DISP — Defence Industry Security Program
The Australian Department of Defence's security programme for organisations in the defence supply chain. DISP membership requires compliance across four security streams -- governance, personnel, physical, and ICT/cyber -- with the cyber stream requiring Essential Eight alignment at a minimum of Maturity Level 2.
See where NodeZero appliesWhat is DISP?
The Defence Industry Security Program (DISP) is the Australian Department of Defence's framework for managing security risks within the defence supply chain. Managed by the Defence Industry Security Branch (DISB), DISP membership is mandatory for entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases, or hold membership as a condition of a Defence contract. The program assesses organisations across four security streams: governance, personnel, physical, and ICT/cyber security.
The ICT/cyber security stream is where autonomous penetration testing has the strongest alignment. DISP requires organisations to implement the ASD Essential Eight at a minimum of Maturity Level 2 across the corporate ICT systems used to correspond with Defence, at all membership levels; classified networks must additionally be employed in accordance with the ISM and the DSPF. Defence has made clear that DISP membership is not a rubber stamp -- organisations must demonstrate that their controls are actively maintained and effective, not just documented. With the 2024 Defence Industry Development Strategy increasing emphasis on supply chain security, the bar for DISP membership continues to rise.
Where NodeZero fits in your DISP membership
DISP's cyber requirement is the Essential Eight at Maturity Level 2. What's specific to DISP is how Defence assesses you -- a layered assurance model that runs from application through to audit. NodeZero produces evidence that holds up across every stage.
The DISP CSQ tests your Essential Eight ML2 implementation control-by-control (Part B). For per-strategy detail of what NodeZero validates, what it doesn't, and what evidence it produces, see the Essential Eight framework page.
See the Essential Eight mapping →- Step 01At application, before membership is granted
Entry Level Assessment (ELA)
What Defence asks forDefence reviews your security documentation, interviews your security staff, and requires a completed Cyber Security Questionnaire. Identified gaps must close before membership is granted.
With NodeZeroRun a pentest before submission to find the credential, patching, hardening and segmentation gaps your assessor will. Use Quick Verify to re-test fixes immediately, then answer your CSQ with evidence behind every claim.
- Step 02Every year, on your certificate anniversary
Annual Security Report (ASR) and CSQ
What Defence asks forA self-attestation against DSPF security obligations, signed off by your CSO. The CSQ is now a recurring obligation, with the full Essential Eight ML2 reassessed each cycle.
With NodeZeroSchedule pentests on a monthly or quarterly cadence so your ASR is backed by current data, not a once-a-year scramble. AD Password Audit, Endpoint Security Effectiveness and Rapid Response outputs map directly to CSQ Part B.
- Step 03Risk-based desktop audit, no advance notice
Ongoing Suitability Assessment (OSA)
What Defence asks forDISB selects members for OSA from an internal risk model. Compliance is reviewed across all four DISP streams, including a fresh cyber questionnaire and an interview with security staff.
With NodeZeroContinuous testing means your most recent evidence is never more than weeks old when DISB calls -- not last year's penetration test report. Your CSQ answers stay backed by current data, on demand.
- Step 04Detailed on-site assessment against DSPF Control 16.1
Deep Dive Audit (DDA)
What Defence asks forA collaborative audit examining whether your controls actually work, including site visits. DDA recommendations are tracked by the DISP audit team to closure.
With NodeZeroExploit-validated evidence shows which controls held under attack and which didn't. After remediation, Quick Verify re-tests each exploit-validated finding and produces proof it has been closed — evidence you can put in front of the audit team for the technical DDA recommendations.
- Step 05If your assessment falls short of ML2
Essential Eight Cyber Standards Uplift Program
What Defence asks forDefence coordinates a Maturity Action Plan with you to lift your environment to ML2, with the DISP Cyber Team supporting and monitoring progress.
With NodeZeroScope the gap by exploitability rather than theoretical CVSS. Re-test after every fix to demonstrate progress between DISP Cyber Team check-ins -- evidence the Maturity Action Plan is tracking to closure.
DISP membership opens defence supply-chain doors -- but only if you can keep proving your security holds up between assessments.
See every control mapped to NodeZero
The full control-by-control coverage map — every DISPrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
DISP membership is mandatory for Australian organisations that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or hold DISP membership as a condition of a Defence contract. This covers defence primes, subcontractors, technology providers, consultants, and any organisation in the defence supply chain that handles sensitive information.
DISP membership is assessed at four levels based on the highest classification of information the organisation will access. Entry Level covers OFFICIAL and OFFICIAL:Sensitive information, Level 1 covers PROTECTED, Level 2 covers SECRET, and Level 3 covers TOP SECRET. All members must meet the Essential Eight at ML2 across the corporate ICT systems used to correspond with Defence, while classified networks must be employed in accordance with the ISM and the DSPF.
