CPS 230 readiness checklist for 1 July 2026

A CPS 230 readiness checklist confirms an APRA-regulated entity can identify its critical operations, has set board-approved tolerance levels, maintains a material service provider register, holds contracts carrying the required protections, and can meet the 72-hour notification clock. CPS 230 commenced 1 July 2025; full effect — including the transition of material service provider contracts — lands by 1 July 2026. This page walks the checklist domain by domain so you know, before that date, exactly which items are evidenced and which still read “manual assessment required.”

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

What CPS 230 replaced — and why the checklist changed

CPS 230 Operational Risk Management consolidated and replaced CPS 231 (Outsourcing) and CPS 232 (Business Continuity Management), pulling operational risk, business continuity and third-party management under one prudential standard. That means a readiness checklist built for the old standards is no longer sufficient: the emphasis has shifted from a static outsourcing policy to demonstrable control over critical operations, quantified tolerance levels, and a live material service provider register. The full standard is published on the APRA site at apra.gov.au. Treat the checklist below as five evidence domains — each item is either backed by an artefact you can produce today, or it is a gap to close before 1 July 2026.

The five readiness domains

A defensible CPS 230 day-one checklist groups into five domains. Each card lists the questions an independent reviewer — or your own board — will ask, and the evidence that answers them.

1. Critical operations

Have you defined and documented your critical operations (the processes that, if disrupted, would materially affect the entity or its customers)? Is there a current process map, and are dependencies — people, technology, facilities, service providers — identified for each? Evidence: a board-noted critical-operations register with mapped dependencies.

2. Tolerance levels

For each critical operation, has the board approved a tolerance level — the maximum tolerable disruption, expressed in time, volume or another measurable dimension? Are those tolerances tested against realistic severe-but-plausible scenarios? Evidence: board minutes approving tolerances plus scenario-test results.

3. Material service providers

Is there a material service provider (MSP) register identifying providers your critical operations rely on, including fourth-party concentrations where known? Evidence: the MSP register with materiality rationale and mapping back to each critical operation.

4. Service provider contracts

Do MSP contracts carry the protections CPS 230 expects — and are they on track to transition by 1 July 2026? Evidence: a clause-mapping matrix per contract (see the clause table below).

5. Incident & notification readiness

Can you notify APRA as soon as possible, and no later than 72 hours, after becoming aware of a material operational risk incident? Are roles, contact paths and a drafting template pre-positioned? Evidence: an incident-response runbook with the notification clock built in.

The seven contract-clause checkpoints

Contract remediation is the item most entities underestimate, because it depends on counterparties, not just internal effort. Work through your material service provider agreements against these checkpoints and record, per contract, whether each is present, absent, or under renegotiation. Where a clause cannot be evidenced from the contract text, it should read “manual assessment required” rather than be assumed satisfied.

CheckpointWhat the contract should evidence
Service scope & levelsClear description of the service and measurable service levels tied to your critical operations.
Audit & access rightsRights for the entity and APRA to access records, premises and personnel.
Sub-contracting & fourth partiesNotice and controls over material sub-contracting arrangements.
Business continuityProvider BCP obligations aligned to your tolerance levels.
Incident notificationProvider must notify you of incidents in time for you to meet your own clocks.
Data & offshoringLocation, handling and return/deletion of data on exit.
Termination & exitExit plan, transition support and continuity of service on wind-down.

Contract wording varies, so treat this as a mapping guide rather than model text. Our CPS 230 templates give you a register and clause-matrix starting point you can populate per provider.

The notification clocks you must be able to hit

Readiness is only real if the clock can actually be met under pressure. Pre-position the mechanics now.

Standards and instruments referenced here are on the Federal Register of Legislation at legislation.gov.au, and broader operational-cyber guidance is published by the ASD at cyber.gov.au.

How CyberSentien supports the checklist — honestly

CyberSentien performs readiness and evidence assessment against CPS 230; it does not certify compliance and it is not your independent assurer. The platform ingests your registers, board papers, scenario tests and contracts, then scores each checklist item against the evidence actually present. Controls with no supporting artefact are never marked green — they read “manual assessment required,” so the board sees the true state, not an optimistic one. From there you can prioritise the gaps most likely to still be open at 1 July 2026.

For the mapped control set, see our APRA CPS 230 framework page, and to quantify where you stand today run the structured CPS 230 gap assessment.

Try it on sample docs

A realistic implementation roadmap to 1 July 2026

If you are working backwards from the transition date, sequence the effort so the counterparty-dependent items start earliest.

Now – Q1

Finalise the critical-operations register and board-approve tolerance levels. These anchor everything downstream.

Q1 – Q2

Complete the MSP register and open contract renegotiations — the longest-lead items because they depend on providers.

Q2 – Q3

Run severe-but-plausible scenario tests against tolerances; remediate BCP gaps they expose.

Ahead of 1 July

Rehearse the notification runbook end-to-end and evidence every checklist item, closing residual “manual assessment required” flags.

Because this is prudential guidance and not legal advice, confirm interpretation against the current standard and, where the tripartite assurance model applies, engage a qualified independent practitioner for the formal assurance work.

Frequently asked

What must be fixed before 1 July 2026 under CPS 230?

Material service provider registers, the seven mandatory contract clauses, critical operations mapping, board-approved tolerance levels, and business continuity testing all need to be evidenced by the commencement date.

What are the seven mandatory CPS 230 contract clauses?

CPS 230 requires service provider contracts to cover matters such as APRA access and audit rights, sub-contracting (fourth party) transparency, service levels, monitoring, business continuity, termination, and notification obligations.

What is the 72-hour incident notification under CPS 230?

Entities must notify APRA within 72 hours of an operational risk incident that has, or is likely to have, a material financial or non-financial impact.

Is a checklist enough for CPS 230?

A checklist scopes the work; CPS 230 requires defensible evidence for each item. CyberSentien turns the checklist into an evidence-based assessment rather than a static tick-box.