The most common overspend in DISP is applying for Level 1 when Entry Level would have done. The most common under-scope is staying at Entry when a contract actually needs PROTECTED handling. The difference is classification, evidence, and whether you can write a business case Defence will believe.
The classification split
- Entry Level aligns to OFFICIAL and OFFICIAL: Sensitive
- Level 1 aligns to PROTECTED
- Level 2 and 3 align to SECRET and TOP SECRET — do not go there without a real requirement
You still choose per domain. You might be Level 1 for personnel because two people need PROTECTED access, and Entry for ICT if systems never hold that material. Governance will follow the highest of the others. Detail sits in membership levels explained.
What Level 1 adds
Business case
Above Entry, Defence wants to know why. "A prime asked us to get membership" may justify Entry. It does not automatically justify PROTECTED.
Clearance sponsorship
Above Entry, sponsorship pathways open — with the Security Officer clearance caveat and no PV sponsorship. If you do not need to sponsor, do not buy the whole Level 1 stack for that reason alone.
Facility and cyber burden
PROTECTED physical and ICT expectations are heavier. If your systems and rooms are built for OFFICIAL, Level 1 is an uplift project, not a form tweak. Cyber still wants Essential Eight ML2 in the corporate environment.
A simple decision test
1. What information will we actually handle in the next 12–24 months? 2. Which domains touch that information? 3. Can we evidence the level we are asking for today, or only after a project? 4. If only after a project, is the contract date real?
If you cannot answer those in a page, you are not ready to pick Level 1. Scope Entry, or split the domains. That is how applications move instead of looping.