Cyber Ethos

APRA CPS 234 Compliance Australia: Requirements, Deadlines & Checklist (2026) | Cyber Ethos
APRA CPS 234 Guide · Australia 2026

APRA CPS 234 Compliance in Australia: What It Requires & How to Comply

A guide for boards, risk and compliance leaders, and IT teams at Australian banks, insurers, and super funds — and the service providers who work with them. What CPS 234 demands, the deadlines that matter, and how to meet them without the jargon.

KK
Dr. Kiran Kewalramani · PhD · CISSP · CISA · GAICD
Founder, Cyber Ethos · 20+ years in cybersecurity · Queensland, Australia
72 hours
Deadline to notify APRA of a material security incident
10 days
Business days to report a material control weakness
A$5.61M
Average data breach cost in Australian financial services (IBM)
2019
In force since 1 July — and now actively enforced

What Is APRA CPS 234?

CPS 234 is the information security rulebook for Australia's financial sector. It's a prudential standard set by APRA — the Australian Prudential Regulation Authority, the body that oversees banks, insurers, and super funds — and it spells out what those organisations must do to protect the information they hold and respond when something goes wrong.

Two things make it matter. First, it carries the force of law — it isn't optional guidance. Second, the Board is ultimately accountable for meeting it, so this is a boardroom issue, not just an IT one.

The one-paragraph answer

APRA CPS 234 (Prudential Standard CPS 234 Information Security) has applied since 1 July 2019. It requires APRA-regulated financial entities to clearly assign responsibility for information security, maintain security capabilities that match the threats they face, protect and test their controls, manage the risk from their service providers, and notify APRA quickly when there's a material incident or control weakness.

In short: it sets the minimum information security standard for anyone APRA regulates — and holds the Board responsible for living up to it.

Who Must Comply With CPS 234?

CPS 234 applies to every entity APRA regulates. If you're in one of these groups, it applies to you directly:

🏦
Banks & ADIs
Authorised deposit-taking institutions — banks, credit unions, and building societies.
🛡️
General insurers
Providers of general insurance regulated under the Insurance Act.
💛
Life insurers
Life insurance companies and friendly societies.
🏥
Private health insurers
Registered private health insurance providers.
💰
Superannuation funds
Registrable superannuation entity (RSE) licensees.
🏢
Holding companies
Relevant authorised non-operating holding companies (NOHCs) in these groups.
The part that catches people out

CPS 234 doesn't stop at the regulated entity. Because a bank or insurer stays accountable for the security of any third party that manages its information assets, cloud, SaaS, and IT service providers to the financial sector are routinely required — through their contracts — to meet CPS 234-style obligations too. You can be bound by CPS 234 in practice even if you're not a bank. More on this below.

The 8 Obligations of CPS 234, Explained Simply

The standard's requirements fall into eight areas. Here's what each one means in plain terms.

  1. Define who's responsible
    Clearly set out the information security roles and responsibilities of the Board, senior management, and staff. The Board is ultimately accountable — security can't be left as "someone in IT's problem."
  2. Maintain a security capability that fits the threat
    Keep an information security capability sized to the threats you actually face — and keep it current as those threats evolve. A small credit union and a major bank are not expected to do identical things, but both must be proportionate.
  3. Classify your information assets
    Identify what information and systems you hold and classify them by how critical and sensitive they are, so your protection matches what matters most.
  4. Put controls in place
    Implement security controls to protect those assets across their whole life — from creation through to disposal — taking account of current and emerging threats.
  5. Manage your third parties
    Where a service provider manages your information assets, assess and assure their security too. You can outsource the work — but not the accountability.
  6. Test that your controls actually work
    Run a systematic testing program to prove your controls are effective — carried out by skilled, functionally independent specialists, at least annually and whenever something material changes.
  7. Have internal audit review it
    Your internal audit function must review the design and operating effectiveness of your information security controls — an extra, independent set of eyes.
  8. Notify APRA, fast
    Tell APRA within 72 hours of a material information security incident, and within 10 business days of a material control weakness you can't fix promptly. (Detailed next.)

The 72-Hour Notification Rule (and the 10-Day One)

The notification obligations are the part of CPS 234 most likely to trip an organisation up in the heat of a real incident — so they're worth knowing cold.

The two clocks you must not miss

72 hours — notify APRA as soon as possible, and no later than 72 hours, after becoming aware of a material information security incident.

