP membership and accreditation services for Australian businesses bidding on defence contracts or working as defence industry subcontractors. As experienced DISP consultants, we guide you through the full DISP certification process, from understanding the different DISP levels to implementing Essential Eight Maturity Level 2 across your corporate IT systems. We help you establish the four security domains required by the Defence Security Authority and provide ongoing compliance support, so you achieve DISP accreditation and have the security capability to maintain it.

You Need DISP Membership to Bid on Defence Contracts, But the Requirements Just Got Significantly Harder

Your business has an opportunity to bid on an Australian Defence contract or work as a subcontractor to a defence prime, but the tender requirements explicitly state that DISP membership is mandatory. Once you begin the DISP certification process, you quickly discover that DISP accreditation now requires Essential Eight Maturity Level 2 across your entire corporate IT environment, not just the previous "Top 4" strategies at Level 1. These changes came into effect in late 2024, and what was once achievable in 3-4 months now demands 6-12 months of dedicated implementation effort.

The Defence Security Authority is clear: without current DISP membership, you cannot process defence-related information or work on defence projects. The application takes approximately 90 days once assigned to a processing officer, assuming your documentation is complete and controls meet requirements. If your Essential Eight implementation falls short, your ICT/Cyber Security domain assessment fails and your application stalls, putting your contract opportunity or existing defence work at risk.

This is where understanding the different DISP levels and having experienced DISP consultants in your corner makes all the difference. DISP accreditation spans four security domains: Security Governance, Personnel Security, Physical Security, and ICT/Cyber Security. A deficiency in any one domain can delay or prevent approval, and all four must be addressed simultaneously to secure your DISP membership.

What We Deliver: Defence Industry Security Program Consulting Services

Siege Cyber provides end-to-end DISP compliance consulting for Australian defence contractors and subcontractors. We assess your readiness across all four security domains, implement Essential Eight Maturity Level 2, prepare your DISP membership application, and provide ongoing support to maintain compliance once membership is granted. You get DISP approval and sustainable security controls that satisfy Defence Security Authority requirements.

Here is what you get:

  • DISP readiness assessment across all four security domains – We assess your current capability against DISP requirements for Security Governance (security policies, risk management, incident response), Personnel Security (security clearances, vetting procedures, ongoing suitability), Physical Security (access control, secure storage, visitor management), and ICT/Cyber Security (Essential Eight ML2, network security, data protection). We identify gaps in each domain, determine which classification level is realistic for your organisation, estimate timeline to DISP-ready status, and provide a prioritised remediation roadmap. You understand exactly what is required before starting the formal application.
  • Essential Eight Maturity Level 2 implementation – DISP's 2026 ICT/Cyber Security requirements mandate Essential Eight ML2 across all corporate IT systems used to correspond with Defence. We implement all eight mitigation strategies at Maturity Level 2 including application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. This is not the previous "Top 4" approach. This is full Essential Eight ML2 with documented evidence and technical validation. Without this, your DISP application cannot proceed.
  • Security governance framework and documentation – DISP requires documented security governance appropriate to the classification level you are seeking. We establish board or executive-level security governance, security risk management framework, documented security policies and procedures, incident management and reporting processes, third-party and supply chain security requirements, and annual security reporting capability. The Defence Security Authority expects to see genuine governance oversight, not policies copied from templates with no evidence of implementation.
  • Personnel and physical security programme development – Beyond ICT security, DISP requires personnel security vetting and physical security controls. We establish personnel security vetting processes aligned with Australian Government Protective Security Policy Framework (PSPF), security clearance management procedures, ongoing suitability monitoring, secure area access control systems, classified information storage and handling procedures, and visitor management protocols. These domains are often overlooked by technology companies but are mandatory for DISP membership.
  • DISP membership application preparation and submission – Once your security controls meet requirements, we prepare your formal DISP membership application including completion of all required documentation, compilation of evidence for each security domain, preparation for Defence Security Authority assessment, coordination with DSA processing officers, and response to any queries or requests for additional information. A well-prepared application moves through the 90-day processing timeline smoothly. A poorly prepared application stalls indefinitely.
  • Annual security reporting and ongoing compliance – DISP membership requires annual security reports demonstrating continued compliance. We establish processes for ongoing monitoring of Essential Eight controls, annual security reporting to Defence, management of security incidents affecting defence work, periodic reassessment of security domains, and maintenance of DISP membership. Achieving DISP membership is significant effort. Maintaining it requires ongoing commitment, and we provide the framework to sustain compliance year after year.

