All insights

What is DISP, and does your business need it to work with Defence?

5 min readBy Brendon Whiting, Founder · 24 July 2026

DISP, the Defence Industry Security Program, is Defence's way of vetting the businesses in its supply chain. If you want defence work, directly or as a subcontractor, membership is increasingly the ticket to the table. It requires demonstrated security across governance, personnel, physical and cyber domains, and the cyber domain is where most businesses have the furthest to travel.

For South Australian businesses the question is not academic. Defence work runs through this state, from shipbuilding at Osborne to the manufacturers, engineers and logistics operators who supply the primes, and every prime is obliged to care about the security of its suppliers. Demanding standards in a supply chain work as market access: they separate the businesses that can bid from the businesses that cannot. DISP is exactly that kind of barrier, which means it is also exactly that kind of advantage. The barrier reads as cost until you are inside it, at which point it reads as a shortlist your competitors are not on. And because the requirements are published, the advantage is available to any business willing to start the work early.

What membership involves, in outline: DISP assesses a business across four security domains. Governance means someone accountable, with documented security practices rather than good intentions. Personnel security means knowing who you employ, with clearances where required. Physical security covers premises and the handling of protected material. And ICT and cyber security means demonstrating that your systems meet the standard Defence expects, with evidence, not assurances. Requirements vary by membership level, and Defence's current documentation is always the authority; treat any article, including this one, as orientation rather than gospel. The levels scale with the sensitivity of the work: the higher the classification of the information and assets involved, the more each domain must demonstrate.

The cyber domain is where most small and mid-sized suppliers start, for two reasons. It is usually the largest gap between current state and required state, and it is the most buyable: the backbone is the Essential Eight, implemented to a demonstrated maturity level with evidence an assessor can inspect. That work is a known quantity, it is what our managed plans deliver by tier, and unlike the paperwork domains it keeps paying for itself whether or not a tender ever lands. The same evidence also survives due diligence from every other direction, because banks, insurers and large private customers now ask strikingly similar questions.

It is not hypothetical. Energy Logistix runs 24/7 freight operations for mining, energy and defence customers, the kind of business where a security question from a customer is really a continuity question. Getting there meant one hundred per cent Essential Eight Maturity Level 1 across the business, SD-WAN connecting five sites, and 99.99 per cent uptime on AWS, and it culminated in DISP accreditation. The sequence is the lesson: the cyber foundation came first, and the accreditation stood on it. None of that was done for a certificate; the certificate recognised what the business had become.

Does your business need it? If defence work, direct or flowed down from a prime, is in your plans, then practically yes, and the time to start is before the tender rather than during it, because the evidence-gathering is the long part. If defence work is not in your future, you do not need DISP, and nobody should sell it to you; but note that the cyber uplift that anchors it, Essential Eight at a demonstrated maturity level, is worth having for its own sake, and leaves the door open. A sensible middle path exists: build the cyber maturity now, and make the membership decision when the first real tender appears.

Where we fit, stated plainly: we are DISP aligned ourselves, and we build and evidence the ICT and cyber domain, the controls, the maturity, the documentation an assessor wants. The governance and personnel domains are decisions only your business can make, with your own advisers; a provider who claims to deliver your entire DISP application is overreaching. What we can promise is that the cyber pillar arrives assessable.

If defence work is on your horizon, the free Essential Eight Cyber Security Scorecard will show you the size of the cyber gap before anyone writes an application, or call us on 1800 456 567.

Size the cyber gap before the tender

The cyber domain is the long part of a DISP application. The free Essential Eight Cyber Security Scorecard shows you where you stand before anyone writes a word.

Frequently asked questions

Increasingly, both. Primes flow security obligations down their supply chains, and a subcontractor bidding for defence-connected work is routinely asked about DISP membership or equivalent security posture. Read the tender and the flow-down clauses in the contract; if defence work is part of your growth plan, assume the question is coming and start before the tender does.

Long enough that starting during a tender is too late. The application requires evidence across governance, personnel, physical and cyber security domains, and gathering that evidence, appointing security officers, documenting practices, lifting controls, is the real timeline. Businesses with their cyber security already in order move much faster, which is another argument for doing that part first.

It is the right foundation, and whether it is sufficient depends on your membership level and the classification of information you will handle; Defence's current requirements are the authority, and they reference ACSC guidance. The practical advice holds either way: demonstrated, evidenced Essential Eight maturity is the cyber backbone of a DISP application, and higher levels ask for more.

Questions? Let's talk.

Call 1800 456 567 or fill out the form.

  • 30-minute discovery — no jargon, no pressure
  • Plain-English Essential Eight Cyber Security Scorecard
  • A clear plan tailored to your business

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, 25 Grenfell Street, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.