If you are aiming for DISP membership and your blocker is the cyber domain, you need more than a strategy slide. You need an Essential Eight ML2 evidence pack. This checklist is the conversation we have with applicants before they tell a prime "we're nearly there."
How to use this Essential Eight ML2 checklist
Work strategy by strategy. For each item, capture: current state, gap, owner, target date, and the artefact you will show an assessor. "In progress" without artefacts is not readiness.
1. Application control
- Do you prevent unapproved executables from running on workstations and servers in scope?
- Are rulesets maintained, reviewed, and exception-managed?
- Can you show what happens when something unapproved is blocked?
Weak application control is one of the most common Essential Eight Maturity Level 2 gaps for DISP membership applicants.
2. Patch applications
- Are internet-facing and high-risk applications patched inside ML2 timeframes?
- Is vulnerability intake continuous, not quarterly theatre?
- Are unsupported applications removed or tightly isolated with a documented risk decision?
3. Configure Microsoft Office macro settings
- Are macros disabled by default for users who do not need them?
- Is trusted locations / publisher policy deliberate rather than wide open?
- Can you evidence the setting across the fleet, not one gold-image laptop?
4. User application hardening
- Are web/office hardening baselines applied and monitored for drift?
- Have you removed or constrained legacy features attackers still abuse?
5. Restrict administrative privileges
- Are privileged accounts separate from everyday user accounts?
- Is local admin removed from standard users?
- Is privileged access time-bound, logged, and reviewable?
For DISP membership, privilege hygiene is both a cyber control and a governance signal.
6. Patch operating systems
- Are workstations and servers patched to ML2 expectations?
- Is there a reliable inventory so "unknown devices" cannot skip patching?
- Are internet-facing systems prioritised correctly?
7. Multi-factor authentication
- Is MFA enforced for remote access, privileged access, and key cloud apps?
- Are SMS-only edge cases understood and minimised?
- Can you produce coverage reports, not screenshots of one account?
MFA gaps are still one of the fastest ways to fail a serious Essential Eight ML2 readiness review.
8. Regular backups
- Are critical systems backed up on a defined schedule?
- Are backups protected from the same identity that administers production?
- Have restore tests happened recently — with records?
What "good enough for DISP membership" looks like
You do not need a perfect score on day one of planning. You do need:
- An honest ML2 gap register
- Funded remediation for the cyber domain
- Evidence that improves every fortnight
- Clear ownership between IT, security, and the DISP Security Officer role
Common mistake: scoping cyber too narrowly
Some applicants try to declare a tiny "DISP enclave" while staff handle Defence-related email and files on ordinary corporate systems. Assessors notice. For DISP membership cyber domain work, scope the environment that actually processes the information — then apply Essential Eight Maturity Level 2 there.
Next step
Complete this checklist once with your technical lead in the room. The first honest pass usually reveals whether you are weeks or months from a credible DISP membership cyber submission.