CPS 234 and ISO/IEC 27001 are not substitutes. CPS 234 is a binding APRA prudential standard for information security that regulated entities must meet, while ISO/IEC 27001 is a voluntary international management-system standard you can be certified against. They overlap heavily on control disciplines — asset classification, access control, testing — but ISO/IEC 27001 certification does not, on its own, make you CPS 234 compliant. CPS 234 adds board accountability, third-party assurance, and hard APRA notification clocks that sit outside the ISO scope.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
The most common misconception we see is that an ISO/IEC 27001 certificate is a shortcut to CPS 234. It is not. CPS 234 is enforceable law-adjacent prudential regulation issued by the Australian Prudential Regulation Authority under the Banking, Insurance and other industry Acts — if you are an APRA-regulated entity, you must comply, and APRA can act where you do not. ISO/IEC 27001 is a management-system standard published by ISO and IEC; conformance is voluntary and, when audited by an accredited certification body, results in a certificate.
The practical consequence: a strong ISO/IEC 27001 Information Security Management System (ISMS) is excellent raw material for CPS 234 readiness, but the two ask different questions. ISO asks “does your ISMS operate to the standard”. CPS 234 asks “can your board demonstrate the information assets of the regulated entity are protected commensurate with the threat, including assets managed by third parties”. Read more in our primer on what CPS 234 requires.
A well-run ISMS covers a large share of the operational substance CPS 234 expects. If you already hold or are pursuing ISO/IEC 27001, these disciplines are largely reusable as evidence.
ISO Annex A controls for information classification map closely to CPS 234’s requirement to identify and classify information assets by criticality and sensitivity.
Access management, cryptography, operations security and supplier controls in Annex A provide much of the control baseline CPS 234 expects you to implement.
ISO internal audit and management-review cycles feed CPS 234’s expectation that controls are tested systematically and remediation tracked.
ISO incident-handling processes give you the detection and response spine CPS 234 relies on — though the reporting obligations differ, as below.
This is the gap that catches entities out. The following CPS 234 obligations are either absent from ISO/IEC 27001 or materially stronger under CPS 234, and an ISO certificate provides no coverage for them by itself.
You can read the standard directly at apra.gov.au, and the ISO family is published via iso.org.
| Dimension | CPS 234 | ISO/IEC 27001 |
|---|---|---|
| Nature | Mandatory prudential standard (APRA) | Voluntary international standard |
| Outcome | Compliance / supervisory expectation | Certificate from accredited body |
| Scope | Whole regulated entity’s information assets | Declared ISMS scope only |
| Accountability | Board of the regulated entity | Top management |
| External notification | APRA within 72 hours (incident); 10 business days (material control weakness) | None inherent |
| Third parties | Assess third/related-party capability, risk-commensurate | Supplier controls (Annex A) |
The efficient path is to treat your ISMS as an evidence source and map it, control by control, onto CPS 234’s obligations — then explicitly identify what ISO does not cover and build that separately. A defensible mapping typically works in four passes: reuse Annex A control evidence for CPS 234 control implementation and testing; close the accountability gap with board-level artefacts and a documented information-security policy owned at board level; stand up the APRA notification runbook with its clocks; and build the third-party assurance register.
This is where CyberSentien fits: we perform CPS 234 readiness and evidence assessment, not certification. Certification against ISO/IEC 27001 is issued only by an accredited certification body, and CPS 234 supervision rests with APRA — neither is something a vendor can grant. Our engine ingests your existing ISO documentation and maps it against each CPS 234 obligation, flagging where evidence exists and where it does not. Critically, a control without supporting evidence is never marked green — it reads “manual assessment required”, so your gap is honest rather than flattering. See how this works for regulated entities in our banking & APRA solution and the underlying CPS 234 framework mapping.
ISO/IEC 27001 is one of the strongest foundations you can bring to a CPS 234 program, and if you already hold it you are well ahead on the control substance. But an ISO certificate is not a CPS 234 attestation. The gap — board accountability, APRA notification clocks, entity-wide scope, and third-party assurance — is exactly where supervisory attention lands. Map the overlap, evidence it honestly, and build the CPS 234-specific obligations deliberately rather than assuming a certificate has already covered them.
No. ISO 27001 is a strong foundation but does not satisfy CPS 234's specific obligations — APRA notification timing, board accountability, control testing frequency and asset classification must be evidenced separately.
Both require an ISMS, asset management, control implementation and incident management. CyberSentien maps the shared controls so ISO 27001 evidence is reused where it genuinely applies to CPS 234.
No. CyberSentien performs readiness and evidence assessment, not certification. ISO 27001 certification is issued only by accredited certification bodies.
For APRA-regulated entities CPS 234 is mandatory; ISO 27001 is optional but complementary. Assess CPS 234 obligations directly and lean on any existing ISO 27001 controls as evidence.