System Status: Operational/// DISP DEFENCE TECH NETWORK ///DISP COMPLIANCE PLATFORM
[THE COMPLETE GUIDE]

DISP MEMBERSHIP AUSTRALIA

Everything an Australian defence contractor needs to know about the Defence Industry Security Program — what it is, who needs it, what it costs, and how to get it.

4
Membership levels & security domains
3–12 mo
Typical timeline, depending on level and clearance processing
$30k–$100k
Indicative initial cost for SMEs — Defence charges no application fee
[DEFINITION]

WHAT IS DISP MEMBERSHIP?

The Defence Industry Security Program (DISP) is the Australian Government's security accreditation for organisations that work with the Department of Defence. Membership demonstrates that your organisation meets the security requirements of the Defence Security Principles Framework (DSPF) — and it is the prerequisite for accessing classified Defence information, systems and facilities.

DISP is not a one-off certificate. It is an ongoing membership with continuous obligations: an Annual Security Report, incident reporting, material-change notifications and security controls that must be maintained — not just achieved. Applications are managed through the DISP Member Portal, where all mandatory documentation must be uploaded before submission, and every application must be submitted within 60 business days of starting.

Read: What is DISP?
[ELIGIBILITY]

WHO NEEDS IT?

DISP membership is required where Defence work or a contract mandates it — typically any organisation that accesses, stores or transmits classified Defence information, whether dealing directly with Defence or as a subcontractor to a prime. It is not required for every defence-adjacent business, but primes increasingly expect it from their supply chain as a condition of engagement.

Membership is open to Australian organisations of all sizes, including SMEs and sole traders. Defence scales its expectations to the size and risk profile of the applicant — but the four security domains apply to everyone.

Read: DISP for subcontractors
[STRUCTURE]

THE FOUR LEVELS

Membership is tiered by the classification of information you can access: Entry Level (OFFICIAL), Level 1 (PROTECTED), Level 2 (SECRET) and Level 3 (TOP SECRET). Levels are chosen per security domain and are driven by your contracts, not preference — most SMEs enter at Entry Level or Level 1.

Read: Membership levels explained
[DOMAINS]

THE FOUR SECURITY DOMAINS

  • Security governance

    Accountability, plans and reporting — CSO/SO roles, policies, incident response.

  • Personnel security

    Suitability of key staff — AGSVA clearances and employment screening.

  • Physical security

    Zones, access control and certified secure areas scaled to your level.

  • ICT & cyber security

    Essential Eight ML2 — mandatory at every level since 30 September 2024.

[PROCESS]

THE APPLICATION AT A GLANCE

Assess your gaps against the DSPF, remediate (Security Management Plan, Essential Eight ML2 evidence, physical and personnel security), then apply via the DISP Member Portal. Under the current portal rules, all mandatory documentation must be uploaded before submission, and the application must be submitted within 60 business days of starting — so preparation comes first. Defence then assesses through the Entry Level Assessment: a documentation review, a phone interview and the Cyber Security Questionnaire.

Read: Step-by-step application guide
[COST]

WHAT IT COSTS

Defence charges no application fee. The real cost is achieving compliance: for most SMEs an indicative $30,000–$100,000 depending on starting maturity — including an independent Essential Eight assessment (indicatively $15,000–$40,000 of that, commissioned voluntarily from providers such as IRAP assessors), documentation, remediation and physical or ICT uplift.

Read: Full cost breakdown
[ONGOING]

ONGOING OBLIGATIONS

Membership must be maintained. Every member submits an Annual Security Report (ASR) — declared by the Chief Security Officer every 12 months, within 10 business days of the membership anniversary, via the DISP Member Portal — alongside incident reporting, material-change notifications and clearance renewals.

Read: The ASR guide
[DIRECTORY]

EVERY DISP GUIDE

The full library — each guide goes deep on one topic.

What is DISP Membership?

The Defence Industry Security Program explained in plain English

Read the guide
DISP Membership Levels

Entry, Level 1, Level 2 and Level 3 — what each tier requires

Read the guide
DISP Membership Cost

Full cost breakdown — assessments, remediation, ongoing fees

Read the guide
DISP Requirements Checklist

All 60 controls across the four security domains

Read the guide
How to Apply for DISP

Step-by-step application guide via the DISP Member Portal

Read the guide
DISP Application Rejected

Why applications fail and how to build a remediation plan

Read the guide
Annual Security Report (ASR)

What the ASR covers, deadlines, and how to automate it

Read the guide
Security Management Plan

What Defence requires in your SMP and how to write it

Read the guide
Essential Eight ML2 for DISP

The mandatory cyber baseline at every membership level

Read the guide
E8 to Essentials Transition

The Essential Eight retirement and what carries forward

Read the guide
DISP vs ISO 27001

Side-by-side comparison — when you need both

Read the guide
CMMC vs Essential Eight

Dual-framework compliance for AUKUS supply chains

Read the guide
DISP Consultant

What they do, what they cost, and when you need one

Read the guide
Consulting vs Software

Traditional consulting vs compliance platforms compared

Read the guide
DISP Accreditation

What accreditation means and how to maintain it

Read the guide
AUKUS Compliance

DISP, CMMC 2.0 and ITAR obligations for AUKUS work

Read the guide
DISP FAQ

Common questions about DISP membership answered

Read the guide
[NEXT_STEP]

READY TO START?

A structured readiness assessment tells you exactly where you stand against the four domains — before the 60-business-day portal clock starts.

Start Readiness Assessment