Defence's security membership programme for the defence supply chain. Four levels across four domains, with Essential Eight Maturity Level Two as the cyber floor.
The Defence Industry Security Program is the Australian Government's security membership programme for businesses in the defence supply chain. It is administered by the Defence Industry Security Branch within the Defence Security Division of the Department of Defence, and underpinned by the Defence Security Principles Framework.
DISP sets requirements across four security domains: security governance and risk management, personnel security, physical security, and information and cyber security. A business selects a membership level for each domain rather than one level for the whole organisation.
There are four membership levels, mapping to the Australian Government security classifications:
You can hold different levels across domains, but the security governance level must always match or exceed the highest level held in any other domain. Levels above Entry require a business case justifying the level sought.
The cyber requirement is the sharp edge. Following the conclusion of assessments against the older top-four model in November 2025, all DISP members are required to achieve and maintain the full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence — from Entry Level upward. This catches a great many applicants off guard.
Clearance sponsorship is not available at Entry Level.
If you handle Defence information, work on Defence projects, or want to compete for Defence contracts, DISP membership is either mandatory or strongly expected.
Primes routinely require DISP membership of their supply chain. This is the most common trigger, and it usually arrives with a deadline attached to a bid.
Above Entry Level, DISP membership allows a business to sponsor clearances for its personnel, with the level determining the ceiling — broadly Baseline at Level 1, NV1 at Level 2 and NV2 at Level 3. Positive Vetting requires Defence sponsorship rather than DISP.
Organisations with no Defence work and no realistic pipeline. DISP is a substantial ongoing commitment, not a credential to hold speculatively.
The cyber requirement is the pacing item for most applicants, so start there.
Driven by the highest classification of information or assets you will handle, and whether you need to sponsor clearances. Levels above Entry require a business case justifying the level sought. Getting this right is the largest single cost lever.
Security governance and risk management, personnel security, physical security, information and cyber security.
Full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence. This is where most applications stall and it is a substantial technical programme in its own right.
Appoint a Chief Security Officer and a Security Officer, develop the Security Management Plan and Security Incident Response Plan, implement access controls, and stand up security awareness training.
A documentation review and interview process conducted by the Defence Industry Security Branch.
Including the Annual Security Report and sustained Essential Eight maturity. Membership is ongoing rather than a one-off grant.
Soveriq runs the level determination first, because scoping the level correctly saves more money than anything else in a DISP engagement. We then assess against all four domains, deliver the Essential Eight uplift that most applications founder on, and author the Security Management Plan and supporting documentation.
A note on our current position. Soveriq is not itself a DISP member. That means we deliver readiness, documentation and the underlying security work, and we cannot sponsor clearances. Stating that plainly is better than you finding out mid-engagement.
On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not grant DISP membership, does not speak for Defence, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
A note on our current position. Soveriq is not itself a DISP member. We deliver DISP readiness and the underlying security work; we cannot sponsor clearances and do not claim to.
It is four answers, not one — a level per domain — and the right ones are usually lower than businesses assume. The driver is the highest classification of information you will actually handle, plus whether you need to sponsor clearances. Over-scoping the level is the most common and most expensive mistake in a DISP application.
Cyber, consistently. All applicants including Entry Level must achieve full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence. This catches many organisations off guard, and it is a genuine technical programme rather than a documentation exercise.
Above Entry Level, yes, with the level determining the ceiling — broadly Level 1 for Baseline, Level 2 for NV1 and Level 3 for NV2. Entry Level cannot sponsor clearances. Positive Vetting requires Defence sponsorship rather than DISP.
Not universally. It is required where you handle classified information or assets, or where a contract specifies it. It is strongly expected by primes and is often a practical prerequisite for subcontracting on classified work.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope