DISP

DISP membership levels explained: Entry, Level 1, Level 2 and Level 3

The Defence Industry Security Program (DISP) has four membership levels — Entry, Level 1, Level 2 and Level 3 — aligned to Australian Government security classifications.

Bottom line

The Defence Industry Security Program (DISP) has four membership levels — Entry, Level 1, Level 2 and Level 3 — aligned to Australian Government security classifications. Levels are set separately for each of the four security domains, and levels above Entry must be justified by a genuine business need. Most suppliers need less than they assume — and choosing the wrong level costs in both directions.

If your organisation is entering or planning to enter the Defence supply chain, one of the first critical decisions you will face is — which level of Defence Industry Security Program (DISP) membership to apply for? It is also one of the most misunderstood concepts.

DISP membership is not a single badge or certification, unlike many others in the industry. It is a profile, built level by level across four security domains. These domains tell Defence what your organisation is accredited to handle and how. Getting the profile right at the beginning of the engagement shortens the application efforts, avoids any unnecessary cost and prevents discovering mid-journey that your membership does not cover the scope of work you are supposed to deliver.

The four levels map to security classifications

Each DISP membership level aligns directly with the Australian Government security classification system, and determines the level of information and assets an entity is accredited to handle:

DISP membership levels Four levels, aligned to Australian Government security classifications
Entry Level handles up to OFFICIAL /
OFFICIAL: Sensitive
Level 1 handles up to PROTECTED
Level 2 handles up to SECRET
Level 3 handles up to TOP SECRET
SecureSupply | Defence Industry Security Program Source: defence.gov.au — DISP eligibility and suitability

The levels are not to be confused with a maturity ladder to be climbed step by step. They are instead an indicator of proportionate security controls of the organisation; proportionate to the sensitivity of the information it will access or possess. A supplier delivering unclassified goods under an OFFICIAL: Sensitive arrangement may not have a need for Level 2 security controls, and Defence may not grant them without strong justification for that level.

DISP Levels are set per security domain, not for the whole business

This is the aspect most first-time applicants commonly misunderstand. DISP membership is assessed across the four security domains of:

Levels are set per security domain Example profile — a legitimate mixed membership
Security governance
L3 L2 L1 ENTRY
Personnel security
L3 L2 L1 ENTRY
Physical security
L3 L2 L1 ENTRY
ICT & cyber security
L3 L2 L1 ENTRY

Rule: the security governance level always equals the highest level held in any other domain

SecureSupply | Defence Industry Security Program Source: defence.gov.au — DISP eligibility and suitability
  • Security governance — accountability, policies, plans, security training, and incident response and reporting
  • Personnel security — ensuring employees and contractors are suitable to access government information and assets, including workforce screening to AS 4811:2022 and, where required, security clearances
  • Physical security — protection of people, property and assets, scaled to the classification of information received, handled, stored or destroyed at your facilities
  • ICT and cyber security — protection of systems and networks, anchored to the ASD Essential Eight at Maturity Level 2 across corporate systems used to correspond with Defence

An entity nominates a level for each domain, and the levels can differ. As an example, a common legitimate profile can be Level 1 or Level 2 for personnel security — so staff can work on classified programs at Defence or prime contractor sites — which can be combined with Entry Level for physical and ICT security, because no classified information is going to be held on the entity’s own premises or systems.

However, one rule always applies: the Security Governance level must match the highest level of information held in any of the other three domains.

What each level involves in practice

Entry Level is the starting point for most suppliers. It requires the foundations: an appointed Chief Security Officer and Security Officer, security policies, controls and plans, workforce screening processes, annual reporting capability, security incident reporting, and Essential Eight Maturity Level 2 across the corporate systems used to deal with Defence. Entry Level is not trivial — the cyber requirement alone is a genuine uplift for many SMEs — but it imposes no classified-environment controls.

Level 1 (PROTECTED) introduces classified-environment obligations: security-cleared personnel for relevant roles, physical zoning appropriate to PROTECTED holdings, and tighter handling and storage arrangements.

Level 2 (SECRET) is a significant step up. Expect higher clearances (typically NV1) for personnel accessing SECRET material, certified secure zones where SECRET information is held on site, and more rigorous ICT arrangements for systems processing classified material.

