System Status: Operational/// DISP DEFENCE TECH NETWORK ///DISP COMPLIANCE PLATFORM
[CONTROL REGISTER // UNCLASSIFIED]

DISP
REQUIREMENTS
CHECKLIST

The complete control register for DISP membership across all four security domains. Use this checklist to assess your readiness before submitting to Defence.

60 Controls4 Domains + Application PackUpdated Apr 2026Includes Sep 2024 ML2 Uplift
Level Key
ALLRequired at all membership levels including Entry
L1+Required from Level 1 (PROTECTED) and above
L2+Required from Level 2 (SECRET) and above
L3Level 3 (TOP SECRET) only
BOOK GAP ASSESSMENT →
[HOW TO USE THIS CHECKLIST]

How to Use This Checklist

This checklist maps the control requirements for DISP membership across all four security domains and the application submission process. Each control is tagged with the minimum membership level at which it applies. Use this register to conduct a structured self-assessment of your current security posture before engaging with Defence.

This checklist reflects the DISP requirements as at April 2026, including the Essential Eight Maturity Level 2 (ML2) requirement in force since 30 September 2024. Until then, the DISP cyber requirement was based on the Essential Eight 'Top 4' strategies — entities that have not reviewed the ICT security domain since the uplift should do so carefully, as the ML2 requirements represent a significant step up for most organisations.

A gap against any control tagged for your target membership level is a potential rejection point. Prioritise gaps by severity: missing governance documentation and ICT security gaps are the most common rejection reasons. Physical security gaps at Level 2 and above require the longest lead time to remediate.

[RECENT UPDATES]

Recent DISP Requirement Updates

DISP requirements are not static. The updates below have materially changed what Defence expects from applicants and current members — each is reflected in the control register on this page.

SEP 2024

Essential Eight ML2 Uplift

Since 30 September 2024, DISP requires the full Essential Eight at Maturity Level 2 across all eight controls for systems used to correspond with Defence — at every membership level, including Entry. Until then, the cyber requirement was based on the Essential Eight 'Top 4' strategies. Members must demonstrate the full uplift — including multi-factor authentication, restricted administrative privileges, operating system patching, and regular backups.

CURRENT CYCLE

Enhanced Annual Security Report Requirements

The Annual Security Report (ASR) now requires explicit attestation of Essential Eight ML2 compliance across all in-scope ICT systems, confirmation of CSO and SO clearance currency, reporting of all DSPF-reportable incidents from the preceding 12 months, and attestation that the Security Management Plan reflects current operations. Late or incomplete submissions trigger compliance notices and potential membership suspension.

ONGOING

AUKUS Pillar II Supply Chain Obligations

Entities seeking AUKUS Pillar II work face requirements beyond standard DISP membership, including alignment with CMMC 2.0 Level 2 for US-origin controlled technical information, ITAR compliance for US-origin defence articles, and enhanced supply chain security obligations under the AUKUS Industrial Base Framework.

DOMAIN 01

Governance & Security Management

11 controls
IDControl RequirementLevelStatus
G1Security Officer (SO) appointed — Australian citizen, no conflicting rolesALL
G2Chief Security Officer (CSO) appointed — accountable for the entity's security arrangementsALL
G3Security Management Plan (SMP) developed and approved by senior managementALL
G4SMP aligned to Defence Security Principles Framework (DSPF)ALL
G5Security risk assessment conducted and treatment register maintainedALL
G6Security awareness training programme established and records maintainedALL
G7Incident reporting procedures documented — Defence notification protocols definedALL
G8Annual security review and self-assessment schedule establishedALL
G9Change management process for SMP updates documentedL1+
G10FOCI (Foreign Ownership, Control, or Influence) declaration preparedALL
G11FOCI mitigation plan developed (if foreign connections exist)L2+
AUTOMATE THIS DOMAIN WITH DISPath

DISPath provides SMP templates, governance frameworks, and DSPF-aligned documentation workflows for all membership levels.

