What Is APRA CPS 234?
CPS 234 is the information security rulebook for Australia's financial sector. It's a prudential standard set by APRA — the Australian Prudential Regulation Authority, the body that oversees banks, insurers, and super funds — and it spells out what those organisations must do to protect the information they hold and respond when something goes wrong.
Two things make it matter. First, it carries the force of law — it isn't optional guidance. Second, the Board is ultimately accountable for meeting it, so this is a boardroom issue, not just an IT one.
APRA CPS 234 (Prudential Standard CPS 234 Information Security) has applied since 1 July 2019. It requires APRA-regulated financial entities to clearly assign responsibility for information security, maintain security capabilities that match the threats they face, protect and test their controls, manage the risk from their service providers, and notify APRA quickly when there's a material incident or control weakness.
In short: it sets the minimum information security standard for anyone APRA regulates — and holds the Board responsible for living up to it.
Who Must Comply With CPS 234?
CPS 234 applies to every entity APRA regulates. If you're in one of these groups, it applies to you directly:
CPS 234 doesn't stop at the regulated entity. Because a bank or insurer stays accountable for the security of any third party that manages its information assets, cloud, SaaS, and IT service providers to the financial sector are routinely required — through their contracts — to meet CPS 234-style obligations too. You can be bound by CPS 234 in practice even if you're not a bank. More on this below.
The 8 Obligations of CPS 234, Explained Simply
The standard's requirements fall into eight areas. Here's what each one means in plain terms.
-
Define who's responsibleClearly set out the information security roles and responsibilities of the Board, senior management, and staff. The Board is ultimately accountable — security can't be left as "someone in IT's problem."
-
Maintain a security capability that fits the threatKeep an information security capability sized to the threats you actually face — and keep it current as those threats evolve. A small credit union and a major bank are not expected to do identical things, but both must be proportionate.
-
Classify your information assetsIdentify what information and systems you hold and classify them by how critical and sensitive they are, so your protection matches what matters most.
-
Put controls in placeImplement security controls to protect those assets across their whole life — from creation through to disposal — taking account of current and emerging threats.
-
Manage your third partiesWhere a service provider manages your information assets, assess and assure their security too. You can outsource the work — but not the accountability.
-
Test that your controls actually workRun a systematic testing program to prove your controls are effective — carried out by skilled, functionally independent specialists, at least annually and whenever something material changes.
-
Have internal audit review itYour internal audit function must review the design and operating effectiveness of your information security controls — an extra, independent set of eyes.
-
Notify APRA, fastTell APRA within 72 hours of a material information security incident, and within 10 business days of a material control weakness you can't fix promptly. (Detailed next.)
The 72-Hour Notification Rule (and the 10-Day One)
The notification obligations are the part of CPS 234 most likely to trip an organisation up in the heat of a real incident — so they're worth knowing cold.
72 hours — notify APRA as soon as possible, and no later than 72 hours, after becoming aware of a material information security incident.
10 business days — notify APRA after becoming aware of a material information security control weakness you don't expect to remediate in a timely way.
What counts as a "material incident" is broader than many assume. The 72-hour clock starts if an incident:
- Materially affected — or could have materially affected — your organisation or your customers, financially or non-financially (including reputational and operational harm); or
- Has been notified to any other regulator, in Australia or overseas. This is an automatic trigger — if you've told another regulator, you tell APRA too.
Crucially, you don't have to wait until you've confirmed harm. The obligation is triggered by actual or potential material impact — so the safe assumption during an incident is that the clock is already running.
Since 2025, Australia's Cyber Security Act has added a separate mandatory reporting obligation for organisations that make a ransomware payment — with its own 72-hour deadline to a different government body. For an APRA-regulated entity that pays a ransom, that can mean two 72-hour clocks running at once, to two different regulators. Knowing this in advance — and having it in your incident plan — matters.
The Part Most Organisations Underestimate: Third-Party Obligations
If there's one area where organisations fall short, it's third-party risk — and it's also the reason CPS 234 reaches well beyond the banks and insurers themselves.
Under CPS 234, an APRA-regulated entity stays accountable for the security of its information assets even when a third party manages them. So if your data sits in a cloud platform, is processed by a SaaS application, or is handled by an outsourced IT provider, you must assess and assure that provider's information security — commensurate with the damage a breach there would cause.
In practice, this flows downhill through contracts. Service providers to the financial sector are routinely required to:
- Maintain information security controls to an agreed standard;
- Allow the regulated entity to assess and review their security;
- Notify the regulated entity of incidents quickly, so the entity can meet its own 72-hour deadline.
This is why many technology and professional-services firms that have never heard of APRA find CPS 234 obligations written into their contracts. And the bar has risen further: the newer CPS 230 standard now also requires regulated entities to keep registers of their material service providers and to hold appropriate contractual rights — with existing contracts needing to comply by the earlier of 1 July 2026 or their next renewal.
