Skip to content
HOME / CYBERSECURITY / APRA CPS 234 VS 1 month AGO

Cybersecurity

APRA CPS 234 vs CPS 230

APRA CPS 234 vs CPS 230

Last Updated on June 8, 2026 by Arnav Sharma

If your organisation is APRA-regulated, the question of CPS 234 vs CPS 230 is no longer theoretical. CPS 230 came into force on 1 July 2025, joining the long-standing CPS 234 information security standard that has been binding since 2019. Together, these two prudential standards form the core of Australia’s operational and information security risk framework for financial institutions. Understanding where they differ, where they intersect, and how to build a compliance programme that addresses both without duplicating effort is now a board-level priority.

This guide is written for compliance officers, CISOs, and risk teams at APRA-regulated entities. It covers the key requirements of both standards, draws out the critical distinctions that matter operationally, and provides practical guidance on running an integrated compliance programme.


What Is APRA and Why These Prudential Standards Matter

The Australian Prudential Regulation Authority (APRA) is the federal regulator responsible for the prudential supervision of banks, credit unions, insurers, and superannuation trustees in Australia. Its mandate is the financial safety of depositors, policyholders, and superannuation fund members. As of 2025, APRA regulates approximately 680 entities overseeing assets across the Australian financial system.

To structure risk obligations across its regulated population, APRA issues cross-industry prudential standards. The three standards most relevant to operational and cyber risk are:

  • CPS 220 Risk Management: Establishes the enterprise-wide risk management framework (RMF), risk appetite, and board accountability structure. CPS 220 is the governance umbrella under which the other standards operate.
  • CPS 230 Operational Risk Management: Applies the risk framework to operational disruptions, critical operations continuity, and material service provider oversight.
  • CPS 234 Information Security: Specialises within the operational risk space to cover information assets, cybersecurity controls, and security incident management.

The relationship is hierarchical. CPS 220 sets the risk appetite. CPS 230 says an entity must prove it can keep critical services running through severe disruptions. CPS 234 says that because many disruptions will be cyber-related, strong information security controls and response capabilities are mandatory.

Neither CPS 230 nor CPS 234 operates in isolation. Any compliance programme that treats them as separate workstreams will create gaps at the intersection. Regulatory expectations across both standards reinforce this: APRA’s supervisory focus is on effective risk management outcomes, not box-ticking against isolated requirements.


CPS 230 Operational Risk Management: What It Requires

Effective date: 1 July 2025 (core requirements). Non-significant financial institutions (non-SFIs) have a deferred deadline of 1 July 2026 for certain provisions, including business continuity planning, scenario analysis requirements, and specific critical operations obligations. The core operational risk management framework obligations still applied to all entities from 1 July 2025.

CPS 230 replaces three earlier standards: CPS 231 (Outsourcing), CPS 232 (Business Continuity Management), and CPG 233 (Operational Risk Management guidance). The new standard consolidates and upgrades obligations across all three into a single, outcomes-focused framework.

Core Obligations Under CPS 230

Operational risk management framework. Entities must establish and maintain a framework that identifies, assesses, and manages operational risks across all business units. The framework must cover legal, regulatory, compliance, conduct, technology, data, and change management risks. The board must approve the risk appetite for operational risk, including defined tolerance limits for each risk category.

Critical operations identification. Organisations must identify which operations are “critical” and document the impact tolerances for disruptions to those operations. Impact tolerances define the maximum time a critical operation can be impaired before causing material harm. These tolerances must be Board-approved and tested.

Business continuity planning. Entities must maintain a credible, tested business continuity plan (BCP) capable of sustaining critical operations through severe disruptions. Regular testing is required, including scenario analysis of extreme but plausible events.

Material service provider management. CPS 230 introduced a new regime for “material service providers.” Entities must maintain a register of material service providers and submit it to APRA annually. Formal agreements must include clear service level descriptions, data protection provisions, and termination rights. For pre-existing contracts, these requirements apply from the earlier of the next contract renewal date or 1 July 2026.

Incident notification. Entities must notify APRA when they activate their BCP due to a disruption to a critical operation outside their defined tolerance. Information security incidents that trigger operational disruptions are a primary notification scenario under this provision. Importantly, APRA has confirmed that a notification submitted under CPS 234 for an information security incident does not need to be separately reported under CPS 230. This removes a significant compliance burden for cyber incidents that trigger both frameworks.

