⚖ APRA CPS 230 & CPS 234

CPS 230 makes operational resilience a board-owned obligation and CPS 234 asks for an information-security posture you can defend line by line — each obligation needs evidence, not an assertion, and the provider-facing ones must be evidenced through your suppliers. Most teams still answer with a spreadsheet assembled the week before the review.

Book a demo → Try it on sample docs
Tier-A breadthOperational resilience · information security · obligation self-assessment

Frameworks on the engine serving this vertical

Read from the live catalogue at build time — a framework that is not live on the engine never renders here. Depth is badged per framework: consultant-grade only where we go deepest (ISM/IRAP, Essential Eight), Tier-A breadth everywhere else.

Depth today — stated honestly

Tier-A breadth: the full curated CPS 230 (operational risk) and CPS 234 (information security) obligation sets, self-assessed with evidence and by-theme rollups, plus flow-down conformance recorded once on a material provider and consumed toward the entity's obligation. CyberSentien is the evidence layer; it does not replace an APRA-appointed reviewer, and nothing shows green without evidence.

The global angle

The SOCI Act is Australian, and there is no dedicated SOCI catalogue on the engine yet — this page says so rather than shading it green. The lanes serving the obligations mix Australian depth (Essential Eight, ISM) with internationally used instruments — NIST CSF 2.0, CIS Controls v8 — exactly as live on the catalogue.

See it on the real engine

Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.

Request the demo →Try it now →