Explore DISPath →
DOMAIN 02

Personnel Security

12 controls
IDControl RequirementLevelStatus
P1Pre-employment screening procedures documented and aligned to AGSVA standardsALL
P2Identity verification process established (100-point check equivalent)ALL
P3Criminal history check procedures documentedALL
P4Employment history verification procedures establishedALL
P5Foreign contact reporting procedure documented and communicated to all personnelL1+
P6Foreign travel reporting procedure documented and communicatedL1+
P7Insider threat awareness programme establishedL1+
P8Security clearance records management system in placeL1+
P9Procedures for handling clearance suspensions and revocations documentedL1+
P10Ongoing suitability assessment procedures for cleared personnelL2+
P11Annual security awareness training for all personnel with classified accessL1+
P12Training completion records maintained and available for Defence reviewALL
AUTOMATE THIS DOMAIN WITH DISPulse

DISPulse tracks personnel security compliance, training records, foreign contact reporting, and clearance status in real time.

Explore DISPulse →
DOMAIN 03

Physical Security

12 controls
IDControl RequirementLevelStatus
PH1Facility security assessment conducted and documentedALL
PH2Security zone classification established (public, restricted, controlled)ALL
PH3Access control system implemented for restricted and controlled areasALL
PH4Visitor management and escort procedures documentedALL
PH5CCTV coverage of controlled areas — specifications documentedL1+
PH6Intruder detection system installed — alarm response procedures documentedL1+
PH7Secure storage for PROTECTED material — GSA-approved container or equivalentL1+
PH8Physical security inspection schedule establishedALL
PH9Key and access card management procedures documentedL1+
PH10SCIF or equivalent secure area constructed to Defence standardsL2+
PH11SCIF construction documentation and Defence approval obtainedL2+
PH12Emanations security (TEMPEST) assessment completedL3
AUTOMATE THIS DOMAIN WITH DISPath

DISPath includes physical security assessment templates and facility security planning workflows aligned to DSPF zone classification requirements.

Explore DISPath →
DOMAIN 04

ICT Security — Essential Eight ML2

15 controls
IDControl RequirementLevelStatus
ICT1Application control implemented — only approved applications can executeALL
ICT2Application patching — internet-facing services within 2 weeks (48 hours applies at ML3)ALL
ICT3Microsoft Office macro settings configured — macros blocked or signed onlyALL
ICT4User application hardening — web browser, PDF reader, office suite hardenedALL
ICT5Administrative privileges restricted — no internet browsing from admin accountsALL
ICT6OS patching — internet-facing services within 2 weeks, others within 1 month (48 hours applies at ML3)ALL
ICT7Phishing-resistant MFA on all internet-facing servicesALL
ICT8MFA for all privileged users and all users of cloud servicesALL
ICT9Regular backups — daily backups, tested restoration, offline/immutable copyALL
ICT10Essential Eight ML2 assessment completed and documentedALL
ICT11Independent Essential Eight assessment commissioned as evidence (e.g. IRAP assessor)ALL
ICT12Network segmentation implemented — PROTECTED workloads isolatedL1+
ICT13Audit logging enabled and log retention policy documentedL1+
ICT14Incident response plan documented — Defence notification procedures includedALL
ICT15Vulnerability management programme established and documentedL1+
AUTOMATE THIS DOMAIN WITH DISPeer

DISPeer provides a sovereign, Australian-hosted cloud environment pre-configured to align with DISP ICT security requirements — eliminating the Essential Eight ML2 build burden.

Explore DISPeer →
DOMAIN 05

Application Package — Submission Readiness

10 controls
IDControl RequirementLevelStatus
APP1DISP membership application form completed via the DISP Member PortalALL
APP2Security Management Plan — current, approved, version-controlledALL
APP3Essential Eight ML2 assessment report attachedALL
APP4Physical security assessment documentation attachedALL
APP5Personnel security screening procedures and training records attachedALL
APP6Chief Security Officer and Security Officer details confirmedALL
APP7FOCI declaration completed — foreign connections disclosedALL
APP8All evidence current — reflective of present operations and systemsALL
APP9Pre-submission review completed against DISP application checklistALL
APP10Security Officer briefed and prepared for Defence assessment interviewALL
AUTOMATE THIS DOMAIN WITH DISPath

DISPath's pre-submission review workflow validates your complete application package against Defence checklist before you submit — preventing avoidable rejections.

Explore DISPath →
[REJECTION RISK]

Where Applications Most Often Fail

Defence can return an application that fails on any single domain. These are the failure points we see most often — every one maps back to a control in the register above.

01

Essential Eight ML2 Gaps

The most common failure point. Organisations that have not completed the full ML2 uplift across all eight controls — particularly multi-factor authentication, restricted administrative privileges, operating system patching, and regular backups — are non-compliant. ML2 compliance must be demonstrated to Defence as part of the Entry Level Assessment.

