DISP compliance
DISP compliance for WA Defence suppliers
Defence asks DISP members to meet or exceed Essential Eight Maturity Level 2 on the corporate systems they use to correspond with Defence. We build those controls, document how they work and keep the evidence ready for your application.
Your price in two minutes, no email needed. Or call 1300 787 429.

- ML2Essential Eight alignment for Powertech, which went on to win a defence grade client
- $0DISP membership fee. The cost is in the security work, not the membership
- 4Security domains, from governance to ICT and cyber security
- ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
Trusted by security conscious businesses across WA








01What DISP asks for
What DISP membership asks of you
The Defence Industry Security Program (DISP) is how Defence manages security across its supply chain. Membership is open to any Australian entity. Depending on the work or the contract, it may be mandatory.
- 01Four membership levels
Entry level covers OFFICIAL and OFFICIAL: Sensitive information. Levels 1, 2 and 3 cover PROTECTED, SECRET and TOP SECRET.
- 02Four security domains
ICT and cyber security, physical security, personnel security and security governance.
- 03Two named roles
A Chief Security Officer responsible for security arrangements and culture. A Security Officer who develops and implements your security policies and plans.
- 04Essential Eight Maturity Level 2
Members must meet or exceed ML2 across the corporate ICT systems they use to correspond with Defence.
- 05Foreign ownership declared
A declaration of any foreign ownership, control or influence goes in with the application and again whenever it changes.
This is a plain English summary. Defence decides membership and your advisers can confirm what a contract requires.
Essential Eight maturity levels02Who does what
Clear roles save time and money
No IT provider can make you a DISP member. This is how the work splits and where we fit.
Defence
Assesses your application, decides your membership level and is the authority on what the requirements mean.
The decision makerYour CSO and Security Officer
Own your security arrangements, policies and culture. They are your people, and Defence expects them to lead.
Roles you appointAustin Technology
Builds and runs the ICT and cyber controls, writes up how they work and keeps the evidence ready for your application and reviews.
The ICT and cyber domain03How it works
From readiness review to Maturity Level 2
The cyber domain usually takes the longest, so it is the right place to start. Your team keeps working while controls roll out.
- Step 1
Readiness review
We check the systems you use with Defence against ML2 and list the security documents you have and the ones you still need.
- Step 2
Choose the scope
Lift your whole environment to ML2, or ring fence the systems and people that work with Defence. We cost both where it makes sense.
- Step 3
Build to ML2
Application control, patching, MFA, admin rights, macro settings, hardening and backups brought to ML2 in planned stages.
- Ongoing
Evidence and review
Written evidence for your application, then quarterly reviews so you stay at ML2 as your systems change.




Not sure which level you need?
Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote.
04Is it a fit
When we are the right partner for DISP
We would rather tell you what sits outside our work than have you find out halfway through an application.
A strong fit Austin Technology
- +Your ICT is the gap, and you need ML2 and the evidence to show it
- +You are a WA engineering, manufacturing or resources firm bidding for Defence work
- +You want the team that runs your IT to run your DISP controls as well
- +You need your Defence facing systems hosted in Perth on infrastructure we manage
Probably another option We will say so
- ×Physical security or facility work, which sits with a physical security specialist
- ×Personnel vetting and security clearances, which run through the government process
- ×A paper exercise that leaves your systems unchanged
SecureShield Command maintains Essential Eight ML2 and includes an ongoing vCISO, at $100 per person per month excluding GST. The uplift to ML2 is quoted as a fixed price project.
SecureShield plans05Proof
Defence ready work for a WA engineering firm
Powertech supplies more than 300 specialists across mining, oil and gas, renewables, infrastructure and defence.
Aligned to ML2
ThreatLocker, Huntress, conditional access, BitLocker and staff training took Powertech to Essential Eight ML2, and it progressed towards DISP and ISO 27001.
Read the case studyMoved to a private cloud in WA
Powertech migrated from AWS to our private cloud and went on to win a defence grade client.
Private cloud serversAudited ourselves
We are certified to ISO/IEC 27001 and ISO 9001, so the provider running your Defence facing systems is externally audited too.
Security and governanceRelated services and industries
06Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
07Questions
DISP compliance questions
What Defence suppliers ask us before they start. Anything else, call 1300 787 429.
01Do we need DISP membership to work with Defence?
Not always. Defence says membership may be mandated depending on the type of work or the contract. It is not mandated in all circumstances. Check the tender or contract first and ask your Defence contact if it is unclear.
02What cyber security does DISP require?
Defence asks members to meet or exceed Essential Eight Maturity Level 2 across the corporate ICT systems used to correspond with Defence. How you show it can change over time, so we confirm the current requirements with you at the readiness review.
03How long does it take to become a member?
It depends on where you start and how much of your environment is in scope. After the readiness review we give you a timeline for the cyber work. Defence sets its own timeframes for assessing applications.
04What does DISP cost?
Defence charges no membership fee. The cost is in the security work: controls, documents and ongoing management. The readiness review ends with a fixed quote, and SecureShield Command, which maintains ML2, is $100 per person per month excluding GST.
05Can an IT provider handle DISP, or do we need a DISP consultant?
We handle the ICT and cyber domain and the documents that support it. For personnel and physical security, or help with the application itself, a specialist DISP consultant can help. If you use one, we work alongside them.
06What happens once we are a member?
Membership comes with ongoing obligations, such as keeping your security arrangements current and telling Defence about changes in foreign ownership, control or influence. We keep your controls at ML2 and review the evidence with you every quarter.
08DISP compliance
Defence work starts
with ML2.
Tell us about your Defence work and your systems. A technical consultant will scope what Maturity Level Two needs with you and send a fixed quote.
Or call 1300 787 429