System Status: Operational/// DISP DEFENCE TECH NETWORK ///DISP COMPLIANCE PLATFORM
[ESSENTIAL EIGHT ML2 FOR DISP]

ESSENTIAL
EIGHT ML2
FOR DISP

The September 2024 mandate, all 8 controls at ML2, the assessment process, and how to achieve compliance before your DISP application.

8
Controls assessed at ML2
30 Sep 2024
Mandatory for all DISP members
3–6mo
Typical uplift timeline
[THE MANDATE]

WHY ESSENTIAL EIGHT ML2 IS MANDATORY FOR DISP

The 2023 Defence Strategic Review identified the defence supply chain's cyber posture as a critical national security vulnerability.

The Australian Government mandated Essential Eight Maturity Level 2 as the minimum cyber security baseline for all DISP members from 30 September 2024. This followed the 2023 Defence Strategic Review (DSR), which identified the cyber security posture of the defence supply chain as a critical vulnerability requiring urgent remediation.

Until September 2024, the DISP cyber requirement was based on the Essential Eight "Top 4" strategies. The September 2024 uplift closed this gap — all DISP members, at every membership level including Entry, must now demonstrate ML2 compliance as a condition of membership. Defence assesses compliance through the Entry Level Assessment; many applicants also commission an independent assessment (for example, from an IRAP assessor) to evidence their posture, though this is not mandated.

ML2 was chosen as the minimum because it provides meaningful protection against the most common attack vectors targeting the defence supply chain — phishing, credential theft, ransomware, and supply chain compromise — without imposing the full burden of ML3 on smaller defence suppliers.

ML1 vs ML2 vs ML3 — Key Differences

LevelConsistencyDISP Requirement
ML1Controls implemented but inconsistently applied. Exceptions permitted.Not sufficient
ML2Controls consistently applied across all in-scope systems. No exceptions.✓ Minimum for all levels
ML3Controls deeply embedded, automated monitoring, continuous improvement.Not a DISP requirement — ML2 applies at every level
Annual Security Report guide
Pre Sep 2024

DISP cyber requirement based on the Essential Eight 'Top 4' mitigation strategies.

30 Sep 2024

Full Essential Eight ML2 across all eight strategies becomes mandatory for all DISP members, new and existing.

Every ASR

Annual Security Reports must reflect full E8 ML2 compliance across all eight strategies.

[SCOPE]

WHICH SYSTEMS ARE IN SCOPE FOR E8 ML2?

If a system touches defence work in any way, it is almost certainly in scope.

DISP requires Essential Eight ML2 across your ICT corporate systems used to correspond with Defence — a deliberately broad definition covering the full range of systems through which your organisation communicates, collaborates, and shares information with the Department of Defence and its supply chain partners.

In practice, that means your email infrastructure, identity and access management systems, collaboration platforms (such as Microsoft 365 or Google Workspace), all managed endpoints (laptops, desktops, servers), document management systems, and any cloud services used to store or process defence-related information.

The Defence Enclave Option

Organisations that maintain a separate, dedicated ICT environment for defence work — sometimes called a defence enclave — can limit their ML2 scope to that environment. This approach requires careful network segregation and governance controls to ensure the boundary between corporate and defence systems is genuinely enforced and auditable.

[THE 8 CONTROLS]

ALL 8 ESSENTIAL EIGHT CONTROLS AT ML2

Each control must be consistently applied across all in-scope systems with no exceptions. Independent assessors (such as IRAP assessors) verify compliance against the ASD E8 Assessment Guide.

[01]High Gap Risk

Application Control

Prevent execution of unapproved programs on all workstations and servers. Application control must be applied to all user profiles and administrator accounts. No exceptions permitted.

[02]Medium Gap Risk

Patch Applications

Patch internet-facing services within 48 hours of release. All other applications patched within 2 weeks. Unsupported applications must be removed.

[03]Low Gap Risk

Configure Microsoft Office Macro Settings

Macros from the internet are blocked. Only macros from trusted locations or digitally signed by a trusted publisher are permitted. Macro antivirus scanning enabled.

[04]Medium Gap Risk

User Application Hardening

Web browsers configured to block Flash, ads, and Java from the internet. Internet Explorer 11 disabled or removed. PDF viewers configured to block internet access.

[05]High Gap Risk

Restrict Administrative Privileges

Admin privileges validated every 12 months. Privileged accounts cannot browse the internet or read email. Just-in-time administration implemented for privileged access.

[06]Low Gap Risk

Patch Operating Systems

Internet-facing systems patched within 48 hours. All other systems patched within 2 weeks. Unsupported operating systems must be removed.

[07]Medium Gap Risk

Multi-Factor Authentication

MFA required for all remote access, all privileged accounts, and all access to important data repositories. Phishing-resistant MFA for internet-facing services.