10 business days — notify APRA after becoming aware of a material information security control weakness you don't expect to remediate in a timely way.

What counts as a "material incident" is broader than many assume. The 72-hour clock starts if an incident:

  • Materially affected — or could have materially affected — your organisation or your customers, financially or non-financially (including reputational and operational harm); or
  • Has been notified to any other regulator, in Australia or overseas. This is an automatic trigger — if you've told another regulator, you tell APRA too.

Crucially, you don't have to wait until you've confirmed harm. The obligation is triggered by actual or potential material impact — so the safe assumption during an incident is that the clock is already running.

The ransomware double-clock

Since 2025, Australia's Cyber Security Act has added a separate mandatory reporting obligation for organisations that make a ransomware payment — with its own 72-hour deadline to a different government body. For an APRA-regulated entity that pays a ransom, that can mean two 72-hour clocks running at once, to two different regulators. Knowing this in advance — and having it in your incident plan — matters.

The Part Most Organisations Underestimate: Third-Party Obligations

If there's one area where organisations fall short, it's third-party risk — and it's also the reason CPS 234 reaches well beyond the banks and insurers themselves.

Under CPS 234, an APRA-regulated entity stays accountable for the security of its information assets even when a third party manages them. So if your data sits in a cloud platform, is processed by a SaaS application, or is handled by an outsourced IT provider, you must assess and assure that provider's information security — commensurate with the damage a breach there would cause.

In practice, this flows downhill through contracts. Service providers to the financial sector are routinely required to:

  • Maintain information security controls to an agreed standard;
  • Allow the regulated entity to assess and review their security;
  • Notify the regulated entity of incidents quickly, so the entity can meet its own 72-hour deadline.

This is why many technology and professional-services firms that have never heard of APRA find CPS 234 obligations written into their contracts. And the bar has risen further: the newer CPS 230 standard now also requires regulated entities to keep registers of their material service providers and to hold appropriate contractual rights — with existing contracts needing to comply by the earlier of 1 July 2026 or their next renewal.

KK
Practitioner's advice
"The single most common gap I see isn't a missing firewall — it's a board that treats CPS 234 as an IT compliance task to be delegated and forgotten. The standard is deliberately written the other way around: the Board is ultimately accountable, and under the Financial Accountability Regime, named executives now are too. Treat it as a governance obligation that IT helps you meet, not an IT obligation the board signs off once a year, and most of the hard parts fall into place."
— Dr. Kiran Kewalramani, PhD, CISSP · Founder, Cyber Ethos

CPS 234 vs CPS 230: How They Fit Together

These two standards are often mentioned in the same breath, and they're related — but they're not the same thing.

  CPS 234 CPS 230
Focus Information security specifically Operational risk management and resilience, broadly
In force since 1 July 2019 1 July 2025 (replaced CPS 231 & CPS 232)
Covers Protecting information assets, testing controls, incident notification Critical operations, business continuity, and managing material service providers
Key notification 72 hours for a material information security incident 24 hours for a disruption to critical operations beyond tolerance

The simplest way to hold them in your head: CPS 234 protects your information; CPS 230 keeps your whole operation running and resilient. They're complementary — CPS 230 deals with operational risk overall and explicitly points to CPS 234 for the information security piece. If you're working on one, you should have the other on your radar.

Does CPS 234 Actually Have Teeth?

It's a fair question — plenty of standards look stern on paper and go unenforced. CPS 234 is not one of them, and the picture in 2026 is very different from 2019.

Rather than rewriting the standard, APRA has chosen to leave CPS 234 unchanged and sharpen its enforcement instead. Three developments show how real the consequences have become:

  • Industry-wide assessments exposed systemic gaps. APRA's tripartite assessment program — independent reviews across more than 300 regulated entities — found widespread, recurring weaknesses, putting the whole sector on notice.
  • The Medibank capital add-on proved the cost is real. Following its major data breach, APRA applied a substantial capital add-on to Medibank (a A$250 million charge), citing weaknesses in its information security environment — a clear signal that failings carry financial consequences.
  • Executives are now personally accountable. Under the Financial Accountability Regime (FAR), named senior executives can be held personally responsible for information security obligations — accountability that simply didn't exist when CPS 234 began.
The bottom line

"Compliant on paper" is no longer enough. APRA increasingly wants to see that your controls genuinely work, that they're independently tested, and that someone accountable can demonstrate it. A folder of policies that no one tests or follows is exactly what enforcement now looks for — and finds.

