What You Need for a DISP Entry Level Application (A Practical Readiness Guide)

For organisations applying to the Defence Industry Security Program (DISP) at Entry Level, the most common challenge is not complexity, it is uncertainty.

Many organisations know they “need DISP,” but are unclear on what Defence actually expects to see in an initial application. This often leads to either under-preparation, where gaps slow the assessment process, or over-preparation, where unnecessary controls are built for a level of risk that does not exist.

This article provides a practical, high-level readiness guide to what is typically required for an Entry Level DISP application. It is not a procedural manual, and it does not replace Defence guidance, but it does help organisations understand what they need to have thought through before applying.

First, understand what Entry Level is assessing

Before looking at specific items, it is important to understand what Defence is actually assessing at Entry Level.

Entry Level is designed for organisations that access OFFICIAL or OFFICIAL: Sensitive information only. Defence is not looking for advanced security infrastructure or classified environments. Instead, it is assessing whether an organisation understands its security responsibilities and has deliberate, proportionate controls in place.

At its core, an Entry Level application answers one question:
Can this organisation be trusted to handle sensitive Defence information appropriately?

Everything that follows flows from that question.

How Entry Level fits within the broader DISP framework

Entry Level does not exist in isolation. It sits within a broader DISP framework that scales security expectations as information sensitivity increases.

Understanding this context helps organisations avoid a common mistake: preparing controls designed for higher DISP levels when they are not required.

The table below provides a high-level reference, based on publicly available DISP guidance, showing how expectations typically scale across DISP membership levels. It is intended to provide context only — actual requirements are always driven by information classification, contract conditions, and risk.

Indicative DISP membership comparison (public guidance overview)

DISP LevelTypical Information AccessGovernance & OversightPersonnel SecurityPhysical SecurityCyber / Information Security
Entry LevelOFFICIAL / OFFICIAL: SensitiveDefined security responsibility; basic governanceSecurity awareness; role-based accessControlled access to workspaces; basic visitor managementBasic cyber hygiene; controlled system access
Level 1PROTECTEDFormalised governance arrangementsBaseline clearances typically requiredDefined secure areas; controlled storageStructured cyber controls appropriate to PROTECTED
Level 2SECRETStrong governance and oversightNV1 clearances requiredSecure facilities and access controlsMature cyber security and monitoring
Level 3TOP SECRETHighly controlled governanceNV2 or higher clearancesDedicated secure facilitiesHighly restrictive and monitored systems

This comparison reinforces an important point for Entry Level applicants: Defence is not expecting Entry Level organisations to demonstrate controls designed for PROTECTED or SECRET environments. It is assessing whether controls are appropriate to where the organisation sits in this framework.

Clear understanding of information access

One of the first things Defence expects an organisation to understand is what information it will access.

For an Entry Level application, this means being clear that access is limited to OFFICIAL or OFFICIAL: Sensitive information, and that higher classifications are not required. Organisations should be able to explain, at a high level, how sensitive information is created, received, stored, and shared within the business.

This does not require detailed mapping of every document, but it does require awareness and clarity around information boundaries.

Defined security responsibility and governance

Even at Entry Level, Defence expects security to be owned.

An organisation should be able to clearly articulate who is responsible for security matters, how security decisions are made, and how DISP obligations are overseen internally. In many Entry Level organisations, this responsibility sits with a senior leader or manager alongside other duties.

What matters is not the size of the governance structure, but that accountability is explicit rather than assumed.

Basic security policies that reflect reality

Entry Level applications typically include a small set of security policies. Defence is far more interested in accuracy and alignment than volume.

Policies should reflect how the organisation actually operates, describe how sensitive information is handled and protected, and be understandable to staff. Overly complex or aspirational policies that do not match reality often slow assessment rather than help it.

At Entry Level, simple and accurate is better than impressive and theoretical.

Personnel awareness and responsibility

Personnel security at Entry Level is primarily about awareness and access control, not clearance.

Organisations should be able to demonstrate that staff understand the sensitivity of Defence information, know their responsibilities, and only access information required for their role. Formal security clearances are often not required at Entry Level, though access to certain government systems may still require Baseline clearance depending on system requirements.

The key is that access is deliberate and justified.

Physical security arrangements that match the risk

Physical security at Entry Level focuses on preventing unauthorised access to Defence information and workspaces.

Defence does not expect secure facilities or specialised infrastructure. It does expect organisations to have considered who can physically access information, how visitors are managed, and how sensitive material is protected when not in use.

Physical security at Entry Level is about discipline and awareness, not fortification.

Cyber security basics and hygiene

Cyber security expectations at Entry Level are centred on reasonable protection against common threats.

Organisations should be able to show that systems used to handle Defence information are protected, access is controlled, and information is not stored or transmitted insecurely. There should also be a basic understanding of how incidents would be identified and managed if they occurred.

Advanced cyber frameworks are not expected, but unmanaged cyber risk is not acceptable.

Understanding ongoing obligations

A frequent oversight in Entry Level applications is treating DISP as a one-time exercise.

Even at Entry Level, organisations are expected to understand that DISP membership involves ongoing obligations, including annual reporting and the requirement to consider and report material changes affecting security.

Demonstrating awareness of these obligations signals maturity and builds Defence confidence.

Bringing it all together

A strong Entry Level DISP application is not about volume or sophistication. It is about clarity, alignment, and intent.

Defence is looking for organisations that understand their security responsibilities, have controls that match their risk profile, and are prepared to maintain compliance over time. When those elements are present, Entry Level applications tend to progress more smoothly.

Final thoughts

Preparing for a DISP Entry Level application does not require perfection, but it does require thought.

Organisations that take the time to understand what Defence is assessing — and why — are far better positioned to submit applications that are proportionate, credible, and aligned with expectations.

Entry Level is not about doing the minimum. It is about doing what is appropriate, deliberately and consistently.

Most organisations entering the Defence supply chain underestimate what DISP actually requires or assume existing policies are enough.

The DISP Readiness Quiz gives you a fast, structured way to understand where your organisation really stands.

more insights