FreeThe +45-page Authentication Analytics Whitepaper — measuring real login journeysDownload
Back to Overview

How to stay compliant with CPS 234 in 2026?

Learn about APRA CPS 234, its requirements, and how to ensure compliance with robust cybersecurity practices to safeguard critical information assets

Vincent Delitz
Vincent Delitz

Created: January 2, 2025

Updated: August 26, 2026

How to stay compliant with CPS 234 in 2026?
Key Facts
  • CPS 234 mandates APRA-regulated entities to maintain information security capabilities commensurate with evolving threats, with the Board of Directors holding ultimate compliance responsibility.
  • Australian financial institutions managing assets exceeding 6.5 trillion AUD are subject to CPS 234, covering banks, insurers, superannuation funds and third-party vendors.
  • Material security incidents must be reported to APRA within 72 hours; material control weaknesses require a separate notification within 10 business days.
  • Third-party vendor oversight is a core CPS 234 obligation, requiring due diligence, contractual security provisions and periodic risk assessments for all parties managing information assets.
  • CPS 234 defines eight compliance areas spanning information security capability, policy framework, asset classification, control implementation, incident management, control testing, internal audit and APRA notification.

1. Overview of APRA Prudential Standard CPS 234#

The Prudential Standard CPS 234 Information Security (CPS 234) was introduced by the Australian Prudential Regulation Authority (APRA) to address the growing threat of cyberattacks in the financial sector. Its primary aim is to ensure APRA-regulated entities maintain robust information security measures to mitigate the risk of information security incidents, including cyberattacks.

APRA's mission is to enforce prudential standards that support a stable, efficient, and competitive financial services sector, ensuring financial promises made by its regulated entities are met under all reasonable circumstances. CPS 234 exemplifies this mission by mandating entities to establish and maintain information security capabilities commensurate with the evolving landscape of security vulnerabilities and threats.

WhitepaperAustralia Icon

Passkeys for Australia. Practical guidance, rollout patterns and KPIs for passkey programs.

Get Whitepaper

This article will cover all important information regarding the compliance with CPS 234 in 2025.

2. Why is CPS 234 important?#

CPS 234 plays a crucial role in safeguarding Australian businesses by ensuring resilience against cyber threats and other security risks. It also requires entities to respond promptly to significant security incidents, such as data breaches.

Cyberattacks targeting financial institutions have become increasingly sophisticated, driven by the potential for financial gain and access to sensitive data, including personally identifiable information (PII) and protected health information (PHI). Financial institutions, which manage assets exceeding $6.5 trillion, are particularly attractive to attackers.

The rise in third-party vendor reliance within the superannuation, banking, and insurance sectors has amplified these risks. Consequently, stakeholders demand higher standards of information security to protect critical information assets.

By enforcing rigorous security measures and vendor risk management practices, CPS 234 aims to reduce the frequency and impact of cybersecurity incidents, ultimately enhancing the resilience of the financial sector.

Igor Gjorgjioski Testimonial

Igor Gjorgjioski

Senior Product Lead, VicRoads

We hit 80% mobile passkey activation across 5M+ users without replacing our IDP.

See how VicRoads scaled passkeys to 5M+ users, alongside their existing IDP.

Read the case study

3. Who is subject to CPS 234?#

CPS 234 applies to all APRA-regulated entities, including:

  • Authorized deposit-taking institutions (ADIs) such as banks, credit unions, and foreign ADIs
  • General insurers, including non-operating holding companies and parent entities of Level 2 insurance groups
  • Life insurance companies, friendly societies, and eligible foreign life insurers
  • Private health insurers
  • Superannuation funds and RSE licensees

The standard also extends to information assets managed by third-party vendors, requiring these parties to comply with CPS 234 mandates.

4. Governance and Responsibility#

The Board of Directors holds ultimate responsibility for CPS 234 compliance. Boards must ensure that their organizations maintain robust information security aligned with the scale of risks to their information assets. While the Board may delegate responsibilities, it must clearly define expectations for engagement, risk escalation, and reporting.