CPS 234 vs CPS 230: How They Fit Together
These two standards are often mentioned in the same breath, and they're related — but they're not the same thing.
| CPS 234 | CPS 230 | |
|---|---|---|
| Focus | Information security specifically | Operational risk management and resilience, broadly |
| In force since | 1 July 2019 | 1 July 2025 (replaced CPS 231 & CPS 232) |
| Covers | Protecting information assets, testing controls, incident notification | Critical operations, business continuity, and managing material service providers |
| Key notification | 72 hours for a material information security incident | 24 hours for a disruption to critical operations beyond tolerance |
The simplest way to hold them in your head: CPS 234 protects your information; CPS 230 keeps your whole operation running and resilient. They're complementary — CPS 230 deals with operational risk overall and explicitly points to CPS 234 for the information security piece. If you're working on one, you should have the other on your radar.
Does CPS 234 Actually Have Teeth?
It's a fair question — plenty of standards look stern on paper and go unenforced. CPS 234 is not one of them, and the picture in 2026 is very different from 2019.
Rather than rewriting the standard, APRA has chosen to leave CPS 234 unchanged and sharpen its enforcement instead. Three developments show how real the consequences have become:
- Industry-wide assessments exposed systemic gaps. APRA's tripartite assessment program — independent reviews across more than 300 regulated entities — found widespread, recurring weaknesses, putting the whole sector on notice.
- The Medibank capital add-on proved the cost is real. Following its major data breach, APRA applied a substantial capital add-on to Medibank (a A$250 million charge), citing weaknesses in its information security environment — a clear signal that failings carry financial consequences.
- Executives are now personally accountable. Under the Financial Accountability Regime (FAR), named senior executives can be held personally responsible for information security obligations — accountability that simply didn't exist when CPS 234 began.
"Compliant on paper" is no longer enough. APRA increasingly wants to see that your controls genuinely work, that they're independently tested, and that someone accountable can demonstrate it. A folder of policies that no one tests or follows is exactly what enforcement now looks for — and finds.
Does ISO 27001 Satisfy CPS 234?
This is one of the most common misconceptions, so let's be clear: no — ISO 27001 certification does not make you CPS 234 compliant.
That said, it's a genuinely strong head start. An ISO 27001 information security management system gives you documented controls, defined processes, and the evidence trails that directly support many CPS 234 obligations. If you're already certified, you've done a lot of the groundwork.
But CPS 234 has APRA-specific requirements that ISO 27001 doesn't cover, and you must address these separately:
- The 72-hour and 10-business-day notification obligations to APRA;
- The Board's ultimate accountability for information security;
- Independent control testing on APRA's terms;
- Third-party assurance aligned to the consequences of a breach.
Think of ISO 27001 as a strong foundation you build CPS 234 on top of — not a substitute for it. The two sit naturally together, alongside the Essential Eight, as part of a single, joined-up compliance picture.
How to Achieve (and Keep) CPS 234 Compliance
Compliance isn't a single project with an end date — it's an ongoing capability. Here's a practical path to get there and stay there.
-
Establish board accountability and clear rolesMake sure the Board understands its ultimate accountability, and document who is responsible for what across leadership, management, and staff.
-
Classify your information assetsMap what you hold and rank it by criticality and sensitivity, so effort flows to what matters most.
-
Run a CPS 234 gap assessmentBenchmark your current state against all eight obligation areas to see exactly where you stand — and where the gaps are.
-
Remediate and strengthen controlsWork through the gaps in priority order, with a roadmap sized to your risk and budget rather than a generic checklist.
-
Put independent control testing in placeSet up the systematic, independently-conducted testing CPS 234 requires — at least annually and after material change.
-
Assess your third partiesIdentify who manages your information assets, assess their security, and get the right notification and assessment terms into your contracts.
-
Build your APRA notification readinessHave the processes, playbooks, and decision-makers ready so the 72-hour and 10-day clocks are met under pressure — not scrambled.
-
Embed it and keep it liveFold CPS 234 into internal audit and ongoing governance, with regular board reporting, so compliance stays current as threats and your business change.
5 Myths About CPS 234
How Cyber Ethos Helps With CPS 234
Cyber Ethos is led by Dr. Kiran Kewalramani — a PhD-qualified cybersecurity specialist with CISSP, CISA, and GAICD credentials and over 20 years of experience across security and governance. We help APRA-regulated entities, and the providers who serve them, get and stay compliant — in plain language the board can act on. That includes:
- A CPS 234 gap assessment. We benchmark you against all eight obligation areas and show you exactly where you stand and what to prioritise.
- A right-sized remediation roadmap. Prioritised, board-ready, and scaled to your risk and budget — not a generic checklist.
- Independent control testing. The skilled, functionally independent testing CPS 234 calls for, with results you can put in front of APRA.
- Third-party assurance. Help assessing the service providers who manage your information assets, and getting the right terms in place.
- APRA notification readiness. Incident processes and playbooks built around the 72-hour and 10-day clocks, so they're met under pressure.
- Ongoing governance and board reporting. Through a Cyber Ethos virtual CISO, we can own the program day to day and report cyber risk to your board — keeping compliance live, not a once-a-year scramble.
Know exactly where you stand on CPS 234
Talk to Dr. Kiran Kewalramani directly. We'll assess your current position against the standard, show you the gaps in plain language, and give you a clear, prioritised path to compliance. No jargon, no pressure.
Request a CPS 234 gap assessment →📞 1800 CETHOS (1800-238-467) · cyberethos.com.au
This guide is general information about APRA CPS 234, not legal or compliance advice. Your specific obligations depend on your circumstances — confirm them against the current standard published by APRA and with your own advisers.