DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/DISP
Australia & NZ compliance

DISP — Defence Industry Security Program

The Australian Department of Defence's security programme for organisations in the defence supply chain. DISP membership requires compliance across four security streams -- governance, personnel, physical, and ICT/cyber -- with the cyber stream requiring Essential Eight alignment at a minimum of Maturity Level 2.

See where NodeZero applies

What is DISP?

The Defence Industry Security Program (DISP) is the Australian Department of Defence's framework for managing security risks within the defence supply chain. Managed by the Defence Industry Security Branch (DISB), DISP membership is mandatory for entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases, or hold membership as a condition of a Defence contract. The program assesses organisations across four security streams: governance, personnel, physical, and ICT/cyber security.

The ICT/cyber security stream is where autonomous penetration testing has the strongest alignment. DISP requires organisations to implement the ASD Essential Eight at a minimum of Maturity Level 2 across the corporate ICT systems used to correspond with Defence, at all membership levels; classified networks must additionally be employed in accordance with the ISM and the DSPF. Defence has made clear that DISP membership is not a rubber stamp -- organisations must demonstrate that their controls are actively maintained and effective, not just documented. With the 2024 Defence Industry Development Strategy increasing emphasis on supply chain security, the bar for DISP membership continues to rise.

Defence -- DISP

Where NodeZero fits in your DISP membership

DISP's cyber requirement is the Essential Eight at Maturity Level 2. What's specific to DISP is how Defence assesses you -- a layered assurance model that runs from application through to audit. NodeZero produces evidence that holds up across every stage.

Looking for the control-by-control E8 mapping?

The DISP CSQ tests your Essential Eight ML2 implementation control-by-control (Part B). For per-strategy detail of what NodeZero validates, what it doesn't, and what evidence it produces, see the Essential Eight framework page.

See the Essential Eight mapping
  1. Step 01At application, before membership is granted

    Entry Level Assessment (ELA)

    What Defence asks for

    Defence reviews your security documentation, interviews your security staff, and requires a completed Cyber Security Questionnaire. Identified gaps must close before membership is granted.

    With NodeZero

    Run a pentest before submission to find the credential, patching, hardening and segmentation gaps your assessor will. Use Quick Verify to re-test fixes immediately, then answer your CSQ with evidence behind every claim.

  2. Step 02Every year, on your certificate anniversary

    Annual Security Report (ASR) and CSQ

    What Defence asks for

    A self-attestation against DSPF security obligations, signed off by your CSO. The CSQ is now a recurring obligation, with the full Essential Eight ML2 reassessed each cycle.

    With NodeZero

    Schedule pentests on a monthly or quarterly cadence so your ASR is backed by current data, not a once-a-year scramble. AD Password Audit, Endpoint Security Effectiveness and Rapid Response outputs map directly to CSQ Part B.

  3. Step 03Risk-based desktop audit, no advance notice

    Ongoing Suitability Assessment (OSA)

    What Defence asks for

    DISB selects members for OSA from an internal risk model. Compliance is reviewed across all four DISP streams, including a fresh cyber questionnaire and an interview with security staff.

    With NodeZero

    Continuous testing means your most recent evidence is never more than weeks old when DISB calls -- not last year's penetration test report. Your CSQ answers stay backed by current data, on demand.

  4. Step 04Detailed on-site assessment against DSPF Control 16.1

    Deep Dive Audit (DDA)

    What Defence asks for

    A collaborative audit examining whether your controls actually work, including site visits. DDA recommendations are tracked by the DISP audit team to closure.

    With NodeZero

    Exploit-validated evidence shows which controls held under attack and which didn't. After remediation, Quick Verify re-tests each exploit-validated finding and produces proof it has been closed — evidence you can put in front of the audit team for the technical DDA recommendations.

  5. Step 05If your assessment falls short of ML2

    Essential Eight Cyber Standards Uplift Program

    What Defence asks for

    Defence coordinates a Maturity Action Plan with you to lift your environment to ML2, with the DISP Cyber Team supporting and monitoring progress.

    With NodeZero

    Scope the gap by exploitability rather than theoretical CVSS. Re-test after every fix to demonstrate progress between DISP Cyber Team check-ins -- evidence the Maturity Action Plan is tracking to closure.

DISP membership opens defence supply-chain doors -- but only if you can keep proving your security holds up between assessments.

DISP kit

See every control mapped to NodeZero

The full control-by-control coverage map — every DISPrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

DISP membership is mandatory for Australian organisations that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or hold DISP membership as a condition of a Defence contract. This covers defence primes, subcontractors, technology providers, consultants, and any organisation in the defence supply chain that handles sensitive information.

DISP membership is assessed at four levels based on the highest classification of information the organisation will access. Entry Level covers OFFICIAL and OFFICIAL:Sensitive information, Level 1 covers PROTECTED, Level 2 covers SECRET, and Level 3 covers TOP SECRET. All members must meet the Essential Eight at ML2 across the corporate ICT systems used to correspond with Defence, while classified networks must be employed in accordance with the ISM and the DSPF.

If your organisation contracts with Defence, subcontracts to a defence prime, provides technology or services to defence projects, or is seeking to enter the defence supply chain, DISP membership is likely a prerequisite. The 2024 Defence Industry Development Strategy signalled that Defence is tightening supply chain security requirements, making DISP compliance more critical than ever.

Membership levels

Four levels, tied to classification

DISP membership is assessed at one of four levels, set by the highest classification of information your organisation will handle. Essential Eight at Maturity Level 2 is the minimum across all levels, with classified networks at each level required to be employed in accordance with the ISM and the DSPF.

Entry Level
OFFICIAL / OFFICIAL:Sensitive

For organisations handling OFFICIAL or OFFICIAL:Sensitive Defence information. The ICT/cyber stream requires Essential Eight at Maturity Level 2 as the baseline.

Defence reference
Level 1
PROTECTED

For organisations handling PROTECTED Defence information. A PROTECTED network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.

Defence reference
Level 2
SECRET

For organisations handling SECRET Defence information. A SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside the Essential Eight ML2 baseline.

Defence reference
Level 3
TOP SECRET

For organisations handling TOP SECRET Defence information. A TOP SECRET network or standalone device must be employed in accordance with the ISM and the DSPF, alongside stringent personnel, physical, and governance controls.

Defence reference
FAQ

Common questions

What is DISP and who needs membership?

The Defence Industry Security Program (DISP) is the Department of Defence's membership-based program setting baseline security requirements for industry entities that want to engage with Defence, managed by the Defence Industry Security Branch. Membership is mandatory for entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases, are Australian Community Members under the Australia-US Defence Trade Cooperation Treaty, or hold membership as a condition of a Defence contract.

defence.gov.au — DISP
What are DISP's cyber security requirements?

DISP requires the ASD Essential Eight at Maturity Level 2 or above across the corporate ICT systems an entity uses to correspond with Defence — at every membership level, from Entry (OFFICIAL) through Level 3 (TOP SECRET). Entities handling classified information must additionally have at least one network accredited under DSPF Principle 23 and Control 23.1, in accordance with the ISM and DSPF. Defence assesses cyber posture through the Cyber Security Questionnaire, annual reporting and audits.

defence.gov.au — DISP eligibility and suitability
Is the full Essential Eight ML2 now mandatory for all DISP members?

Yes. Cyber assessments against the top four of the Essential Eight concluded on 15 November 2025, and all DISP members are now required to achieve and maintain compliance with the full Essential Eight Maturity Level 2 standard across the corporate ICT systems used to correspond with Defence. Where an assessment falls short, the DISP Cyber Team coordinates a maturity action plan through the Essential Eight Cyber Standards Uplift Program. Defence has also introduced a conditional membership pathway, so applicants can progress before their maturity action plan is complete, and a 12-month extension for existing members awaiting a cyber assessment.

defence.gov.au — DISP cyber assurance
How does NodeZero help with DISP compliance?

NodeZero, a continuous security validation platform, tests the ICT and cyber security stream of DISP: it produces direct technical evidence across the Essential Eight by safely executing real attacks — strongest on the six strategies governing privilege, credentials and exploitable weakness, with attack-impact evidence for macros and backups — and tests the network segmentation, access controls and system hardening that classified-system accreditation expects — attack-based evidence you can put in front of an assessor. The governance, personnel and physical security streams require organisational evidence.

cyber.gov.au — Essential Eight maturity model
Does NodeZero replace the Annual Security Report or Cyber Security Questionnaire?

No. The Annual Security Report is a self-attestation of compliance with Defence Security Principles Framework obligations — agreed by your executive (board equivalent) and submitted by your Chief Security Officer — and the Cyber Security Questionnaire is a recurring part of that assurance cycle. NodeZero puts evidence behind your answers: AD Password Audit, Endpoint Security Effectiveness and Rapid Response outputs map directly to the CSQ's Essential Eight Part B, while Part A and administrative items remain documentation work.

defence.gov.au — DISP cyber assurance
Does NodeZero replace Defence accreditation or an IRAP assessment?

No. Accreditation of classified ICT systems is Defence's own process under the DSPF, and where a system needs an IRAP assessment that remains a separate certification engagement performed by a human assessor. NodeZero replaces the annual penetration test, vulnerability scanner and breach and attack simulation — producing exploit-validated evidence of which controls held under attack and which didn't — and closes the gap between accreditation cycles.

defence.gov.au — DSPF Principle 16 (PDF)
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.