Australian suppliers often arrive with ISO 27001 and assume DISP membership is a paperwork translation. It is not. ISO 27001 certifies an information security management system against a standard. DISP is the Department of Defence's membership framework for industry that handles Defence information or wants into the supply chain. You can hold one, both, or neither. They answer different questions.
What ISO 27001 is good for
ISO 27001 is strong at showing you have a managed ISMS: scope, risk, controls, internal audit, management review. Many primes like seeing it. It can accelerate parts of a DISP conversation because you already have policies, registers, and a language for control.
What it does not automatically prove
- Domain-by-domain DISP levels tied to classification
- A Defence business case above Entry Level
- Personnel screening specifically to AS 4811:2022 and clearance sponsorship rules
- Physical measures proportional to PROTECTED or above
- Essential Eight ML2 as Defence currently expects in the ICT/cyber domain
An ISMS that never mentions Essential Eight, DISP, or DSA reporting is still an ISMS. It is not a DISP pack.
What DISP is
DISP is membership under DSPF Principle 16 across governance, personnel, physical, and ICT/cyber. Levels map to OFFICIAL through TOP SECRET. Governance matches your highest other domain. Cyber is currently gated by Essential Eight Maturity Level 2, with the Essentials series already announced as the longer-term replacement.
When you need both
- Primes ask for ISO 27001 and DISP membership
- You sell into Defence and into commercial regulated markets
- You already have ISO 27001 and do not want to throw it away — you should not. Reuse the artefacts. Rewrite the story for Defence reviewers.
Do not pause a DISP application to "finish ISO first" unless a contract literally requires the certificate this quarter. Do not skip DISP because you have ISO. Map the overlap, fund the gaps, and keep one Security Officer who understands both clocks.