[08]Low Gap Risk

Regular Backups

Daily backups of important data, applications, and settings. Backups retained for 3+ months. Restoration tested at least quarterly. Backups disconnected from network.

[CSQ & ASSESSMENTS]

THE CSQ AND THE THREE DISP ASSESSMENTS

The CSQ is not a pass/fail test — gaps produce a Maturity Action Plan, not a rejection.

DISP assesses your Essential Eight posture using the Cyber Security Questionnaire (CSQ). Part B contains around 100 ML2-aligned control questions (reported by industry advisers as 107) covering all eight mitigation strategies. It is completed during the initial application as part of the Entry Level Assessment and revisited annually as part of the Annual Security Report (ASR) cycle.

The CSQ is a structured self-assessment that produces a maturity profile across all eight strategies. Where gaps are identified, DISP issues a Maturity Action Plan (MAP) documenting the remediation steps required and the timeframe for completing them. New applicants who cannot yet demonstrate full ML2 are placed in an uplift program — you do not need ML2 before applying, but you must have a credible, documented plan to get there.

Every ASR Must Reflect Full ML2

Essential Eight ML2 has been mandatory for all DISP members since 30 September 2024, so members who have not yet achieved full ML2 across all eight strategies are already outside the requirement. The ASR is a self-attestation of compliance submitted on the anniversary of your DISP membership via the DISP Member Portal. Reporting a maturity level below ML2 will trigger a remediation requirement and potentially affect your membership status.

[ELA]

Entry Level Assessment

Conducted during the application process. Includes a documentation review, a phone interview with your Chief Security Officer or Security Officer, and completion of the CSQ. Establishes your baseline maturity profile.

[OSA]

Ongoing Suitability Assessment

A periodic desktop audit verifying your security posture remains compliant. Reviews your Annual Security Report, governance documentation, and evidence of continued E8 ML2 compliance.

[DDA]

Deep Dive Audit

A detailed, evidence-based assessment that may include site visits and technical testing. Typically triggered by a significant change in risk profile, a security incident, or a higher-level membership application.

[IRAP ASSESSMENT]

IRAP ASSESSMENT FOR DISP — WHAT TO EXPECT

4–8wk
Typical IRAP assessment duration
[01]

Scope Definition

Define the boundary of systems in scope for the assessment. All systems that process, store, or transmit classified Defence information must be in scope.

[02]

Evidence Collection

Provide the IRAP assessor with evidence of compliance for each E8 control — configuration screenshots, policy documents, audit logs, and test results.

[03]

Assessment & Findings

The assessor tests controls against the ASD E8 Assessment Guide and documents findings. Findings are rated by severity — Critical, High, Medium, Low.

[04]

Remediation & Report

Remediate critical and high findings before DISP submission. An independent assessment report (for example, from an IRAP assessor) can be submitted with your DISP application as evidence of ML2 compliance — Defence does not mandate it, but many applicants commission one. See assessment costs for budget guidance.

[EVIDENCE & ASR]

PREPARING FOR YOUR ANNUAL SECURITY REPORT

Most common gaps: phishing-resistant MFA for privileged accounts, application control on servers, and immutable backup storage.

The Annual Security Report (ASR) is your organisation's annual self-attestation of DISP compliance, submitted via the DISP Member Portal on the anniversary of your membership. All members must be able to demonstrate full E8 ML2 compliance across all eight strategies.

Preparing for your ASR requires more than completing the questionnaire. You need documented evidence of your controls — configuration baselines, patch management records, MFA deployment logs, backup test results, and privileged access reviews. DISP assessors may request this evidence during an Ongoing Suitability Assessment or Deep Dive Audit, and the quality of your documentation directly affects the outcome.

Start Uplift Work Early

The most common gaps identified in DISP assessments — phishing-resistant MFA for privileged accounts, application control on servers, and immutable backup storage — are not quick fixes. They require infrastructure changes, policy updates, and staff training. Starting early gives you time to implement controls properly and gather the evidence needed to support your ASR.

If you need expert guidance, a qualified DISP consultant can accelerate your ML2 uplift and prepare your evidence package.

[FAQs]

ESSENTIAL EIGHT ML2 FOR DISP — FAQs

10 key questions about E8 ML2 requirements for DISP membership.

Why is Essential Eight ML2 required for DISP?

The Australian Government mandated Essential Eight Maturity Level 2 as the minimum cyber security baseline for all DISP members — at every membership level, including Entry — from 30 September 2024, following the 2023 Defence Strategic Review (DSR). The DSR identified that the cyber security posture of the defence supply chain was a critical vulnerability. ML2 was chosen as the minimum because it provides meaningful protection against the most common attack vectors targeting the defence supply chain, including phishing, credential theft, and ransomware.

