DISP vs SOCI Act
Understanding the Difference Between DISP and the Security of Critical Infrastructure Act
Australia’s national security framework includes multiple overlapping regimes. Two of the most important are:
The Defence Industry Security Program (DISP)
The Security of Critical Infrastructure Act 2018 (SOCI Act)
While both are designed to enhance the security and resilience of Australia’s assets, they serve different purposes, target different sectors, and are managed by different government agencies.
This page breaks down the distinctions, compliance requirements, and how they can work together to strengthen your organisation’s security posture.
What is DISP?
DISP is administered by the Department of Defence and applies specifically to organisations working on or supporting Defence contracts. Its purpose is to ensure contractors meet high standards in:
Security Governance
Personnel Security
Physical Security
Information and Cyber Security
DISP accreditation is voluntary, but in practice, it is frequently required for Defence-related projects and often built into tender or subcontracting conditions.
Read: What is DISP →
What is the SOCI Act?
The Security of Critical Infrastructure Act 2018 (SOCI Act) is managed by the Department of Home Affairs and applies to businesses operating in Australia’s critical infrastructure sectors, including:
Energy
Water
Ports
Communications
Data storage and processing
Space, transport, healthcare, food and grocery, education
The SOCI Act imposes mandatory obligations related to risk management, incident reporting, and access control for assets deemed nationally significant. It is legislated, and non-compliance can result in regulatory enforcement.
Do I Need to Comply with Both?
Yes, in some cases.
If your organisation is both:
A supplier to Defence, and
An operator or service provider to a critical infrastructure asset,
then you may need to comply with both DISP and SOCI obligations.
In such scenarios, integration of compliance strategies becomes essential. We recommend:
Centralised security governance frameworks
Mapped controls across DISP, SOCI, and ISO 27001/31000
Consolidated risk registers and incident reporting workflows
How Are They Aligned?
While separate frameworks, DISP and SOCI share several common requirements:
Cybersecurity uplift (aligned to ACSC’s Essential Eight)
Insider threat mitigation
Supply chain due diligence
Incident response and breach reporting
Board-level governance and accountability
See our DISP-to-SOCI mapping guide →
Our Support Services
DefenceIndustries.com.au helps organisations navigate both DISP and SOCI with:
Joint DISP/SOCI control mapping templates
Risk management plans aligned to ISO 31000
Cybersecurity strategies aligned with ACSC and Australian Signals Directorate
ReadiNow integration for continuous governance
Board briefings and executive risk workshops