DISP
COMPLIANCE
AUSTRALIA
What DISP compliance means, what the four security domains require, and how to achieve and maintain compliance as an Australian defence supplier.
WHAT IS DISP COMPLIANCE?
Governed by the Defence Security Principles Framework (DSPF), Principle 16, Control 16.1.
DISP compliance means an organisation meets all security requirements of the Defence Industry Security Program (DISP) at its membership level — and continues to meet those requirements on an ongoing basis. It is not a one-time certification. It is a continuous compliance status that must be actively maintained through annual reporting, security management, and proactive notification of material changes to Defence.
DISP compliance is structured around four security domains: personnel security, physical security, information and cyber security, and industrial security. Each domain has specific requirements that scale with the membership level — from Entry Level (no classified access) through to Level 3 (access to the most sensitive national security information).
The consequences of non-compliance are severe. Defence can suspend or cancel DISP membership at any time, immediately disqualifying the organisation from holding Defence contracts that require DISP membership. A cancelled membership can result in contract termination, loss of revenue, and reputational damage that is difficult to recover from in the defence supply chain.
Continuous Compliance Obligations
Submit the ASR to Defence each year documenting your security posture, incidents, personnel changes, and compliance across all four domains.
Maintain Essential Eight Maturity Level 2 compliance across all in-scope ICT systems. Defence may verify this through Deep Dive Audits at any time.
Notify Defence within required timeframes of ownership changes, key personnel changes, new facilities, or significant changes to ICT or Defence work scope.
Track and renew AGSVA clearances for the Chief Security Officer (CSO), Security Officer (SO), and all cleared personnel before they expire.
Report security incidents to Defence promptly — as soon as practicable after becoming aware. Failure to report is itself a compliance breach.
THE FOUR DISP SECURITY DOMAINS
Personnel Security
Suitability of the Chief Security Officer (CSO), Security Officer (SO), and all personnel with access to classified information — including insider threat management, security awareness training, and employment screening under AS 4811:2022. The CSO and SO must be able to obtain a clearance commensurate with the membership level; staff clearances match the classification accessed — Baseline for PROTECTED, NV1 for SECRET, NV2 for TOP SECRET.
Physical Security
Protecting facilities, secure areas, and physical access to classified information and assets. Requirements include access control systems, CCTV, secure storage for classified documents and media, and physical security inspections. At Level 2 and above, a Secure Working Area (SWA) configured to DSPF standards is required.
ICT & Cyber Security
Implementing Essential Eight Maturity Level 2 across all in-scope ICT corporate systems used to correspond with Defence, meeting ISM control requirements, and complying with incident reporting obligations. Since 30 September 2024, ML2 is the mandatory minimum for all DISP members. ICT systems handling SECRET information require additional controls.
Security Governance
Accountability, plans, processes and people that keep the entity secure — the Chief Security Officer (CSO) and Security Officer (SO) roles, security policies and plans, incident response and reporting, security awareness training, and the Annual Security Report declared by the CSO every 12 months. Governance is always set at the highest level held in any other domain.
WHO NEEDS DISP MEMBERSHIP?
DISP is not limited to traditional defence manufacturers — it applies equally to software developers, cloud providers, legal firms, and engineering consultancies in the Defence supply chain.
Classified Information Access
Any entity that receives, stores, processes, or transmits information classified at PROTECTED, SECRET, or TOP SECRET.
Controlled Facility Access
Entities that require unescorted access to Defence establishments, bases, or controlled areas.
Clearance Sponsorship
Organisations that need to sponsor employees for AGSVA-administered Baseline, NV1, NV2, or PV clearances.
ITAR & EAR-Controlled Technology
Entities handling US International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) controlled items under AUKUS or bilateral agreements.
Prime Contractor Supply Chain
Subcontractors and suppliers to primes (BAE Systems, Thales, Lockheed Martin, Boeing Defence Australia) where the prime's contract mandates DISP membership downstream.
AUKUS Pillar II Capabilities
Entities participating in AUKUS Pillar II technology streams — AI, quantum, hypersonics, electronic warfare, cyber — where Five Eyes information sharing is involved.
DISP MEMBERSHIP LEVELS
Baseline membership for entities with limited Defence engagement. Suitable for businesses accessing unclassified Defence information, attending Defence facilities as escorted visitors, or early in the supply chain onboarding process.
Basic governance documentation, security awareness training, and a nominated Security Officer. No facility clearance or clearance sponsorship rights.
SMEs entering the defence supply chain, professional services firms, early-stage defence technology companies.
Authorises access to PROTECTED information and the ability to sponsor personnel for Baseline security clearances. The most common membership level for established defence industry participants.
Full Security Management Plan, Essential Eight ML2 ICT controls, physical security for PROTECTED material storage, personnel security screening, and incident reporting procedures.
Systems integrators, ICT service providers, engineering firms, and logistics companies with active Defence contracts.
Authorises access to SECRET information and the ability to sponsor personnel for Negative Vetting Level 1 (NV1) clearances. Requires a significantly more mature security posture.
