The Defence Industry Security Program (DISP) has introduced a revised Maturity Action Plan (MAP) implementation model designed to simplify cyber uplift processes, improve accountability, and provide organizations with a more practical pathway to achieving security maturity. The new approach is effective immediately and represents a significant shift in how cyber remediation activities are managed and monitored across the DISP community.  

A Simpler, More Effective Approach 

Under the previous model, organizations were required to return MAPs within prescribed 28-business-day and 75-day timeframes. These requirements have now been removed. Instead, organizations will be granted 12 months from the date a MAP is issued to complete implementation activities 

This change delivers several benefits: 

  • Reduces the administrative burden associated with extension requests. 
  • Provides organizations with a realistic timeframe to implement meaningful cyber security improvements. 
  • Strengthens accountability for achieving security maturity outcomes. 
  • Enables more consistent monitoring and reporting of progress.

How the New MAP Framework Works 

The revised MAP model is built around continuous engagement and assurance rather than short-term compliance deadlines. 

Key Components

The new framework includes: 

  • 12-Month Implementation Period 
    Organizations have up to 12 months to complete agreed cyber security uplift activities after receiving a MAP.  
  • Monthly Assurance Reviews 
    DISP Cyber will conduct regular assurance reviews to assess progress, identify emerging risks, and ensure implementation activities remain on track.  
  • Quarterly Touchpoints 
    Structured engagements between organizations and DISP Cyber will provide opportunities to discuss progress, challenges, and support requirements.  
  • Ongoing Progress Tracking 
    Progress will be monitored throughout the implementation period, allowing for greater transparency and visibility of cyber maturity uplift efforts.  
  • Integrated Escalation Process 
    MAP oversight will now be incorporated into the DISP Audit and Assurance Escalation Process. Where risks warrant faster action, risk-based escalation mechanisms remain available. 

What This Means for DISP Members 

The revised MAP framework shifts the focus from meeting short-term administrative milestones to achieving sustainable cyber security outcomes. Organizations are encouraged to treat the 12-month period as an opportunity to implement meaningful improvements, demonstrate measurable progress, and strengthen resilience against evolving cyber threats.  

For organizations already working through existing MAPs, transitional arrangements will apply. These arrangements include additional implementation timeframes for members with outstanding or unreviewed MAPs, helping ensure a smooth transition to the new model.  

Supporting Continuous Cyber Maturity 

DISP Cyber will be responsible for operationalizing the revised framework through consistent application, robust record keeping, and timely escalation where implementation risks or non-completion concerns arise. The result is a more collaborative and outcomes-focused approach that supports both compliance and long-term cyber security maturity.  

Looking Ahead 

The introduction of the revised MAP model reinforces DISP’s commitment to helping industry partners build stronger cyber security capabilities while maintaining accountability and assurance. By providing greater flexibility, structured engagement, and ongoing oversight, the framework aims to support sustainable security uplift across the Defence industry ecosystem.