Skip to content

DEFENCE · 17 AUGUST 2026 · 2 MIN READ

DISP and the defence supply chain: what suppliers are actually asked for

Membership levels, the Essential Eight maturity clause, the ISMS question and the evidence primes expect: a practical map for engineering and services suppliers.

If you supply into Defence, directly or through a prime, you will meet three asks, usually in this order.

1. DISP membership

The Defence Industry Security Program has entry-level and higher membership tiers across governance, personnel, physical and ICT/cyber security. Entry level is achievable for most SMEs and is increasingly a precondition for being on a prime's approved supplier list. The cyber element leans on the Essential Eight.

2. An Essential Eight maturity level, in the contract

Flow-down clauses from primes now routinely specify Maturity Level 2 and ask for evidence at onboarding and annually. "We have MFA" is not evidence. A per-requirement assessment with dated exports is. Expect to be asked for the exceptions you carry and the compensating controls behind them.

3. "Do you have an ISMS?"

The larger primes and Defence itself ask for ISO 27001 certification or a documented ISMS aligned to it, particularly where you handle OFFICIAL: Sensitive information. Certification is the answer that ends the conversation; a structured, evidenced ISMS is the answer that gets you through the door while you work toward it.

What the evidence looks like

AskWhat satisfies itWhat does not
E8 ML2 patchingPatch compliance report from your endpoint tool, dated, with exceptions listedA policy saying you patch
MFAIdentity-provider export showing enforcement and methodA screenshot of one login
Admin privilegeQuarterly access review record with sign-offAn org chart
BackupsRestore test record with date and outcomeThe backup vendor's brochure
ISMSStatement of Applicability, internal audit report, management review minutesA folder of templates

Running both on one ledger

The overlap between the Essential Eight and ISO 27001 Annex A is large, access control, patching, backups, logging, awareness. Run them as one programme: each piece of evidence linked once, credited to every requirement it satisfies in both frameworks. That is the model ISO Assist uses, and it is why a supplier can reach ML2 evidence coverage and a 27001 Stage 1 dossier in the same quarter. The defence worked example walks the first eight weeks.

By ISO Assist. Tagged DISP · DEFENCE · ESSENTIAL-EIGHT · ISO-27001 · SUPPLY-CHAIN.

Reading about it is the slow way.

Book a demo and see the standard adopted in a workspace.