Does ISO 27001 Satisfy CPS 234?

This is one of the most common misconceptions, so let's be clear: no — ISO 27001 certification does not make you CPS 234 compliant.

That said, it's a genuinely strong head start. An ISO 27001 information security management system gives you documented controls, defined processes, and the evidence trails that directly support many CPS 234 obligations. If you're already certified, you've done a lot of the groundwork.

But CPS 234 has APRA-specific requirements that ISO 27001 doesn't cover, and you must address these separately:

  • The 72-hour and 10-business-day notification obligations to APRA;
  • The Board's ultimate accountability for information security;
  • Independent control testing on APRA's terms;
  • Third-party assurance aligned to the consequences of a breach.

Think of ISO 27001 as a strong foundation you build CPS 234 on top of — not a substitute for it. The two sit naturally together, alongside the Essential Eight, as part of a single, joined-up compliance picture.

How to Achieve (and Keep) CPS 234 Compliance

Compliance isn't a single project with an end date — it's an ongoing capability. Here's a practical path to get there and stay there.

  1. Establish board accountability and clear roles
    Make sure the Board understands its ultimate accountability, and document who is responsible for what across leadership, management, and staff.
  2. Classify your information assets
    Map what you hold and rank it by criticality and sensitivity, so effort flows to what matters most.
  3. Run a CPS 234 gap assessment
    Benchmark your current state against all eight obligation areas to see exactly where you stand — and where the gaps are.
  4. Remediate and strengthen controls
    Work through the gaps in priority order, with a roadmap sized to your risk and budget rather than a generic checklist.
  5. Put independent control testing in place
    Set up the systematic, independently-conducted testing CPS 234 requires — at least annually and after material change.
  6. Assess your third parties
    Identify who manages your information assets, assess their security, and get the right notification and assessment terms into your contracts.
  7. Build your APRA notification readiness
    Have the processes, playbooks, and decision-makers ready so the 72-hour and 10-day clocks are met under pressure — not scrambled.
  8. Embed it and keep it live
    Fold CPS 234 into internal audit and ongoing governance, with regular board reporting, so compliance stays current as threats and your business change.

5 Myths About CPS 234

Myth 1: "CPS 234 is just an IT problem."
Reality: The Board is ultimately accountable, and under the Financial Accountability Regime named executives can be personally on the hook. It's a governance obligation that IT helps deliver — not the other way around.
Myth 2: "We use a major cloud provider, so security is their problem."
Reality: Cloud is a shared responsibility, and CPS 234 makes you accountable for assessing and assuring any provider that manages your information assets. You can outsource the function, never the accountability.
Myth 3: "We're ISO 27001 certified, so we're compliant."
Reality: ISO 27001 is a strong foundation but doesn't satisfy CPS 234's APRA-specific obligations — notification deadlines, board accountability, independent testing, and third-party assurance still need to be addressed directly.
Myth 4: "We're not a bank, so CPS 234 doesn't apply to us."
Reality: It applies directly to insurers, health insurers, and super funds too — and indirectly to the service providers who manage APRA-regulated entities' information assets, via contractual flow-down.
Myth 5: "Compliance is a one-off project."
Reality: CPS 234 requires ongoing, at-least-annual independent testing, live readiness to notify within tight deadlines, and internal audit review. It's a continuous obligation, not a box ticked once.

How Cyber Ethos Helps With CPS 234

Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience across security and governance. We help APRA-regulated entities, and the providers who serve them, get and stay compliant — in plain language the board can act on. That includes:

  • A CPS 234 gap assessment. We benchmark you against all eight obligation areas and show you exactly where you stand and what to prioritise.
  • A right-sized remediation roadmap. Prioritised, board-ready, and scaled to your risk and budget — not a generic checklist.
  • Independent control testing. The skilled, functionally independent testing CPS 234 calls for, with results you can put in front of APRA.
  • Third-party assurance. Help assessing the service providers who manage your information assets, and getting the right terms in place.
  • APRA notification readiness. Incident processes and playbooks built around the 72-hour and 10-day clocks, so they're met under pressure.
  • Ongoing governance and board reporting. Through a Cyber Ethos virtual CISO, we can own the program day to day and report cyber risk to your board — keeping compliance live, not a once-a-year scramble.

