CPS 230 compliance entered a new phase on 1 July 2026, when transitional relief for pre-existing service provider contracts expired. The standard itself has applied since July 2025. That distinction matters, and getting it wrong is a common way to misjudge your exposure.

First, clear up the date confusion
A lot of commentary this year has described CPS 230 as newly live. That is not accurate, and the error leads people to the wrong remediation plan.
APRA Prudential Standard CPS 230 commenced on 1 July 2025. Therefore it has applied to banks, insurers and superannuation funds for more than a year. Nothing about the standard switched on last month.
What expired on 1 July 2026 was narrower. Specifically, it was the transitional relief for material service provider contracts that already existed when the standard commenced. Those legacy agreements had to be brought into line by the earlier of their next renewal date or 1 July 2026.
In addition, APRA finalised targeted amendments to the standard on 30 April 2026. Those amendments also commenced on 1 July 2026. As a result, three separate things converged on one date, which explains some of the confusion.
Who CPS 230 compliance applies to
The standard reaches every APRA-regulated entity. That means authorised deposit-taking institutions, general insurers, life insurers, private health insurers and registrable superannuation entity licensees.
Scale does affect expectations, though. APRA applies the standard proportionately, so a small non-significant financial institution is not held to the same operational depth as a major bank. Proportionality changes the depth of your evidence. It does not remove the obligation.
Service providers themselves sit outside the standard. Nevertheless, they feel it immediately, because regulated entities must push specific terms into their contracts. Consequently many technology and outsourcing vendors have spent the past year renegotiating agreements they did not expect to reopen.
One further point is easy to miss. Being a material service provider is a question of function, not spend. A low-cost provider supporting a critical operation can be material, while an expensive provider supporting a peripheral process may not be. So build your register from your critical operations map, not from your accounts payable ledger.
The two obligations people keep conflating
Two requirements involve material service providers, and they carry different dates. Mixing them up is the single most common error we see.
The register. Regulated entities had to submit their first material service provider register to APRA on 1 October 2025. This is a reporting obligation.
The contracts. Existing agreements had to meet the contractual requirements in CPS 230 by the earlier of renewal or 1 July 2026. This is a contractual obligation.
Consequently, an entity can have filed a complete register on time and still have non-compliant contracts. The two are not the same test, and passing one says nothing about the other.
Where CPS 230 compliance gaps are surfacing
Now that transitional relief has gone, the gaps that remain are mostly contractual rather than conceptual. Several patterns recur.
Contracts that renewed quietly. Auto-renewing agreements often rolled over without anyone applying the CPS 230 checklist. Because no negotiation event occurred, nobody reviewed the terms.
Missing audit and access rights. Legacy contracts frequently lack the rights APRA expects, particularly around access to information and the ability to conduct assurance activity.
Sub-contracting blind spots. Many agreements say nothing about fourth parties. However, your critical operation can fail because of a provider you have never contracted with directly.
Registers that do not match reality. A register filed in October 2025 may no longer reflect the provider landscape. Providers change, and services get reclassified.
Tolerance levels that were never tested. Setting a tolerance is straightforward. Demonstrating that you can operate within it during a severe disruption is considerably harder.
CPS 230 and CPS 234 both still apply
This question comes up constantly, so it is worth answering plainly. CPS 234 was not revoked. It remains in force as the information security standard.

Moreover, the two standards are deliberately linked. CPS 230 expressly requires entities to meet CPS 234 in relation to technology risk. So the newer standard builds on the older one rather than replacing it.
The simplest way to hold the distinction is by purpose. CPS 234 is about protecting information assets. CPS 230, by contrast, is about keeping critical operations running when something goes wrong.
What good CPS 230 compliance evidence looks like
Boards increasingly ask what proof looks like. Four artefacts carry most of the weight.
- A current critical operations map. It should show dependencies, including the providers and systems each operation relies on.
- Documented tolerance levels with test results. The tolerance is only half the requirement. Evidence that you tested against it completes the picture.
- A reconciled material service provider register. It should match both your contracts and your actual arrangements.
- A contract compliance position per provider. For each material arrangement, record whether it complies, and if not, what the remediation plan and date are.
Above all, keep these live. A point-in-time pack assembled for one board meeting ages quickly.
CPS 230 compliance and the SOCI regime
Some entities sit under both CPS 230 and the Security of Critical Infrastructure Act. If that describes you, there is good news and bad news.
The good news is real overlap. Dependency mapping, supplier risk work and continuity testing all serve both regimes. Therefore you can reuse a great deal of the underlying analysis.
The bad news is that the enhanced Critical Infrastructure Risk Management Program rules, registered on 9 June 2026, are more prescriptive than before. They also introduce periodic independent assurance. Phase-in periods push the first hard dates into 2027 and 2028, so there is time. Even so, the assurance requirement is worth planning for now.
Where to start on CPS 230 compliance if you are behind
If your contract remediation is incomplete, sequence the work by consequence rather than by contract value. In practice, that means starting with the providers your critical operations cannot tolerate losing.
You can read the standard and APRA guidance on the APRA operational risk management page, and the amendments are summarised in APRA announcement of the finalised amendments.
Our team supports Australian financial institutions with operational risk and continuity work, including business continuity management, enterprise risk management and vendor risk management. We also work with entities managing overlapping obligations under CIRMP. If a second pair of eyes on your contract position would help, get in touch.


