NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
CPS 234 compliance software

The information security standard APRA will test.

Venvera is CPS 234 compliance software that runs the standard the way it is actually assessed: all 24 requirements from paragraphs 13 to 36 with the evidence a reviewer accepts, third party coverage that reaches past the outsourcing register, and both notification clocks where someone can find them at 2am.

24 requirementsParagraphs 13 to 369 sections72 hour notificationThird party coverage

How much of CPS 234 do you already have?

Pick the framework you already run. Every control domain that appears in both is listed with the requirement reference on each side, so you can see the reusable part of your existing programme before you scope any new work.

You already run
You have been asked to add
7 of the 53 domains in this crosswalk appear in both NIST CSF 2.0 and CPS 234.
DomainNIST CSF 2.0CPS 234
Incident Management
RS.MA-01Incident Management Execution
RS.AN-03Forensic Analysis
CPS234-23Detection and response mechanisms
CPS234-24Information security response plans
CPS234-25Response plan content and escalation
Incident Reporting
RS.CO-02Internal Stakeholder Reporting
CPS234-35Notification of material incidents within 72 hours
CPS234-36Notification of material control weakness within 10 business days
Post-Incident Review
RS.AN-08Incident magnitude is estimated and validated
CPS234-26Annual review and testing of response plans
Third-Party Risk Management
GV.SC-03Supply chain risk management is integrated into risk management
CPS234-16Assessment of related party and third party capability
Supplier Due Diligence
GV.SC-06Planning and due diligence are performed for supplier relationships
CPS234-22Evaluation of third party control design
Information Security Policy
GV.PO-01Cybersecurity Policy
CPS234-18Information security policy framework
CPS234-19Policy direction for all obligated parties
Data Classification
PR.DS-10Data-in-Use Protection
CPS234-20Classification of information assets by criticality and sensitivity

A row means the two requirements cover the same ground, so one implementation and one set of evidence can usually serve both. It does not mean satisfying one certifies the other: each framework keeps its own scope, wording and assessment, and some requirements have no counterpart at all. Treat this as a starting map for planning, then confirm each row against the requirement text.

CPS 234 compliance software built around the 24 requirements

Venvera ships APRA Prudential Standard CPS 234 as its 24 operative requirements, paragraphs 13 to 36, grouped under the standard’s own nine headings: roles and responsibilities, information security capability, policy framework, information asset identification and classification, implementation of controls, incident management, testing control effectiveness, internal audit and APRA notification. Each requirement carries an owner, a status, its own evidence and authored guidance on what satisfies it and what a reviewer rejects. A 42 question gap assessment scores the judgements the standard deliberately leaves open, and the recurring duties land on a compliance calendar with owners and dates.

What is CPS 234, and who has to comply?

CPS 234 Information Security is the APRA prudential standard requiring an APRA-regulated entity to be resilient against information security incidents, including cyber attacks. It applies to ADIs including foreign ADIs, general insurers, life companies and friendly societies, private health insurers and RSE licensees. It commenced on 1 July 2019, and where a third party manages your information assets it applied from the earlier of the next contract renewal or 1 July 2020. The Board is ultimately responsible for the information security of the entity, which is stated in paragraph 13 and is the sentence that shapes everything else: the evidence has to be good enough to put in front of directors who carry the accountability personally.

 app.venvera.com
/ CPS 234 · requirements, evidence and notification in one view
/ CPS 234 · requirements, evidence and notification in one view
24
Requirements, each with guidance
9
Sections, paragraphs 13 through 36
42
Gap questions on the judgement calls
72h
Notification clock, tracked from awareness
Requirements

All 24 requirements, cited the way APRA cites them.

Every operative paragraph of CPS 234, from the Board’s ultimate responsibility in paragraph 13 to the 10 business day control weakness notification in paragraph 36, referenced by paragraph number because that is how APRA, your internal audit function and a tripartite reviewer all cite it. Each one carries authored guidance on the artefacts a reviewer asks for and, just as importantly, what gets rejected: an undated plan, a questionnaire standing in for an evaluation of control design, a capability assessment that has not moved in two years.

  • All 24 requirements under the standard’s own nine headings
  • Cited by paragraph number, not an invented control id
  • Authored evidence guidance on each, including what fails
  • An owner, a status and its own evidence on every requirement
  • Sub-paragraph factors kept inside the requirement they belong to
 app.venvera.com
/ REQUIREMENTS · an owner, a status and the evidence on each one
/ REQUIREMENTS · an owner, a status and the evidence on each one
Commensurate

The word the standard never defines, evidenced.

Commensurate appears again and again in CPS 234 and is deliberately left undefined, because APRA regulates everything from a small RSE licensee to a major bank. That shifts the burden onto you: it is not enough for controls to be adequate, you have to show the reasoning by which you decided they were the right size for the threats to your information assets. The 42 question gap assessment targets exactly these judgements, scoring them 0 to 4 so the sizing rationale becomes a record rather than an argument you have to reconstruct in a review.

