CPS 230 Is in Force. Essential Eight Is the Control Backbone APRA Expects Underneath It.

CPS 230 Is in Force. Essential Eight Is the Control Backbone APRA Expects Underneath It.

8/1/2026 · Compliance365

CPS 230 (Operational Risk Management) came into force on 1 July 2025, sitting alongside the existing CPS 234 (Information Security) standard. For APRA-regulated entities — and increasingly, for the third parties and material service providers that support them — the two standards are converging around the same practical question: can you evidence that your operational and information-security controls are actually working, not just documented?

Essential Eight has become the de facto technical control backbone many APRA-regulated entities and their suppliers use to answer that question for the ICT and cyber-resilience components of both standards.


Why CPS 230 and CPS 234 are converging in practice

CPS 234 has always focused specifically on information security — identifying and managing information security risks, testing controls, and having a plan for a material incident. CPS 230 broadens the lens to operational resilience generally: can the business continue delivering critical operations through a disruption, whatever the cause, including one triggered by a cyber incident.

In practice, an APRA-regulated entity (or a material service provider supporting one) increasingly needs to show both:

  • CPS 234-style evidence — information security controls implemented, tested, and monitored.
  • CPS 230-style evidence — that a failure of those controls has a defined operational impact tolerance, a tested response, and clear accountability at the board level.

Essential Eight, mapped and evidenced properly, does a large share of the CPS 234 heavy lifting. The gap most organisations have isn’t the technical controls — it’s connecting that technical evidence to CPS 230’s operational resilience and impact-tolerance requirements.


Who this applies to

This isn’t limited to APRA-regulated entities directly. It increasingly reaches:

  • APRA-regulated entities themselves — banks, insurers, superannuation trustees directly subject to both standards.
  • Material service providers — any third party an APRA-regulated entity depends on for a critical operation, who now face contractual flow-down of CPS 230 expectations, in much the same way NIS2 pushes obligations down EU supply chains.
  • Fintech and SaaS vendors selling into the regulated financial sector, who are seeing CPS 230/234-aligned questions appear in vendor due diligence that didn’t exist a year or two ago.

What an Essential Eight + CPS 230/234 alignment engagement actually covers

Rather than treating Essential Eight uplift and CPS 230/234 readiness as two separate projects, we run them as one aligned engagement:

  1. Essential Eight assessment and ML2 uplift — the technical control baseline, evidenced against ASD’s published criteria.
  2. Mapping that evidence explicitly to CPS 234 — showing an APRA reviewer or auditor exactly how each control satisfies the relevant CPS 234 expectation, rather than leaving them to infer it.
  3. Operational impact-tolerance documentation for CPS 230 — defining what “critical operation” means for your business, what tolerance you’ve set for disruption, and how the Essential Eight control set supports staying inside it.
  4. Board-level reporting artefacts — CPS 230 explicitly expects board and senior-management oversight of operational risk; we build the reporting pack that makes that oversight demonstrable, not just claimed.

APRA-regulated, or a material service provider to one? If your Essential Eight programme and your CPS 230/234 evidence currently live in separate silos, aligning them is usually faster than it sounds — most of the technical work overlaps.

See our Essential Eight services, or book a call to talk through your specific APRA obligations.

Share this article: Share on LinkedIn

Found this useful? Get the ISO/Privacy/AI readiness checklists.

Browse resources

Ready to take the next step?

Essential Eight

ASD Essential Eight maturity uplift to ML1, ML2, or ML3 using your existing Microsoft environment.

Learn more Book a free call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.

Keep reading

Microsoft Teams