All Level 1 requirements plus: certified secure zone, enhanced personnel security programme, foreign ownership/control/influence (FOCI) assessment, and annual Defence security assessment.
Prime contractors, advanced technology developers, intelligence support companies, and entities with classified programme access.
The highest DISP membership tier. Authorises access to TOP SECRET information and the ability to sponsor personnel for Negative Vetting Level 2 (NV2) and Positive Vetting (PV) clearances.
All Level 2 requirements plus: certified secure zone to Defence standards, comprehensive FOCI mitigation plan, and ongoing compliance demonstrated through the Annual Security Report process.
Entities directly supporting ADF operations, intelligence community contractors, and AUKUS Pillar I submarine programme participants.
THE DEFENCE COMPLIANCE FRAMEWORK STACK
DISP compliance sits inside a wider obligations stack. What applies depends on the classification level accessed, the nature of the work, and the contracting entity.
| Framework | When Required | Administered By | Typical Timeline |
|---|---|---|---|
| DISP Membership | Access to classified info (PROTECTED+), controlled technology, or Defence facilities | Defence (Dept of Defence) | 3–6 months (Level 1) |
| DSPF Compliance | All entities working with Defence — embedded in DISP obligations | Dept of Defence | Ongoing — part of DISP |
| Essential Eight ML2 | Mandatory for all DISP members since 30 Sep 2024 | ASD / ACSC | 3–6 months uplift |
| Independent E8 Assessment | Commonly commissioned as independent E8 ML2 evidence (e.g. IRAP) — not formally mandated | ASD-endorsed assessors | 4–8 weeks |
| ITAR Compliance | Work involving US-origin defence articles or technical data | US State Dept / DECO | Ongoing — licence-based |
| AGSVA Clearances | Personnel requiring access to classified information | AGSVA (Dept of Defence) | AGSVA targets: 20 (Baseline) to 180 (PV) business days |
CYBER COMPLIANCE OBLIGATIONS UNDER DISP
Cyber compliance for defence suppliers is governed by the DSPF, the ISM, and the Essential Eight — demonstrated to Defence through its assessment processes, with independent assessments (e.g. IRAP) commonly used as evidence.
Essential Eight ML2
Mandatory for all DISP members since 30 September 2024. All 8 controls must be consistently implemented across all in-scope systems with no exceptions. Demonstrated to Defence through the Entry Level Assessment; many applicants also commission an independent assessment (e.g. from an IRAP assessor) as evidence.
Full guideISM Controls
Relevant Information Security Manual controls must be implemented for ICT systems processing classified Defence information. The specific controls required depend on the classification level and the nature of the information processed.
Independent E8 Assessment
Many applicants commission an independent assessment of their Essential Eight posture — for example, from an ASD-endorsed IRAP assessor — to evidence ML2 compliance. This is not formally mandated: Defence assesses through the Entry Level Assessment (ELA), and a conditional membership pathway exists via an E8 ML2 Maturity Action Plan.
Full guideSecurity Incident Reporting
Significant security incidents must be reported to Defence promptly — as soon as practicable after becoming aware. Failure to report is itself a compliance breach. Incidents include ransomware, unauthorised access to classified systems, and data breaches.
Annual Security Report
The ICT security section of the Annual Security Report (ASR) must document the current E8 compliance status, any incidents during the year, and any material changes to in-scope ICT systems.
Continuous Monitoring
Defence may conduct Deep Dive Audits at any time to verify ICT security compliance. Organisations must maintain evidence of ongoing E8 ML2 compliance — not just at the time of assessment.
CONSEQUENCES OF DISP NON-COMPLIANCE
Compliance Notice
Defence issues a formal compliance notice requiring the organisation to remediate identified gaps within a specified timeframe. Failure to remediate leads to suspension.
Membership Suspension
Defence suspends DISP membership, preventing the organisation from performing classified Defence work. Contracts may be suspended pending remediation.
Membership Cancellation
Defence cancels DISP membership. The organisation is immediately disqualified from holding Defence contracts requiring DISP. Re-application is required and is not guaranteed.
MANAGING DISP COMPLIANCE: MANUAL VS AUTOMATED
Most Australian defence contractors manage DISP compliance the same way they did a decade ago — spreadsheets, annual consultant engagements, and a frantic scramble before each Annual Security Report deadline. The result is a compliance posture that exists only on paper, is invisible between audits, and costs $40,000–$120,000 per year (indicative market range) in consultant fees for work that should take hours, not months.
The Essential Eight Maturity Level 2 mandate made this approach untenable. ML2 requires continuous evidence of control effectiveness — not a point-in-time snapshot. Spreadsheets cannot collect continuous evidence, and consultants cannot monitor your environment 24/7. A purpose-built DISP GRC platform can.
What DISPulse Automates
Generate a Defence-ready ASR in minutes, not weeks. Live compliance data is mapped directly to Defence reporting requirements.
Continuous monitoring of your E8 ML2 posture with automated evidence collection, gap identification, and remediation task assignment.
A live view of your compliance status across all four security domains — know your posture before your assessor does.