 

DISP membership levels showing the governance, personnel security, physical security and ICT and cyber security clearance required at entry level and levels 1, 2 and 3

 

 

Our DISP Compliance Process

We have guided Australian defence contractors through DISP membership application and compliance. Here is how it works.

1. DISP Readiness Assessment and Classification Scoping

We meet with your leadership team to understand your defence industry engagement (prime contractor, subcontractor, or aspiring bidder), target classification level for DISP membership (PROTECTED, SECRET, TOP SECRET), current security posture across the four domains, and timeline requirements (existing contract obligations, upcoming tender deadlines). We conduct a DISP readiness assessment to determine gaps, realistic timeline to application-ready status, and estimated effort required. This establishes whether DISP membership is achievable within your required timeline.

2. Essential Eight ML2 Gap Analysis and Implementation Planning

We assess your current Essential Eight maturity level and plan implementation to reach Maturity Level 2 across all corporate IT systems. This includes detailed gap analysis for all eight strategies, prioritised remediation roadmap, technical implementation plan, evidence collection framework, and timeline to Essential Eight ML2 compliance. Without Essential Eight ML2, your DISP application will not be approved, so ICT/Cyber Security domain readiness is critical path.

3. Security Governance and Documentation Development

We establish or enhance your security governance framework to meet DISP requirements including board or executive security oversight, security risk management processes, comprehensive security policies and procedures, incident management framework, third-party security requirements, and annual security reporting processes. The Defence Security Authority assesses whether your governance is genuine and sustainable, not superficial documentation created solely for compliance.

4. Personnel and Physical Security Implementation

While Essential Eight implementation progresses, we establish personnel and physical security programmes including personnel security vetting procedures, security clearance management, secure area access control, classified information handling procedures, visitor management protocols, and ongoing suitability monitoring. These domains require coordination with HR, facilities, and management, and implementation timelines vary based on your starting point.

5. Evidence Collection and Validation

We compile comprehensive evidence demonstrating compliance across all four security domains including Essential Eight ML2 technical validation, security governance documentation, personnel security records, physical security assessments, incident management logs, and third-party security agreements. The Defence Security Authority requires documented proof of compliance, not claims. We ensure evidence is complete, accurate, and audit-ready before application submission.

6. DISP Membership Application and DSA Liaison

We prepare and submit your formal DISP membership application, coordinate with Defence Security Authority processing officers, respond to queries or requests for additional information, facilitate any required site assessments, and track application progress through the 90-day processing timeline. Once membership is granted, we establish ongoing compliance monitoring to maintain your DISP membership and prepare annual security reports.

Who This Is For: DISP Membership Application Consulting

This service is designed for Australian businesses that work or intend to work with the Australian Defence Force, defence primes, or on defence-related projects requiring DISP membership.

You are a good fit if:

  • You are bidding on Australian Defence contracts that explicitly require DISP membership as a prerequisite
  • You are working as a subcontractor to a defence prime contractor and customer requires DISP compliance
  • You are an existing defence contractor with expiring DISP membership that must be renewed to maintain current work
  • You handle or will handle classified defence information at PROTECTED, SECRET, or TOP SECRET levels
  • You are a technology company, engineering firm, or professional services provider seeking to enter the defence market
  • You attempted to prepare a DISP application internally but realised the complexity exceeds your security expertise
  • You need to achieve DISP membership within a specific timeline to satisfy contract obligations or tender deadlines
  • You need assistance implementing Essential Eight Maturity Level 2 to meet the 2026 DISP ICT/Cyber Security requirements

Why Choose Siege Cyber for DISP Consulting Services Australia

20+ years of information security and compliance expertise. Our Technical Director, Peter Stewart, has spent over two decades in cybersecurity roles including security assessments, penetration testing, and compliance consulting. We understand both the technical implementation and governance aspects of DISP requirements, allowing us to guide you through all four security domains effectively.

Deep expertise in Essential Eight Maturity Level 2 implementation. DISP's 2026 ICT/Cyber Security requirements mandate Essential Eight ML2, which is significantly more demanding than the previous "Top 4" approach. We have extensive experience implementing Essential Eight across Australian organisations and understand the ASD maturity model requirements, evidence expectations, and sustainable implementation approaches. We know how to achieve and maintain Essential Eight ML2 efficiently.

