DISP · ISM · IRAP · Brisbane · Canberra · Australia-Wide
DISP, ISM & IRAP – Defence-Ready Fast
Win Defence contracts and government opportunities sooner with practical DISP (Defence Industry Security Program) uplift, ISM (Information Security Manual) alignment, and IRAP (Infosec Registered Assessors Program) assessment readiness — without disruption or unnecessary complexity.
Defence and government customers expect strong, defensible security. We deliver it in weeks — with clear controls, audit-ready evidence, and fast procurement assurance — so you can focus on delivery, not delays.
- 10–16 weeks
- No disruption
- Audit-ready
- Procurement-friendly
Why is DISP right for me?
A 20-second self-check. DISP is your path if any one of these describes you.
You're bidding for or delivering Defence work
A tender, contract or prime contractor's flow-down requires DISP membership — often Entry or Level 1 to start — as a condition of doing the work.
You handle Defence information or assets
You store or process official or security-classified Defence information, or need access to Defence systems or estates — triggering the ICT/cyber (ISM-aligned) and personnel security obligations DISP governs.
"Just get ISO 27001" or "just do the Essential Eight" didn't fit
Defence wants DISP membership specifically, with ICT controls mapped to the ISM and, for systems, IRAP assessment. ISO 27001 or the Essential Eight on their own don't grant membership — DISP spans governance, personnel, physical and ICT together.
Not sure which DISP level your contract needs, or whether IRAP applies to your system? That's the first thing we settle on a call — book 30 minutes and we'll tell you plainly, no pitch.
"Which DISP level do we actually need?"
It depends on the sensitivity of the information and assets you handle, and what the contract specifies. Most members start at Entry or Level 1 and step up as classified work grows — we confirm the right level before you commit to controls you don't need.
"Is DISP the same as IRAP?"
No. DISP is Defence-industry membership across four security domains; IRAP is an ISM-based security assessment of a specific system. They're related — DISP's ICT controls reference the ISM — but distinct, and we deliver both.
"We already do the Essential Eight — how far does that get us?"
It covers a good part of the ICT/cyber domain, but DISP also spans governance, personnel and physical security and maps ICT to the broader ISM. We reuse your Essential Eight work rather than redo it.
"Where does our data live, and how long does it take?"
Everything stays in your own Microsoft 365 tenant — nothing copied to a vendor platform. Timelines depend on your target level and current maturity; an existing ISO 27001 or Essential Eight programme moves materially faster.
Why DISP, ISM & IRAP Matter Right Now
Defence and government contracts are increasingly competitive. Procurement teams now routinely require evidence of ISM alignment, DISP membership, and IRAP readiness before shortlisting suppliers.
Win More Defence Work
DISP membership and ISM alignment are often mandatory for tender eligibility. IRAP gives you the strongest assurance — helping you stand out and win.
Shorten Procurement Cycles
Clear, defensible evidence means faster security reviews and fewer back-and-forth requests.
Protect Your Reputation
Demonstrating ISM controls and IRAP readiness reduces breach risk and shows you take security seriously.
Why DISP, ISM & IRAP Matter to Your Business
Defence and government contracts increasingly require proven security controls. DISP, ISM and IRAP demonstrate you meet those expectations — helping you win work, build trust, and reduce risk.
Win Defence & Government Contracts
DISP membership and ISM alignment are often mandatory — we get you there fast so you can compete and win.
Reduce Security & Compliance Risk
Practical controls aligned to ISM and IRAP expectations — protecting your organisation from breaches and regulatory findings.
Build Buyer & Partner Confidence
Clear, defensible evidence reassures procurement teams and partners — opening doors and shortening sales cycles.
Common Defence Security Fears We Solve
We help teams overcome the same concerns — unclear requirements, long assessment timelines, high costs, and fear of failing IRAP or losing contracts.
“We don't know where to start”
We assess your current state, map ISM controls, and give you a clear, prioritized roadmap — no guesswork.
“It will take too long”
Focused uplift and evidence preparation mean most teams achieve IRAP readiness in 10–16 weeks.
“We're worried about failing assessment”
We prepare evidence packs, support assessor Q&A, and track remediation — so the process is calm and successful.
