APRA CPS 234: What It Requires and Who It Applies To
Information security obligations for Australian financial entities
If you sit on the board or in the risk function of an APRA-regulated entity, CPS 234 is not a framework you can treat as guidance. It is an enforceable prudential standard, and the board carries direct accountability for it.
This guide sets out what CPS 234 actually requires, in plain language, and where it sits alongside CPS 230 and the rest of Australia's regulatory landscape.
What is CPS 234?
Prudential Standard CPS 234 Information Security is APRA's cross-industry standard requiring regulated entities to maintain information security capability that matches the size and extent of the threats they face. It has applied since 1 July 2019.
CPS 234 is short and principles-based rather than prescriptive. It does not hand you a control checklist. It sets out obligations and expects the entity to demonstrate that its controls are commensurate with its actual risk profile.
Who does CPS 234 apply to?
CPS 234 applies to all APRA-regulated entities, including:
- Authorised deposit-taking institutions (ADIs), including foreign ADIs
- General insurers
- Life insurers
- Private health insurers
- Superannuation trustees (registrable superannuation entity licensees)
- Friendly societies and reinsurance companies
If your organisation is not itself APRA-regulated but supplies services to one of these entities, CPS 234 still reaches you indirectly. The standard's obligations extend to information assets managed by related parties and third parties, not only those covered by formal outsourcing agreements. An APRA-regulated entity is required to assess the information security capability of any third party with access to its information assets, which means your organisation's own security posture becomes part of your client's compliance evidence.
The five core obligations
1. Board accountability
The board of an APRA-regulated entity is ultimately responsible for ensuring the entity maintains information security commensurate with the size and extent of threats to its information assets, in a way that enables the entity's continued sound operation. CPS 234 also requires the entity to clearly define information security roles and responsibilities across the board, senior management, governing bodies, and individuals with decision-making, approval, oversight or operational responsibility.
2. Information security capability
The entity must maintain an information security capability commensurate with the vulnerabilities and threats to its information assets, including those managed by related and third parties. As the threat environment and the entity's information assets change, that capability must evolve with it.
3. Implementation of controls
The entity must implement controls to protect its information assets, sized to the criticality and sensitivity of each asset, its lifecycle stage, and the potential consequences of an incident. Where a related party or third party manages an information asset, the entity must evaluate the design of that party's information security controls.
4. Testing and internal audit
Controls must be tested systematically, with the frequency and method of testing matched to the rate at which threats and vulnerabilities change and to the criticality of the asset in question. Internal audit must review the design and operating effectiveness of information security controls, including those of third parties where internal audit intends to rely on that party's assurance.
5. Incident and control weakness notification to APRA
This is the obligation with the least room for interpretation, and the one enforcement most often turns on.
72 hours — the entity must notify APRA as soon as possible, and no later than 72 hours after becoming aware of an information security incident that materially affected, or had the potential to materially affect, the entity or the interests of depositors, policyholders, beneficiaries or other customers, or that has been notified to another regulator in Australia or overseas.
10 business days — a separate clock applies to a material information security control weakness that the entity does not expect to be able to remediate in a timely manner.
Both clocks start at the point the entity becomes aware, not at the point a formal materiality determination is completed. In practice, this means the materiality assessment has to happen inside the 72-hour window, not before it starts.
How CPS 234 relates to CPS 230
CPS 234 is about information security specifically. CPS 230, which took effect 1 July 2025, is APRA's broader operational risk management standard, covering business continuity, third-party and service provider risk, and operational resilience across the whole entity, not only information assets.
The two standards overlap where information security incidents threaten operational continuity, and CPS 230's third-party provisions extend the same logic CPS 234 already applies to information assets: your suppliers' resilience is your resilience, from your regulator's perspective. An entity working through CPS 230 uplift should expect CPS 234 obligations to surface again in that process, particularly around third-party assessment and incident escalation.
Where entities most often fall short
- Third-party scope. CPS 234's third-party obligations apply to every information asset a third party manages, not only those captured under a formal material outsourcing agreement. Treating "no outsourcing contract" as "no CPS 234 exposure" is a common and costly misreading.
- Under-notification. Entities have not consistently notified APRA of material incidents or material control weaknesses. Receiving an assessment finding that identifies a material gap is not an alternative to notifying APRA; the finding itself can trigger the notification obligation.
- Board evidence. APRA's thematic reviews routinely request board and committee papers looking for evidence that information security risk was actually discussed, that investment in capability was challenged rather than rubber-stamped, and that incidents and control weaknesses were escalated in a timely way. A board that cannot produce that paper trail is exposed regardless of its actual security posture.
How Insicon Cyber helps
Insicon Cyber works with organisations across Australia and New Zealand on CPS 234 readiness across three connected services: Managed Compliance for the ongoing control testing, evidence and reporting CPS 234 expects; Board Cyber Advisory for the board papers and governance trail APRA's thematic reviews specifically look for; and Executive Tabletop and Cyber Simulation Exercises to pressure-test whether your materiality assessment and notification process can actually run inside the 72-hour window, not just on paper.
Talk to Insicon Cyber about Managed Compliance | Explore Board Cyber Advisory | Explore Tabletop and Cyber Simulation Exercises | info@insiconcyber.com
Frequently asked questions
Is CPS 234 a law or a guideline?
CPS 234 is a legally enforceable prudential standard made under the Banking Act, Insurance Act, Life Insurance Act and Superannuation Industry (Supervision) Act. APRA supervises and enforces it directly. It is not voluntary guidance.
Does CPS 234 require penetration testing specifically?
CPS 234 does not name penetration testing as a mandatory method. It requires a systematic testing program matched to the entity's threat environment and asset criticality, which in practice typically includes a mix of penetration testing, vulnerability scanning, configuration assessment and, for higher-risk assets, red team exercises.
What counts as a material incident under CPS 234?
CPS 234 does not set a fixed threshold. An incident is assessed as material based on its actual or potential financial and non-financial impact on the entity or on depositors, policyholders, beneficiaries or other customers, or on the fact that it has already been reported to another regulator. Entities are expected to have their own documented materiality assessment process ready to run inside the 72-hour notification window.
Do CPS 234 and the Notifiable Data Breaches scheme both apply to the same incident?
They can. CPS 234's 72-hour APRA notification is separate from Privacy Act 1988 (Cth) Notifiable Data Breaches obligations to the OAIC, and from ASIC continuous disclosure obligations for listed entities. A single incident can trigger several parallel notification obligations to different regulators, each with its own clock and its own form.
How does CPS 234 apply to a New Zealand-based operation?
CPS 234 is an Australian prudential standard and applies to APRA-regulated entities regardless of where their operations sit, including New Zealand-based subsidiaries or branches of an APRA-regulated group. A New Zealand-only entity with no APRA-regulated parent is not directly captured by CPS 234, but should still expect NZISM and Reserve Bank of New Zealand requirements to impose comparable information security obligations.
Sources: Australian Prudential Regulation Authority, Prudential Standard CPS 234 Information Security (apra.gov.au / handbook.apra.gov.au); APRA, CPS 230 Operational Risk Management (apra.gov.au); Office of the Australian Information Commissioner, Notifiable Data Breaches scheme (oaic.gov.au).