DISP applications rarely fail because a company is "not defence enough." They stall because the pack does not match the level requested, the evidence is thin, or questions from DSA sit unanswered. Those are fixable problems if you catch them before you submit — and still fixable, at higher cost, if you already have.
Mistake 1: One level for the whole business
There is no single DISP level. There are four domains. Asking for Level 2 everywhere because one engineer might need SECRET access is how you inherit a facility and cyber burden you cannot evidence. Read levels explained before you lock the form.
Mistake 2: No business case above Entry
Defence is explicit: above Entry Level you need a genuine reason tied to work. "We might tender later" is not a business case. Neither is matching a competitor.
Mistake 3: Policies without operating proof
A policy PDF is not evidence that staff follow it. Reviewers look for registers, tickets, configuration, screening files, and reporting. Cyber is the sharpest version of this — Essential Eight ML2 has to be an operating posture, not a slide.
Mistake 4: Cyber treated as "IT will sort it"
The ICT/cyber domain is currently the gate for many applications because ML2 across all eight strategies is a real uplift. If laptops, identity, backups, and admin rights are not in the pack, the rest of the application waits. Use the ML2 checklist as a working list, not a brochure.
Mistake 5: Slow answers to DSA
Questions are not a rejection. Silence is. Assign an owner, put a response SLA on it, and keep versions of what you sent.
Mistake 6: Stopping at the membership letter
DISP is continuous. If reporting and controls decay, you have a membership you cannot defend. Plan ongoing cover as part of the engagement, not as an afterthought.
Fix the scoping and the evidence first. The application is then a packaging job, not a negotiation with reality.