"How long does DISP membership take?" is the second question after "what level do we need?" There is no published stopwatch. Time is driven by how honestly you scoped the four domains, how complete the evidence is, and how fast you answer DSA.
What you can control
Preparation, not the queue
You control gap assessment, business case, evidence, and response time. You do not control DSA's internal queue. Companies that blame "Defence being slow" are often still missing artefacts.
A working sequence
1. Discovery and gap assessment 2. Domain-by-domain roadmap 3. Application pack and liaison 4. Implementation of anything still open — often Essential Eight ML2 5. Ongoing membership hygiene
If step 4 is still a wish list when you submit, the clock is not really running on membership. It is running on uplift.
What usually adds months
- Asking for a higher level than the business case supports
- Cyber not at ML2, with no dated plan
- Personnel screening that exists only as a verbal process
- Physical security described in adjectives instead of zones and access lists
- A Security Officer who cannot be reached for two weeks at a time
A realistic way to talk about time internally
Tell the board: "We can be application-ready in X weeks if we freeze scope and fund the gaps. DSA then takes as long as the pack and the queue require." That is an adult forecast. "We will be members by the tender date no matter what" is how businesses sign contracts they cannot support.
If you want the path in one place, start with how to apply and keep the common mistakes list next to the project plan.