Quick answer
CPS 234 is the Australian Prudential Regulation Authority's information security standard, binding for APRA-regulated entities: banks, insurers, and superannuation funds. It requires clearly assigned security roles, capability proportionate to threats, a policy framework, controls testing, incident management with APRA notification (material incidents within 72 hours, control weaknesses within 10 business days), and, significantly for vendors, assurance over information assets managed by third parties. If you provide services to Australian financial institutions, CPS 234 arrives in your contracts.
The board owns it
CPS 234's first substantive requirement makes the board of an APRA-regulated entity ultimately responsible for information security. That framing (mirrored later by NIS 2 and DORA in Europe) drives the rest: roles and responsibilities defined, capability maintained relative to the threat environment, and the board receiving reporting that lets it actually govern. Regulated entities that can't evidence board oversight fail the standard regardless of technical strength.
What it demands operationally
- A policy framework proportionate to exposures, maintained and followed.
- Information asset identification and classification, including assets managed by related and third parties.
- Controls implemented and tested: systematic testing of control effectiveness, with escalation of weaknesses, not just annual pentests.
- Incident management: detection, response plans, annual plan testing, and the APRA notification clocks (72 hours for material incidents, 10 business days for material control weaknesses that can't be remediated quickly).
- Third-party assurance: where a vendor holds or manages the entity's information assets, the entity must evaluate the vendor's security capability and obtain assurance over their controls.
What it means for technology vendors
The third-party provisions convert into vendor obligations: security capability questionnaires, control assurance evidence (a SOC 2 report or ISO 27001 certificate plus specifics), incident notification clauses feeding the entity's 72-hour clock, and periodic re-assessment. Vendors with a maintained, shareable posture turn that recurring diligence into a link; vendors without one re-earn the deal every review cycle.

Get a personalized walkthrough of automated compliance for your team. No commitment required.