DISP preparation
Turn DISP requirements into assigned work
A DISP application is easier to manage when each requirement has an owner, current evidence, a known gap and a next action. This DISP readiness checklist gives Sydney defence suppliers a working structure for that preparation. You can also download the free, fillable working checklist to record owners, evidence, gaps and next actions.
Defence says any Australian entity can apply, but applicants must meet eligibility requirements and nominate the membership levels needed across security governance, personnel security, physical security, and ICT and cyber security. Defence eligibility guidance [5] also explains when membership may be mandatory.
Milnsbridge defence IT support and the Essential Eight uplift program support the ICT implementation and evidence work around an application. The applicant's Chief Security Officer and Security Officer retain their Defence-defined responsibilities, while Defence assesses the application. This article does not replace Defence guidance or decide whether an application will be accepted.
Download the working checklist
Use this fillable PDF to assign owners, record evidence references, flag gaps and set next actions with due dates. It is free to download with no email required.
Download the working checklistPDF · 5 pages · 91 KB · Version 1.0 · 22 September 2026
Work through these preparation tasks
- Confirm eligibility and contract needs
- Record the requested levels and boundary
- Assign the CSO and SO
- Review security policies and reporting
- Check personnel security arrangements
- Check sites and information handling
- Map the ICT boundary and all eight controls
- Prepare the cyber questionnaire evidence
- Assign uplift work and unresolved decisions
- Check supplier and subcontractor responsibilities
- Reconcile evidence before CSO review
- Schedule ongoing reviews and reporting
Save a local copy and open it in a PDF reader that supports forms. Use controlled evidence references, not passwords, classified information or sensitive personnel details. Keep the completed file in your approved storage.
This Milnsbridge worksheet is a preparation aid, not an official Defence checklist, a complete control assessment, certification or a guarantee of membership. Use it with the current Defence guidance linked below.
Working register
Start with five fields for every requirement
A long requirement list becomes useful when every row answers the same questions.
Requirement and owner
Write the Defence or contract expectation in plain language. Name the person accountable for the decision and completion.
Current evidence
Link to the current policy, report, configuration record, test result or approved exception. Add its date and location.
Known gap
Record what is missing, incomplete, out of date or outside the declared boundary. Do not turn uncertainty into a yes answer.
Next action
Set the action, delivery owner and date. Include any approval or business decision that IT cannot make alone.
Use one shared register rather than separate notes held by directors, HR, facilities and IT. The official DISP membership requirements checklist [10] covers governance, personnel security, physical security, and information and cyber security. Follow those domains and identify contract-specific requirements separately.
Scope first
Set the application boundary before collecting evidence
Do not begin by gathering every security document in the business. First record the membership level requested in each domain, why that level is needed, and which systems, locations, people and suppliers sit inside the boundary.
Defence says entities self-nominate the levels they need and must justify higher levels. The security governance level equals the highest level requested in the other three domains. An entity normally needs one DISP membership even when it has more than one Defence contract. Defence describes these level considerations [5].
Your boundary note should identify the corporate ICT systems used to correspond with Defence. Defence states that Essential Eight Maturity Level Two applies across those systems. List the tenant, identity platform, managed endpoints, internet-facing services, backup systems and administrative paths that support the relevant work.
The boundary can change. New contracts, offices, systems and providers may affect membership records and cyber posture. Defence lists physical and ICT changes, major system updates, maturity changes and a new or changed IT provider among the changes members may need to report. See the membership maintenance guidance [9].
Role boundaries
Keep CSO, SO and IT responsibilities distinct
Applicant leadership
The CSO is responsible for security arrangements and champions the entity's security culture. The CSO reviews, declares and submits in the portal.
The SO develops and applies security policies and plans, starts and edits submissions, then sends them to the CSO. One person can hold both roles.
ICT implementation support
Milnsbridge can assess controls, apply agreed changes, manage systems and produce operating evidence such as patch reports, access reviews, backup tests and change logs.
Milnsbridge does not select a membership level, declare the submission, approve the application or guarantee membership. Those decisions remain with the applicant and Defence.
Defence's role summary [5] sets the portal responsibilities. Put the same boundary into the project plan so nobody mistakes a technical completion report for a DISP outcome.
Evidence plan
Build evidence across four workstreams
Governance and people
Name the CSO and SO, confirm training and portal access, and record how the governing body approves security reporting. Assign owners for policies, staff training, incident reporting, screening and required registers.
Physical and information handling
Record the sites, rooms, storage methods and access arrangements relevant to the requested level. Identify who can receive, use, move and destroy protected material.
ICT and Essential Eight
Map each in-scope system against all eight mitigation strategies. Keep implementation evidence rather than a simple yes or no. Document exceptions, compensating controls and review dates.
Suppliers and contracts
List providers that support the boundary. Record each contract owner, service scope, access level and required evidence. The applicant remains responsible for applicable subcontractor requirements.