Understanding of Australian defence security requirements. Beyond technical controls, DISP requires understanding of the Defence Security Principles Framework (DSPF), Australian Government Protective Security Policy Framework (PSPF), and Defence Security Authority expectations. We understand what the DSA looks for during assessments, what documentation satisfies requirements, and what constitutes genuine governance versus superficial compliance. You get guidance grounded in defence industry security standards.

Practical approach to the four security domains. Technology companies typically have reasonable ICT security but weak governance and physical security programmes. We help you address all four DISP domains systematically, leveraging existing controls where possible and implementing new controls where required. We prioritise based on your timeline, classification level requirements, and available resources.

Proven track record with Australian defence contractors. We have guided defence primes, subcontractors, and aspiring defence industry participants through DISP membership application and compliance. You benefit from our experience with Defence Security Authority processes, common application issues, and what actually satisfies DSA assessment requirements versus what looks good on paper but fails scrutiny.


Frequently Asked Questions

What changed in DISP requirements for 2026?

In September 2024, DISP introduced significant cyber security updates effective for 2026. Previously, DISP required only four Essential Eight strategies ("Top 4": Application Whitelisting, Patching Applications, Restricting Administrative Privileges, Patching Operating Systems) at Maturity Level 1. From 2026, DISP requires all eight Essential Eight mitigation strategies at Maturity Level 2 across your entire corporate IT environment. This represents a substantial increase in requirements and implementation effort.

How long does DISP membership application take?

The Defence Security Authority processing timeline is approximately 90 days once your application is assigned to a processing officer. However, this assumes your application is complete and your security controls meet requirements when submitted. Most organisations require 6-12 months of preparation before submitting, depending on their starting security posture. Attempting to rush the preparation phase typically results in application rejection or extensive delays as the DSA requests additional information or remediation.

What classification level should we apply for?

DISP membership levels align with Australian Government security classifications: PROTECTED, SECRET, and TOP SECRET. The appropriate level depends on the classification of defence information you will handle. Most defence contractors start with PROTECTED level, which is sufficient for most non-classified or low-classification defence work. Higher classification levels require increasingly stringent security controls, longer processing times, and more extensive personnel security vetting. Start with the minimum classification level your defence work requires.

Do all employees need security clearances for DISP membership?

Not necessarily. Personnel security requirements depend on your DISP membership level and the specific defence work involved. At minimum, key personnel who will handle classified information need appropriate security clearances. Some contracts require all staff with access to defence systems or information to hold clearances, while others only require clearance for specific roles. We help you determine which personnel require vetting based on your DISP classification level and contract requirements.

Can we maintain DISP membership without full-time security staff?

Yes, though it requires established processes and periodic expert support. Many smaller defence contractors use a combination of internal IT staff managing day-to-day security operations, periodic security consultant support for quarterly or annual assessments, and external audit or vCISO services for governance oversight and annual security reporting. The key is establishing sustainable processes that maintain Essential Eight ML2 compliance and evidence collection without requiring full-time dedicated security personnel.

What happens if our DISP membership application is rejected?

The Defence Security Authority typically does not outright reject applications but rather identifies deficiencies requiring remediation before approval. Common issues include insufficient Essential Eight maturity, inadequate security governance documentation, gaps in personnel security vetting, or physical security deficiencies. If your application reveals deficiencies, you remediate the identified gaps and resubmit evidence. This extends the approval timeline but does not permanently disqualify you from DISP membership.

Does DISP membership expire and require renewal?

DISP membership itself does not have a fixed expiration date, but the Defence Security Authority requires annual security reports demonstrating ongoing compliance with membership requirements. Additionally, security clearances for personnel have defined validity periods requiring renewal. If your security posture degrades significantly or you fail to provide required annual reporting, your DISP membership can be suspended or revoked. Ongoing compliance is mandatory, not optional.


Benefits of DISP Compliance

 

 

Ready to Achieve DISP Membership and Secure Defence Contracts?

DISP membership is not optional for Australian defence contractors. It is mandatory for bidding on defence tenders, working on defence projects, or handling classified defence information. The 2026 DISP accreditation requirements are significantly more demanding than previous years, with Essential Eight Maturity Level 2 now required across your entire corporate IT environment. Without experienced DISP consultants guiding the process, businesses routinely face extended timelines, application delays, or outright rejection.

Book a free 30-minute consultation with our team. We will assess your current security posture across all four DISP domains, explain the different DISP levels and what Essential Eight ML2 implementation involves, and provide a realistic timeline to DISP certification and membership approval. You will leave the call understanding exactly what is required and whether you can achieve DISP membership within your contract deadlines.

