CPS 230 Is in Force. Essential Eight Is the Control Backbone APRA Expects Underneath It.
8/1/2026 · Compliance365
CPS 230 (Operational Risk Management) came into force on 1 July 2025, sitting alongside the existing CPS 234 (Information Security) standard. For APRA-regulated entities — and increasingly, for the third parties and material service providers that support them — the two standards are converging around the same practical question: can you evidence that your operational and information-security controls are actually working, not just documented?
Essential Eight has become the de facto technical control backbone many APRA-regulated entities and their suppliers use to answer that question for the ICT and cyber-resilience components of both standards.
Why CPS 230 and CPS 234 are converging in practice
CPS 234 has always focused specifically on information security — identifying and managing information security risks, testing controls, and having a plan for a material incident. CPS 230 broadens the lens to operational resilience generally: can the business continue delivering critical operations through a disruption, whatever the cause, including one triggered by a cyber incident.
In practice, an APRA-regulated entity (or a material service provider supporting one) increasingly needs to show both:
- CPS 234-style evidence — information security controls implemented, tested, and monitored.
- CPS 230-style evidence — that a failure of those controls has a defined operational impact tolerance, a tested response, and clear accountability at the board level.
Essential Eight, mapped and evidenced properly, does a large share of the CPS 234 heavy lifting. The gap most organisations have isn’t the technical controls — it’s connecting that technical evidence to CPS 230’s operational resilience and impact-tolerance requirements.
Who this applies to
This isn’t limited to APRA-regulated entities directly. It increasingly reaches:
- APRA-regulated entities themselves — banks, insurers, superannuation trustees directly subject to both standards.
- Material service providers — any third party an APRA-regulated entity depends on for a critical operation, who now face contractual flow-down of CPS 230 expectations, in much the same way NIS2 pushes obligations down EU supply chains.
- Fintech and SaaS vendors selling into the regulated financial sector, who are seeing CPS 230/234-aligned questions appear in vendor due diligence that didn’t exist a year or two ago.
What an Essential Eight + CPS 230/234 alignment engagement actually covers
Rather than treating Essential Eight uplift and CPS 230/234 readiness as two separate projects, we run them as one aligned engagement:
- Essential Eight assessment and ML2 uplift — the technical control baseline, evidenced against ASD’s published criteria.
- Mapping that evidence explicitly to CPS 234 — showing an APRA reviewer or auditor exactly how each control satisfies the relevant CPS 234 expectation, rather than leaving them to infer it.
- Operational impact-tolerance documentation for CPS 230 — defining what “critical operation” means for your business, what tolerance you’ve set for disruption, and how the Essential Eight control set supports staying inside it.
- Board-level reporting artefacts — CPS 230 explicitly expects board and senior-management oversight of operational risk; we build the reporting pack that makes that oversight demonstrable, not just claimed.
APRA-regulated, or a material service provider to one? If your Essential Eight programme and your CPS 230/234 evidence currently live in separate silos, aligning them is usually faster than it sounds — most of the technical work overlaps.
See our Essential Eight services, or book a call to talk through your specific APRA obligations.
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources