Skip to main content
Rules Mate

Defence Industry Security Program (DISP)

Defence contractors handling classified info must be DISP-accredited at appropriate level.

highcurrentongoing

Who must comply

Australian entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or whose Defence contract requires membership. Exceptions apply where classified work is done only inside Defence facilities or on Defence networks, or the entity is recognised under a Security of Information Agreement or Arrangement. Membership is open to, and recommended for, any Australian entity seeking to join the Defence supply chain.

What triggers it

Tendering for or performing a Defence contract that involves classified information, weapons or explosive ordnance, or base security, or a contract clause requiring DISP membership.

When due

Before the classified work or contract begins; ongoing reporting documents are submitted for membership management, and a Foreign Ownership, Control or Influence (FOCI) declaration is lodged with the application and again whenever FOCI status changes.

Evidence required

ABN or ACN and evidence of financial solvency; a Chief Security Officer (a director or senior executive) and a Security Officer able to obtain security clearances and a Digital ID; FOCI declaration covering foreign directors, shareholders, revenue and agreements; security governance documents and incident reporting; Essential Eight ML2 assessment (ISO/IEC 27001, NIST SP 800-171 or Def Stan 5-138 documentation can help); AS 4811:2022 workforce screening records; facility certification and accreditation.

Max penalty

DISP is a contractual and policy requirement rather than a statute, so there is no statutory fine for non-membership; an entity without the required membership cannot perform the classified or mandated Defence work, and members must keep meeting the security standards for their level to retain it.

Summary

The Defence Industry Security Program is Defence's membership-based security program for industry, underpinned by the Defence Security Principles Framework (Principle 16, Control 16.1). It has four membership levels aligned to government security classifications: Entry level (OFFICIAL and OFFICIAL: Sensitive), Level 1 (PROTECTED), Level 2 (SECRET) and Level 3 (TOP SECRET), each assessed across four domains: security governance, personnel security, physical security, and ICT and cyber security. Applicants self-nominate the level they need and must justify higher levels. Members must meet ASD's Essential Eight at Maturity Level 2 across corporate ICT systems used to correspond with Defence, and screen staff to AS 4811:2022. There is no membership fee, but certification, clearances and physical security carry costs, and membership does not of itself secure Defence contracts, which remain subject to normal procurement.

Topics

defencecyber-security

Related

Frequently asked questions

Who must comply with Defence Industry Security Program (DISP)?
Australian entities that work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or whose Defence contract requires membership. Exceptions apply where classified work is done only inside Defence facilities or on Defence networks, or the entity is recognised under a Security of Information Agreement or Arrangement. Membership is open to, and recommended for, any Australian entity seeking to join the Defence supply chain.
What triggers Defence Industry Security Program (DISP)?
Tendering for or performing a Defence contract that involves classified information, weapons or explosive ordnance, or base security, or a contract clause requiring DISP membership.
When is Defence Industry Security Program (DISP) due?
Before the classified work or contract begins; ongoing reporting documents are submitted for membership management, and a Foreign Ownership, Control or Influence (FOCI) declaration is lodged with the application and again whenever FOCI status changes.
What is the maximum penalty for Defence Industry Security Program (DISP)?
DISP is a contractual and policy requirement rather than a statute, so there is no statutory fine for non-membership; an entity without the required membership cannot perform the classified or mandated Defence work, and members must keep meeting the security standards for their level to retain it.
What evidence is required for Defence Industry Security Program (DISP)?
ABN or ACN and evidence of financial solvency; a Chief Security Officer (a director or senior executive) and a Security Officer able to obtain security clearances and a Digital ID; FOCI declaration covering foreign directors, shareholders, revenue and agreements; security governance documents and incident reporting; Essential Eight ML2 assessment (ISO/IEC 27001, NIST SP 800-171 or Def Stan 5-138 documentation can help); AS 4811:2022 workforce screening records; facility certification and accreditation.

Source: https://www.defence.gov.au/business-industry/industry-governance/industry-regulators/defence-industry-security-program/eligibility-suitability. Rules Mate is not a law firm. Always verify against the live regulator source before acting.