System Status: Operational/// DISP DEFENCE TECH NETWORK ///DISP COMPLIANCE PLATFORM
INDUSTRY BRIEFDATA CENTRES & COLOCATION

DISP COMPLIANCE
FOR DATA
CENTRES

Data centres are where Defence data physically lives. Operators hosting PROTECTED workloads — or chasing the sovereign-cloud demand flowing from AUKUS — need their own DISP membership. Your tenants' accreditation does not cover your facility.

L1+

Membership level needed to host Defence information at PROTECTED — the most common Defence workload classification

E8 ML2

Mandatory on the corporate/management network and systems used to correspond with Defence since 30 September 2024

NV1

Clearance for operations staff with floor access where you host PROTECTED and above; Baseline is the floor

AS 4811

AS 4811:2022 employment screening expected for all staff with access to secure zones

THE COMPLIANCE IMPERATIVE

Why Data Centres Need DISP

01

Classified hosting is squarely in scope

Facilities that store or process Defence information at PROTECTED and above sit inside DISP's mandatory scope. If your racks host classified Defence workloads, membership is not optional.

02

Sovereign demand is growing

Defence and AUKUS programs need Australian-sovereign hosting. DISP membership is the entry ticket — screened for before capacity, latency, or price.

03

Your customers' membership does not cover you

DISP obligations flow down. A tenant's membership covers their organisation, not your facility. Operators hosting DISP members' classified workloads need their own.

04

Named facilities get pulled into scope

When a DISP member's contract or security plan names your facility, your physical security becomes part of their compliance evidence — and Defence expects the operator behind it to be a member too.

DSPF DOMAINS FOR OPERATORS

The Four Domains for Data Centres

DOM-01

Security Governance

DISPulse →
Zone governance and site security plan
Access registers for all secure areas
Incident reporting to Defence via the DISP Member Portal
Annual Security Report every 12 months, declared by your CSO
DOM-02

Personnel Security

DISPath →
Baseline minimum for cleared operations staff with floor access
NV1 where you host PROTECTED and above
AS 4811:2022 screening for all floor staff
Ongoing suitability monitoring and clearance register
DOM-03

Physical Security — The Dominant Domain

DISPulse →
Zone classifications and certified secure zones
Layered access control, CCTV, and mantraps
Tamper evidence across secure areas
Rack and cage separation for Defence tenants
DOM-04

ICT & Cyber Security

DISPulse →
E8 ML2 on the corporate/management network — mandatory since 30 September 2024
Systems used to correspond with Defence in scope
Tenant segmentation evidence
Vulnerability management across your management plane

THE SOVEREIGN OPPORTUNITY

DISP-Member Facilities Are the Scarce Asset

AUKUS and Defence cloud demand is converging on one requirement: sovereign hosting in DISP-member facilities. Certified secure zones take time and money to build — making the DISP-member data centre the scarce asset, and membership the moat around it.

Serious Defence fits at three points: DISPeer as sovereign cloud for your tenants, DISPulse running the operator's own compliance program, and DISPath carrying the application.

[FAQS]

Data Centre DISP — Frequently Asked Questions

Does my data centre need its own DISP membership?

Yes, if your facility hosts Defence information or infrastructure at PROTECTED or above, or a Defence contract names your facility. A tenant's DISP membership covers their organisation, not your building — obligations flow down to the facility operator, and Defence screens for member facilities before awarding hosting work.

What physical security does DISP require of a data centre?

The dominant DISP domain for data centres. Expect zone classifications and certified secure zones, layered access control, CCTV, mantraps or equivalent entry control, tamper evidence, and rack or cage separation for Defence tenants — documented in your site security plan and evidenced in your Annual Security Report.

Do my ops staff need clearances?

Operations staff with floor access to areas hosting Defence workloads need AGSVA clearances — Baseline minimum, NV1 where you host PROTECTED and above. All floor staff should be screened to AS 4811:2022, and your CSO and SO need clearances matching your membership level.

Does E8 ML2 apply to tenant systems or just ours?

Yours. Since 30 September 2024, Essential Eight Maturity Level 2 applies to the ICT corporate systems used to correspond with Defence — for a data centre, that means your corporate and management network. Tenant environments are the tenant's domain; your management plane is yours.

[RELATED GUIDES]

[SOURCES]

[NEXT STEP]

Make Your Facility
Defence-Ready.

Book a facility assessment. We map your site against all four DISP domains — zones, clearances, E8 ML2, and governance — and give you a scoped path to the membership level your pipeline needs.