DISP MEMBERSHIP AUSTRALIA
Everything an Australian defence contractor needs to know about the Defence Industry Security Program — what it is, who needs it, what it costs, and how to get it.
WHAT IS DISP MEMBERSHIP?
The Defence Industry Security Program (DISP) is the Australian Government's security accreditation for organisations that work with the Department of Defence. Membership demonstrates that your organisation meets the security requirements of the Defence Security Principles Framework (DSPF) — and it is the prerequisite for accessing classified Defence information, systems and facilities.
DISP is not a one-off certificate. It is an ongoing membership with continuous obligations: an Annual Security Report, incident reporting, material-change notifications and security controls that must be maintained — not just achieved. Applications are managed through the DISP Member Portal, where all mandatory documentation must be uploaded before submission, and every application must be submitted within 60 business days of starting.
Read: What is DISP?WHO NEEDS IT?
DISP membership is required where Defence work or a contract mandates it — typically any organisation that accesses, stores or transmits classified Defence information, whether dealing directly with Defence or as a subcontractor to a prime. It is not required for every defence-adjacent business, but primes increasingly expect it from their supply chain as a condition of engagement.
Membership is open to Australian organisations of all sizes, including SMEs and sole traders. Defence scales its expectations to the size and risk profile of the applicant — but the four security domains apply to everyone.
Read: DISP for subcontractorsTHE FOUR LEVELS
Membership is tiered by the classification of information you can access: Entry Level (OFFICIAL), Level 1 (PROTECTED), Level 2 (SECRET) and Level 3 (TOP SECRET). Levels are chosen per security domain and are driven by your contracts, not preference — most SMEs enter at Entry Level or Level 1.
Read: Membership levels explainedTHE FOUR SECURITY DOMAINS
- Security governance
Accountability, plans and reporting — CSO/SO roles, policies, incident response.
- Personnel security
Suitability of key staff — AGSVA clearances and employment screening.
- Physical security
Zones, access control and certified secure areas scaled to your level.
- ICT & cyber security
Essential Eight ML2 — mandatory at every level since 30 September 2024.
THE APPLICATION AT A GLANCE
Assess your gaps against the DSPF, remediate (Security Management Plan, Essential Eight ML2 evidence, physical and personnel security), then apply via the DISP Member Portal. Under the current portal rules, all mandatory documentation must be uploaded before submission, and the application must be submitted within 60 business days of starting — so preparation comes first. Defence then assesses through the Entry Level Assessment: a documentation review, a phone interview and the Cyber Security Questionnaire.
Read: Step-by-step application guideWHAT IT COSTS
Defence charges no application fee. The real cost is achieving compliance: for most SMEs an indicative $30,000–$100,000 depending on starting maturity — including an independent Essential Eight assessment (indicatively $15,000–$40,000 of that, commissioned voluntarily from providers such as IRAP assessors), documentation, remediation and physical or ICT uplift.
Read: Full cost breakdownONGOING OBLIGATIONS
Membership must be maintained. Every member submits an Annual Security Report (ASR) — declared by the Chief Security Officer every 12 months, within 10 business days of the membership anniversary, via the DISP Member Portal — alongside incident reporting, material-change notifications and clearance renewals.
Read: The ASR guideEVERY DISP GUIDE
The full library — each guide goes deep on one topic.
The Defence Industry Security Program explained in plain English
Read the guideEntry, Level 1, Level 2 and Level 3 — what each tier requires
Read the guideFull cost breakdown — assessments, remediation, ongoing fees
Read the guideAll 60 controls across the four security domains
Read the guideStep-by-step application guide via the DISP Member Portal
Read the guideWhy applications fail and how to build a remediation plan
Read the guideWhat the ASR covers, deadlines, and how to automate it
Read the guideWhat Defence requires in your SMP and how to write it
Read the guideThe mandatory cyber baseline at every membership level
Read the guideThe Essential Eight retirement and what carries forward
Read the guideSide-by-side comparison — when you need both
Read the guideDual-framework compliance for AUKUS supply chains
Read the guideWhat they do, what they cost, and when you need one
Read the guideTraditional consulting vs compliance platforms compared
Read the guideWhat accreditation means and how to maintain it
Read the guideDISP, CMMC 2.0 and ITAR obligations for AUKUS work
Read the guideCommon questions about DISP membership answered
Read the guideREADY TO START?
A structured readiness assessment tells you exactly where you stand against the four domains — before the 60-business-day portal clock starts.
Start Readiness Assessment