DISP UPDATES · 7 MIN READ

New changes coming to DISP: what Australian suppliers should watch in 2026

New changes are coming to DISP — not as a single overnight rewrite of the membership rulebook, but as a set of overlapping shifts that suppliers feel in assessments, prime questionnaires, and cyber uplift programs. If you only track "are we DISP members yet?" you will miss the moving parts that decide how hard membership is to win and keep.

Change 1: Cyber expectations hardened around Essential Eight ML2

For many applicants, the most tangible change in the DISP membership journey has been the ICT/cyber domain. The practical bar is Essential Eight Maturity Level 2 across corporate IT, not a lightweight subset of controls at Maturity Level 1.

That change alone has stretched timelines for companies that treated cyber as a paperwork exercise.

Change 2: Essential Eight itself is on a retirement path

In June 2026, ASD confirmed the Essential Eight will be retired over roughly two years and replaced by the broader Essentials series, starting with Essentials for Enterprise IT.

What that means for DISP membership planning:

  • Essential Eight remains live and supported now
  • ML2 work you do today should map forward, not be thrown away
  • Waiting for the "final final" framework is a bad strategy if you have contracts depending on DISP

So yes — new changes are coming to DISP-relevant cyber guidance — while today's assessable baseline is still Essential Eight-shaped.

Change 3: Primes are raising the floor before contracts land

Even where Defence's published wording moves carefully, primes often move faster in procurement. DISP membership is increasingly a gate. Evidence of Essential Eight ML2 is increasingly a second gate. Suppliers who only chase the membership certificate without cyber depth get stuck between "approved on paper" and "not trusted on the network."

Change 4: Domain scoping is under more scrutiny

DISP membership is four domains, not one score. Governance must track the highest level elsewhere. Personnel, physical, and cyber must be justified with a business case above Entry Level. New applicants who still ask "what level do we need?" as a single number are asking the wrong question — and changes in how primes review subcontractors make that mistake more expensive.

What to do this quarter

1. Re-baseline your cyber domain against Essential Eight Maturity Level 2. 2. Document DISP membership scope domain-by-domain with a real business case. 3. Assign a single owner for framework transition watching (Essentials series drafts). 4. Build evidence continuously — membership and cyber assurance both feed on artefacts. 5. Brief leadership that DISP is an operating system, not a one-time application event.

What not to do

  • Do not freeze Essential Eight ML2 projects "until Essentials is finished."
  • Do not assume Entry Level cyber thinking will satisfy modern prime due diligence.
  • Do not treat DISP membership as finished on the day the letter arrives — managed compliance is the product.

The Skyline view

New changes coming to DISP are best read as a direction of travel: higher assurance, clearer cyber baselines, and less patience for theatre. Companies that treat 2026 as a year to professionalise governance and complete Essential Eight ML2 will be in better shape than companies waiting for certainty that will not arrive all at once.

NEXT STEP

Want a DISP change briefing tailored to your company?

Tell Skyline AI what domain you are targeting and we can point you to the right next conversation.

Talk to Skyline AI
Skyline AI