Who owns CPS 230 compliance. The Chief Operations Officer, business continuity team, and third-party management function carry day-to-day accountability. The Board is ultimately responsible for approving risk appetites, tolerances, and the overall framework.

Where APRA determines an entity has material weaknesses in its operational risk management, it may require an independent review, a remediation programme, or the entity to hold additional capital.


CPS 234 Information Security: What It Requires

Effective date: 1 July 2019. CPS 234 has been binding for over six years. Unlike CPS 230, it has not been formally amended since commencement. However, APRA has intensified enforcement and issued supplementary guidance through its tripartite assessment programme, which has covered more than 300 entities.

CPS 234 organises its obligations across four core pillars.

Core Obligations Under CPS 234

Roles and responsibilities. The board of an APRA-regulated entity holds ultimate accountability for the organisation’s information security posture. This means active involvement in setting information security strategy, understanding the risk exposure, and ensuring adequate resources. Accountability must flow clearly from board level through senior management to operational teams before an incident occurs.

Information security capability. Entities must maintain information security capability that is proportionate to the size and nature of threats to their information assets. This is not a static baseline. APRA expects continuous assessment and enhancement as the threat environment evolves.

Information asset identification and classification. Entities must maintain an up-to-date register of information assets and classify them based on sensitivity and criticality. Security controls must be commensurate with the classification level. This applies to information assets regardless of whether they are managed internally or by a third party.

Security controls implementation. Controls must match the threat and vulnerability profile of the entity. Risk assessment drives control selection: entities must identify the cyber threats they face, assess their exposure, and implement risk controls commensurate with that risk profile. Required controls include access control, encryption, network segmentation, monitoring, authentication, and logging. Controls must be tested regularly through penetration testing, red team exercises, and scenario-based assessments, and must be reviewed after any material system changes.

Third-party and fourth-party information security. Where information assets are managed or held by a third party, the CPS 234 requirements extend to that third party. APRA expects entities to satisfy themselves that third parties, and where relevant their sub-contractors, have sufficient information security controls in place. Point-in-time assessments, sole reliance on self-assessment questionnaires, and accepting ISO 27001 certifications without reviewing scope have all been identified by APRA as insufficient approaches.

Incident notification. Entities must notify APRA within 72 hours of becoming aware of an information security incident that has, or could have, a material impact on the entity or the interests of depositors, policyholders, or beneficiaries.

Audit and assurance. Entities must conduct internal audits of their information security controls and test the effectiveness of those controls through third-party assurance where appropriate.

Enforcement reality. APRA’s enforcement toolkit for CPS 234 non-compliance includes intensified supervisory oversight, root cause analysis requirements, remediation plan obligations, material control weakness breach notifications, and additional capital charges. The $250 million capital charge imposed on Medibank Private following its 2022 data breach established that CPS 234 enforcement consequences are real and material. The Financial Accountability Regime (FAR), operative from 2024, has added a further layer of personal accountability, making individual named executives directly accountable for CPS 234 obligations in a way that did not exist before.

Who owns CPS 234 compliance. The CISO carries primary accountability for day-to-day management. The board retains ultimate responsibility. The data protection function and IT security team hold operational execution responsibility.


CPS 234 vs CPS 230: The Core Differences

The primary distinction between these two standards is scope. CPS 230 addresses operational risk broadly, covering the full spectrum of disruption scenarios including technology failures, supply chain disruptions, human error, natural disasters, and cyberattacks. CPS 234 is a focused specialisation within that broader operational risk space, addressing specifically the information security dimension.

The practical implication: CPS 234 is a mandatory input to CPS 230 compliance. An entity that satisfies CPS 234 has addressed the information security pillar of its operational risk obligations. But CPS 234 compliance alone does not satisfy CPS 230, because CPS 230 covers disruption scenarios and service provider risks that go well beyond cyber.

DimensionCPS 230CPS 234
ScopeBroad operational risk, including technology, data, legal, conduct, third-party, and change management riskInformation security specifically: confidentiality, integrity, and availability of information assets
Effective date1 July 2025 (core); 1 July 2026 (non-SFI deferred provisions)1 July 2019
Primary standard ownerCOO, Business Continuity team, Risk functionCISO, IT Security team
Board obligationApprove risk appetite, impact tolerances, and operational risk frameworkOversee information security strategy and maintain ultimate accountability for information security posture
Critical focusCritical operations continuity and resilience; service provider managementInformation asset protection, security controls, and incident response
Incident notificationNotify APRA when BCP activated outside tolerance for a critical operationNotify APRA within 72 hours of a material information security incident
Notification overlapA CPS 234 security incident notification does not need to be separately reported under CPS 230Primary notification obligation for cyber incidents
Third-party obligationsMaterial service provider register, formal agreements, annual APRA submissionSecurity controls must extend to third parties managing information assets; fourth-party sub-contractor oversight expected
Testing requirementsScenario analysis of severe but plausible disruptions; BCP testingRegular penetration testing, red team exercises, post-change validation
AssuranceIndependent review where APRA identifies material weaknessesInternal audit of controls; third-party assurance