The current DISP cyber standard uses the full Essential Eight at Maturity Level Two rather than the earlier top four controls. Defence cyber and assurance guidance [6] confirms the full standard. ASD also recommends reaching the same maturity level across all eight controls before claiming that level. Documented exceptions need approval and regular review under the Essential Eight maturity model [11].
Cyber questionnaire
Prepare each answer from operating evidence
Defence recommends that someone with sufficient knowledge of the ICT infrastructure complete the Cyber Security Questionnaire. Incomplete answers may delay an application. Part B contains 107 controls for the Essential Eight, so early planning matters. These details are set out in the Defence cyber and assurance page [6].
For each response, link to a current report, configuration record, policy, ticket, test result or approved exception. Add the collection date and evidence owner. Screenshots can support a response, but a repeatable report or exported configuration usually gives the next review more value.
Run a challenge session before submission. Ask the control owner to explain the evidence without relying on the person who configured the system. Check that the scope matches the declared boundary and that an exception has a business owner, compensating control and review date.
If one control is described differently in the policy, questionnaire and technical report, resolve the mismatch before it reaches Defence. Consistent evidence is more useful than a collection of disconnected files.
Action plan
Use open gaps to drive achievable uplift
A DISP readiness checklist should expose gaps. Prioritise actions that affect eligibility, application completeness, the declared ICT boundary or several controls at once. Assign a realistic date and include any business decision that IT cannot make alone.
Defence has introduced a conditional membership pathway that can allow applicants to progress without finishing an Essential Eight Maturity Level Two Maturity Action Plan before membership is granted. That pathway does not remove the need to plan and complete uplift. Check the current DISP application process [7] before relying on it.
Milnsbridge's Essential Eight uplift program is the relevant technical service when an assessment identifies implementation work. It combines a baseline, a roadmap and staged delivery. Scope and commercial terms are confirmed after discovery.
The historical DISP case study describes one engineering firm's move from Maturity Level Zero to Maturity Level One in one week. It is not a promise of timing or current Maturity Level Two readiness for another business. Today's requirements and each applicant's starting position control the work.
Workload markers
Four numbers that shape the preparation
Security domains
Defence eligibility and suitability
Application sections
Defence how to apply
Controls in CSQ Part B
Defence cyber and assurance
MAP extension described for eligible existing entities
Defence how to apply
FAQ
DISP readiness questions
Is DISP membership mandatory for every defence supplier?
No. Defence says membership depends on the work and contractual requirements. It is mandatory in specific circumstances and recommended more broadly for entities working on Defence projects or seeking to partner with Defence. Confirm the position with the relevant Defence contract manager.
Does Milnsbridge certify DISP compliance?
No. Milnsbridge can support ICT assessment, implementation, ongoing management and evidence preparation. Defence assesses DISP applications and membership. The applicant's CSO and SO remain responsible for their defined roles.
What Essential Eight maturity level applies?
Defence states that DISP entities must meet or exceed the full Essential Eight at Maturity Level Two across corporate ICT systems used to correspond with Defence. Contract, system and information requirements still need to be checked for the entity's circumstances.
Can the same person be CSO and SO?
Yes. Defence allows one person to hold both roles. That person then carries the combined responsibilities for starting, editing, reviewing, approving, declaring and submitting the relevant portal work.
What evidence should IT prepare?
Useful evidence can include asset inventories, patch and vulnerability reports, identity and privileged-access records, configuration baselines, backup and restore tests, security monitoring records, change logs and approved exceptions. Match each item to the declared system boundary and control.
Primary sources
Check the current official guidance
Explore more
Defence and cyber security guidance
IT for defence suppliers
ICT support and security alignment for Defence supply chain businesses.
ExploreEssential Eight uplift
Baseline assessment, staged implementation and operating evidence.
ExploreEndpoint protection
Managed endpoint controls, hardening, monitoring and reporting.
ExploreHistorical DISP case study
A prior engineering client uplift, recorded as historical proof rather than a current ML2 promise.
ExploreKeep the next actions together
Save the fillable worksheet for your next preparation review. Each task has space for an owner, current evidence, a gap, a working status and the next action with a due date.
Download the working checklistFree PDF · No email required · 5 pages
Plan the technical work
Turn the checklist into assigned actions
Milnsbridge can help Sydney defence suppliers assess their ICT position, plan technical uplift and keep operating evidence current. Our team publishes a 20-second average answer time and 87% first-call resolution.
Talk to a SpecialistAbout the Author
Adrian Weir
Adrian Weir is the Managing Director and founder of Milnsbridge Managed IT Services, with over 30 years of global IT experience spanning Telstra, Citibank, Unilever, and hundreds of Sydney SMBs. A Microsoft Partner since 2002, Adrian leads a team of IT specialists delivering responsive, business-focused managed IT support across Greater Sydney.
Meet the Milnsbridge Team
