DISP

DISP cyber — the part that makes or breaks your application

We lead the cyber security component of DISP applications — the most complex and heavily assessed domain — and support integration with governance, personnel, and physical security requirements.

AGSVA Cleared Consultants Government-Experienced Team DSPF & E8 Expertise

DISP Readiness

Application Tracker
E8 ML2 Gap Assessment COMPLETE
Cyber Risk Assessment COMPLETE
ISM Controls Implementation IN PROGRESS
Security Plan (Cyber Sections) IN PROGRESS
CSQ Cyber Evidence Pack PENDING

E8 Maturity

ML2 ON TRACK

Cyber Readiness

72%

2 of 5 cyber controls met

Sound familiar?

The challenges you're facing

The cyber piece is the hardest part

DISP covers multiple security domains, but cyber is where most applications stall. E8 ML2, ISM controls, and evidence standards are specific and unforgiving — and most SMEs don’t have the in-house capability to get it right on the first attempt.

You can't afford to get it wrong

A rejected or delayed application means lost contracts and missed opportunities in the defence supply chain. The stakes are too high to figure this out on your own.

Your team doesn't have the specialist knowledge

DISP requires specific understanding of defence security practices, focused on DSPF and E8, that your internal team hasn't encountered before.

What you get

What's included in DISP Support

Cyber security posture assessment

Assessment of your cyber security posture against DISP membership requirements to identify gaps and required uplift.

ISM/ASD-aligned controls implementation

Closing the cyber gaps — implementing and documenting the controls Defence reviewers will look for, in the format they expect.

Essential Eight ML2 compliance

Assessment and uplift of your E8 maturity — the core prerequisite for DISP cyber requirements. Assessed and remediated as an integrated workstream.

Security plan — cyber sections

The cyber and ICT security sections of your organisational security plan, written to DISP standards and ready for Defence review.

Evidence package for the DISP cyber section

Compiled, structured evidence demonstrating E8 ML2 and ISM compliance — the artefacts Defence needs to process the cyber component of your application.

Response to DISP assessor cyber clarifications

When Defence comes back with cyber-related queries during their assessment, we prepare and support your responses — accurate, evidenced, and timely.

Implementation support

Hands-on guidance to implement DSPF controls and build the documentation Defence expects.

Progressing towards E8 ML2

Milestone-based delivery aligning your environment, controls, and documentation to E8 ML2 in step with DISP submission.

DISP submission and CSQ preparation (cyber)

We prepare your DISP submission and CSQ for the cyber security domain, ensuring requirements are clearly evidenced and documented.

Submission and Defence assessment support (cyber)

We support submission and Defence assessment activities for the cyber security domain, responding to queries and clarifications as they arise.

Our process

How it works

01

Cyber Readiness Assessment

We evaluate your ICT and cyber security environment and controls against DISP membership requirements — E8 ML2 and DSPF-aligned obligations — and give you a clear picture of where you stand.

02

Controls Implementation

We close the cyber gaps — implementing ISM/ASD-aligned controls, building the cyber sections of your security plan, and progressing towards E8 ML2.

03

Application Prep

We prepare your DISP application and CSQ (Cyber-Security Questionnaire) for the cyber security domain, ensuring requirements are clearly evidenced and documented.

04

Submission & Support

We support submission and Defence assessment activities for the cyber security domain, responding to queries and clarifications as they arise.

Is this right for you?

Who this service is for

Entering defence supply chain

Entering the defence supply chain

You've been told DISP is required and need to understand what's involved and how to meet the cyber security requirements.

Complex environments

Suppliers with complex or cloud-based environments

Your environment introduces additional complexity, and you need to meet DISP cyber security requirements in a controlled and defensible way.

Prime-pressured

Prime-pressured suppliers

A contract or prime requirement demands DISP registration within a defined timeframe, and you need to move quickly.

Proof

Real engagements, real outcomes

Anonymised

DISP member

Cyber evidence accepted without additional remediation during DISP reporting

Supported a DISP member through annual security reporting by preparing cyber security evidence and completing the CSQ. The submission was accepted without a maturity action plan for cyber, indicating the evidence and responses met assessment expectations.

Anonymised

DISP member

OSA remediation delivered across multiple security domains

Supported a DISP member to address findings from an Ongoing Suitability Assessment across governance and operational domains, ensuring recommendations were closed and evidence prepared for review.

Common questions

Frequently asked questions

Can we apply without being fully ML2?

Yes. Defence allows conditional membership pathways where ML2 gaps can be addressed post-membership under a defined action plan.

How long does DISP preparation take?

Preparation typically takes 3–6 months depending on your current maturity and documentation. Defence assessment timelines vary based on demand and prioritisation. Priority applications may be processed in around 90 days once assigned, while others may take longer depending on the queue. (Source: How to apply | Business & Industry | Defence)

Timeline from readiness to submission

For a prepared environment, we typically move from readiness assessment to submission in 3–4 months. Overall timelines depend on your starting position and Defence's assessment queue.

What does DISP cover?

DISP covers governance, personnel security, physical security, and ICT and cyber security (including Essential Eight). We focus on the cyber security domain and support integration with the broader security requirements where needed.

Why not self-submit?

Self-submissions may stall on evidence quality and interpretation of requirements. We bring experience aligning cyber security evidence to DISP expectations and supporting organisations through the assessment process.

What if we're not ready yet?

Start with our free health check — scoped to E8 readiness. We'll give you an indicative view of your cyber security maturity and a realistic timeline. It gives you clarity on what's needed without any commitment.

How do we budget for DISP support?

DISP engagements are scoped and priced individually because the gap between current state and Defence's requirements varies widely. We'll give you a firm range after a free health check so you know what to allocate.

Get started

Ready to start your DISP engagement?

Talk to our team about your cyber requirements for DISP. We’ll give you an honest assessment of where you stand and what it will take to get the cyber piece right.

Canberra-based • AGSVA cleared • Government-experienced