CPS 234 focuses on protecting information assets from unauthorised access, degradation, or loss. CPS 230 focuses on whether the entity can continue to deliver critical operations when disruptions occur, including but not limited to cyber disruptions. A ransomware attack, for example, triggers CPS 234 (information security incident) and CPS 230 (operational disruption to critical operations). Both frameworks apply, but the notification obligations can be satisfied through a single CPS 234 report.


Where CPS 230 and CPS 234 Overlap

The overlap between these two standards is significant and deliberate. CPS 234 complements CPS 230 by providing the specific information security practices and controls that underpin operational resilience. In Australia’s financial services industry, the majority of severe but plausible disruption scenarios involve either a cyber incident or a technology failure with a security dimension. Treating the two standards as separate programmes is both inefficient and dangerous, because gaps often appear at exactly the intersection point.

Shared Third-Party and Service Provider Obligations

Both standards impose obligations on the management of external parties. CPS 230 requires entities to identify material service providers, maintain a formal register, submit it to APRA annually, and ensure all material arrangements include specific contractual protections. CPS 234 requires that where information assets are held or managed by a third party, the security requirements of CPS 234 extend to that third party.

The practical implication for a unified programme: many of the same service providers will be subject to both regimes. A cloud provider managing critical workloads is both a material service provider under CPS 230 and a third party managing information assets under CPS 234. The due diligence, contractual requirements, and monitoring obligations overlap substantially. A shared third-party risk register that captures both dimensions is more efficient and less likely to produce inconsistencies than maintaining two separate inventories.

Note the important clarification APRA made in the finalisation of CPS 230: service providers that manage information assets classified as critical or sensitive under CPS 234 are not automatically classified as material service providers under CPS 230. This was a proposed linkage in earlier drafts that APRA removed. The classification under each standard now operates independently. Entities should assess material service provider status under CPS 230 on the basis of the CPS 230 criteria, separately from CPS 234 third-party classification.

Incident Response Integration

CPS 234 requires an information security incident response plan. CPS 230 requires a business continuity plan capable of sustaining critical operations through disruptions. These are complementary, not duplicative. An integrated response strategy enables an entity to contain a cyber threat under the CPS 234 incident response framework while simultaneously activating the CPS 230 business continuity obligations to maintain critical service delivery.

The notification overlap rule matters here: a CPS 234 information security incident notification satisfies both standards for that incident. Entities do not need to file separate reports under CPS 230 for the same event. This rule reduces the administrative burden during the high-pressure period immediately after a material incident.

Shared Board Accountability Structure

Both standards place the board at the top of the accountability chain. CPS 220 establishes the risk appetite. CPS 230 requires board approval of operational risk tolerances and the overall framework. CPS 234 places ultimate responsibility for information security with the board. In practice, a single board reporting pack that addresses operational risk (CPS 230), information security posture (CPS 234), and the enterprise risk framework (CPS 220) is both more efficient and more informative than three separate reports.

Scenario Testing Requirements

Both standards require testing. CPS 230 requires scenario analysis of extreme but plausible disruption events. CPS 234 requires regular security testing including penetration testing and red team exercises. A cyber attack scenario, properly designed, simultaneously tests CPS 230 resilience obligations (can critical operations continue?) and CPS 234 controls effectiveness (did the controls detect and contain the attack?). Joint scenario exercises are a natural integration point for organisations with mature programmes.


Building a Unified Compliance Programme for Both Standards

Running separate CPS 230 and CPS 234 compliance programmes is a structural inefficiency that also creates risk. Prudential Standard CPS 234 and Prudential Standard CPS 230 share a common risk governance spine: the board sets the risk appetite under CPS 220, and both standards require that spine to be active and evidenced. To comply with CPS 230 and comply with CPS 234 simultaneously, organisations must integrate their risk management practices rather than run parallel workstreams. Controls that sit at the intersection of both standards, third-party security assessments, incident response, board reporting, and testing, are the most likely places for gaps to appear when accountability is split. The following approach is designed for CISOs, risk managers, and compliance teams building or consolidating their frameworks post July 2025.

