DISP — Defence Industry Security Program

Defence's security membership programme for the defence supply chain. Four levels across four domains, with Essential Eight Maturity Level Two as the cyber floor.

Department of Defence, through the Defence Industry Security Branch within the Defence Security Division. Underpinned by the Defence Security Principles Framework.

What it is

The Defence Industry Security Program is the Australian Government's security membership programme for businesses in the defence supply chain. It is administered by the Defence Industry Security Branch within the Defence Security Division of the Department of Defence, and underpinned by the Defence Security Principles Framework.

DISP sets requirements across four security domains: security governance and risk management, personnel security, physical security, and information and cyber security. A business selects a membership level for each domain rather than one level for the whole organisation.

There are four membership levels, mapping to the Australian Government security classifications:

  • Entry Level — OFFICIAL and OFFICIAL: Sensitive
  • Level 1 — PROTECTED
  • Level 2 — SECRET
  • Level 3 — TOP SECRET

You can hold different levels across domains, but the security governance level must always match or exceed the highest level held in any other domain. Levels above Entry require a business case justifying the level sought.

The cyber requirement is the sharp edge. Following the conclusion of assessments against the older top-four model in November 2025, all DISP members are required to achieve and maintain the full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence — from Entry Level upward. This catches a great many applicants off guard.

Clearance sponsorship is not available at Entry Level.

Who it's for

Businesses in the defence supply chain

If you handle Defence information, work on Defence projects, or want to compete for Defence contracts, DISP membership is either mandatory or strongly expected.

Subcontractors to Defence primes

Primes routinely require DISP membership of their supply chain. This is the most common trigger, and it usually arrives with a deadline attached to a bid.

Organisations needing to sponsor security clearances

Above Entry Level, DISP membership allows a business to sponsor clearances for its personnel, with the level determining the ceiling — broadly Baseline at Level 1, NV1 at Level 2 and NV2 at Level 3. Positive Vetting requires Defence sponsorship rather than DISP.

Who does not need it

Organisations with no Defence work and no realistic pipeline. DISP is a substantial ongoing commitment, not a credential to hold speculatively.

Why implement it

  • It is the entry ticket to Defence work. Where a contract specifies membership, there is no route around it.
  • Primes require it of their supply chain. For subcontractors, membership is frequently the difference between being shortlisted and not being considered.
  • It enables clearance sponsorship above Entry Level, which removes a serious constraint for businesses whose people need access to classified material.
  • The cyber uplift has independent value. Essential Eight Maturity Level Two across the corporate environment is a genuine security improvement, not just an application requirement.
  • It signals seriousness. Membership tells a prime that your security governance has been externally examined rather than self-asserted.

How implementation works

The cyber requirement is the pacing item for most applicants, so start there.

1. Determine the level for each domain

Driven by the highest classification of information or assets you will handle, and whether you need to sponsor clearances. Levels above Entry require a business case justifying the level sought. Getting this right is the largest single cost lever.

2. Assess against the four domains

Security governance and risk management, personnel security, physical security, information and cyber security.

3. Close the cyber gap

Full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence. This is where most applications stall and it is a substantial technical programme in its own right.

4. Appoint and document

Appoint a Chief Security Officer and a Security Officer, develop the Security Management Plan and Security Incident Response Plan, implement access controls, and stand up security awareness training.

5. Entry Level Assessment

A documentation review and interview process conducted by the Defence Industry Security Branch.

6. Maintain

Including the Annual Security Report and sustained Essential Eight maturity. Membership is ongoing rather than a one-off grant.

How Soveriq helps

Soveriq runs the level determination first, because scoping the level correctly saves more money than anything else in a DISP engagement. We then assess against all four domains, deliver the Essential Eight uplift that most applications founder on, and author the Security Management Plan and supporting documentation.

A note on our current position. Soveriq is not itself a DISP member. That means we deliver readiness, documentation and the underlying security work, and we cannot sponsor clearances. Stating that plainly is better than you finding out mid-engagement.

On internal review. Where Soveriq has built your security framework, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not grant DISP membership, does not speak for Defence, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis. Level determination per domain, plus an evidence-based assessment against the requirements — including current Essential Eight maturity, which is usually the binding constraint.
  • Module 02 — Build. Security Management Plan, incident response plan, awareness training, access controls and the Essential Eight remediation.
  • Module 03 — Internal review ahead of assessment, subject to the impartiality position above.
  • Module 04 — Representation through the Entry Level Assessment process.
  • Module 05 — Continuous compliance, including the Annual Security Report and sustaining Essential Eight maturity.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

A note on our current position. Soveriq is not itself a DISP member. We deliver DISP readiness and the underlying security work; we cannot sponsor clearances and do not claim to.

Common questions

Which level do we need?

It is four answers, not one — a level per domain — and the right ones are usually lower than businesses assume. The driver is the highest classification of information you will actually handle, plus whether you need to sponsor clearances. Over-scoping the level is the most common and most expensive mistake in a DISP application.

What is the biggest obstacle?

Cyber, consistently. All applicants including Entry Level must achieve full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence. This catches many organisations off guard, and it is a genuine technical programme rather than a documentation exercise.

Can DISP membership sponsor security clearances?

Above Entry Level, yes, with the level determining the ceiling — broadly Level 1 for Baseline, Level 2 for NV1 and Level 3 for NV2. Entry Level cannot sponsor clearances. Positive Vetting requires Defence sponsorship rather than DISP.

Is DISP mandatory to work with Defence?

Not universally. It is required where you handle classified information or assets, or where a contract specifies it. It is strongly expected by primes and is often a practical prerequisite for subcontracting on classified work.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope