DISP
REQUIREMENTS
CHECKLIST
The complete control register for DISP membership across all four security domains. Use this checklist to assess your readiness before submitting to Defence.
How to Use This Checklist
This checklist maps the control requirements for DISP membership across all four security domains and the application submission process. Each control is tagged with the minimum membership level at which it applies. Use this register to conduct a structured self-assessment of your current security posture before engaging with Defence.
This checklist reflects the DISP requirements as at April 2026, including the Essential Eight Maturity Level 2 (ML2) requirement in force since 30 September 2024. Until then, the DISP cyber requirement was based on the Essential Eight 'Top 4' strategies — entities that have not reviewed the ICT security domain since the uplift should do so carefully, as the ML2 requirements represent a significant step up for most organisations.
A gap against any control tagged for your target membership level is a potential rejection point. Prioritise gaps by severity: missing governance documentation and ICT security gaps are the most common rejection reasons. Physical security gaps at Level 2 and above require the longest lead time to remediate.
Recent DISP Requirement Updates
DISP requirements are not static. The updates below have materially changed what Defence expects from applicants and current members — each is reflected in the control register on this page.
Essential Eight ML2 Uplift
Since 30 September 2024, DISP requires the full Essential Eight at Maturity Level 2 across all eight controls for systems used to correspond with Defence — at every membership level, including Entry. Until then, the cyber requirement was based on the Essential Eight 'Top 4' strategies. Members must demonstrate the full uplift — including multi-factor authentication, restricted administrative privileges, operating system patching, and regular backups.
Enhanced Annual Security Report Requirements
The Annual Security Report (ASR) now requires explicit attestation of Essential Eight ML2 compliance across all in-scope ICT systems, confirmation of CSO and SO clearance currency, reporting of all DSPF-reportable incidents from the preceding 12 months, and attestation that the Security Management Plan reflects current operations. Late or incomplete submissions trigger compliance notices and potential membership suspension.
AUKUS Pillar II Supply Chain Obligations
Entities seeking AUKUS Pillar II work face requirements beyond standard DISP membership, including alignment with CMMC 2.0 Level 2 for US-origin controlled technical information, ITAR compliance for US-origin defence articles, and enhanced supply chain security obligations under the AUKUS Industrial Base Framework.
Governance & Security Management
| ID | Control Requirement | Level | Status |
|---|---|---|---|
| G1 | Security Officer (SO) appointed — Australian citizen, no conflicting roles | ALL | |
| G2 | Chief Security Officer (CSO) appointed — accountable for the entity's security arrangements | ALL | |
| G3 | Security Management Plan (SMP) developed and approved by senior management | ALL | |
| G4 | SMP aligned to Defence Security Principles Framework (DSPF) | ALL | |
| G5 | Security risk assessment conducted and treatment register maintained | ALL | |
| G6 | Security awareness training programme established and records maintained | ALL | |
| G7 | Incident reporting procedures documented — Defence notification protocols defined | ALL | |
| G8 | Annual security review and self-assessment schedule established | ALL | |
| G9 | Change management process for SMP updates documented | L1+ | |
| G10 | FOCI (Foreign Ownership, Control, or Influence) declaration prepared | ALL | |
| G11 | FOCI mitigation plan developed (if foreign connections exist) | L2+ |
DISPath provides SMP templates, governance frameworks, and DSPF-aligned documentation workflows for all membership levels.
Personnel Security
| ID | Control Requirement | Level | Status |
|---|---|---|---|
| P1 | Pre-employment screening procedures documented and aligned to AGSVA standards | ALL | |
| P2 | Identity verification process established (100-point check equivalent) | ALL | |
| P3 | Criminal history check procedures documented | ALL | |
| P4 | Employment history verification procedures established | ALL | |
| P5 | Foreign contact reporting procedure documented and communicated to all personnel | L1+ | |
| P6 | Foreign travel reporting procedure documented and communicated | L1+ | |
| P7 | Insider threat awareness programme established | L1+ | |
| P8 | Security clearance records management system in place | L1+ | |
| P9 | Procedures for handling clearance suspensions and revocations documented | L1+ | |
| P10 | Ongoing suitability assessment procedures for cleared personnel | L2+ | |
| P11 | Annual security awareness training for all personnel with classified access | L1+ | |
| P12 | Training completion records maintained and available for Defence review | ALL |
DISPulse tracks personnel security compliance, training records, foreign contact reporting, and clearance status in real time.
Physical Security
| ID | Control Requirement | Level | Status |
|---|---|---|---|
| PH1 | Facility security assessment conducted and documented | ALL | |
| PH2 | Security zone classification established (public, restricted, controlled) | ALL | |
| PH3 | Access control system implemented for restricted and controlled areas | ALL | |
| PH4 | Visitor management and escort procedures documented | ALL | |
| PH5 | CCTV coverage of controlled areas — specifications documented | L1+ | |
| PH6 | Intruder detection system installed — alarm response procedures documented | L1+ | |
| PH7 | Secure storage for PROTECTED material — GSA-approved container or equivalent | L1+ | |
| PH8 | Physical security inspection schedule established | ALL | |
| PH9 | Key and access card management procedures documented | L1+ | |
| PH10 | SCIF or equivalent secure area constructed to Defence standards | L2+ | |
| PH11 | SCIF construction documentation and Defence approval obtained | L2+ | |
| PH12 | Emanations security (TEMPEST) assessment completed | L3 |
DISPath includes physical security assessment templates and facility security planning workflows aligned to DSPF zone classification requirements.
ICT Security — Essential Eight ML2
| ID | Control Requirement | Level | Status |
|---|---|---|---|
| ICT1 | Application control implemented — only approved applications can execute | ALL | |
| ICT2 | Application patching — internet-facing services within 2 weeks (48 hours applies at ML3) | ALL | |
| ICT3 | Microsoft Office macro settings configured — macros blocked or signed only | ALL | |
| ICT4 | User application hardening — web browser, PDF reader, office suite hardened | ALL | |
| ICT5 | Administrative privileges restricted — no internet browsing from admin accounts | ALL | |
| ICT6 | OS patching — internet-facing services within 2 weeks, others within 1 month (48 hours applies at ML3) | ALL | |
| ICT7 | Phishing-resistant MFA on all internet-facing services | ALL | |
| ICT8 | MFA for all privileged users and all users of cloud services | ALL | |
| ICT9 | Regular backups — daily backups, tested restoration, offline/immutable copy | ALL | |
| ICT10 | Essential Eight ML2 assessment completed and documented | ALL | |
| ICT11 | Independent Essential Eight assessment commissioned as evidence (e.g. IRAP assessor) | ALL | |
| ICT12 | Network segmentation implemented — PROTECTED workloads isolated | L1+ | |
| ICT13 | Audit logging enabled and log retention policy documented | L1+ | |
| ICT14 | Incident response plan documented — Defence notification procedures included | ALL | |
| ICT15 | Vulnerability management programme established and documented | L1+ |
DISPeer provides a sovereign, Australian-hosted cloud environment pre-configured to align with DISP ICT security requirements — eliminating the Essential Eight ML2 build burden.
Application Package — Submission Readiness
| ID | Control Requirement | Level | Status |
|---|---|---|---|
| APP1 | DISP membership application form completed via the DISP Member Portal | ALL | |
| APP2 | Security Management Plan — current, approved, version-controlled | ALL | |
| APP3 | Essential Eight ML2 assessment report attached | ALL | |
| APP4 | Physical security assessment documentation attached | ALL | |
| APP5 | Personnel security screening procedures and training records attached | ALL | |
| APP6 | Chief Security Officer and Security Officer details confirmed | ALL | |
| APP7 | FOCI declaration completed — foreign connections disclosed | ALL | |
| APP8 | All evidence current — reflective of present operations and systems | ALL | |
| APP9 | Pre-submission review completed against DISP application checklist | ALL | |
| APP10 | Security Officer briefed and prepared for Defence assessment interview | ALL |
DISPath's pre-submission review workflow validates your complete application package against Defence checklist before you submit — preventing avoidable rejections.
Where Applications Most Often Fail
Defence can return an application that fails on any single domain. These are the failure points we see most often — every one maps back to a control in the register above.
Essential Eight ML2 Gaps
The most common failure point. Organisations that have not completed the full ML2 uplift across all eight controls — particularly multi-factor authentication, restricted administrative privileges, operating system patching, and regular backups — are non-compliant. ML2 compliance must be demonstrated to Defence as part of the Entry Level Assessment.
SO Clearance Lapsed or Ineligible
If the Security Officer's clearance lapses, is suspended, or does not match the target membership level, the application is returned without assessment. Confirm clearance status and currency before submission.