 

 

An Australian Navy frigate and submarine at sea

DISP Membership Levels: Entry Level, Level 1, Level 2 and Level 3

Most of the confusion we are asked to clear up is about which level a business actually needs. Defence does not expect every supplier to hold the highest level, and applying for more than your contracts require adds cost and time without adding work you can win.

Entry Level suits suppliers who need to demonstrate baseline governance and cyber security but do not handle classified information. It is the most common starting point, and for many businesses it is the only level they will ever need.

Level 1 applies where you handle information up to PROTECTED. It brings formal personnel security obligations, appointed security officers and a higher evidence bar across all four domains.

Level 2 and Level 3 apply at SECRET and TOP SECRET, and bring physical security and personnel clearance requirements that materially change how your business operates. If a contract genuinely requires these, the conversation starts well before the application.

We work through this with you before any paperwork starts, because the level determines everything that follows. There is a longer treatment in our guide to DISP Entry Level versus Level 1 and in DISP levels and requirements explained.

The Four Domains Defence Assesses

DISP is not a cyber security certification, which is the single most common misunderstanding we encounter. It covers four domains, and cyber is one of them:

  • Governance. Your security officers, your policies, your risk management and your reporting obligations to Defence.
  • Personnel security. Clearance sponsorship, onboarding and offboarding, insider threat, and the Annual Security Report.
  • Physical security. How your premises, storage and access control match the level you are applying for.
  • ICT and cyber security. Where ASD Essential Eight Maturity Level 2 sits, aligned to the Information Security Manual.

A business with excellent cyber security and no governance documentation fails. So does a business with perfect policies and an unpatched network. We cover all four, which is why this is a programme rather than an assessment.

What DISP Membership Costs

Defence does not charge an application fee. The cost is the work required to meet the standard, and the cost of keeping it current once you have it.

We price that as a fixed monthly programme: $3,750 per month excluding GST over twelve months, for up to 50 employees, then $1,000 per month for each additional 40 employees. That covers the four domain gap analysis, ISM-aligned controls, a customised DISP policy and procedure suite, CSO and SO advisory support, Defence-aligned incident response planning and Annual Security Report preparation.

What it does not cover is the external audit or Defence's own assessment, which sit outside any provider's control. The full breakdown is on our compliance pricing page, and there is a longer discussion in what DISP certification costs in Australia.

How Long DISP Membership Takes

From a standing start, plan on three to nine months to be application ready, then Defence's own assessment time on top. The variables are how much governance documentation already exists, whether you are close to Essential Eight Maturity Level 2, and how quickly your people can be made available for the personnel security work.

The businesses that take longest are usually the ones that applied first and discovered the gaps afterwards. A gap analysis before you apply is the cheapest part of the whole exercise.

DISP, Essential Eight, ISO 27001 and IRAP

These overlap more than most suppliers expect, and the overlap is worth using. Essential Eight Maturity Level 2 is effectively the ICT and cyber component of DISP, so work done there counts twice. ISO 27001 gives you the governance and risk management structure that the governance domain asks for, which is why suppliers already certified tend to move faster. IRAP is a different thing again, assessing systems rather than organisations, and is usually driven by a specific contract.

If you are weighing these up, we have written about how DISP relates to ISO 27001 and other frameworks and how Essential Eight, ISO 27001 and DISP work together.

Do You Actually Need DISP?

Not every Defence supplier does. DISP is required where a contract says it is required, and the trigger is usually access to Defence information, Defence assets or Defence sites. Plenty of businesses in the supply chain never touch any of those, and for them a DISP application is an expensive answer to a question nobody asked.

It is also increasingly requested by primes further up the chain as a condition of subcontracting, whether or not Defence itself requires it. If a prime has asked you for it, that is a commercial requirement and the answer is usually yes.

We will tell you if we think you do not need it. More detail in is DISP certification mandatory in Australia.

Keeping DISP Once You Have It

Membership is not a certificate you file away. Defence expects an Annual Security Report, ongoing reporting of security incidents and changes to your business, and evidence that your controls are still operating. Suppliers most often come unstuck here rather than at the application.

Our programme continues past the application for exactly that reason, which is also why it is priced monthly rather than as a project.

Get a Fixed-Price Quote for DISP Membership

Tell us which level your contracts require, roughly how many people you employ and where you are starting from. We will come back with a fixed monthly price and a realistic date for being application ready. If a gap analysis is the sensible first step rather than a full programme, we will say so.

Next step: Book 30 minutes with Peter, or send us your details and we will put a number in front of you.