New changes are coming to DISP — not as a single overnight rewrite of the membership rulebook, but as a set of overlapping shifts that suppliers feel in assessments, prime questionnaires, and cyber uplift programs. If you only track "are we DISP members yet?" you will miss the moving parts that decide how hard membership is to win and keep.
Change 1: Cyber expectations hardened around Essential Eight ML2
For many applicants, the most tangible change in the DISP membership journey has been the ICT/cyber domain. The practical bar is Essential Eight Maturity Level 2 across corporate IT, not a lightweight subset of controls at Maturity Level 1.
That change alone has stretched timelines for companies that treated cyber as a paperwork exercise.
Change 2: Essential Eight itself is on a retirement path
In June 2026, ASD confirmed the Essential Eight will be retired over roughly two years and replaced by the broader Essentials series, starting with Essentials for Enterprise IT.
What that means for DISP membership planning:
- Essential Eight remains live and supported now
- ML2 work you do today should map forward, not be thrown away
- Waiting for the "final final" framework is a bad strategy if you have contracts depending on DISP
So yes — new changes are coming to DISP-relevant cyber guidance — while today's assessable baseline is still Essential Eight-shaped.
Change 3: Primes are raising the floor before contracts land
Even where Defence's published wording moves carefully, primes often move faster in procurement. DISP membership is increasingly a gate. Evidence of Essential Eight ML2 is increasingly a second gate. Suppliers who only chase the membership certificate without cyber depth get stuck between "approved on paper" and "not trusted on the network."
Change 4: Domain scoping is under more scrutiny
DISP membership is four domains, not one score. Governance must track the highest level elsewhere. Personnel, physical, and cyber must be justified with a business case above Entry Level. New applicants who still ask "what level do we need?" as a single number are asking the wrong question — and changes in how primes review subcontractors make that mistake more expensive.
What to do this quarter
1. Re-baseline your cyber domain against Essential Eight Maturity Level 2. 2. Document DISP membership scope domain-by-domain with a real business case. 3. Assign a single owner for framework transition watching (Essentials series drafts). 4. Build evidence continuously — membership and cyber assurance both feed on artefacts. 5. Brief leadership that DISP is an operating system, not a one-time application event.
What not to do
- Do not freeze Essential Eight ML2 projects "until Essentials is finished."
- Do not assume Entry Level cyber thinking will satisfy modern prime due diligence.
- Do not treat DISP membership as finished on the day the letter arrives — managed compliance is the product.
The Skyline view
New changes coming to DISP are best read as a direction of travel: higher assurance, clearer cyber baselines, and less patience for theatre. Companies that treat 2026 as a year to professionalise governance and complete Essential Eight ML2 will be in better shape than companies waiting for certainty that will not arrive all at once.