Step 1: Map Your Control Inventory Against Both Standards

Start with a single control register. For each control, tag it against the relevant CPS 230 and/or CPS 234 obligations it satisfies. Many controls will be dual-tagged. Access controls, for example, directly satisfy CPS 234 information security requirements and also contribute to CPS 230 operational resilience by reducing the probability of disruptions caused by unauthorised access. Effective risk management under both standards depends on risk mitigation strategies that are coherent across both frameworks. To meet CPS 230 requirements for operational resilience while simultaneously maintaining CPS 234 compliance, a unified control register is the most reliable foundation. Building it from the start eliminates the problem of discovering, mid-audit, that a control gap affects both standards.

Step 2: Align Your Third-Party Risk Programme

Maintain one third-party risk register that captures both material service provider status (CPS 230) and information asset management obligations (CPS 234). For each provider, document:

  • Whether they qualify as a material service provider under CPS 230 criteria
  • Whether they manage or hold information assets classified as critical or sensitive under CPS 234
  • The contractual provisions in place for each regime
  • The last assessment date and next scheduled review
  • Sub-contractor (fourth-party) visibility status

The material service provider register must be submitted to APRA annually under CPS 230. Having it aligned with the CPS 234 third-party inventory avoids duplication and ensures consistency in how the same providers are assessed under both frameworks.

Step 3: Build a Unified Testing Calendar

Consolidate your CPS 230 scenario testing and CPS 234 security testing into a single annual testing calendar. Include:

  • Penetration testing and vulnerability assessments (primarily CPS 234, supports CPS 230 resilience evidence)
  • Business continuity and disaster recovery exercises (primarily CPS 230, incorporates cyber scenarios that satisfy CPS 234 incident response testing)
  • Red team / adversarial simulation exercises (satisfies both)
  • Tabletop exercises simulating specific threat scenarios (satisfies both)

Each test should produce documented evidence mapped back to both standards where applicable. This evidence base is what APRA reviews during supervisory assessments and what internal audit relies on.

Step 4: Produce a Single Board Risk Report

Your board risk reporting should integrate operational risk management (CPS 230) and information security posture (CPS 234) into a single view. Separate reports create siloed board awareness and make it harder for the board to understand how a cyber incident (CPS 234 scope) could trigger operational continuity obligations (CPS 230 scope). A unified report covering:

  • Critical operations status and current tolerance positions
  • Key operational risk indicators and trend data
  • Information security posture including control effectiveness
  • Third-party risk status across both regimes
  • Outstanding audit findings and remediation progress

This format satisfies the board accountability obligations of both standards and provides the board with the integrated view needed to exercise informed oversight.

Step 5: Clarify Incident Response Escalation and Notification Paths

Ensure your incident response procedures clearly define the escalation path and notification obligations for cyber incidents. Specifically:

  • A material information security incident triggers a 72-hour APRA notification under CPS 234.
  • If that incident disrupts a critical operation outside its defined tolerance, the CPS 230 BCP activation notification obligation also applies. However, the CPS 234 notification satisfies the CPS 230 notification requirement for the same incident.
  • Document this clearly in your incident response runbooks so that on-call staff are not filing duplicate notifications under time pressure.

Step 6: Clarify Ownership and the FAR Accountability Map

Under the Financial Accountability Regime, named accountability holders at APRA-regulated entities are personally accountable for the functions they lead. Organisations must map both CPS 230 and CPS 234 obligations to specific named individuals in their accountability maps. Typical allocation:

  • CPS 230 operational risk management framework: Chief Risk Officer or Chief Operations Officer
  • CPS 230 critical operations and BCP: Chief Operations Officer
  • CPS 230 material service provider oversight: Chief Procurement Officer or CRO, depending on structure
  • CPS 234 information security framework: CISO or equivalent
  • CPS 234 board accountability: Board or designated Board committee

Where one individual holds accountability for functions that span both standards, document that cross-standard accountability explicitly. This is particularly common in smaller APRA-regulated entities where the CRO and CISO functions may overlap.

Arnav Sharma
Arnav Sharma Microsoft MVPMCT
Microsoft Certified Trainer · Cloud · Cybersecurity · AI

I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.

Frequently Asked Questions

KEEP READING

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.