CYBER BASELINE · 7 MIN READ

DISP membership cyber domain: Essential Eight Maturity Level 2 explained

For most Australian companies pursuing DISP membership, the ICT/cyber domain is where timelines slip. Governance paperwork can be drafted. Personnel processes can be designed. Facility measures can be scoped. Cyber is different: Essential Eight Maturity Level 2 is a real technical uplift across the corporate IT environment, and Defence expects evidence, not slides.

What DISP membership expects in the cyber domain

DISP membership is assessed across four security domains. The ICT/cyber domain is where your organisation proves it can protect Defence-related information on the systems people actually use day to day.

The live baseline for many DISP members and applicants is the Australian Signals Directorate Essential Eight, at Maturity Level 2 (ML2), applied across the corporate IT environment rather than a narrow "Defence project subnet" that does not reflect how work really happens.

That is a bigger ask than older DISP cyber expectations. Earlier guidance emphasised a smaller set of strategies at a lower maturity. The shift to Essential Eight ML2 is one of the most material requirement changes applicants feel in practice.

Essential Eight Maturity Level 2, in plain terms

The Essential Eight is eight mitigation strategies. Maturity Level 2 means each strategy is implemented to a defined depth — not "we have a tool" but "the control works the way ASD describes at ML2."

In practice, companies preparing for DISP membership cyber domain work usually find the pressure points are:

  • Application control that actually blocks unapproved executables
  • Patching cadence for applications and operating systems that matches ML2 timeframes
  • Multi-factor authentication covering the accounts and remote access paths that matter
  • Restricting administrative privileges so everyday work does not run as admin
  • Backups that are retained, protected, and tested — not just configured once

Essential Eight Maturity Level 2 is not a badge you buy. It is an operating posture you can evidence.

Why this matters for DISP membership timelines

Assessors and primes do not need you to be perfect on day one of a conversation, but they do need a credible path. If your DISP membership application claims cyber readiness while the estate is still at ad-hoc patching and shared admin accounts, the cyber domain becomes the bottleneck for the whole membership outcome.

Treat Essential Eight ML2 as a project with owners, milestones, and evidence folders — the same seriousness you would give a contract deliverable.

A practical way to start

1. Inventory the corporate IT scope Defence will actually care about (identity, endpoints, email, collaboration, remote access, backups). 2. Score each Essential Eight strategy honestly against Maturity Level 2. 3. Separate quick wins (MFA coverage, admin privilege cleanup) from longer engineering work (application control, patch automation). 4. Build evidence as you go: configs, screenshots, tickets, exception registers, test results.

Related reading on this blog

If you are still scoping which DISP level applies where, start with our post on DISP membership levels. If you are tracking ASD's longer-term move away from Essential Eight toward the Essentials series, read that update next — ML2 remains the live target today even while the framework roadmap evolves.

NEXT STEP

Need a clear view of your Essential Eight ML2 gaps?

Skyline AI can map where you sit against DISP cyber requirements and line up a call with a specialist.

Talk to Skyline AI
Skyline AI