DISP membership requirements are easy to misunderstand because people flatten four domains into one slogan. This post focuses on the ICT/cyber domain — the place where Essential Eight and Essential Eight Maturity Level 2 show up in real assessments.
What the cyber domain is asking
At a practical level, the cyber domain asks: can your organisation protect information to the standard implied by the DISP level you are seeking, on the systems that actually handle that information?
For many Australian suppliers, answering that question now means demonstrating Essential Eight ML2 outcomes across corporate IT — identity, endpoints, email/collaboration, remote access, privileged access, and backups included.
DISP membership requirements are level-and-domain specific
You do not hold "one cyber level for marketing." You select a level for ICT/cyber based on the classification of information that domain must handle, and you justify levels above Entry Level with a business case.
That interacts with cyber uplift:
- Higher information sensitivity usually means stronger assurance expectations
- Weak cyber evidence can undermine an otherwise tidy governance pack
- Over-claiming level without ML2 depth creates audit pain later
Corporate IT, not a fictional island
A recurring failure mode against DISP membership requirements is artificial scoping: declaring that Defence work happens only on three locked PCs while staff discuss contract detail on ordinary Microsoft 365 tenants and personal-admin laptops.
If the information lives on the corporate environment, the cyber domain requirements follow it. Plan Essential Eight Maturity Level 2 for that environment.
Evidence beats narrative
Assessors and serious primes look for artefacts:
- Configuration baselines and coverage reports
- Privileged access reviews
- Patch and vulnerability metrics
- MFA enrolment and enforcement proof
- Backup and restore test records
- Exception registers with owners and expiry dates
A well-written policy that nobody operationalises does not satisfy DISP membership cyber expectations.
How cyber links to the other domains
- Governance must oversee cyber risk, exceptions, and continuous monitoring
- Personnel security decides who can access what — cyber enforces it
- Physical security protects the spaces where systems and media live
Treat DISP membership requirements as a system. Cyber is one domain, not a side quest.
Sequencing advice
If you are early:
1. Confirm target levels per domain and the business case 2. Run an Essential Eight ML2 gap assessment on true corporate scope 3. Fund the cyber remediation stream before you promise membership dates to sales 4. Stand up evidence collection from week one
Summary
DISP membership requirements in the ICT/cyber domain are no longer a light questionnaire for most suppliers chasing Defence work. They are an operational cyber program with Essential Eight Maturity Level 2 at the centre — scoped to reality, evidenced continuously, and governed like any other regulated control set.