Entities are required to establish clearly defined roles and responsibilities for all stakeholders involved in information security, including senior management, governing bodies, and operational teams. These roles are supported by role statements, policies, reporting lines, and governance charters to avoid ambiguity and ensure accountability.

Effective oversight requires non-technical stakeholders to receive comprehensible reports supplemented by analysis of business implications, ensuring informed decision-making.

Substack Icon

Subscribe to our Passkeys Substack for the latest news.

Subscribe

5. What are the Key Requirements of CPS 234?#

CPS 234 outlines critical requirements to ensure comprehensive information security. These include:

  1. Information Security Capability
    Entities must maintain capabilities proportional to the size and nature of threats to their information assets, actively adapting to evolving risks and vulnerabilities.

  2. Policy Framework
    An information security policy framework must define roles, responsibilities, and security practices for all stakeholders, including contractors and third-party vendors.

  3. Information Asset Identification and Classification
    Information assets must be classified by their sensitivity and criticality to prioritize protection measures.

  4. Control Implementation
    Security controls must be designed, tested, and maintained throughout the lifecycle of information assets.

  5. Incident Management
    Entities must have robust mechanisms to detect, respond to, and recover from information security incidents.

  6. Control Testing
    Regular and systematic testing must validate the effectiveness of security measures.

  7. Internal Audit
    Independent audits must assess the adequacy of information security controls and provide assurance to the Board.

  8. APRA Notification
    Material security incidents or weaknesses must be reported to APRA within specified timeframes.

Why are Passkeys important?

Passkeys for Enterprises

Passwords & phishing put enterprises at risk. Passkeys offer the only MFA solution balancing security and UX. Our whitepaper covers implementation and business impact.

Passkeys for Enterprises

Download free whitepaper

6. How to Achieve Compliance with CPS 234#

To comply with CPS 234, entities need to develop and implement a robust security framework that addresses the standard's key requirements. This involves aligning organizational processes, resources, and technologies with the demands of evolving cybersecurity threats. Key steps include:

6.1 Establishing and Maintaining Adaptive Security Capabilities#

  • Conduct regular assessments of the organization's resourcing, including funding, personnel, and access to specialized skill sets.
  • Implement a dynamic control environment that evolves with emerging threats, vulnerabilities, and business changes.
  • Ensure continuous training for staff involved in cybersecurity to maintain awareness of current risks and mitigation strategies.

6.2 Identifying and Classifying Information Assets#

  • Develop an inventory of all information assets, including those managed by third-party vendors.
  • Categorize assets based on their criticality and sensitivity to prioritize security measures.
  • Use tools like configuration management databases (CMDBs) to maintain up-to-date asset relationships and dependencies.

6.3 Enhancing Vendor and Third-Party Oversight#

  • Conduct due diligence on third-party vendors to ensure their security practices align with CPS 234 requirements.
  • Establish clear contractual obligations for information security, including provisions for monitoring, audits, and incident management.
  • Regularly evaluate vendor performance through periodic reviews, testing, and risk assessments.

6.4 Strengthening Incident Management#

  • Develop a comprehensive incident response plan to address various security threats, such as ransomware, phishing, or unauthorized access.
  • Test incident response plans regularly to ensure their effectiveness in mitigating potential breaches.
  • Define clear roles and escalation paths to ensure timely responses to incidents.

6.5 Implementing and Testing Security Controls#

  • Apply security controls commensurate with the criticality and sensitivity of information assets, ensuring timely remediation of vulnerabilities.
  • Conduct regular testing of controls, such as penetration testing and vulnerability assessments, to validate their effectiveness.
  • Include scenarios for worst-case incidents in the testing plan to prepare for extreme but plausible threats.

6.6 Establishing a Policy Framework#

  • Develop a hierarchical set of policies, standards, and procedures addressing all aspects of information security, from access control to data lifecycle management.
  • Periodically review and update policies to ensure alignment with evolving regulatory and industry standards.
  • Incorporate measures to address exemptions, ensuring compensating controls are in place and monitored.

