On this page

Defence is one of the most demanding environments an Australian small or medium business can supply into. The work is often long-cycle and milestone-based, the margins have to survive years of delivery, and sitting over all of it is a security framework that touches who can see your information, where it is held and how it is protected. Getting the bookkeeping right in that environment is not just about clean books, it is about keeping sensitive data onshore, auditable and under control. This guide sets out the framework factually, then explains why the financial side belongs onshore.

Security clearances needed at each level of defence support

Personal security clearances in Australia are issued by the Australian Government Security Vetting Agency (AGSVA). The level of clearance a person needs is set by the highest classification of information they will access, not by their job title. There are four levels.

Clearance levelAccess up to and includingTypical defence-support context
BaselinePROTECTEDStaff handling sensitive but lower-classified Defence information or sites
Negative Vetting 1 (NV1)SECRETRoles working with SECRET material in a supply chain or project
Negative Vetting 2 (NV2)TOP SECRETRoles needing access to TOP SECRET information
Positive Vetting (PV)TOP SECRET, including caveated and code-wordThe most sensitive roles and compartmented information

The information itself is classified as OFFICIAL, OFFICIAL:Sensitive, PROTECTED, SECRET or TOP SECRET. A great many supply-chain roles, including most back-office and financial roles, never touch classified material and so need no personal clearance at all. Where they do, the clearance must match the classification, and access is granted on a need-to-know basis. The practical point for a business owner is simple: know exactly what classification your people and systems touch, because that drives everything else.

DISP membership: the business-level requirement

Separate from individual clearances is the Defence Industry Security Program (DISP), which is Defence's membership scheme for the business. You will generally need DISP membership when your business handles sensitive or classified information or assets, stores or transports Defence weapons or explosive ordnance, provides security services for Defence bases, or joins a Defence supply chain. Membership is tiered and set per security domain:

DISP levelAligned to
Entry LevelBaseline governance, suitable for lower-risk supply-chain entry
Level 1PROTECTED
Level 2SECRET
Level 3TOP SECRET

DISP sets requirements across four security domains: security governance (accountability, plans, processes, training and incident reporting), personnel security (the suitability of staff and contractors, including screening to Australian Standard AS 4811:2022), physical security (protecting people, property and assets at your sites), and information and cyber security (protecting Defence information on your corporate systems). Your financial systems and the people who run them sit inside the personnel and information-security domains, which is exactly why where your bookkeeping is done, and by whom, becomes a security question, not just a cost one.

Why defence financial and contract data should be onshore

Financial and operational data for Defence work is more sensitive than it looks. Contract values, milestone schedules, cost breakdowns, supplier lists and capacity information can be commercially sensitive, export-controlled, or revealing of capability even when no single document is formally classified. Defence contracts and DISP obligations commonly require that information stay onshore, that access is limited to the people who need it, and that it can be audited. Sending that bookkeeping offshore, even just data entry, puts the information outside Australian control and can quietly breach a contract or a DISP condition. For defence-adjacent businesses, onshore is the safe default and offshore is a risk that is rarely worth the hourly saving.

Why that data should be secured in Australia

Keeping data onshore is about data sovereignty: information held in Australia stays under Australian law and Australian jurisdiction, rather than exposed to foreign access regimes. For Defence information the expectation is that it sits on appropriately assessed systems, Australian-hosted cloud or infrastructure evaluated through programs such as the Information Security Registered Assessors Program (IRAP), with proper access controls and logging. It is also a privacy obligation: under Australian Privacy Principle 8 you remain accountable for how any overseas party handles personal information, so the responsibility does not travel with the data. In short, for Defence work, Australian-hosted and Australian-controlled is the standard, and a bookkeeping arrangement has to respect it.

Audit, traceability and record-keeping

Defence businesses live with more scrutiny than most. DISP members report security incidents and undergo ongoing assurance, project contracts carry their own audit and reporting clauses, and the financial records behind milestone claims and cost-recovery have to stand up to examination. That makes disciplined bookkeeping a security and contractual asset, not just good practice: every transaction coded correctly and traceable, milestone and progress claims reconciled against the contract, grant and program funding acquitted cleanly, and records retained for the required period with a clear audit trail. When an audit or a review comes, the answer should be a report you run, not a reconstruction. Keeping that system onshore, with controlled access, means the audit trail itself never leaves Australian control.

Interpreting the numbers in the current economic climate

Clean books are the floor. The value for a defence-supply-chain business is in reading them in context, and the context right now is demanding. Long, milestone-based contracts mean cash can be committed years ahead of payment, so cash-flow forecasting against the contract schedule matters more than a month-end snapshot. Input-cost inflation and higher interest rates squeeze margins that were quoted against an earlier cost base, so tracking real margin per contract, not just revenue, is essential. Supply-chain and currency movements affect imported components and timelines. And against all of that sits a period of rising defence investment under the national strategy, which creates opportunity but also pressure to scale capacity without over-committing cash. Interpreting the financials means pairing the numbers with that climate: forecasting to the milestone schedule, protecting margin as costs move, and keeping the business liquid enough to deliver long programs. That is CFO-level thinking applied to the books, and it is where bookkeeping stops being compliance and starts being strategy.

How True Tally supports defence-adjacent businesses

We are an Australian, onshore bookkeeping practice and registered BAS service provider. For businesses in the Defence supply chain that means your financial data stays in Australia, under Australian control, with access limited to the people who need it. We keep the books disciplined and audit-ready, reconcile milestone and progress claims against the contract, and provide the management reporting and cash-flow forecasting that long defence programs demand, working alongside your own security governance rather than stepping into it. For the classified and security-controlled elements, your cleared personnel and DISP-compliant systems lead; we make sure the financial record-keeping that supports it is accurate, onshore and defensible.

Who this applies to

Defence supply chains are far broader than the primes. The obligations above reach manufacturers and machine shops making components, engineering and technical services firms, logistics and transport providers, ICT and cyber suppliers, facilities and maintenance businesses, and the many professional and trade subcontractors that sit beneath a prime contractor. Many of these are ordinary small and medium businesses that took on Defence work and inherited a security framework they did not previously have to think about. The financial-data obligations do not only apply to those handling TOP SECRET material; a business at DISP Entry Level or Level 1, handling nothing more than PROTECTED information and commercially sensitive contract data, still has good reason to keep its books onshore and controlled, because the contract data behind the work is sensitive and the obligation to protect it is the same.

Common financial pitfalls for defence SMEs

  • Treating milestone claims as income when invoiced, not when earned, which distorts both profit and the real cash position on a long contract.
  • Losing visibility of true margin per contract as input costs rise against a price quoted on an older cost base.
  • Letting cash get committed years ahead of payment without forecasting against the milestone schedule, so a profitable program still creates a cash squeeze.
  • Under-costing the compliance overhead of DISP, security governance and audit, then wearing it out of margin.
  • Offshoring back-office data entry to save a little, and putting sensitive contract data outside Australian control to do it.

None of these are exotic. They are ordinary bookkeeping and reporting failures made costly by the Defence context, and all of them are avoidable with disciplined, onshore books read against the contract.

Supplying Defence and want your bookkeeping kept onshore, disciplined and audit-ready? Book a free call. General information only, not security or legal advice, confirm your specific obligations with Defence or your security officer.