If your organisation contracts with Defence, subcontracts to a defence prime, provides technology or services to defence projects, or is seeking to enter the defence supply chain, DISP membership is likely a prerequisite. The 2024 Defence Industry Development Strategy signalled that Defence is tightening supply chain security requirements, making DISP compliance more critical than ever.
Four levels, tied to classification
DISP membership is assessed at one of four levels, set by the highest classification of information your organisation will handle. Essential Eight at Maturity Level 2 is the minimum across all levels, with classified networks at each level required to be employed in accordance with the ISM and the DSPF.
For organisations handling OFFICIAL or OFFICIAL:Sensitive Defence information. The ICT/cyber stream requires Essential Eight at Maturity Level 2 as the baseline.
Defence reference →For organisations handling PROTECTED Defence information. A PROTECTED network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.
Defence reference →For organisations handling SECRET Defence information. A SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.
Defence reference →For organisations handling TOP SECRET Defence information. A TOP SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside stringent personnel, physical, and governance controls.
Defence reference →For organisations handling OFFICIAL or OFFICIAL:Sensitive Defence information. The ICT/cyber stream requires Essential Eight at Maturity Level 2 as the baseline.
Defence reference →For organisations handling PROTECTED Defence information. A PROTECTED network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.
Defence reference →For organisations handling SECRET Defence information. A SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.
Defence reference →For organisations handling TOP SECRET Defence information. A TOP SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside stringent personnel, physical, and governance controls.
Defence reference →Common questions
What is DISP and who needs membership?
The Defence Industry Security Program (DISP) is the Department of Defence's membership-based program setting baseline security requirements for industry entities that want to engage with Defence, managed by the Defence Industry Security Branch. Membership is mandatory for entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases, are Australian Community Members under the Australia-US Defence Trade Cooperation Treaty, or hold membership as a condition of a Defence contract.
defence.gov.au — DISPWhat are DISP's cyber security requirements?
DISP requires the ASD Essential Eight at Maturity Level 2 or above across the corporate ICT systems an entity uses to correspond with Defence — at every membership level, from Entry (OFFICIAL) through Level 3 (TOP SECRET). Entities handling classified information must additionally have at least one network accredited under DSPF Principle 23 and Control 23.1, in accordance with the ISM and DSPF. Defence assesses cyber posture through the Cyber Security Questionnaire, annual reporting and audits.
defence.gov.au — DISP eligibility and suitabilityIs the full Essential Eight ML2 now mandatory for all DISP members?
Yes. Cyber assessments against the top four of the Essential Eight concluded on 15 November 2025, and all DISP members are now required to achieve and maintain compliance with the full Essential Eight Maturity Level 2 standard across the corporate ICT systems used to correspond with Defence. Where an assessment falls short, the DISP Cyber Team coordinates a maturity action plan through the Essential Eight Cyber Standards Uplift Program. Defence has also introduced a conditional membership pathway, so applicants can progress before their maturity action plan is complete, and a 12-month extension for existing members awaiting a cyber assessment.
defence.gov.au — DISP cyber assuranceHow does NodeZero help with DISP compliance?
NodeZero, a continuous security validation platform, tests the ICT and cyber security stream of DISP: it produces direct technical evidence across the Essential Eight by safely executing real attacks — strongest on the six strategies governing privilege, credentials and exploitable weakness, with attack-impact evidence for macros and backups — and tests the network segmentation, access controls and system hardening that classified-system accreditation expects — attack-based evidence you can put in front of an assessor. The governance, personnel and physical security streams require organisational evidence.
cyber.gov.au — Essential Eight maturity modelDoes NodeZero replace the Annual Security Report or Cyber Security Questionnaire?
No. The Annual Security Report is a self-attestation of compliance with Defence Security Principles Framework obligations — agreed by your executive (board equivalent) and submitted by your Chief Security Officer — and the Cyber Security Questionnaire is a recurring part of that assurance cycle. NodeZero puts evidence behind your answers: AD Password Audit, Endpoint Security Effectiveness and Rapid Response outputs map directly to the CSQ's Essential Eight Part B, while Part A and administrative items remain documentation work.
defence.gov.au — DISP cyber assuranceDoes NodeZero replace Defence accreditation or an IRAP assessment?
No. Accreditation of classified ICT systems is Defence's own process under the DSPF, and where a system needs an IRAP assessment that remains a separate certification engagement performed by a human assessor. NodeZero replaces the annual penetration test, vulnerability scanner and breach and attack simulation — producing exploit-validated evidence of which controls held under attack and which didn't — and closes the gap between accreditation cycles.
defence.gov.au — DSPF Principle 16 (PDF)Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.