Skip to main content
APRA CPS 230 · CPS 234 · Operational resilience

Show APRA your security and resilience hold up under test.

APRA-regulated entities must protect information assets, keep critical operations running and control their service providers. CPS 230 took effect 1 July 2025, so boards need evidence that controls work, not just exist.

Human-led VAPT · NDA first · report in 48h

1 Jul 2025
date CPS 230 Operational Risk Management took effect
72 h
to notify APRA of a material information security incident under CPS 234
10 days
business days to notify APRA of a material information security control weakness
2
standards that work together: CPS 234 for information security and CPS 230 for operational risk
Board and leadership view

Why APRA CPS 230 and CPS 234 matter to your board

The work is technical. The consequences of getting APRA CPS 230 & CPS 234 wrong show up in revenue, liability and reputation, which is why we report on it in the language of the boardroom first.

Licence and supervisory standing

APRA supervises both standards. Weak evidence invites closer scrutiny, directions and conditions on how you operate.

Customer and counterparty confidence

Customers, members and institutions expect operations to continue through disruption and data to stay protected.

Reputation after an incident

A material incident reported to APRA within 72 hours tests how well you handle trust. Tested controls make the story easier to tell.

Accountability and deadlines

The board is ultimately responsible. CPS 230 is already in force and the supplier contract alignment date was 1 July 2026 at the latest.

Fit

Who the standards affect

Banks and authorised deposit-taking institutions

CPS 230 and CPS 234 apply directly, with APRA supervision of both.

Insurers and superannuation funds

APRA-regulated insurers and RSE licensees fall under both standards.

Technology and service providers

Cloud, software and managed service suppliers face contract clauses and evidence requests.

Boards and executives

Directors must oversee the risk framework and challenge the evidence they receive.

Scope of work

What Summit delivers for APRA CPS 230 & CPS 234

One accountable team takes you from scoping to retest. The people who test your systems are the people who explain the findings to your leadership.

Gap analysis

We map your controls, critical operations and supplier arrangements to CPS 234 and CPS 230 expectations.

Penetration testing

Human-led testing of critical applications, APIs, cloud and networks, including systems that suppliers run for you.

Control validation

We check that access, logging, recovery and monitoring controls work as documented, with independent evidence.

Evidence pack

Scope, methods, findings and results organised for internal audit, the board and APRA discussions.

Remediation support and retest

Practical fix guidance for your engineers and a retest that confirms each issue is closed.

Board-ready report

A plain-language summary of exposure, progress and decisions needed from directors.

Fixed scope, one team, no hand-offsYou get a named lead, a clear scope document before work starts and a report your leadership, customers and reviewers can read without a translator. We stay with you through your review to answer questions about what we tested and found.
How it works

A practical APRA readiness path

Timelines are typical ranges, not promises. Yours depends on scope, team size and how much is already in place.

  1. 1

    Confirm scope

    Weeks 1 to 2

    Identify which entities and critical operations are covered and who owns each.

  2. 2

    Assess gaps

    Weeks 2 to 6

    Compare CPS 234 controls, CPS 230 tolerances and supplier arrangements with expectations.

  3. 3

    Test the controls

    Months 2 to 4

    Run penetration testing and control validation on critical information assets and exposed services.

  4. 4

    Align suppliers

    Months 3 to 8

    Fix and retest findings, then update the service provider register, contracts and assurance evidence for material providers.

  5. 5

    Report to the board

    Quarterly

    Give directors a clear view of test results, open findings and tolerance performance.

Deliverables

What your leadership team receives

Every engagement ends with material written for two audiences: a plain-language view for executives and the board, and full technical detail for the engineers who fix things.

  • Which operations are critical?

    Ask for the list, the owners and the board-approved tolerances.

  • When were our critical assets last tested?

    Ask for dates, scope and retest status.

  • Who tests, and are they independent?

    Confirm testers are skilled and independent of the teams being tested.

  • What assurance do we hold over suppliers?

    Ask for test evidence on material service providers.

  • Could we meet the 72 hour notice?

    Ask when the incident process was last rehearsed.

The detail

What CPS 230 and CPS 234 actually are

APRA, the Australian Prudential Regulation Authority, sets binding prudential standards for banks, insurers, and superannuation funds. CPS 234 Information Security requires entities to maintain an information security capability that fits their threats and vulnerabilities, and to test the effectiveness of controls. It extends to information assets managed by related parties and third parties.

CPS 230 Operational Risk Management, in effect from 1 July 2025, requires entities to manage operational risk, identify critical operations, set tolerance levels for disruption and manage material service providers. It replaces earlier standards on outsourcing and business continuity and sits alongside CPS 234.