6.7 Ensuring Clear Governance and Accountability#

  • Define roles and responsibilities for information security at all organizational levels, from the Board to operational teams.
  • Ensure robust reporting mechanisms that provide stakeholders with actionable insights into the organization’s security posture.
  • Regularly engage the Board and senior management to reinforce accountability and drive strategic alignment with cybersecurity objectives.

6.8 Maintaining a Culture of Security#

  • Foster a culture of security awareness throughout the organization by providing regular training and communication about cybersecurity practices.
  • Promote the integration of security into all business processes and decision-making.

7. Incident Notification and Escalation#

Under CPS 234, material security incidents must be reported to APRA within 72 hours. Entities must provide detailed information, including the incident’s nature, status, and mitigation actions. Similarly, material control weaknesses must be reported within 10 business days, along with planned remediation efforts.

8. How Corbado can help#

CPS 234 asks for controls that are systematically tested, a Board that can be held to what it was told and an internal audit that can check both. Applied to the authentication control, that means being able to show what the login actually did over a period, in a form somebody outside the team can take away. Corbado Observe, the authentication observability layer, produces that record from the login stack you already run.

See Executive Reporting in Corbado Observe →
  • The Board sees the same view on a schedule. Executive Reporting is the long-horizon KPI page, and a page subscription emails it to one named project member weekly or monthly, carrying the filters and the reporting window that were active when it was set up. The accountability described in section 4 stops depending on somebody remembering to build a slide. One named recipient is the whole distribution list, so the Board pack is still assembled by a person from what lands in that inbox.
  • Control changes carry a date. Annotations are short project-scoped notes tied to a day, reached through a badge beside the date picker. Section 6.5 asks for regular testing of security controls, and this is where the date a control was changed or retested sits next to the numbers it moved.
  • The evidence leaves the tool. A page exports to CSV as an ordinary browser download, with no API key involved, which is the fastest way to attach a figure to a paper. The machine-readable route is the daily table exports, Parquet files behind short-lived signed download links, and there an API key needs observe:tableExports:read to list the files and mint a link. A separate permission, observe:dataExports:read, covers the per-user subject export, so keep the two apart when you write the key up for your access register. The internal audit requirement in section 5 works better against your own copy of the data.
  • The telemetry is itself an information asset. Section 6.2 is about identifying and classifying what you hold. Observe keys its records on opaque IDs, and what reaches it is whatever your integration chooses to send, so that payload is a classification decision you make once and review the way you review the rest.

9. Conclusion#

CPS 234 is a cornerstone of APRA’s efforts to enhance cybersecurity in the financial sector. By enforcing robust security practices, fostering a culture of vigilance, and ensuring compliance across the value chain, CPS 234 helps safeguard critical information assets and maintain trust in the financial services industry.

Corbado

About Corbado

Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert

Frequently Asked Questions#

What are the exact APRA notification deadlines for security incidents under CPS 234?#

CPS 234 sets two distinct reporting deadlines. Material security incidents must be reported to APRA within 72 hours, including details on the incident's nature, status and mitigation actions. Material control weaknesses carry a longer window of 10 business days, accompanied by planned remediation efforts.

Which types of organizations are legally required to comply with APRA CPS 234?#

CPS 234 applies to all APRA-regulated entities, including authorized deposit-taking institutions such as banks and credit unions, general insurers, life insurance companies, private health insurers and superannuation funds. Compliance obligations also extend to third-party vendors that manage information assets on behalf of these regulated entities.

How does CPS 234 handle security requirements for third-party vendors?#

CPS 234 requires regulated entities to conduct due diligence on third-party vendors and establish contractual obligations covering monitoring, audits and incident management. Vendors managing information assets must comply with CPS 234 mandates directly, and entities must perform periodic performance reviews and risk assessments to validate ongoing compliance.

What specific governance responsibilities does the Board of Directors carry under CPS 234?#

The Board of Directors holds ultimate responsibility for CPS 234 compliance and must ensure information security capabilities match the scale of organizational risk. While operational duties can be delegated, the Board must define clear expectations for risk escalation, reporting lines and engagement from senior management and governing bodies.

See what's really happening in your passkey rollout.

Book a Demo

Share this article


LinkedInTwitterFacebook