A live, DSPF-aligned risk register with structured incident workflows that ensure Defence incident reporting obligations are met promptly.
| Capability | Traditional Approach | DISPulse |
|---|---|---|
| Annual Security Report (ASR) generation | Manual — 40–80 hrs/year | 1-click — under 30 minutes |
| Essential Eight ML2 evidence collection | Spreadsheets, screenshots, email chains | Automated continuous collection |
| Compliance posture visibility | Point-in-time audit snapshots | Real-time live dashboard |
| Policy documentation | Generic templates, manual customisation | DISP-native auto-generated policies |
| Risk register | Separate spreadsheet, manually updated | Integrated, DSPF-aligned, live |
| Incident management | Email-based, no audit trail | Structured workflow, full audit trail |
| Cost (annual) | $40,000–$120,000 consultant fees (indicative market range) | Flat SaaS subscription |
DISP COMPLIANCE — FREQUENTLY ASKED QUESTIONS
9 key questions about DISP compliance in Australia.
What does DISP compliance mean?
DISP compliance means an organisation meets all security requirements of the Defence Industry Security Program (DISP) at its membership level. This covers four security domains: personnel security, physical security, information and cyber security, and industrial security. Compliance is not a one-time achievement — it is a continuous obligation that must be actively maintained through annual reporting, ongoing security management, and proactive notification of material changes to Defence.
What are the four DISP security domains?
The four DISP security domains are: (1) Security governance — accountability, plans, processes and people that keep the entity secure, including the CSO and SO roles, incident response and reporting, and security awareness training; (2) Personnel security — ensuring staff and contractors are suitable to access government information, including AGSVA clearances and AS 4811:2022 employment screening; (3) Physical security — protecting facilities, secure areas and physical access to classified information and assets; and (4) ICT and cyber security — meeting or exceeding the Essential Eight at Maturity Level 2 across ICT corporate systems used to correspond with Defence.
What happens if you fail DISP compliance?
Failure to maintain DISP compliance can result in Defence issuing a compliance notice, suspending membership, or cancelling membership entirely. Cancellation immediately disqualifies the organisation from holding Defence contracts that require DISP membership, resulting in potential contract termination and loss of revenue. Defence may also conduct unannounced Deep Dive Audits to verify compliance at any time.
How often do you need to report to Defence?
DISP members must submit an Annual Security Report (ASR) to Defence every year. The ASR documents the organisation's security posture across all four domains, any security incidents that occurred during the year, changes to key personnel or facilities, and the organisation's compliance with all DISP obligations. In addition, members must notify Defence of material changes (ownership, key personnel, facilities, ICT) within required timeframes throughout the year.
What is a DISP Deep Dive Audit?
A DISP Deep Dive Audit is an unannounced or scheduled assessment conducted by Defence to verify that a DISP member is actually compliant with its stated security posture. Audits can cover any or all of the four security domains. Defence typically triggers a Deep Dive Audit following a security incident, an ASR that raises concerns, or as part of a random compliance verification program. Organisations that fail a Deep Dive Audit may receive a compliance notice or have their membership suspended.
Is DISP membership mandatory for defence contractors?
DISP membership is mandatory for any organisation that requires access to classified Defence information (PROTECTED and above), controlled technology, or Defence facilities. It is not mandatory for all defence supply chain work — organisations performing unclassified work may not require DISP membership. However, most significant Defence contracts require DISP membership, and prime contractors increasingly require subcontractors to hold DISP membership as a condition of engagement.
What is the DSPF and how does it relate to DISP?
The Defence Security Principles Framework (DSPF) is the overarching security policy framework for the Australian Department of Defence. It sets out the security principles and controls that apply to all entities working with Defence. DISP is the mechanism through which industry entities demonstrate compliance with the DSPF — specifically Principle 16 (Industry Security). Achieving DISP membership means the organisation has been assessed as meeting the relevant DSPF requirements for its membership level.
What are the DISP membership levels?
DISP membership is tiered across four levels, each corresponding to the classification level of information the entity is authorised to access: Entry (OFFICIAL), Level 1 (PROTECTED), Level 2 (SECRET), and Level 3 (TOP SECRET). Higher levels require proportionally more rigorous security controls and greater organisational investment — including certified secure zones and FOCI mitigation at Level 2 and above.
What is the difference between IRAP and DISP?
IRAP (Information Security Registered Assessors Program) is an assessment methodology — the process by which an ASD-endorsed assessor independently verifies that ICT systems meet the required security standards. DISP (Defence Industry Security Program) is the membership program — the overall framework that Australian defence suppliers must join to access classified Defence information. For DISP, Essential Eight ML2 must be demonstrated to Defence through the Entry Level Assessment; many applicants commission an independent assessment (for example, from an IRAP assessor) to evidence their posture, though this is not mandated. Think of IRAP as one way to evidence the test, and DISP as the qualification.
ACHIEVE DISP
COMPLIANCE
WITHOUT THE RISK.
Book a free DISP Compliance Assessment. We'll map your current posture against all four security domains and give you a clear remediation roadmap.
