The most expensive DISP mistake after a bad application is treating the membership letter as a trophy. DISP is a continuous obligation. Governance reporting, personnel suitability, facility discipline, and cyber posture all have to hold. If they decay, you have a membership you cannot defend at the next review or the next prime questionnaire.
Why altitude decays
- Staff turn over and screening files are not updated
- New laptops arrive without the gold-image controls
- Admin rights creep back because a project was in a hurry
- The Security Officer changes jobs and nobody reassigns the title
- Essential Eight settings are "mostly still there" until someone measures
Cyber is the fastest decay curve. ML2 is an operating posture. Our ML2 checklist is useless if it is only used once.
What ongoing cover should include
Governance
A reporting calendar, a living evidence pack, and a Security Officer who still has time. Not a folder named DISP_FINAL_v7.
Personnel and physical
Onboarding and offboarding that still match AS 4811:2022 and your facility rules. Contractors included.
ICT / cyber
Patching, application control, MFA, backups, admin rights — kept at ML2, with evidence you can show. Watch the Essentials series transition so you are not surprised when the framework name changes.
MSP is not a luxury add-on
For a small team, keeping four domains current is a part-time job that never quite gets done. A managed security partner exists so membership does not depend on one busy person remembering the calendar. That is the point of staying on after the application: not extra theatre, just altitude that does not decay.
If you are still applying, build this into the engagement path now. Retrofitting an operating model after a scare is slower and more expensive.