Level 3 (TOP SECRET) is the highest tier, held by a small number of organisations embedded in the most sensitive programs, with commensurate facility, personnel and system requirements.

Levels above Entry must be justified

Entities will generally self-nominate their membership levels, but Defence assesses their suitability against the level applied for, and Level 1, 2 and 3 applications require appropriate and additional justification — such as work on classified programs or projects. Holding a Defence contract is not, on its own, justification for a higher level.

Business need is typically demonstrated through the contract itself, a Notice of Engagement, or a letter of endorsement from a Defence Contract Manager or, for subcontractors, from the sponsoring entity.

The practical approach is to apply for the levels the work requires. Over-applying will add higher cost, evidence burden and inflated assessment time; on the other hand, under-applying can exclude you from, or delay your access to tenders that specify a minimum membership level.

However, we do recommend at a minimum that suppliers looking to supply future Defence programs should familiarise themselves with the requirements and to align with the DISP controls should the need arise. That will assist suppliers to quickly process and apply for DISP memberships and fulfil the requirements.

When DISP membership is mandatory

DISP membership is mandatory for entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or hold membership as a condition of a Defence contract. There may be exceptions applied, where classified work is performed only within Defence facilities or on Defence networks. Subcontractors engaged in classified (or access to same level of sensitive information) work are subject to the same criteria — sitting one tier down the supply chain does not automatically remove the obligation.

An entity holds only one DISP membership, irrespective of how many Defence contracts it may hold. The detailed requirements for each domain and level sit in the Defence Security Principles Framework, Principle 16, Control 16.1, Annex A.

Choosing well the first time

The right question is not “what is the highest level we could achieve?” but “what will the work in front of us, and the pipeline behind it, actually require in each domain?” To answer it one must read the tender security requirements very carefully, understanding where classified information will live, and being honest about the uplift each domain demands.

SecureSupply helps Defence suppliers scope the right membership profile, prepare the evidence for each domain, assist in addressing Essential Eight ML2 gaps, and get applications progress with minimal rework. If you are unsure which levels your next contract requires, that is exactly the conversation to have before you apply.

Additional note: The Essential Eight is retiring soon

On 15 June 2026, the Australian Signals Directorate opened national consultation on the evolution of the Essential Eight into a new Essentials series, grounded in the Information Security Manual, with an evolved first chapter titled Essentials for enterprise IT. The ACSC has indicated the Essential Eight will begin to be deprecated in approximately 12 months and be retired in approximately 24 months (Around mid-2028), although no fixed retirement date has been published.

The Essential Eight is changing ASD’s transition to the Essentials series — indicative timeline
JUN 2026 Consultation opened on ‘Essentials for enterprise IT’
~MID 2027 Essential Eight deprecation expected to begin
~MID 2028 Essential Eight retirement expected; Essentials series replaces it

DISP requirement today: unchanged Essential Eight Maturity Level 2 across corporate systems used to correspond with Defence

Dates beyond June 2026 are indicative only — no fixed retirement date has been published by ASD

SecureSupply | Defence Industry Security Program Sources: cyber.gov.au (15 Jun 2026); ACSC as reported by industry press

For DISP members, nothing has changed yet: the DSPF requirement remains Essential Eight Maturity Level 2 across corporate systems used to correspond with Defence, and Defence has not yet published how the DISP ICT and cyber security requirement will transition to the new series. What is reasonably foreseeable is that the way members demonstrate cyber maturity will shift — from a fixed maturity ladder toward threat-informed, principles-based guidance suited to cloud and SaaS environments. ASD has indicated that existing Essential Eight investment will align closely with the new controls, so current ML2 uplift is not wasted effort; it is the foundation the transition will be measured against. DISP members should continue their ML2 uplift, keep their evidence current, and watch for DSPF updates as the Essentials series matures.

Sources

Deprecation and retirement timing is indicative, reported by industry press. ASD has published no fixed retirement date.

Found this useful? Share on LinkedIn
Speak with us

Discuss your DISP, IRAP or security obligations.

We move from first conversation to active engagement in two to three weeks.