⚖ APRA CPS 230 & CPS 234
CPS 230 makes operational resilience a board-owned obligation and CPS 234 asks for an information-security posture you can defend line by line — each obligation needs evidence, not an assertion, and the provider-facing ones must be evidenced through your suppliers. Most teams still answer with a spreadsheet assembled the week before the review.
Book a demo → Try it on sample docsTier-A breadthOperational resilience · information security · obligation self-assessment
Frameworks on the engine serving this vertical
Read from the live catalogue at build time — a framework that is not live on the engine never renders here. Depth is badged per framework: consultant-grade only where we go deepest (ISM/IRAP, Essential Eight), Tier-A breadth everywhere else.
Depth today — stated honestly
Tier-A breadth: the full curated CPS 230 (operational risk) and CPS 234 (information security) obligation sets, self-assessed with evidence and by-theme rollups, plus flow-down conformance recorded once on a material provider and consumed toward the entity's obligation. CyberSentien is the evidence layer; it does not replace an APRA-appointed reviewer, and nothing shows green without evidence.
The global angle
The SOCI Act is Australian, and there is no dedicated SOCI catalogue on the engine yet — this page says so rather than shading it green. The lanes serving the obligations mix Australian depth (Essential Eight, ISM) with internationally used instruments — NIST CSF 2.0, CIS Controls v8 — exactly as live on the catalogue.
See it on the real engine
Run the frameworks above against synthetic sample documents now, or tell us where you sit and we'll send a gated, revocable demo link.
Request the demo →Try it now →