What are the 8 controls at ML2?

The 8 Essential Eight controls at Maturity Level 2 are: (1) Application Control — prevent execution of unapproved/malicious programs; (2) Patch Applications — patch internet-facing services within 48 hours, others within 2 weeks; (3) Configure Microsoft Office Macro Settings — disable macros from the internet, allow only vetted macros; (4) User Application Hardening — configure browsers, disable Flash/ads/Java; (5) Restrict Administrative Privileges — validate and revalidate admin access every 12 months; (6) Patch Operating Systems — patch internet-facing systems within 48 hours, others within 2 weeks; (7) Multi-Factor Authentication — MFA for remote access, privileged accounts, and important data repositories; (8) Regular Backups — daily backups of important data, retained for 3+ months, tested quarterly.

What is an IRAP assessment for DISP?

An IRAP (Information Security Registered Assessors Program) assessment is an independent assessment of your ICT systems conducted by an ASD-endorsed assessor. For DISP, Essential Eight ML2 must be demonstrated to Defence, which assesses your posture through the Entry Level Assessment (ELA) — a review of security documentation, a phone interview with security staff, and completion of the Cyber Security Questionnaire. Many applicants commission an independent assessment (for example, from an IRAP assessor) to evidence their ML2 posture, though this is not mandated.

What is the difference between ML1, ML2, and ML3?

Maturity Level 1 (ML1) provides basic cyber hygiene — controls are implemented but not consistently applied and may have exceptions. Maturity Level 2 (ML2) requires controls to be consistently applied across all systems in scope, with no exceptions, and with evidence of effectiveness. Maturity Level 3 (ML3) requires controls to be deeply embedded in organisational processes, with automated monitoring, continuous improvement, and resistance to sophisticated targeted attacks. DISP requires ML2 as the minimum at every membership level, including Entry. ML3 is not a DISP requirement — it represents best practice for organisations facing sophisticated, targeted threats.

How long does Essential Eight ML2 uplift take?

For most organisations, achieving Essential Eight ML2 from a typical starting point takes 3–6 months. Organisations with complex ICT environments, legacy systems, or significant gaps (particularly in application control and privileged access management) may require 6–12 months. The most time-consuming controls are typically Application Control (requires comprehensive application inventory and testing) and Restrict Administrative Privileges (requires process changes and potentially significant IAM work). Starting the uplift process early — before the DISP application — is critical to avoiding timeline delays.

What is the deadline for DISP Essential Eight ML2 compliance?

Essential Eight ML2 has been required for DISP membership since 30 September 2024. Until then, the DISP cyber requirement was based on the Essential Eight 'Top 4' strategies. From 30 September 2024, all DISP members — both new applicants and existing members — must demonstrate compliance with the full Essential Eight at Maturity Level 2, and every Annual Security Report must reflect full E8 ML2 compliance across all eight strategies.

Which ICT systems are in scope for DISP Essential Eight ML2?

DISP requires Essential Eight ML2 across your ICT corporate systems used to correspond with Defence. This includes email, identity management, collaboration platforms, endpoints, and any systems that store, process, or transmit defence-related information. Organisations running a segregated defence enclave can limit scope to that environment, provided the boundary is enforced and auditable.

Do I need to achieve ML2 before submitting a DISP application?

No. New applicants are not required to achieve full ML2 before lodging their application. DISP issues a Maturity Action Plan (MAP) and places applicants in an uplift program, providing a structured pathway to achieve ML2 within an agreed timeframe. You need a credible, documented plan to reach ML2 — not ML2 itself — at application time.

Does ISO 27001 satisfy DISP's Essential Eight ML2 requirement?

No. ISO 27001, NIST SP 800-171, and UK Def Stan 05-138 can help demonstrate aspects of your security posture, but none of them replace the Essential Eight ML2 requirement. DISP specifically mandates the ASD Essential Eight framework at Maturity Level 2. An organisation can be ISO 27001 certified and still fail E8 ML2 — particularly in application control, macro settings, and phishing-resistant MFA.

What is the DISP Cyber Security Questionnaire (CSQ)?

The Cyber Security Questionnaire (CSQ) is the structured self-assessment tool used by DISP to evaluate your Essential Eight posture. Part B contains around 100 ML2-aligned control questions covering all eight mitigation strategies (reported by industry advisers as 107 questions). It is completed during the application process as part of the Entry Level Assessment and revisited annually as part of the Annual Security Report (ASR) cycle.

[RELATED GUIDES]
[NEXT STEP]

GET YOUR
E8 ML2 GAP
ANALYSIS FREE.

Book a free Essential Eight ML2 Gap Analysis. We'll assess your current posture against all 8 controls and give you a prioritised remediation roadmap before your DISP application or independent assessment.