Existing service provider contracts needed to align with CPS 230 by the earlier of the next renewal and 1 July 2026. Boards hold ultimate accountability for both standards. For suppliers, this means regulated customers push security testing and evidence requirements down through contracts.

Key terms in plain English

Critical operations
Processes whose disruption beyond tolerance would materially harm customers or financial stability.
Material service provider
A supplier on which the entity relies for critical operations or that exposes it to material operational risk.
Tolerance level
The maximum disruption an entity will accept for a critical operation.
Information asset
Information and the technology that stores, processes or transmits it, including assets managed by others.
Requirements

What the standards ask for

CPS 234 is about protecting information assets. CPS 230 is about running critical operations through disruption and managing the suppliers involved. Together they ask for evidence that controls work.

1

Information security capability

Maintain a capability proportionate to the size and extent of threats. Capability must adapt as threats change and extend to information assets managed by related and third parties.

What it looks like in practice

  • Clear roles and responsibilities up to the board
  • An asset inventory with criticality ratings
  • Security policy framework aligned to threats
2

Controls and systematic testing

Implement controls in line with asset criticality across the lifecycle, and test their effectiveness through a systematic programme. Test results must be escalated and tracked, and testing must be done by appropriately skilled and functionally independent people.

What it looks like in practice

  • A risk-based testing plan covering critical assets
  • Findings tracked to closure with retesting
  • Independent testers or reviewers
3

Incident management and notification

Maintain response plans, test them annually and notify APRA within 72 hours of a material security incident. Under CPS 230, material operational risk incidents have a similar clock, and business continuity activation has its own notice.

What it looks like in practice

  • Incident criteria for material events
  • Tested response and recovery plans
  • Pre-agreed notification roles
4

Critical operations and tolerances

Identify critical operations, set tolerance levels for disruption and keep a business continuity plan that can be shown to work under severe but plausible scenarios.

What it looks like in practice

  • A list of critical operations with owners
  • Tolerance levels approved by the board
  • Scenario testing results
5

Material service providers and assurance

Keep a register of service providers, assess their materiality, set contract terms that preserve audit and notification rights and obtain assurance that their controls are effective. CPS 234 expects assurance from third parties whose control strength matters to your information assets.

What it looks like in practice

  • A service provider register with materiality ratings
  • Contracts with security and notification obligations
  • Independent test evidence from key suppliers
Where testing fits

How penetration testing supports APRA CPS 230 & CPS 234

CPS 234 requires systematic testing of control effectiveness, and APRA expects results to be escalated and tracked. Independent penetration testing of critical assets gives the board and APRA evidence that goes beyond policy.

CPS 234

Control effectiveness testing

Penetration testing and control validation show that safeguards work against realistic attacks.

CPS 234

Independent testers

Testing must be done by appropriately skilled people who are independent of the function being tested.

CPS 234

Third-party assurance

Test evidence for systems run by suppliers supports your assurance over assets managed by others.

CPS 230

Operational resilience

Testing the systems behind critical operations helps show disruption risk is understood and managed.

Avoid these

Common APRA CPS 230 & CPS 234 mistakes, and how to avoid them

!

Treating CPS 230 as a policy rewrite

APRA expects tested tolerances and workable recovery, not only updated documents.

!

Testing only internal systems

CPS 234 reaches assets managed by third parties. Supplier-run systems need evidence too.

!

No retest after fixes

Test results must be tracked and escalated. A closed finding needs proof it is closed.

!

Leaving the board out

Both standards place ultimate accountability on the board. Reporting must be clear enough to challenge.

FAQ

APRA CPS 230 & CPS 234 questions, answered

When did CPS 230 take effect?

1 July 2025. Existing service provider contracts had until the earlier of their next renewal and 1 July 2026 to align.

What is the difference between CPS 230 and CPS 234?

CPS 234 covers information security. CPS 230 covers operational risk management, including critical operations, tolerance levels and service providers. They apply together.

Who must follow them?

APRA-regulated entities such as banks, insurers and superannuation funds. Their suppliers feel the effect through contracts and assurance requests.

What does CPS 234 say about testing?

Entities must test the effectiveness of controls through a systematic programme, using skilled and functionally independent testers, and escalate and track results.

How fast must incidents be notified?

CPS 234 requires notice to APRA within 72 hours of a material information security incident. CPS 230 has its own 72 hour notice for material operational risk incidents.

What does CPS 234 expect for third parties?

That you maintain information security for assets managed by third parties, and obtain assurance that their controls are effective, proportionate to the criticality of the assets.

Is this legal or regulatory advice?

No. It is general education. Confirm your obligations with qualified counsel or APRA guidance.

Ready to get APRA CPS 230 & CPS 234 sorted?

Tell us your scope, your deadline and who is asking. You get a fixed-scope quote in 15 minutes and a named lead from day one.

Get a Quote in 15 mins →