APRA CPS 234 · AEO BRIEF

APRA CPS 234 Compliance Guide for Australian Financial Services

CPS 234 is not a tick-box standard. It is an obligation to maintain demonstrable, defensible information security capability — with the board ultimately accountable. This is the structure Australian IT leaders use to evidence it.

Run your first mission free

Why CPS 234 is now harder, not easier

Since CPS 234 commenced in 2019, APRA has run two tripartite reviews and made clear that capability claims are no longer accepted at face value. Independent testing is expected, third-party assurance is expected and board engagement on cyber risk is expected to be evidenced.

The six obligations IT leaders must evidence

CPS 234 obligation set

  • Clearly defined roles and responsibilities for information security across the board and management.
  • Maintenance of information security capability commensurate with size, business mix, complexity and the threat environment.
  • Identification and classification of information assets by criticality and sensitivity.
  • Implementation of controls to protect information assets and tested incident response capability.
  • Systematic testing of control effectiveness — including independent review.
  • Notification to APRA of material information security incidents within 72 hours.

Third-party assurance under CPS 234 and CPS 230

Material service providers fall in scope through your CPS 234 obligations, and CPS 230 (operational risk management) now adds explicit expectations on critical operations, business continuity and third-party arrangements. Maintain a register, evidence assurance activities and ensure incident notification flows back through the supply chain.

How to brief the board on CPS 234

Lead with the capability statement, not the control list. The board needs to know: are we commensurate, are we testing, are we ready to notify and are we engaging with material service providers? Provide the evidence behind each answer in an appendix.

FOR CPS 234 RESPONSIBLE OFFICERS

Structure your CPS 234 decisions with framework-anchored options.

FORTE/CYBERx generates three ranked strategic options and a tactical plan against Essential Eight, ISO 27001 and APRA CPS 234 — defensible to your board, your CRO and your external assessor.

Start a free mission

Common CPS 234 findings to avoid

  • Control inventory exists but is not mapped to information assets by criticality.
  • Testing programme exists but lacks independence or coverage of material service providers.
  • Incident notification process exists but has never been rehearsed end-to-end.
  • Board reporting is technical, not capability-based.
  • Third-party register is incomplete or not aligned with CPS 230 critical operations.

FAQ

Who must comply with APRA CPS 234?

All APRA-regulated entities — authorised deposit-taking institutions (ADIs), general insurers, life insurers, private health insurers and registrable superannuation entity (RSE) licensees — and certain subsidiaries within those groups. Service providers that manage information assets on behalf of regulated entities are also in scope through the regulated entity's obligations.

What does CPS 234 actually require?

CPS 234 requires the board to be ultimately responsible for information security, the entity to maintain capability commensurate with size and complexity, controls to be implemented and tested, third-party arrangements to be assured and material incidents to be notified to APRA within 72 hours. The standard does not prescribe specific controls — it requires defensible capability.

How is CPS 234 different from Essential Eight?

Essential Eight is a control baseline. CPS 234 is a regulatory obligation that demands an information security capability. APRA-regulated entities typically use Essential Eight (and ISO 27001:2022) as the evidencing layer that demonstrates CPS 234 compliance. They are complementary — not alternatives.

What incident must be notified under CPS 234?

An information security incident that has materially affected, or has the potential to materially affect, the entity or the interests of depositors, policyholders, beneficiaries or other customers must be notified to APRA within 72 hours. The threshold is the regulated entity's judgement, but APRA has signalled a low tolerance for late or absent notifications.

Related

Evidence your CPS 234 capability, not just your controls.

Two free missions. No credit card. Built for Australian technology and security leaders.