Outdated Security Management Plan
SMPs written for an original application and not updated to reflect the ML2 uplift, new personnel, or changed ICT systems fail Defence review. The SMP must reflect current operations and be version-controlled.
Missing or Stale Assessment Evidence
Evidence that does not reflect your current environment undermines an application. Your Essential Eight assessment and physical security documentation must be current and specific — many applicants commission an independent assessor (e.g. an IRAP assessor) to strengthen their evidence.
Late or Incomplete Annual Security Report
For existing members, failure to submit the ASR on time — or an ASR that does not address all security domains — results in a compliance notice and potential membership suspension.
Further analysis: Why DISP applications are rejected →
From Checklist to Accreditation
Completing this checklist gives you a point-in-time view of your DISP readiness. But a checklist alone does not get you accredited — you need documented evidence for every control, a current Security Management Plan, and a Security Officer who can defend your posture in a Defence assessment interview.
The most effective path from checklist to accreditation is a structured readiness programme that converts your gap register into a prioritised remediation plan with defined milestones, responsible owners, and measurable outcomes. This is what DISPath is built to do.
Assess
Run a structured gap assessment against this checklist. Identify which controls are implemented, partially implemented, or missing. Generate a prioritised remediation register.
Learn More →Remediate
Implement missing controls. DISPeer handles ICT security. DISPulse tracks compliance posture across all four domains. DISPath guides governance and documentation.
Learn More →Certify
Assemble your application package, complete the pre-submission review, and submit through the DISP Member Portal with confidence. DISPath guides you through every step.
Learn More →Get a Professional Gap Assessment
Our team will conduct a structured DISP gap assessment against all 60 controls, identify your critical gaps, and provide a clear remediation roadmap with realistic timelines and costs.
Frequently Asked Questions
What are the DISP membership requirements?
DISP membership requires demonstrated compliance with the Defence Security Principles Framework (DSPF) across four security domains: governance and security management, personnel security, physical security, and ICT security. ICT security is anchored to the full Essential Eight at Maturity Level 2 — required since 30 September 2024 — for systems used to correspond with Defence, at every membership level including Entry. The specific controls scale with the membership level sought, from Entry through Level 3.
What changed in the recent DISP requirement updates?
The most significant recent change is the Essential Eight ML2 uplift: until September 2024 the DISP cyber requirement was based on the Essential Eight 'Top 4' strategies, and from 30 September 2024 the full Essential Eight at Maturity Level 2 is required across systems used to correspond with Defence — at every membership level, including Entry. The Annual Security Report cycle has also introduced enhanced self-assessment and evidence requirements, including explicit attestation of ML2 compliance and CSO/SO clearance currency.
Is an IRAP assessment required for DISP?
No — an IRAP assessment is not formally mandated for DISP. Essential Eight ML2 must be demonstrated to Defence, which assesses your posture through the Entry Level Assessment: a review of security documentation, a phone interview with security staff, and completion of the Cyber Security Questionnaire. Many applicants commission an independent Essential Eight assessment (e.g. from an IRAP assessor) to evidence their posture, though this is not required. Defence also offers a conditional membership pathway via an Essential Eight ML2 Maturity Action Plan where gaps remain.
What is the Annual Security Report (ASR) requirement?
All current DISP members must submit an Annual Security Report every 12 months, within 10 business days of the anniversary of membership being granted. Declared by the CSO, the ASR confirms ongoing compliance with DSPF obligations — including attestation of Essential Eight ML2 compliance for in-scope ICT systems, confirmation of CSO and SO clearance currency, reporting of security incidents from the preceding 12 months, and confirmation that the Security Management Plan remains current. Late or incomplete submissions trigger compliance notices.
What clearances does the Security Officer need?
The Security Officer must be an Australian citizen and hold, or be eligible for, an AGSVA security clearance appropriate to the membership level sought. Applications submitted without a suitably cleared Security Officer are returned without assessment, and any lapse in the SO's clearance renders the organisation immediately non-compliant.
DISP Compliance Australia
Full guide to DISP requirements, security domains, and membership levels.
Read Guide →How to Get DISP Membership
Step-by-step operational guide from gap assessment to DISP accreditation.
Read Guide →DISP Consulting vs Software
Compare traditional consulting with technology-enabled compliance approaches.
Read Guide →Why Applications Fail
Analysis of the most common Defence rejection reasons and how to avoid them.
Read Guide →