DEFENCE INDUSTRY SECURITY PROGRAM
DISP membership is what lets you work with defence primes and access classified information. We configure your systems to the required security baseline, build your policy documentation, and sit with you through the DSD assessment.
THE PLATFORM
Assessment readiness
DSD framework progress
CA policies enforced in Entra ID for all users. Phishing-resistant MFA required for administrators. Legacy authentication protocols blocked.
Defender for Business licensed and activated. Cloud-delivered protection, automatic sample submission, and attack surface reduction rules deployed.
DKIM signing enabled and verified for the client domain. DMARC policy set to quarantine with weekly aggregate reporting. Anti-phishing and impersonation protection deployed.
Intune compliance policy drafted — covers OS version, encryption, screen lock, and Defender health. Awaiting your review and sign-off before deployment to devices.
Label taxonomy being drafted to match your DISP classification requirements: UNOFFICIAL, OFFICIAL, OFFICIAL:Sensitive. Configuration follows device compliance sign-off.
Core information security policy covering classification, access control, incident reporting, and acceptable use. Written for your structure and DISP application scope.
Covers personal devices, remote access, social media, and data handling. Staff acknowledgement register complete — all staff signed.
Incident classification, escalation contacts, and DSD notification obligations defined. In your review queue — awaiting feedback on the escalation path for after-hours incidents.
Template complete — tracks NV1/NV2 clearance status, role-based access, and vetting dates for all staff with access to DISP-covered information. Awaiting your staff roster data.
Covers access to systems and information by subcontractors, suppliers, and auditors within the DISP scope. Follows IRP approval — expected by end of week.
WHAT THIS GETS YOU
DISP membership is a prerequisite for working with most defence contractors and primes. Without it, you can't be formally considered for classified or sensitive work — regardless of your capability.
Axel gets you to the point where you can submit a credible DISP application. We build what the DSD company assessment framework requires, so you're not starting from scratch when the assessor arrives.
WHAT'S INCLUDED
Your Microsoft 365 environment configured to the DISP security baseline — CIS Level 1 hardening plus the DISP-specific delta. Access controls, email security, device management, and information classification.
The policy set the assessment requires, written for your business — not generic templates. Each document is tailored to your size, structure, and the scope of your DISP application.
We don't hand you a folder and walk away. When the DSD assessor comes in, we're there. We handle the technical questions, respond to findings, and make adjustments during the assessment process.
THE PROCESS
We review your existing setup, confirm your application scope, and identify any specifics your industry or customer requires. Most businesses can submit within six to eight weeks of kickoff.
We configure your Microsoft 365 environment and build your policy set. You review and sign off — we do the technical work and the writing.
We run your documentation through the DSD company assessment framework before you submit — the same checklist the assessor uses. Gaps get fixed before they become findings.
When the assessor arrives, we're in the room. We answer the technical questions, manage any findings on the day, and stay available until your membership is confirmed.
If you have a named defence customer or are responding to a tender that requires DISP membership, book a call. We'll tell you what's involved and whether we're the right fit.
30 minutes. No sales deck. We'll tell you whether we can help and what it would cost.
Book a 30-minute call