02

SO Clearance Lapsed or Ineligible

If the Security Officer's clearance lapses, is suspended, or does not match the target membership level, the application is returned without assessment. Confirm clearance status and currency before submission.

03

Outdated Security Management Plan

SMPs written for an original application and not updated to reflect the ML2 uplift, new personnel, or changed ICT systems fail Defence review. The SMP must reflect current operations and be version-controlled.

04

Missing or Stale Assessment Evidence

Evidence that does not reflect your current environment undermines an application. Your Essential Eight assessment and physical security documentation must be current and specific — many applicants commission an independent assessor (e.g. an IRAP assessor) to strengthen their evidence.

05

Late or Incomplete Annual Security Report

For existing members, failure to submit the ASR on time — or an ASR that does not address all security domains — results in a compliance notice and potential membership suspension.

Further analysis: Why DISP applications are rejected →

[NEXT STEPS]

From Checklist to Accreditation

Completing this checklist gives you a point-in-time view of your DISP readiness. But a checklist alone does not get you accredited — you need documented evidence for every control, a current Security Management Plan, and a Security Officer who can defend your posture in a Defence assessment interview.

The most effective path from checklist to accreditation is a structured readiness programme that converts your gap register into a prioritised remediation plan with defined milestones, responsible owners, and measurable outcomes. This is what DISPath is built to do.

01

Assess

DISPath

Run a structured gap assessment against this checklist. Identify which controls are implemented, partially implemented, or missing. Generate a prioritised remediation register.

Learn More →
02

Remediate

DISPeer + DISPulse

Implement missing controls. DISPeer handles ICT security. DISPulse tracks compliance posture across all four domains. DISPath guides governance and documentation.

Learn More →
03

Certify

DISPath

Assemble your application package, complete the pre-submission review, and submit through the DISP Member Portal with confidence. DISPath guides you through every step.

Learn More →

Get a Professional Gap Assessment

Our team will conduct a structured DISP gap assessment against all 60 controls, identify your critical gaps, and provide a clear remediation roadmap with realistic timelines and costs.

[FAQ]

Frequently Asked Questions

What are the DISP membership requirements?

DISP membership requires demonstrated compliance with the Defence Security Principles Framework (DSPF) across four security domains: governance and security management, personnel security, physical security, and ICT security. ICT security is anchored to the full Essential Eight at Maturity Level 2 — required since 30 September 2024 — for systems used to correspond with Defence, at every membership level including Entry. The specific controls scale with the membership level sought, from Entry through Level 3.

What changed in the recent DISP requirement updates?

The most significant recent change is the Essential Eight ML2 uplift: until September 2024 the DISP cyber requirement was based on the Essential Eight 'Top 4' strategies, and from 30 September 2024 the full Essential Eight at Maturity Level 2 is required across systems used to correspond with Defence — at every membership level, including Entry. The Annual Security Report cycle has also introduced enhanced self-assessment and evidence requirements, including explicit attestation of ML2 compliance and CSO/SO clearance currency.

Is an IRAP assessment required for DISP?

No — an IRAP assessment is not formally mandated for DISP. Essential Eight ML2 must be demonstrated to Defence, which assesses your posture through the Entry Level Assessment: a review of security documentation, a phone interview with security staff, and completion of the Cyber Security Questionnaire. Many applicants commission an independent Essential Eight assessment (e.g. from an IRAP assessor) to evidence their posture, though this is not required. Defence also offers a conditional membership pathway via an Essential Eight ML2 Maturity Action Plan where gaps remain.

What is the Annual Security Report (ASR) requirement?

All current DISP members must submit an Annual Security Report every 12 months, within 10 business days of the anniversary of membership being granted. Declared by the CSO, the ASR confirms ongoing compliance with DSPF obligations — including attestation of Essential Eight ML2 compliance for in-scope ICT systems, confirmation of CSO and SO clearance currency, reporting of security incidents from the preceding 12 months, and confirmation that the Security Management Plan remains current. Late or incomplete submissions trigger compliance notices.

What clearances does the Security Officer need?

The Security Officer must be an Australian citizen and hold, or be eligible for, an AGSVA security clearance appropriate to the membership level sought. Applications submitted without a suitably cleared Security Officer are returned without assessment, and any lapse in the SO's clearance renders the organisation immediately non-compliant.

[RELATED RESOURCES]