DSPF

Defence Security Principles Framework compliance

Practical guidance for meeting DSPF requirements across personnel, physical, cyber, and governance security domains — for organisations in the Australian defence supply chain.

AGSVA Cleared Team Canberra-Based Defence-Experienced

DSPF Domains

Compliance Status

Personnel Security COMPLETE
Physical Security COMPLETE
Cyber Security IN PROGRESS
Governance IN PROGRESS
Domains
4 Assessed

DISP

Aligned

Why organisations need DSPF compliance support

Multiple security domains

The DSPF spans personnel, physical, cyber, and governance security. Understanding what's required across all four domains — and how they interact — is a significant undertaking.

Unclear requirements

DSPF requirements can be difficult to interpret, especially for organisations encountering defence security frameworks for the first time.

DSPF underpins DISP

Meeting DSPF requirements is fundamental to DISP membership. Gaps in any domain can delay or derail your DISP application.

What's included in our DSPF support

DSPF gap assessment

Assessment of your current posture against DSPF requirements across all applicable security domains.

Domain-specific remediation plans

Targeted action plans for personnel, physical, cyber, and governance security gaps.

Policy and procedure development

Security policies and procedures aligned to DSPF requirements and your operational context.

DISP alignment mapping

Clear mapping of your DSPF compliance to DISP membership requirements.

Implementation support

Hands-on guidance to implement DSPF controls and build the documentation Defence expects.

Who this service is for

Pre-DISP organisations

Early Stage

You're preparing for DISP membership and need to understand and meet DSPF requirements as the foundation for your application.

Existing DISP members

Ongoing

You need to maintain compliance with evolving DSPF requirements and ensure your security posture stays current.

Defence subcontractors

Urgent

Your prime contractor or Defence engagement requires demonstrated DSPF alignment across your security domains.

Proof

Real engagements, real outcomes

Anonymised

Federal department

ML2 across a complex, multi-system estate.

Led the department's Essential Eight maturity review using ACSC verification methodology, then ran continuous-assurance activities through annual PSPF reporting and ASD cyber survey submissions — keeping E8 posture live between formal reviews.

Anonymised

Federal agency

3 Security Risk Assessments cleared in one review window.

Scoped, assessed, and reported on three high-priority SRAs in a single calendar year — an enterprise integration platform, a supplier-security uplift, and a public-facing online services portal with paired penetration testing — all delivered inside the agency's assessment window.

Anonymised

Federal agency

Board-ready cyber governance, stood up from scratch.

Delivered executive and board-ready cyber governance papers, stood up a Foreign Ownership Control and Influence process, and supported system accreditation activities across a shared-services environment — so the agency walked into its next review with defensible answers.

Frequently asked questions about DSPF compliance

What's the difference between DSPF and DISP?

The DSPF is the framework that defines the security principles and requirements. DISP is the program that assesses organisations against those requirements for membership. Think of DSPF as the rules, and DISP as the registration process.

Do we need to comply with all DSPF domains?

It depends on your DISP membership level and the nature of your defence work. We help you determine which domains and requirements apply to your specific situation.

How does DSPF relate to ISM and PSPF?

The DSPF draws on elements from both the ISM (for cyber security) and PSPF (for protective security). We help you understand how these frameworks interact and where your existing compliance efforts already cover DSPF requirements.

How long does DSPF alignment take?

For a pre-DISP SME, DSPF mapping and evidence prep typically runs 4-8 weeks. For existing DISP members it's integrated into ongoing member obligations so you're not pulling extra effort each review cycle.

How do we budget for DSPF work?

DSPF work is scoped alongside your broader DISP or Essential Eight program. Pricing is provided per engagement after an initial scoping call.

How is this different from generic cyber advisory?

DSPF is defence-specific and the evidence standards are exacting. We've mapped DSPF requirements against ISM and E8 for federal agencies — not a generic framework translated at arm's length.

Need help navigating the DSPF?

Talk to our team about your defence security requirements.

Canberra-based · AGSVA cleared · Defence-experienced