AUKUS Security Obligations for Australian Industry Partners

aukus defence security disp security security compliance Jul 23, 2026

AUKUS Security Obligations for Australian Industry Partners

AUKUS β€” the trilateral security partnership between Australia, the United Kingdom, and the United States β€” represents the most significant shift in Australia's strategic posture in decades. Pillar II of the partnership, which covers advanced capabilities including hypersonics, quantum, artificial intelligence, undersea systems, and electronic warfare, creates substantial opportunities for Australian defence industry companies.

It also creates substantial security obligations.

For Australian organisations seeking to participate in AUKUS programs β€” or already doing so β€” understanding what those obligations look like is not optional. They are a condition of access.


The AUKUS Security Framework

AUKUS involves the sharing of some of the most sensitive defence technology and information among the three partner nations. The security requirements attached to that sharing reflect the sensitivity of what is being protected.

For Australian industry participants, AUKUS security obligations build on the existing DISP framework β€” but in many cases go beyond it. The specific requirements depend on the nature of the program, the classification level of information involved, and the specific arrangements between the Australian Government and industry partners.

At a minimum, AUKUS industry participation requires:

DISP accreditation at the appropriate tier. The baseline requirement for access to classified Australian defence information. The tier required will depend on the classification level of information the organisation will handle in the AUKUS context.

Alignment with US and UK security requirements. AUKUS information sharing involves information from all three nations, and Australian industry participants must be able to meet the security requirements of US and UK information β€” not just Australian requirements. This creates additional obligations around facility security, ICT security, and personnel security that may exceed what DISP alone requires.

Foreign ownership and control assessment. AUKUS partners β€” and particularly the United States β€” have significant concerns about foreign ownership, control, and influence (FOCI) over organisations that will have access to AUKUS technology. Organisations with foreign shareholders, foreign board members, or foreign operational relationships must carefully assess the implications for their AUKUS participation.

Supply chain security. AUKUS supply chains are themselves a security concern. Organisations participating in AUKUS programs must assess and manage the security of their own supply chains β€” ensuring that subcontractors and suppliers do not create security risks that would undermine the program's protection requirements.


Foreign Ownership, Control, and Influence

FOCI is one of the most complex and consequential security considerations for Australian industry partners in AUKUS programs.

The US National Industrial Security Program (NISP), which governs US classified information sharing with industry, has detailed FOCI requirements. Australian companies with US foreign ownership or significant US operations may already be familiar with these requirements. For those that are not, the assessment can be complex and the mitigation measures β€” which can include board resolutions, security agreements, and in some cases structural changes β€” take time to implement.

Similarly, Australian companies seeking to participate in AUKUS programs should expect scrutiny of any foreign shareholding, foreign board representation, or foreign contractual relationships that could provide foreign principals with access to, or influence over, AUKUS-related activities.

This is not a concern limited to obviously foreign-owned organisations. Even minority foreign shareholdings, in the wrong circumstances, can create FOCI issues that affect program eligibility.


ICT Security Requirements

The information security requirements for AUKUS program participants go beyond standard DISP ICT requirements in many cases. Organisations should expect:

  • Essential Eight at Maturity Level 2 or above as a baseline
  • Specific network segregation requirements for AUKUS information
  • Device management and endpoint security requirements
  • Specific controls for US and UK classified information that may differ from ASD ISM requirements
  • Incident reporting requirements that include both Australian and partner nation authorities

The specific ICT requirements will be defined in program documentation and security agreements. Organisations should not assume that existing DISP-compliant ICT environments automatically satisfy AUKUS requirements without confirmation.


Personnel Security

Access to AUKUS information at higher classification levels requires security clearances that match the classification. For access to US AUKUS information, Australian personnel may need to meet both Australian and US personnel security requirements.

The timelines for obtaining and maintaining appropriate clearances are not short. Organisations entering AUKUS programs need to start clearance sponsorship processes well ahead of when access will be required.


What Organisations Should Do Now

For organisations seeking AUKUS participation:

  1. Assess current DISP accreditation status and the gap to the tier required for the program
  2. Conduct a FOCI assessment β€” understand the foreign ownership and control picture before it becomes a disqualifying surprise
  3. Map current ICT security posture against likely AUKUS ICT requirements
  4. Begin clearance sponsorship processes for personnel who will require access
  5. Engage with the Defence Industry Security Office early β€” DISO is the primary engagement point for DISP and AUKUS security requirements

Empire Protection β€” AUKUS Security Advisory

Empire Protection provides security advisory services for organisations seeking to participate in AUKUS programs. We assist with DISP gap assessments, Security Management Plan development, FOCI analysis, and ICT security posture review in the AUKUS context.

Contact Empire Protection


Empire Protection β€” Demand Excellence in everything we do. Sydney, Australia | empireprotection.global

The Right People, The Right Methods, The Right Results.
In everything we do,Β Empire ProtectionΒ Demands Excellence.