Our CPS 230 and CPS 234 advisory helps APRA-regulated banks, insurers and superannuation trustees meet APRA’s information security and operational risk standards, prove it to the board, and stay ready for supervisory review. Security Solution Consultants (SSC) provides gap assessments, maturity assessments, independent control testing and audit support for CPS 234 Information Security and CPS 230 Operational Risk Management.

| CPS 234 Information Security | CPS 230 Operational Risk Management | |
|---|---|---|
| In force | 1 July 2019 | Commenced 1 July 2025; targeted amendments apply from 1 July 2026 |
| Focus | Information security capability, controls, testing and incident notification | Operational risk, critical operations, business continuity and material service providers |
| Key requirements | Board accountability, information asset classification, controls, systematic testing, internal audit, third-party assurance | Critical operations and tolerance levels, business continuity plans tested annually, service provider management and a register of material arrangements |
| APRA notifications | 72 hours for a material information security incident; 10 business days for a material control weakness | 72 hours for a material operational risk incident; 24 hours when a critical operation is disrupted beyond tolerance; 20 business days after entering or materially changing a material arrangement |
The two standards overlap: a cyber incident is an operational risk event, and a service provider that holds your data is both a CPS 234 third party and a CPS 230 material service provider. We assess them together so you build one set of controls and evidence.

CPS 230 requires a comprehensive service provider management policy, a register of material arrangements submitted to APRA, and controls over material arrangements, including those with offshore providers. CPS 234 adds that you must assess the information security capability of third parties that manage your information assets. We build the register, design a proportionate due diligence and monitoring approach, and draft the contract clauses that make it enforceable.

CPS 234 expects testing to be risk-based, carried out by appropriately skilled and independent people, and reported to the board with remediation tracked. We design the testing program, test key controls such as access management, privileged access, vulnerability management, backup and recovery, and third-party access, and report results in a form the board and APRA can rely on.
Related: what changed in CPS 230 on 1 July 2026, business continuity management, enterprise risk management and cyber security maturity assessments.
APRA-regulated entities, including authorised deposit-taking institutions, general, life and private health insurers, and RSE licensees of superannuation funds.
A board-accountable information security capability, classification of information assets, controls proportionate to threats, systematic and independent testing of control effectiveness, internal audit coverage, and notification to APRA of material incidents and control weaknesses.
CPS 230 commenced on 1 July 2025, replacing APRA's earlier outsourcing and business continuity standards. APRA made targeted amendments that apply from 1 July 2026.
Critical operations are processes whose disruption would have a material adverse impact on customers or the entity. For each, the entity sets tolerance levels for the maximum period of disruption, the maximum extent of data loss and minimum service levels.
Under CPS 234, within 72 hours for a material information security incident. Under CPS 230, within 72 hours for a material operational risk incident and within 24 hours when a critical operation is disrupted beyond its tolerance.
Yes. Our consultants are independent of your operations team and can run the systematic control testing CPS 234 expects, with results reported to the board.
Tell us where you are today and what you need to achieve. We will come back with a clear scope, timeline and fixed quote.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informed with the latest cybersecurity news and expert tips.
Copyright © 2026 Security Solution Consultants. ABN 87 616 212 063. Tarneit, Victoria 3029, Australia. All Rights Reserved.