Defence industry security, representing the Defence Industry Security Program.

The Defence Industry Security Program (DISP) is the membership program a business must hold to work on Defence contracts that involve security requirements. It is administered by Defence, underpinned by the Defence Security Principles Framework, and sets requirements across four security domains and four membership levels, mapped to the Australian Government information classifications. Membership covers four domains, governance, personnel, physical and cyber security, and since 15/11/2025 every member must also meet the ASD Essential Eight at Maturity Level 2.

For a business that wants to work with Defence, DISP membership is often the entry ticket. This page explains who is eligible, the four security domains, the four membership levels and what each allows, the Essential Eight requirement that now applies to every member, and how to prepare for and keep membership.

Overview

What is the DISP?

The Defence Industry Security Program is the framework through which Defence assures the security of the businesses it works with. It is administered by the Defence Industry Security Branch within the Department of Defence and is underpinned by the Defence Security Principles Framework, specifically Principle 16. Membership gives Defence confidence that a supplier can protect Defence people, information, and assets, and gives the supplier access to classified work and sponsorship for security clearances.

The program is built on the same protective security thinking as the PSPF, applied to the defence-industry context.

Eligibility

Who is eligible for DISP membership?

To be eligible for DISP membership, a business must be registered as a legal entity in Australia with an Australian Business Number and be financially solvent. It must nominate a Chief Security Officer, a senior person responsible for the security arrangements and for championing security culture, and a Security Officer, who develops and implements the security policies and plans. In smaller businesses the two roles can be held by the same person.4

Applicants also assess their foreign ownership, control or influence (FOCI) and submit a FOCI declaration as part of the application. Defence then assesses suitability against the Defence Security Principles Framework across the four security domains.

The structure

What are the DISP security domains and membership levels?

DISP four membership levels mapped to classifications, and the four security domains.

DISP requirements are set across four security domains: security governance and risk management, personnel security, physical security, and information and cyber security. A business selects a membership level for each domain, from Entry Level, through Level 1, Level 2 and Level 3.

The levels map to the information classifications: Entry Level corresponds to OFFICIAL and OFFICIAL: Sensitive; Level 1 to PROTECTED; Level 2 to SECRET; and Level 3 to TOP SECRET. A business can hold different levels across the domains, but the security governance level must always match or exceed the highest level held in any other domain. Clearance sponsorship is not available at the Entry Level.

In practice

What does each DISP domain require in practice?

  • Security governance. A security policy and plan, clear accountability through the Chief Security Officer and Security Officer, a security risk assessment, insider threat awareness, and reporting of all security incidents to Defence.
  • Personnel security. Workforce screening in line with AS 4811:2022, the Australian standard for workforce screening, security awareness training, and processes for clearance sponsorship at Level 1 and above.
  • Physical security. Facilities protected in proportion to the classification of the work, from sound access control at Entry Level to accredited secure areas at higher levels.
  • Information and cyber security. Protection of the corporate ICT environment used for Defence business, including the Essential Eight at Maturity Level 2.

For many suppliers the governance, personnel and physical domains are where applications stall, because they require written policies, trained people and evidence rather than technology alone. A security risk assessment is usually the starting point for all three.

Cyber requirement

Does DISP membership require the Essential Eight?

Cyber security has become the sharpest DISP requirement. Following the conclusion of assessments against the top four mitigations on 15/11/2025, all DISP members are now required to achieve and maintain the full ASD Essential Eight at Maturity Level 2 across the corporate ICT environment they use to deal with Defence.

This is a significant lift for many suppliers. The Essential Eight is explained in the cyber security pillar, and meeting Maturity Level 2 is now a condition of membership rather than an aspiration.

Membership

How do you apply for and maintain DISP membership?

Preparing for DISP membership means assessing where the business stands against the requirements in each of the four domains, closing the gaps, and assembling the evidence Defence will want to see. The cyber domain, with its Essential Eight Maturity Level 2 requirement, is usually the longest pole.

Membership is not a one-off. Members must maintain their security posture, report changes, and continue to meet the requirements of the levels they hold, including the Essential Eight obligation. Members also complete an annual security report and report security incidents as they occur. Treating DISP as an ongoing program, not a certificate, is what keeps a supplier eligible for the work.

How we help

How Agilient supports DISP membership

Agilient is itself a current DISP member, holding Level 2 in the governance and personnel domains and Entry Level in the physical and the ICT and cyber security domains. The firm therefore understands the program from the inside, as a member, as well as advising others on achieving and maintaining membership.

Where a DISP member must also manage foreign ownership, control or influence arising from foreign investment, Agilient extends the same discipline to FIRB and foreign investment security compliance.

Agilient helps defence-industry businesses achieve and maintain DISP membership across all four domains, and supports the wider defence and defence industry sector. As an Australian-owned security consultancy active in the defence sector, with membership of the Ai Group Defence Council and the Australian Industry and Defence Network, Agilient understands what Defence expects of its suppliers.

 

DISP readiness assessment

Where you stand against the requirements in each domain.

 

Security governance and risk

The governance and risk management program expects.

 

Personnel security

Screening, clearances and ongoing suitability.

 

Physical security

Facility security to the level you are seeking.

 

Information and cyber

Uplift to the Essential Eight at Maturity Level 2.

 

Membership maintenance

Keeping your posture and evidence current.

Agilient works across Sydney, Melbourne, Brisbane, Adelaide, Canberra and regional Australia.

Get DISP-ready, across all four domains

A readiness assessment shows where you stand against the DISP requirements and what it will take to reach the membership level your Defence work needs.

Talk to us about DISP membershipor read about the service

FAQs

Frequently asked questions

What is the DISP?
The Defence Industry Security Program is the membership program that a business must hold to work on Defence contracts with security requirements. It is administered by Defence, underpinned by the Defence Security Principles Framework, and sets out requirements across four security domains.
What are the four DISP security domains?
Security governance and risk management, personnel security, physical security, and information and cyber security. A business selects a membership level for each domain based on the classification of the work it does.
What are the DISP membership levels?
Entry Level (OFFICIAL and OFFICIAL: Sensitive), Level 1 (PROTECTED), Level 2 (SECRET) and Level 3 (TOP SECRET). A business can hold different levels across domains, but the governance level must match or exceed the highest level held in any other domain.
Do DISP members have to meet the Essential Eight?
Yes. Since 15/11/2025, all DISP members are required to achieve and maintain the ASD Essential Eight at Maturity Level 2 across the corporate ICT environment they use to conduct Defence business.
Can you get a security clearance at Entry Level?
No. Clearance sponsorship is not available at Entry Level. A business needs at least Level 1 in the relevant domain to sponsor personnel security clearances.
Who can apply for DISP membership?
A business registered in Australia with an ABN that is financially solvent, has nominated a Chief Security Officer and a Security Officer, and has assessed and declared its foreign ownership, control or influence. Defence then assesses the business against the requirements for the membership levels it seeks.
What does a DISP Chief Security Officer do?
The Chief Security Officer is the senior person accountable for the business’s security arrangements and security culture. Day-to-day management can be delegated to a Security Officer, who develops and implements the security policies and plans.
Defence and aerospace industry, representing DISP membership.

References

  1. Department of Defence, Defence Industry Security Program, defence.gov.au
  2. Department of Defence, DISP cyber and assurance — Essential Eight Maturity Level 2, defence.gov.au
  3. Department of Defence, Defence Security Principles Framework (Principle 16), defence.gov.au
  4. Department of Defence, DISP eligibility and suitability, defence.gov.au
  5. Standards Australia, AS 4811:2022 Workforce screening, standards.org.au