APRA CPS 234 & CPS 230 Compliance
Meet APRA's information security and operational resilience requirements, whether you're regulated or you supply someone who is.
APRA expects banks, insurers and super funds to protect their information assets (CPS 234) and to keep critical operations running through disruption (CPS 230). Those expectations don't stop at the regulated entity. They flow through contracts to every material service provider. We help both sides meet them, with practical controls and evidence that hold up to scrutiny.
For APRA-regulated entities
CPS 234 assessment and uplift. We review your information security capability, policy framework, asset classification, controls, incident response and testing against CPS 234 and its guidance, then help you close the gaps.
CPS 230 operational resilience. We help you identify critical operations, set tolerance levels, maintain your material service provider register, and build business continuity plans and scenario testing that meet APRA's expectations.
Third-party risk management. We help you assess the security and resilience of your service providers and make sure contracts include what CPS 230 requires.
Board and executive reporting. We give your board clear, defensible reporting on information security and operational risk, so directors can meet their accountability.
For service providers to APRA-regulated entities
If you provide technology, data, outsourcing or other material services to a bank, insurer or super fund, your customer's APRA obligations become your obligations. Expect contract clauses on security, incident notification, business continuity, audit rights and subcontracting, along with detailed due diligence.
CPS 230 and CPS 234 readiness. We explain what your customers will expect and help you get ready before the questionnaire arrives.
Due diligence support. We help you answer security assessments clearly and accurately, backed by real evidence.
ISO 27001 certification. Independent certification is one of the strongest ways to show your customers you take security seriously. Learn about our ISO 27001 service →
How we work
1. Gap assessment
We assess where you stand against CPS 234 and CPS 230, or against what your regulated customers will expect of you.
2. Prioritised roadmap
You get a practical plan that ranks gaps by regulatory and business risk, not a list of everything that could be better.
3. Uplift
We help your team put policies, controls, processes and testing in place, sized to your organisation.
4. Evidence and assurance
We make sure you can show compliance, not just claim it, whether to APRA, your board or your customers.
Why Cyber Systems HQ
Built on ISO 27001. CPS 234 and ISO 27001 overlap heavily. We map the two together, so you maintain one set of controls instead of two parallel programs.
Risk expertise. Gavin Oh holds ISACA's CISM and CRISC certifications, covering security management and IT risk, which is the core of what CPS 234 and CPS 230 ask for.
Regulatory depth. Dan Goldberg has contributed to policy discussions on Australian cyber and privacy reform, including the SOCI Act and Privacy Act amendments, and has guided more than 20 organisations through ISO 27001 certification.
Both sides of the contract. We understand what regulated entities need from their suppliers and what suppliers can realistically deliver, which makes for faster, smoother negotiations.
Start with a gap assessment
Our combined CPS 234 and CPS 230 gap assessment shows you where you stand in 6–10 weeks, with a prioritised roadmap to close the gaps.
Frequently asked questions
We're not regulated by APRA. Does CPS 230 apply to us?
Not directly. But if you provide a material service to an APRA-regulated entity, it must ensure your contract and your operations meet CPS 230's requirements. In practice, that means your customer will ask you to meet them.
Is ISO 27001 certification enough to meet CPS 234?
It's a strong foundation and covers much of what CPS 234 requires. But CPS 234 has specific requirements of its own, including board accountability, notifying APRA of material incidents, and assessing the security of third parties. We help you close the gap between the two.
What changed on 1 July 2026?
CPS 230 is now fully in effect. Existing contracts with material service providers must now comply, and the deferred business continuity requirements apply to all regulated entities.