Guide to DISP Requirements

Your Ultimate Guide to DISP Requirements

Compliance is an ever-pressing concern for businesses of all shapes and sizes. But it’s especially important for market research companies, who handle enormous amounts of data on a daily basis. Even a minor breach could leave you at the mercy of numerous heavy fines, as well as long-term reputational harm.

This risk is only compounded further if you work with – or plan to work with – the Australian Department of Defence. Here, the regulations are stricter and the penalties harsher. But DISP requirements can be tricky to understand. Unlike many other cyber security frameworks, they are not commonly discussed. The limited knowledge available about DISP makes compliance feel impossible, holding many companies back from even trying.

So what are the DISP membership requirements? And how can you comply effectively?

Explore leading cyber security services in Australia

What is the DISP Framework?

The Defence Industry Security Program (DISP) is a membership-based framework designed and managed by the Department of Defence. It is built for organisations working as part of the Defence supply chain, to ensure a high level of security is maintained while handling sensitive physical and digital assets. DISP compliance is essential (and often mandatory) for any Australian business planning to work alongside this field. 

DISP is part of the Defence Security Principles Framework (DSPF), which provides overall governance on risk management within the Defence sector. Specifically, it is referenced within that document under Principle 16. This strong foundation ensures that high standards are consistently maintained by all parts of the sector.

Understanding the Four DISP Domains

The DISP framework covers four separate domains, each of which relate to a different area of security:

Governance

This domain ensures your business has appropriate policies, procedures, and organisational structures in place to effectively mitigate risk. It includes planning, incident management, internal audits, and improvement strategies. Governance also covers leadership roles that oversee security, such as your Chief Security Officer (CSO) if present.

Personnel Security

Personnel security focuses on making sure that employees, contractors, partners, and other insiders are trustworthy. This means thoroughly vetting them out, which includes verifying their identity, conducting background checks, and managing security clearances where required. It also involves checking that your team understands their responsibilities, through security awareness training and behaviour management practices.

Physical Security

This security domain addresses the protection of physical environments where Defence-related work is performed or sensitive data is stored. It covers access controls, surveillance, facility hardening, and secure storage tactics. The goal of the physical security domain is to reduce the risk associated with unauthorised access, theft, or tampering.

Information and Cyber Security

The purpose of this domain is to protect digital systems and information from cyber threats. It requires compliance with the Australian government’s Essential Eight mitigation strategies, strong data classification practices, secure communications, and thorough incident response planning.

DISP Membership Levels

DISP uses a tiered membership system, aligned to the sensitivity of defence-related information. The higher your level, the more protection is required and the more sensitive data you will have access to.

The level you must reach depends on the nature of your association with the Defence sector, and the type of information you are likely to handle.

Why Compliance With DISP Membership Requirements Matters

There are a few reasons that compliance with DISP requirements is critical for any business aiming to work with the Defence supply chain:

Contractual Obligations

First and most obvious, DISP compliance is mandatory in order to work with certain parts of the Defence sector. This is especially important for market research, where data handling is a major business activity. Without DISP membership, you are not authorised to access sensitive information, deeply harming your chances of being able to work with this sector.

Trust & Credibility

Beyond simply obeying your obligations, DISP compliance signals that you are a trustworthy and secure organisation. This will benefit far more than your work with the Defence sector – a high standard of security is equally appreciated by consumers and other business partners. Modern society values data protection above almost everything else, and a demonstrated dedication to this will significantly improve your reputation.

Regulatory Compliance

The beauty of cyber security frameworks is that by following one, you are automatically improving your compliance with all relevant laws and regulations. Aiming for the Defence sector means you achieve the highest level of security possible, which will bring you into alignment with many global data protection laws and reduce your risk of experiencing a fine.

Essential Eight Compliance Explained

One major DISP membership requirement is that you must comply with at least Level 2 of the Essential Eight. Understanding this framework is thus crucial to ensure DISP compliance.

What is the Essential Eight?

Put simply, the Essential 8 is a list of strategies developed by the Australian Cyber Security Centre (ACSC) to help businesses prevent cyber-attacks. It is designed at its core to provide a well-rounded security posture with very little resources required, making it accessible to all organisations regardless of size and industry. It is not typically mandatory, but DISP members are an exception to this.

The eight mitigation strategies are:

  1. Application Control: Introduce a whitelist system to prevent unauthorised applications from running on company systems.
  2. Patching Applications: Update applications regularly to address known vulnerabilities.
  3. Patching Operating Systems: Manage OS updates the same way you would applications.
  4. Restricting Administrative Privileges: Restrict admin privileges to only those who need them.
  5. Configuration of Microsoft Office Macro Settings: Disable macros that originate from the internet, and set strict policies on how others may be used.
  6. User Application Hardening: Disable unnecessary features within approved applications to reduce possible attack vectors.
  7. Multi-Factor Authentication (MFA): Implement MFA to protect sensitive accounts.
  8. Regular Backups: Back data up daily, to prevent loss. 

The “Maturity Level” refers to the scale by which Essential Eight compliance is judged. In short, there are four levels, from 0 – 3, indicating how prepared your business is to prevent cyber threats. DISP requires Level 2, which represents that you are prepared to handle targeted, relatively sophisticated attacks.

DISP Membership: Eligibility and Application

Benefits of Membership

DISP membership provides your business with:

Note that DISP membership will not necessarily guarantee you a Defence contract. However, it can be extremely helpful in obtaining one.