Know exactly where you stand on CPS 234

Talk to Dr. Kiran Kewalramani directly. We'll assess your current position against the standard, show you the gaps in plain language, and give you a clear, prioritised path to compliance. No jargon, no pressure.

Request a CPS 234 gap assessment →
📞 1800 CETHOS (1800-238-467) · cyberethos.com.au

This guide is general information about APRA CPS 234, not legal or compliance advice. Your specific obligations depend on your circumstances — confirm them against the current standard published by APRA and with your own advisers.

Common Questions About APRA CPS 234

What is APRA CPS 234 in simple terms? +
CPS 234 is APRA's prudential standard for information security — the rulebook for how Australian banks, insurers, and super funds must protect their information and respond to incidents. It has applied since 1 July 2019, carries the force of law, and makes the Board ultimately accountable. In essence, it sets the minimum information security standard for anyone APRA regulates.
Who must comply with CPS 234? +
All APRA-regulated entities: banks and other authorised deposit-taking institutions, general insurers, life insurers, private health insurers, superannuation (RSE) licensees, and relevant holding companies. Its obligations also flow down to the third-party and related-party service providers that manage those entities' information assets — so cloud, SaaS, and IT providers to the financial sector are often bound by CPS 234-style requirements through their contracts, even though they aren't directly regulated by APRA.
What is the CPS 234 72-hour notification rule? +
You must notify APRA as soon as possible, and no later than 72 hours, after becoming aware of an information security incident that materially affected — or could have materially affected — your organisation or your customers, or that has been notified to any other regulator. You don't need to confirm harm first; potential material impact is enough to start the clock. Separately, you must notify APRA within 10 business days of a material control weakness you can't promptly fix.
What are the eight obligations of CPS 234? +
In plain terms: (1) define roles and responsibilities, with the Board ultimately accountable; (2) maintain a security capability matched to your threats; (3) classify your information assets by criticality and sensitivity; (4) implement controls to protect them; (5) assess the security of third parties that manage your assets; (6) systematically test control effectiveness using skilled, independent specialists; (7) have internal audit review those controls; and (8) notify APRA of material incidents within 72 hours and material control weaknesses within 10 business days.
Does CPS 234 apply if we only supply services to a bank or insurer? +
Indirectly, yes. CPS 234 makes the APRA-regulated entity accountable for the information security of any third party that manages its information assets. In practice, that means cloud, SaaS, and IT providers to financial institutions are usually required, through their contracts, to maintain controls, allow security assessments, and notify incidents quickly enough for their client to meet its own 72-hour deadline — even though they aren't directly regulated by APRA.
What's the difference between CPS 234 and CPS 230? +
CPS 234 is specifically about information security and has applied since 2019. CPS 230, effective 1 July 2025, is the broader operational risk management standard that replaced CPS 231 and CPS 232 — it covers operational resilience, critical operations, business continuity, and management of material service providers. They're complementary: CPS 230 handles operational risk overall and points to CPS 234 for the information security piece.
Does ISO 27001 satisfy CPS 234? +
No, but it's a strong foundation. An ISO 27001 management system gives you documented controls, processes, and evidence that support many CPS 234 obligations. However, certification alone doesn't make you compliant — you still need to address APRA-specific requirements such as the 72-hour and 10-business-day notifications, the Board's ultimate accountability, independent control testing, and third-party assurance.
What are the penalties for breaching CPS 234? +
CPS 234 is a legally enforceable prudential standard rather than one with set fines. APRA's enforcement tools include stepping up supervision, requiring independent audits and reviews, applying capital add-ons (as it did with Medibank), and imposing licence conditions. Under the Financial Accountability Regime, named senior executives can also be held personally accountable. The practical message is that failings carry real financial and personal consequences.
How often do we need to test our controls under CPS 234? +
CPS 234 requires a systematic testing program, with testing conducted at least annually — and additionally whenever there's a material change to your information assets or business environment. Importantly, the testing must be carried out by appropriately skilled and functionally independent specialists, not simply self-assessed by the team that runs the controls.
How do we get started with CPS 234 compliance? +
The best starting point is a gap assessment: a clear benchmark of where you stand against all eight obligation areas, which becomes the basis for a prioritised roadmap. Call Cyber Ethos on 1800 CETHOS (1800-238-467) or visit cyberethos.com.au/contact to arrange one — we'll tell you honestly where your gaps are and the most efficient path to close them, in language your board can act on.