has not changed since it took effect on 1 July 2019. If you have gone looking for what is new in APRA's information security standard and found nothing, that is why. What has changed is the standard next to it. CPS 230 Operational Risk Management commenced on 1 July 2025, and it reaches into the same technology, the same service providers and the same incidents that CPS 234 covers, with its own clocks and its own register.
This page sets the two standards side by side, lists every dated event since mid-2025, and works through what a cyber incident looks like when both apply at once. It is built from the standards as published by APRA and is current at 29 September 2026. It is not legal advice.
The two standards side by side
| CPS 234 Information Security | CPS 230 Operational Risk Management | |
|---|---|---|
| What it covers | The confidentiality, integrity and availability of information assets: information and information technology, including software, hardware and data. | Operational risk in full, the continuity of critical operations through severe disruption, and the risks arising from service providers. |
| In force since | 1 July 2019. | 1 July 2025. For contracts that already existed on that date, from the earlier of the next renewal or 1 July 2026. |
| Who owns it | The Board is ultimately responsible for information security (paragraph 13). | The Board is ultimately accountable for oversight of operational risk management (paragraph 20). |
| Third parties | Assess a third party's security capability (16), evaluate the design of its controls (22), assess its control testing (28), and have internal audit review its assurance (32 to 34). | Keep a register of material service providers (49), submit it to APRA annually (51), and hold a formal agreement with each that meets the minimum terms in paragraphs 54 and 55. |
| What must be classified | Information assets, by criticality and sensitivity (20). | Critical operations (35 and 36) with tolerance levels for downtime, data loss and minimum service (38); material service providers (49 and 50). |
| Testing | A systematic program testing the effectiveness of information security controls, by skilled and functionally independent testers (27 to 31). | A systematic testing program for the business continuity plan, tailored to material risks (43 and 44), and regular monitoring, review and testing of operational risk controls (30). |
| Notify APRA within 72 hours | A material information security incident, or one notified to another regulator (35). | An operational risk incident likely to have a material financial impact or a material impact on critical operations (33). |
| Other clocks | 10 business days for a material control weakness that will not be remediated in a timely manner (36). | 24 hours after a disruption to a critical operation outside tolerance (42). 20 business days after entering or materially changing an agreement for a critical operation (59). Before entering any material offshoring arrangement (59). |
| Practice guide | CPG 234, June 2019. | CPG 230, final version released 13 June 2024. |
Where they overlap
Your IT provider, your cloud platform and your security vendor sit in both. CPS 234 requires you to assess their security capability and evaluate their controls. CPS 230 goes further and says core technology services are a material service provider by default, unless you can justify otherwise, which means a register entry, a formal agreement with APRA access rights and audit access written in, and notification to APRA within 20 business days of signing or materially changing the deal.
A is the clearest case of both standards firing at once. It is an information security incident under CPS 234, so if it is material, or you have told another regulator such as the , APRA must hear within 72 hours. It is an operational risk incident under CPS 230, so if it is likely to have a material financial impact or hit a critical operation, that is a second 72-hour notification. And if claims processing, payments or customer enquiries stop for longer than your tolerance level, that is a third notification, within 24 hours. Three clocks, two standards, one incident.
The same overlap runs the other way for weaknesses. A control weakness you cannot fix in a timely manner is a 10-business-day notification under CPS 234, and the same weakness may be a material operational risk that CPS 230 requires you to remediate and report on through your risk framework. Our CPS 234 requirements checklist has the evidence expected under each paragraph.
What changed, in date order
| Date | What happened | What it means |
|---|---|---|
| 1 July 2019 | CPS 234 commences. CPG 234 published the previous month. | Unchanged since. Every CPS 234 obligation on this page is the original wording. |
| 17 July 2023 | APRA finalises CPS 230, with commencement deferred to 1 July 2025 after industry consultation. | Two years' notice, with a further year for existing contracts. |
| 13 June 2024 | Final CPG 230 released. | The practice guide supervisors measure CPS 230 implementation against. |
| 14 October 2024 | APRA releases the material service provider register template. | The register format entities now submit annually. |
| 1 July 2025 | CPS 230 commences. | Critical operations, tolerance levels, the incident and disruption clocks and the service provider policy all apply from this date. |
| 1 October 2025 | First material service provider registers due to APRA from ADIs, superannuation trustees and insurers. | APRA now holds a list of who every regulated entity depends on, including its technology providers. |
| 30 April 2026 | Targeted amendments to CPS 230, CPG 230 and the register template: limited exemptions from specific contractual requirements for material arrangements with certain categories of service provider where contractual compliance is not practicable. | A defined list of exempt provider categories, reflected in the register template. |
| 1 July 2026 | Transition ends for pre-existing service provider contracts. The 30 April amendments take effect. | Every material arrangement now has to meet the paragraph 54 and 55 terms, or fall within an exempt category. |
Nothing on that list touches CPS 234's text. What it changes is the environment around it: the third parties are now on an APRA register, the incidents carry a second set of notification duties, and the board signs off on both.
What supervisors are looking at
On the CPS 234 side, APRA's thematic review in 2020 and 2021 found the same three gaps across most entities: control testing not frequent enough, third-party risk assumed rather than assessed, and incident detection below expectation.
On the CPS 230 side the first year has been about the register and the contracts. The 1 October 2025 register submission put every entity's material providers in front of APRA, and the 1 July 2026 transition deadline turned the paragraph 54 and 55 agreement terms from a future obligation into a current one. If a technology contract renewed after 1 July 2025 and still lacks audit access, APRA access, sub-contractor notification or termination rights, that is the gap most likely to be asked about.
Frequently asked questions
Is CPS 234 being replaced by CPS 230?
No. CPS 230 replaced the outsourcing and business continuity standards. CPS 234 stands alongside it, unchanged, and both apply to every APRA-regulated entity.
Has CPS 234 changed in 2025 or 2026?
No. The standard in force is the July 2019 version, and is the June 2019 guide. As at 29 September 2026 APRA has not consulted on amendments to either.
Which standard applies to a cyber attack?
Both. It is an information security incident under CPS 234 and an operational risk incident under CPS 230. Each has its own 72-hour notification test, and a disruption to a critical operation beyond tolerance adds a 24-hour notification under CPS 230.
Is our IT or security provider a material service provider?
Under paragraph 50 of CPS 230, core technology services are a material service provider by default for every APRA-regulated entity, unless the entity can justify otherwise. That puts most IT, cloud and managed security providers on the register and inside the formal agreement requirements.
Did our existing provider contracts have to change by 1 July 2026?
Yes, unless they had already renewed. Paragraph 7 of CPS 230 applies the standard to pre-existing contracts from the earlier of the next renewal date or 1 July 2026. The 30 April 2026 amendments carve out limited exemptions for certain provider categories where contractual compliance is not practicable; APRA publishes the list.
Where to start
For most entities the join between the two standards is the provider file: one assessment of each technology provider that satisfies CPS 234's capability and control evaluation and CPS 230's register and agreement terms at the same time. Our CPS 234 compliance service builds that file, and the CPS 234 explainer covers the standard's ten areas in more depth.