What You Get with DISP/ISM/IRAP Support
Practical, audit-ready deliverables designed to help you win Defence & government work faster — with ongoing confidence.
Gap Analysis & Roadmap
Evidence-based assessment against DISP/ISM/IRAP requirements, prioritized remediation plan, and quick wins.
Control Uplift & Hardening
Practical implementation of ISM-aligned controls — identity, endpoint, data, logging, and governance.
Audit-Ready Evidence Packs
Repeatable test scripts, exports, and documentation — ready for IRAP assessors or DISP reviews.
IRAP Assessment Support
Coordination with assessors, sample request (PBC) responses, findings tracking, and remediation to closure.
Defence-Grade Documentation
System Security Plan (SSP) inputs, risk registers, control matrices, and assessor-ready artefacts — aligned to ISM and IRAP.
Ongoing Compliance Support
Quarterly reviews, control monitoring, and evidence refresh — so you stay ready for DISP surveillance and future IRAP assessments.
Typical DISP/ISM/IRAP Timeline
Fast, focused, and built around your real risk profile — not theory.
Weeks 1–3
Gap analysis + roadmap
Weeks 4–8
Control uplift & evidence preparation
Weeks 9–12
Internal validation + IRAP readiness
Weeks 13–16
Assessment support & findings closure
What your ISM control register looks like
Every IRAP engagement is backed by a live ISM control register — control ID, domain, compliance status, and the exact Microsoft 365 evidence source mapped against each ASD requirement.
ISM Control Assessment Register
DISP / ISM / IRAP FAQs
What is DISP, ISM, and IRAP?
DISP (Defence Industry Security Program) is the pathway to Defence contractor accreditation. ISM (Information Security Manual) is ASD's control framework for government systems. IRAP (Infosec Registered Assessors Program) is the assessment process where an ASD-authorised assessor evaluates your environment against ISM requirements. Depending on your contract type and data classification, you may need one, two, or all three.
How long does DISP / IRAP readiness take?
Most organisations achieve meaningful ISM control uplift and IRAP readiness in 10–16 weeks with focused scope and prioritised remediation. DISP application timeline depends on the Department of Defence's processing queue, which is typically 4–8 weeks after submission. We prepare your submission materials as part of the engagement.
Do we need new security tools?
Not necessarily. For organisations already on Microsoft 365 E5 or Azure Government, the majority of ISM controls are achievable using native tooling — Defender, Intune, Entra ID, Purview. We assess what you have before recommending anything new. Buying tools before assessing the gap is one of the most common ways organisations waste budget on Defence uplift.
Can you support us during the IRAP assessment itself?
Yes. We coordinate with the IRAP assessor, prepare PBC (Provided by Client) evidence packs, attend assessor walkthroughs, track findings in real time, and manage remediation to closure. Our goal is to make the assessment process calm and predictable — not a scramble. We've supported multiple IRAP assessments and know what assessors look for.
What if our system is classified?
ISM controls are tiered by data classification (Official, Protected, Secret). Our engagements cover Official and Protected classifications, which cover the vast majority of Defence Industry and government-adjacent work. Systems requiring Secret or higher classification have additional requirements we can advise on, though delivery at those levels involves specialist security-cleared resources beyond our standard engagement.
Can DISP / IRAP work combine with ISO 27001 or Essential Eight?
Yes — and this is the most efficient path for most organisations. ISM maps directly to ISO 27001 Annex A and the Essential Eight. Building a shared control set and evidence infrastructure once, then mapping it to all three frameworks, avoids rebuilding from scratch for each requirement. Combined engagements typically reduce total programme cost by 25–35%.
Related Services
Build on DISP/ISM/IRAP with security, privacy, AI governance or other frameworks — all aligned.
Keep reading — DISP / ISM / IRAP
Guides, checklists and case studies
Get a realistic scope in 30 seconds
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Ready to Become Defence-Ready?
Book a free 30-minute call — we'll show you how to uplift DISP, align to ISM, prepare for IRAP, and win government contracts faster.
Most teams achieve readiness in under 16 weeks.