Basic Eligibility Criteria

To obtain DISP membership, you must:

The following factors are also considered:

How to Apply

Follow these steps to submit an application:

  1. Choose a Level: Understand which level you wish to apply for. Consider the nature of any contracts you aim to sign, and the type of data you will need access to. For example, you may only need to comply with DISP entry level requirements, rather than level 3.
  2. Study the DSPF Framework: Familiarise yourself with the DSPF framework, particularly Principle 16 Control 16.
  3. Hire Necessary Staff: Identify a CSO and SO, whether this is through internal promotion or external hire.
  4. Use the DISP Membership Requirements Checklist: Go through the DISP membership requirements checklist (found on the website) and ensure you’re compliant.
  5. Create an Email: Create a special DISP@username email.
  6. Document: Collect all necessary documentation demonstrating your alignment with DISP membership requirements.
  7. Submit: Fill out and submit your application using the DISP member portal.

Strong Security Practices to Align Your Market Research Company With DISP

Before even submitting your application, there is plenty you can do to increase your chances of success. The presence of robust security standards will help make your case, improving the likelihood of your business being awarded membership. Follow these best practices to strengthen your cyber defence and better align with DISP membership requirements:

Formalise Data Handling Policies

The implementation of formal data handling policies tackles two important areas of DISP at once: governance and cyber security. This is also mandatory to comply with many data protection regulations. Establish clear, documented policies for:

Implement Role-Based Access Controls

If you plan to take on Defence contracts, you must get used to strict access controls. Use the principle of least privilege to guide your efforts. The golden rule here is that no employee should ever have access to information beyond their role. An intern hired two months ago, for example, likely does not need the same data as your CSO.

Pair this strategy with multi-factor authentication (MFA) for a stronger defence. MFA requires at least two forms of verification before granting access to sensitive accounts, providing an additional layer of protection should login credentials be stolen or leaked.

Vet and Train Staff

DISP’s personnel security domain stresses the importance of staff vetting and clearance. Conduct thorough background checks before hiring a new employee, and regularly review all staff to ensure they meet your security standards. The assignment of specific clearance levels may not be necessary for entry level membership, but you should always know how trustworthy a given staff member is and what they currently have access to.

You must also provide regular cyber security awareness training. As a rule of thumb, you should hold at least one or two comprehensive training sessions per year, and support these with multiple smaller “Refresher” courses at regular intervals. Include information on:

In addition to training sessions, it may also be useful to run regular drills, tabletop exercises, and fake scams. This allows you to test your employees’ knowledge and address any gaps early.

Apply the Essential Eight Security Controls

Aim for Maturity Level 3 in the Essential Eight. This will help guarantee that you at least reach Level 2, which is mandatory for DISP membership. Implement all eight mitigation controls to the best of your ability, and compare your progress against the Maturity Model. You should also study the purpose behind each control. Understanding why they exist can provide you with a blueprint to further strengthen your security.

Secure Physical and Virtual Workspaces

DISP compliance is as much about physical spaces as it is cyber security. Take steps to secure physical offices and, if applicable, remote work environments.

Establish Incident Response Protocols

The reality is, you won’t always be able to prevent an attack from occurring. It is also essential to prepare for the occasional, inevitable breach. Create an incident response plan that outlines:

Include a post-mortem analysis, to help you identify what went wrong and how it can be prevented in future. Once your plan has been created, run all key staff members through each step. Place the plan somewhere it can be easily accessed, even when systems are offline. 

Most importantly, run regular drills. These will help you identify any problems with the plan in a safe environment, allowing you to address them before they can compromise your recovery.

Discover advanced backup and recovery solutions

Speak to an Expert

You may lack the necessary in-house funds, expertise, or resources to address all DISP membership requirements on your own. In this case, a managed service provider (MSP) can cover the shortfall. This strategy can be particularly useful if you find an MSP who specialises in compliance. They can help you address any gaps in your current security posture, bringing your business into closer alignment with DISP.

FAQs

Is there a cost to join DISP?

DISP membership has no direct fee. However, the necessary improvements to your security posture will incur expenses of their own.

Can small businesses achieve DISP membership?

Businesses of almost any size can achieve DISP membership, as long as they are eligible and meet the requirements for their desired level. 

Why must I implement all Essential Eight controls?

The Essential Eight is openly recommended by the Australian government as one of the best security frameworks available, and thus it is often required as a bare minimum standard for partnerships. If you need assistance, partner with an MSP who specialises in Essential Eight compliance.

How long does accreditation typically take?

As of 2025, thousands of businesses are applying for DISP membership at any given time. Because of this, the Defence Force recommends that you should wait around 90 days for your application to be processed.

Achieve Faster, Easier DISP Membership

Whether you’re struggling to meet DISP level 1 requirements, or applying for level 3, the right strategy can get you there. It may feel like a high bar, and for very good reason: the Defence sector is one of the most high-risk out there. But it doesn’t need to be overwhelming. If you start small, prioritise the right things, and build a strong foundation, you can fulfill the requirements and gain your membership with ease. In the process you will not only open up the possibility of Defence contracts – you will also strengthen your reputation with existing clients.

Need help strengthening your security posture for DISP membership? Platform 24 assesses your existing defences, figures out what’s missing, and works with you to fill the gaps. We protect you from every angle, while you focus on chasing your goals. If you’d like to hear more, get in touch with a security expert today.

1300 602 480