  • A 42 question assessment across the nine sections
  • Focused on the judgements the standard leaves to the entity
  • Scored 0 to 4, so movement is visible between reviews
  • Unanswered questions count as gaps, not as excluded
  • Findings link to the requirements that close them
 app.venvera.com
/ GAP ASSESSMENT · the judgement calls, scored
/ GAP ASSESSMENT · the judgement calls, scored
Third party

Coverage that reaches past the outsourcing register.

Paragraphs 16, 22, 28 and 34 each carry a footnote saying they apply to all information assets managed by related parties and third parties, not only those under material outsourcing agreements per CPS 231 or SPS 231. Scoping that work to the outsourcing register is the most common real gap in the standard, and it is usually invisible until someone counts the parties that actually hold data against the parties that were assessed. Venvera tracks the four third party duties separately: capability assessment, evaluation of control design, assessment of the testing you rely on, and internal audit’s assessment of assurance.

  • The four third party paragraphs tracked as distinct duties
  • Capability assessment under paragraph 16
  • Evaluation of control design under paragraph 22
  • Assessment of relied-upon testing under paragraph 28
  • Internal audit assessment of assurance under paragraph 34
 app.venvera.com
/ THIRD PARTY · every party that holds an asset, not just the register
/ THIRD PARTY · every party that holds an asset, not just the register
Testing

Systematic testing, by someone who does not own the control.

Paragraph 27 asks for a systematic testing programme whose nature and frequency are set against five factors, including the risk from environments where you cannot enforce your own policies. Paragraph 30 asks that testing be done by specialists who are appropriately skilled and functionally independent, which is about reporting lines rather than about hiring an external firm. Paragraph 29 asks you to escalate deficiencies you cannot remediate in time, and that escalation record is usually the first thing a reviewer asks for. All three are tracked as separate requirements because entities commonly satisfy one and assume it covers the others.

  • The five paragraph 27 factors kept visible on the requirement
  • Untrusted environments treated as a factor, not an exception
  • Functional independence recorded against the tester
  • Escalation of unremediated deficiencies evidenced
  • Annual review of the programme itself, separate from its results
 app.venvera.com
/ TESTING · systematic, independent and escalated
/ TESTING · systematic, independent and escalated
Notification

Two clocks, both starting at awareness.

Paragraph 35 gives you 72 hours from becoming aware of a material information security incident, and it has a second limb most procedures miss: an incident notified to any other regulator, in Australia or overseas, triggers APRA notification whether or not you assess it as material to yourself. Paragraph 36 is a separate 10 business day clock for a material control weakness you expect you cannot remediate in a timely manner, and it starts when you become aware of the weakness, not when you conclude it is unfixable. Both are carried as requirements with their own evidence, so the procedure and its rehearsal are recorded rather than assumed.

  • 72 hour incident clock, running from awareness
  • The other-regulator limb of paragraph 35 tracked explicitly
  • 10 business day clock for material control weakness
  • Rehearsal evidenced through the annual response plan test
  • Escalation path to the Board recorded with the requirement
 app.venvera.com
/ NOTIFICATION · both clocks, and who starts them
/ NOTIFICATION · both clocks, and who starts them
Calendar

The duties that repeat, each with a date and an owner.

CPS 234 creates recurring work, and the year between reviews has to produce a record. Venvera carries those duties on the compliance calendar: the annual review and test of the information security response plans required by paragraph 26, the annual review of the testing programme’s sufficiency under paragraph 31, the internal audit review of control design and operating effectiveness under paragraphs 32 to 34, the refresh of the asset classification that paragraphs 20 and 21 depend on, and the reassessment of the third parties covered by paragraphs 16, 22 and 28. Each carries the paragraph it serves, so a calendar entry traces back to the standard.

  • Annual response plan review and test, paragraph 26
  • Annual testing programme sufficiency review, paragraph 31
  • Internal audit information security review, paragraphs 32 to 34
  • Asset classification refresh, paragraphs 20 and 21
  • Third party reassessment, paragraphs 16, 22 and 28
 app.venvera.com
/ CALENDAR · the recurring duties, owned and dated
/ CALENDAR · the recurring duties, owned and dated
Why switch

The spreadsheet or Venvera.

Manual approach
Venvera
The 24 requirements
A spreadsheet keyed to a consultant’s control numbering
Paragraphs 13 to 36 with authored evidence guidance on each
Commensurate
Asserted in a policy, argued for during the review
A 42 question assessment scoring the sizing judgement
Third party scope
The material outsourcing register, and hope
Four third party duties tracked across every party that holds an asset
Testing independence
The team that runs the control also tests it
Independence recorded against the tester on the requirement
Notification
A procedure nobody has run
Both clocks tracked, rehearsal evidenced in the annual test
Recurring duties
Calendar invites and whoever remembers
Scheduled obligations citing the paragraph they serve

CPS 234, answered.

Information security and regulator guides

See where your CPS 234 evidence actually stands.

Start with a free gap report on the framework that is blocking you - 10 minutes, no email to start.

Every paid plan: audit-ready in 90 days, or your money back*

10 minutes · no email to start · no credit card · yours to keep