CPS 234 is APRA’s prudential standard for information security, and its core requirements are that an APRA-regulated entity identify and classify its information assets, implement and regularly test security controls sized to the threat, hold the board accountable, manage third-party and related-party providers, and notify APRA within 72 hours of a material information-security incident and within 10 business days of a material control weakness. It applies to banks, insurers and superannuation trustees, and it reaches the vendors that hold or process regulated data on their behalf.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
CPS 234 (Prudential Standard CPS 234 Information Security) is principles-based rather than a control checklist, which is what makes it easy to misread. It does not tell you to buy a firewall or adopt a named framework. It tells you to establish an information-security capability commensurate with the size and extent of threats to your information assets, and to keep that capability current as those threats evolve. In practice, the obligations resolve into a small number of concrete, testable duties that an assessor — and ultimately APRA — will expect you to evidence.
The board of the APRA-regulated entity is ultimately responsible for information security. Clearly defined roles must sit under it, so accountability is not diffuse.
Classify information assets, including those managed by related parties and third parties, by criticality and sensitivity. This register is the spine everything else hangs off.
Implement controls to protect assets commensurate with the threat, and test them regularly — with the frequency and rigour tied to how critical and how exposed the asset is.
Maintain response plans and mechanisms to detect and respond to incidents, then notify APRA on the required clocks.
The full text is worth reading directly: legislation.gov.au and APRA’s standards library at apra.gov.au. Our plain-language mapping of every paragraph lives on the CPS 234 framework page.
CPS 234 carries two distinct notification obligations, and conflating them is a common failure. The first is incident-driven; the second is weakness-driven. Missing either is itself a compliance breach, so build the trigger logic into your incident process rather than relying on someone remembering.
| Trigger | Clock | What counts |
|---|---|---|
| Material information-security incident | Notify APRA within 72 hours | An incident that materially affected, or had the potential to materially affect, the entity or the interests of depositors, policyholders or beneficiaries — including incidents notified to other regulators. |
| Material control weakness | Notify APRA within 10 business days | A material information-security control weakness the entity expects it will not be able to remediate in a timely manner. |
Note the asymmetry: the incident clock runs in hours, the weakness clock in business days, and the weakness one is proactive — you self-report a gap you cannot close quickly. That second duty surprises teams, because it obliges honesty about your own posture.
If you are scoping readiness, this sequence tends to hold up under independent review. It is deliberately evidence-first: for each item, the question is not “do we have a policy” but “can we show the artefact that proves the control operated”.
Third-party assurance is where scope quietly balloons, because CPS 234 explicitly reaches vendors that manage your information assets. Our third-party risk management guidance covers how to size that assessment without boiling the ocean.
APRA may require an APRA-regulated entity to arrange an independent review of its information security — commonly discussed as a “tripartite” arrangement between the entity, APRA and an independent assurance practitioner, often performed under the ASAE 3150 assurance standard. This is important to be precise about: the independent assurance opinion is issued by that qualified, independent practitioner, not by a software tool and not by CyberSentien. What a readiness platform can do is prepare you for that engagement so it goes quickly and without surprises.
That distinction is the whole honesty of the exercise. Assurance means someone independent forms and signs an opinion on whether your controls are designed and operating effectively. Readiness means assembling and testing the evidence so that opinion is well-founded. Confusing the two — or buying a product that claims to “certify” CPS 234 — is a red flag, because CPS 234 has no certificate to issue.
Where CPS 234 sits relative to a recognised information-security management framework is a frequent question; we work through it in CPS 234 vs ISO 27001. The short version: ISO 27001 controls can supply much of the evidence CPS 234 wants, but CPS 234 imposes its own board-accountability, testing and notification duties that a certificate does not automatically satisfy.
CyberSentien is an evidence-led readiness engine. It builds and maintains the information-asset register, maps assets to controls, and tracks whether each control has current, corroborating evidence behind it. The design rule we hold to is “never a false green”: a control with no evidence does not silently pass — it reads “manual assessment required” so nothing is overstated to your board or to an assessor. We prepare the readiness pack; the independent assurance opinion remains the practitioner’s to give.
CPS 234 also does not stand alone in 2026. APRA’s operational-risk standard CPS 230 commenced on 1 July 2025 and reaches full effect, including material-service-provider contract transition, by 1 July 2026 — and it consolidated the former CPS 231 and CPS 232. Information assets classified for CPS 234 feed directly into the critical-operations and material-service-provider work CPS 230 demands, so treating them together saves duplicated effort. Our APRA solutions overview shows how the two connect.
For the underlying standards, always go to source: APRA at apra.gov.au, the registered instruments at legislation.gov.au, and ASD’s security guidance at cyber.gov.au. CPS 234 rewards teams that treat it as an ongoing capability rather than a point-in-time audit — and the entities that fare best in an independent review are the ones whose evidence was already assembled, current and honest before the practitioner walked in.
CPS 234 requires information security capability commensurate with threats, clear roles including board accountability, information asset identification and classification, control implementation and testing, incident management, and APRA notification.
It is an independent assurance engagement (ASAE 3150) where an assurance practitioner assesses an entity's compliance, often at APRA's request. CyberSentien prepares readiness for it but does not perform the audit.
The board of the APRA-regulated entity is ultimately responsible for information security under CPS 234, supported by management and internal audit.
Manual engagements are commonly scoped at one to two weeks; the most frequent blocker is an inaccurate information asset register. Evidence-based tooling shortens the evidence-gathering step.
CPS 234 obligations 'trickle down' — regulated entities must ensure their service providers manage information security of the entity's assets to an equivalent standard.