Guide
APRA CPS 234, Explained: Information Security for Banks, Insurers & Super Funds
August 30, 2026 · 8 min read
CPS 234 is APRA’s information-security standard — mandatory for banks, insurers and super funds. Here’s what it requires, the notification clock everyone forgets, and how ISO 27001 gets you most of the way.
Quick answer: APRA CPS 234 is a Prudential Standard on Information Security issued by the Australian Prudential Regulation Authority. It is mandatory for APRA-regulated entities — banks (ADIs), general and life insurers, private health insurers, and superannuation (RSE) licensees, along with their subsidiaries. It requires the Board to be ultimately accountable for information security and sets requirements for capability, controls, testing, incident management, notification and third-party management.
Who must comply?
CPS 234 binds APRA-regulated entities: authorised deposit-taking institutions, general/life/private-health insurers, and registrable superannuation entity licensees — and it reaches their related parties and third parties that manage their information assets. If APRA regulates you, CPS 234 is not optional.
What CPS 234 requires
- Roles and responsibilities — the Board is ultimately responsible for information security.
- Information security capability — commensurate with the size and extent of threats, including for assets managed by third parties.
- Policy framework — direction for everyone with information-security obligations.
- Asset identification and classification — by criticality and sensitivity.
- Implementation of controls — commensurate with criticality, sensitivity and threat.
- Incident management — robust detection and response, with tested response plans.
- Testing control effectiveness — a systematic program whose frequency reflects change, criticality and threat.
- Internal audit — independent review of the design and operating effectiveness of controls.
- APRA notification — notify APRA within 72 hours of a material incident, and within 10 business days of a material control weakness.
- Third-party management — assurance over information assets managed by related or third parties.
The notification clock everyone forgets
CPS 234 has two hard notification obligations: notify APRA as soon as possible and no later than 72 hours after becoming aware of an information-security incident that materially affected (or could have) the entity or its customers; and no later than 10 business days after identifying a material control weakness you can’t remediate in time. A documented, rehearsed notification procedure is essential.
How ISO 27001 and SOC 2 map onto CPS 234
CPS 234’s governance, asset-classification, incident, testing and third-party requirements overlap strongly with ISO 27001 and SOC 2. CATAAM cross-maps a single evidence set, so an ISO- or SOC 2-certified entity auto-satisfies much of CPS 234 and builds only the APRA-specific pieces — Board accountability, the notification duty and the systematic testing program. The control-effectiveness testing requirement pairs naturally with CATAAM’s built-in penetration testing and breach & attack simulation.
Automate APRA CPS 234 with CATAAM
→