36 catalogued controls across 10 areas, assessed deterministically against your uploaded and connector-collected evidence — honest coverage against the full catalogue, consultant-grade reporting from one run.
Book a demo on APRA CPS 234 (Information Security) → Open the sample-evidence demoApplies to: Banks & APRA-regulated · Insurers & APRA-regulated · Superannuation & RSE licensees · GRC consultants & practices · Third-party & supplier risk · APRA CPS 230 & CPS 234
Generated from the live catalogue at build time — control identifiers and CyberSentien's own labels; no standard text is reproduced.
Verdicts against the FULL catalogue — controls without evidence read “manual assessment required”, never a fabricated pass.
Every report carries a run id and SHA-256 integrity anchor; sections trace to the controls and evidence they rest on.
The same run renders the APRA CPS 234 (Information Security) report, executive brief and board pack — no drift between audiences.
Run it against synthetic sample documents now, or bring your own evidence in a gated demo week.
CPS 234 is APRA's information security standard requiring regulated entities to maintain security capability proportionate to threats, classify information assets, test controls, and notify APRA of material incidents within 72 hours.
No. The formal CPS 234 assurance is an ASAE 3150 engagement performed by an independent assurance practitioner. CyberSentien prepares evidence-based readiness so that engagement is defensible.
No. ISO 27001 certification does not equal CPS 234 compliance — CPS 234 has specific APRA obligations (notification timing, board accountability, control testing) that must be evidenced separately.
Within 72 hours of becoming aware of a material information security incident, and within 10 business days of identifying a material control weakness.