Licence and supervisory standing
APRA supervises both standards. Weak evidence invites closer scrutiny, directions and conditions on how you operate.
APRA-regulated entities must protect information assets, keep critical operations running and control their service providers. CPS 230 took effect 1 July 2025, so boards need evidence that controls work, not just exist.
Human-led VAPT · NDA first · report in 48h
The work is technical. The consequences of getting APRA CPS 230 & CPS 234 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.
APRA supervises both standards. Weak evidence invites closer scrutiny, directions and conditions on how you operate.
Customers, members and institutions expect operations to continue through disruption and data to stay protected.
A material incident reported to APRA within 72 hours tests how well you handle trust. Tested controls make the story easier to tell.
The board is ultimately responsible. CPS 230 is already in force and the supplier contract alignment date was 1 July 2026 at the latest.
CPS 230 and CPS 234 apply directly, with APRA supervision of both.
APRA-regulated insurers and RSE licensees fall under both standards.
Cloud, software and managed service suppliers face contract clauses and evidence requests.
Directors must oversee the risk framework and challenge the evidence they receive.
One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.
We map your controls, critical operations and supplier arrangements to CPS 234 and CPS 230 expectations.
Human-led testing of critical applications, APIs, cloud and networks, including systems that suppliers run for you.
We check that access, logging, recovery and monitoring controls work as documented, with independent evidence.
Scope, methods, findings and results organised for internal audit, the board and APRA discussions.
Practical fix guidance for your engineers and a retest that confirms each issue is closed.
A plain-language summary of exposure, progress and decisions needed from directors.
Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.
Identify which entities and critical operations are covered and who owns each.
Compare CPS 234 controls, CPS 230 tolerances and supplier arrangements with expectations.
Run penetration testing and control validation on critical information assets and exposed services.
Fix and retest findings, then update the service provider register, contracts and assurance evidence for material providers.
Give directors a clear view of test results, open findings and tolerance performance.
Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.
Ask for the list, the owners and the board-approved tolerances.
Ask for dates, scope and retest status.
Confirm testers are skilled and independent of the teams being tested.
Ask for test evidence on material service providers.
Ask when the incident process was last rehearsed.
APRA, the Australian Prudential Regulation Authority, sets binding prudential standards for banks, insurers, and superannuation funds. CPS 234 Information Security requires entities to maintain an information security capability that fits their threats and vulnerabilities, and to test the effectiveness of controls. It extends to information assets managed by related parties and third parties.
CPS 230 Operational Risk Management, in effect from 1 July 2025, requires entities to manage operational risk, identify critical operations, set tolerance levels for disruption and manage material service providers. It replaces earlier standards on outsourcing and business continuity and sits alongside CPS 234.
Existing service provider contracts needed to align with CPS 230 by the earlier of the next renewal and 1 July 2026. Boards hold ultimate accountability for both standards. For suppliers, this means regulated customers push security testing and evidence requirements down through contracts.
CPS 234 is about protecting information assets. CPS 230 is about running critical operations through disruption and managing the suppliers involved. Together they ask for evidence that controls work.
Maintain a capability proportionate to the size and extent of threats. Capability must adapt as threats change and extend to information assets managed by related and third parties.
Implement controls in line with asset criticality across the lifecycle, and test their effectiveness through a systematic programme. Test results must be escalated and tracked, and testing must be done by appropriately skilled and functionally independent people.
Maintain response plans, test them annually and notify APRA within 72 hours of a material security incident. Under CPS 230, material operational risk incidents have a similar clock, and business continuity activation has its own notice.
Identify critical operations, set tolerance levels for disruption and keep a business continuity plan that can be shown to work under severe but plausible scenarios.
Keep a register of service providers, assess their materiality, set contract terms that preserve audit and notification rights and obtain assurance that their controls are effective. CPS 234 expects assurance from third parties whose control strength matters to your information assets.
CPS 234 requires systematic testing of control effectiveness, and APRA expects results to be escalated and tracked. Independent penetration testing of critical assets gives the board and APRA evidence that goes beyond policy.
Penetration testing and control validation show that safeguards work against realistic attacks.
Testing must be done by appropriately skilled people who are independent of the function being tested.
Test evidence for systems run by suppliers supports your assurance over assets managed by others.
Testing the systems behind critical operations helps show disruption risk is understood and managed.
APRA expects tested tolerances and workable recovery, not only updated documents.
CPS 234 reaches assets managed by third parties. Supplier-run systems need evidence too.
Test results must be tracked and escalated. A closed finding needs proof it is closed.
Both standards place ultimate accountability on the board. Reporting must be clear enough to challenge.
1 July 2025. Existing service provider contracts had until the earlier of their next renewal and 1 July 2026 to align.
CPS 234 covers information security. CPS 230 covers operational risk management, including critical operations, tolerance levels and service providers. They apply together.
APRA-regulated entities such as banks, insurers and superannuation funds. Their suppliers feel the effect through contracts and assurance requests.
Entities must test the effectiveness of controls through a systematic programme, using skilled and functionally independent testers, and escalate and track results.
CPS 234 requires notice to APRA within 72 hours of a material information security incident. CPS 230 has its own 72 hour notice for material operational risk incidents.
That you maintain information security for assets managed by third parties, and obtain assurance that their controls are effective, proportionate to the criticality of the assets.
No. It is general education. Confirm your obligations with qualified counsel or APRA guidance.
Browse all 23 security and compliance frameworks or see our penetration testing services.
Last reviewed October 2026. Requirements change; confirm current texts and dates before you commit to a plan.
Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.
Get a Quote in 15 mins →Disclaimer. Summit provides independent technical and risk assessments. This is not legal advice or a regulatory certification. Acceptance of any report is decided by the requesting auditor, customer or regulator.