DEFENCE INDUSTRY SECURITY PROGRAM

Get cleared for defence supply. We handle the process end to end.

DISP membership is what lets you work with defence primes and access classified information. We configure your systems to the required security baseline, build your policy documentation, and sit with you through the DSD assessment.

THE PLATFORM

Track your readiness — and know exactly where you stand before the assessor arrives.

DISP Readiness Workspace Assessment in 6 weeks
Meridian Engineering Pty Ltd
67%

Assessment readiness

On track

DSD framework progress

3 Systems configured Of 5 required
2 Policies approved Of 5 required
6w To DSD assessment Target date set
OS Classification OFFICIAL:Sensitive
System configuration

CA policies enforced in Entra ID for all users. Phishing-resistant MFA required for administrators. Legacy authentication protocols blocked.

CA policy screenshot MFA registration report

Defender for Business licensed and activated. Cloud-delivered protection, automatic sample submission, and attack surface reduction rules deployed.

Defender portal screenshot ASR rule audit log

DKIM signing enabled and verified for the client domain. DMARC policy set to quarantine with weekly aggregate reporting. Anti-phishing and impersonation protection deployed.

DKIM DNS verification DMARC aggregate report

Intune compliance policy drafted — covers OS version, encryption, screen lock, and Defender health. Awaiting your review and sign-off before deployment to devices.

Policy draft (pending approval)

Label taxonomy being drafted to match your DISP classification requirements: UNOFFICIAL, OFFICIAL, OFFICIAL:Sensitive. Configuration follows device compliance sign-off.

Policy documentation

Core information security policy covering classification, access control, incident reporting, and acceptable use. Written for your structure and DISP application scope.

Info security policy v2.1 (signed) Management sign-off record

Covers personal devices, remote access, social media, and data handling. Staff acknowledgement register complete — all staff signed.

AUP v1.3 (signed) Staff acknowledgement register

Incident classification, escalation contacts, and DSD notification obligations defined. In your review queue — awaiting feedback on the escalation path for after-hours incidents.

IRP v1.0 (awaiting approval)

Template complete — tracks NV1/NV2 clearance status, role-based access, and vetting dates for all staff with access to DISP-covered information. Awaiting your staff roster data.

Covers access to systems and information by subcontractors, suppliers, and auditors within the DISP scope. Follows IRP approval — expected by end of week.

WHAT THIS GETS YOU

Access to the defence supply chain.

DISP membership is a prerequisite for working with most defence contractors and primes. Without it, you can't be formally considered for classified or sensitive work — regardless of your capability.

Axel gets you to the point where you can submit a credible DISP application. We build what the DSD company assessment framework requires, so you're not starting from scratch when the assessor arrives.

WHAT'S INCLUDED

Everything the assessment requires.

System configuration

Your Microsoft 365 environment configured to the DISP security baseline — CIS Level 1 hardening plus the DISP-specific delta. Access controls, email security, device management, and information classification.

  • Conditional access and MFA enforcement
  • Microsoft Defender configuration
  • Email security (DKIM, DMARC, anti-phishing)
  • Device compliance policy
  • Protective marking and sensitivity labels

Policy documentation

The policy set the assessment requires, written for your business — not generic templates. Each document is tailored to your size, structure, and the scope of your DISP application.

  • Information security policy
  • Acceptable use and BYOD policy
  • Incident response plan
  • Personnel security register
  • Third-party access and supplier policy

Assessment support

We don't hand you a folder and walk away. When the DSD assessor comes in, we're there. We handle the technical questions, respond to findings, and make adjustments during the assessment process.

  • Pre-submission review against the company assessment framework
  • Assessor briefing materials
  • On-call support during the assessment
  • Gap remediation if findings are raised

THE PROCESS

From kickoff to cleared.

  1. 1

    Scoping call

    We review your existing setup, confirm your application scope, and identify any specifics your industry or customer requires. Most businesses can submit within six to eight weeks of kickoff.

  2. 2

    Configuration and documentation

    We configure your Microsoft 365 environment and build your policy set. You review and sign off — we do the technical work and the writing.

  3. 3

    Pre-submission review

    We run your documentation through the DSD company assessment framework before you submit — the same checklist the assessor uses. Gaps get fixed before they become findings.

  4. 4

    We sit with you through the assessment

    When the assessor arrives, we're in the room. We answer the technical questions, manage any findings on the day, and stay available until your membership is confirmed.

A defence prime is asking. Let's get you ready.

If you have a named defence customer or are responding to a tender that requires DISP membership, book a call. We'll tell you what's involved and whether we're the right fit.

30 minutes. No sales deck. We'll tell you whether we can help and what it would cost.

Book a 30-minute call